Elastic low stable eql

Unusual Linux Network Port Activity

Identifies unusual destination port activity that can indicate command-and-control, persistence mechanism, or data exfiltration activity. Rarely used destination port activity is generally unusual in Linux fleets, and can indicate unauthorized access or threat actor activity.

View Source

Detection Logic

False Positives

  • A newly installed program or one that rarely uses the network could trigger this alert.

Field Validations

Loading…

Comments (0)

Loading comments...