Suspicious Linux Process Connection to Bulletproof Hosting ASN
This rule detects outbound connection attempts from unusual Linux process locations or common living-off-the-land utilities to autonomous systems associated with bulletproof or high-abuse hosting. Adversaries often…
Description
This rule detects outbound connection attempts from unusual Linux process locations or common living-off-the-land utilities to autonomous systems associated with bulletproof or high-abuse hosting. Adversaries often stage payloads in world-writable or web directories and beacon to infrastructure that ignores abuse reports, including providers such as Storm Industries, Ecatel/IP Volume, Aeza, and Proton66.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- event_index
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| attack.mitre.org/techniques/T1071/ | 2from 2 sources |
| www.spamhaus.org/blocklists/do-not-route-or-peer/ | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- 01d8b52c-61b0-4a28-96cf-14d5b3c01e05
- Tagged by the source as
- Data Source: Elastic DefendDomain: EndpointDomain: NetworkOS: LinuxPlatform: LinuxResources: Investigation GuideRule Type: Event Correlation (EQL)Tactic: Command and ControlTactic: ExecutionUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 8, 2026
- Version
- 1