logo

Identifying beaconing malware using Elastic

ID: 66bef196-eec2-53fc-b0e5-de54991d1d44

STIX ID: report--66bef196-eec2-53fc-b0e5-de54991d1d44

Feed Name: Elastic Security Labs

Date Published: 2023-03-01

Date Updated: 2026-04-27

...
...

This blog introduces an Elasticsearch-based framework to identify C2 beaconing as an early-warning signal in intrusions, using scalable aggregations and Painless scripts to compute indicators such as coefficient of variation for byte uniformity, relative variance for high-frequency regularity, and autocorrelation (with jitter handling) for periodicity. It outlines deployment via transforms, provides tunable parameters to balance precision/recall, and includes dashboards for analysts. The approach is validated against Emotet, Koadic, and NOBELIUM data, surfacing relevant beacons and example destination IPs, and demonstrates significant reduction of the threat hunting search space.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.