Elastic low stable eql
Unusual Windows Network Activity
Identifies Windows processes that do not usually use the network but have unexpected network activity, which can indicate command-and-control, lateral movement, persistence, or data exfiltration activity. A process with unusual network activity can denote process exploitation or injection, where the process is used to run persistence mechanisms that allow a malicious actor remote access or control of the host, data exfiltration, and execution of unauthorized network applications.
Detection Logic
False Positives
- ⚠ A newly installed program or one that rarely uses the network could trigger this alert.
Field Validations
Loading…
Comments (0)
Loading comments...