Elastic high stable kql

Threat Intel URL Indicator Match

This rule is triggered when a URL indicator from the Threat Intel Filebeat module or integrations has a match against an event that contains URL data, like DNS events, network logs, etc.

View Source

Detection Logic

url.full:*

Field Validations

Loading…

Comments (0)

Loading comments...