Elastic medium stable kql

Thrift RPC Method from an External Client

Identifies the first decoded Apache Thrift RPC relationship from a public client address to a server. Thrift commonly connects trusted internal microservices and data platforms, and an externally originated method invocation can indicate an exposed service, unauthorized access, or exploitation of a public-facing Thrift endpoint.

View Source

Detection Logic

data_stream.dataset:network_traffic.thrift and
client.ip:(
  * and
  not (
    10.0.0.0/8 or
    100.64.0.0/10 or
    127.0.0.0/8 or
    169.254.0.0/16 or
    172.16.0.0/12 or
    192.0.0.0/24 or
    192.0.2.0/24 or
    192.31.196.0/24 or
    192.52.193.0/24 or
    192.88.99.0/24 or
    192.168.0.0/16 or
    192.175.48.0/24 or
    198.18.0.0/15 or
    198.51.100.0/24 or
    203.0.113.0/24 or
    224.0.0.0/4 or
    240.0.0.0/4 or
    "::1" or
    "fc00::/7" or
    "fe80::/10" or
    "ff00::/8"
  )
) and
server.ip:* and
network_traffic.thrift.method:*

False Positives

  • Publicly accessible Thrift APIs, partner integrations, remote offices, and routed environments that preserve public client addresses can generate legitimate alerts. Validate the client, service, method, server role, and expected network path before escalating.

Field Validations

Loading…

Comments (0)

Loading comments...