Threat report

www.elastic.co/security-labs/beyond-behaviors-ai-augmented-detection-engineering-with-esql-completion

https://www.elastic.co/security-labs/beyond-behaviors-ai-augmented-detection-engineering-with-esql-completion
Published on
www.elastic.co

ATT&CK techniques those detections carry

  • T1005Data from Local System
  • T1048Exfiltration Over Alternative Protocol
  • T1105Ingress Tool Transfer
  • T1036Masquerading
  • T1204User Execution
  • T1204.002Malicious File
  • T1219Remote Access Tools
  • T1219.002Remote Desktop Software
Open the original

5 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Lure-Themed Internet-Delivered RMM ExecutableMedium
LLM-Based Wget Activity TriageMedium
LLM-Based Wget Activity Triage via AuditdMedium
LLM-Based Curl Activity TriageMedium
LLM-Based Curl Activity Triage via AuditdMedium

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice