Elastic high stable kql

Threat Intel Hash Indicator Match

This rule is triggered when a hash indicator from the Threat Intel Filebeat module or integrations has a match against an event that contains file hashes, such as antivirus alerts, process creation, library load, and file operation events.

View Source

Detection Logic

file.hash.*:* or process.hash.*:* or dll.hash.*:*

Field Validations

Loading…

Comments (0)

Loading comments...