THREATOPS
THREAT OPSThreat News › How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

medelastic_securityPublished 2026-07-23

<p>We ran a noisy <code>wget</code> detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) <code>COMPLETION</code> triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from <code>curl</code> and <code>wget</code> executions, filters known-good

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/esql-completion-curl-wget-detection-triage