THREAT OPS › Threat News › How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
<p>We ran a noisy <code>wget</code> detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) <code>COMPLETION</code> triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from <code>curl</code> and <code>wget</code> executions, filters known-good
MITRE ATT&CK techniques
- ServerlessT1583.007
- CredentialsT1589.001
- ServerlessT1584.007
- Ingress Tool TransferT1105
- ServerlessAML.T0008.004
- Container RegistryAML.T0010.004
Indicators of compromise
- 168.63.129.16ipv4
- 1.1.1.1ipv4
- 10.0.0.0/8cidr
- 127.0.0.0/8cidr
- acs-mirror.azureedge.netdomain
- login.microsoftonline.comdomain
- artifacts.elastic.codomain
- download.elastic.codomain
- apt.puppetlabs.comdomain
- standards.ieee.orgdomain
- motd.ubuntu.comdomain
- get.gravitational.comdomain
- archive.apache.orgdomain