elastic-protections
high
eql
Environment Variable Secret Collection
Identifies the execution of the env or printenv commands followed by a grep command to collect environment variable secrets. This is a common technique used by attackers to collect sensitive information from the environment.