elastic
high
kql
First-Time Destructive MongoDB Command from a Client IP
Identifies the first client IP observed issuing MongoDB commands that can drop databases, collections, indexes, users,
or roles within a five-day history window. Adversaries with access to an exposed or compromised MongoDB service may use
these commands to destroy data, disrupt applications, or prepare a wipe-and-extort attack.