ML-Beaconing-20211216-1
Pre-release
Pre-release
·
2278 commits
to main
since this release
For details, reference: https://github.com/elastic/detection-rules/tree/main/docs/experimental-machine-learning
Tested and compatible with Elastic Stack version 7.16.
Changelog
This is the first release for our experimental Network Beaconing framework. It consists of the following:
- Scripts, ingest pipelines and transforms to monitor network event data and flag beaconing-like activity
dashboards.ndjsoncontains all the assets required for three dashboards- "Network Beaconing", which is the main dashboard to monitor beaconing activity, "Beaconing Drilldown" to drilldown into relevant event logs and some statistics related to the beaconing activity, and finally, "Hosts Affected Over Time By Process Name" to monitor the reach of beaconing processes across hosts in your environment, in the past two weeks.