elastic
medium
kql
Thrift RPC Method from an External Client
Identifies the first decoded Apache Thrift RPC relationship from a public client address to a server. Thrift commonly
connects trusted internal microservices and data platforms, and an externally originated method invocation can indicate
an exposed service, unauthorized access, or exploitation of a public-facing Thrift endpoint.