Elastic low stable eql

Unusual Windows Network Activity

Identifies Windows processes that do not usually use the network but have unexpected network activity, which can indicate command-and-control, lateral movement, persistence, or data exfiltration activity. A process with unusual network activity can denote process exploitation or injection, where the process is used to run persistence mechanisms that allow a malicious actor remote access or control of the host, data exfiltration, and execution of unauthorized network applications.

View Source

Detection Logic

False Positives

  • A newly installed program or one that rarely uses the network could trigger this alert.

Field Validations

Loading…

Comments (0)

Loading comments...