elastic
medium
kql
LLM-Based Curl Activity Triage
Detects non-allowlisted curl activity on Linux, macOS, and Windows hosts and uses an LLM to assess whether the activity
is malicious, benign, or requires investigation. The rule parses and normalizes the destination, redacts sensitive
command-line values, and aggregates activity by host and destination before invoking the ES|QL COMPLETION command. Only
true positive or suspicious verdicts with confidence above 0.7 generate alerts.