Elastic high stable kql
Threat Intel URL Indicator Match
This rule is triggered when a URL indicator from the Threat Intel Filebeat module or integrations has a match against an event that contains URL data, like DNS events, network logs, etc.
Detection Logic
url.full:* Field Validations
Loading…
Comments (0)
Loading comments...