Elastic high stable kql
Threat Intel Hash Indicator Match
This rule is triggered when a hash indicator from the Threat Intel Filebeat module or integrations has a match against an event that contains file hashes, such as antivirus alerts, process creation, library load, and file operation events.
Detection Logic
file.hash.*:* or process.hash.*:* or dll.hash.*:* Field Validations
Loading…
Comments (0)
Loading comments...