Elastic medium stable eql
FortiGate SOCKS Traffic from an Unusual Process
This detection correlates FortiGate's application control SOCKS events with Elastic Defend network event to identify the source process performing SOCKS traffic. Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
Detection Logic
sequence by source.port, source.ip, destination.ip with maxspan=1m
[network where data_stream.dataset == "fortinet_fortigate.log" and event.action == "signature" and network.application in ("SOCKS4", "SOCKS5")]
[network where event.module == "endpoint" and event.action in ("disconnect_received", "connection_attempted")] Field Validations
Loading…
Comments (0)
Loading comments...