Elastic low stable eql
Unusual Linux Network Port Activity
Identifies unusual destination port activity that can indicate command-and-control, persistence mechanism, or data exfiltration activity. Rarely used destination port activity is generally unusual in Linux fleets, and can indicate unauthorized access or threat actor activity.
Detection Logic
False Positives
- ⚠ A newly installed program or one that rarely uses the network could trigger this alert.
Field Validations
Loading…
Comments (0)
Loading comments...