Detecting Living-off-the-land attacks with new Elastic Integration
ID: 7ece29bd-b408-5954-8db9-58c817e28b77
STIX ID: report--7ece29bd-b408-5954-8db9-58c817e28b77
Feed Name: Elastic Security Labs
This post introduces Elastic’s ProblemChild package for detecting Living-off-the-Land (LotL) activity on Windows using an integrated pipeline of ML inference on process lineage, anomaly detection for rare parent-child processes, and prebuilt detection rules. It provides step-by-step setup in Kibana (install assets, enrich data via ingest pipelines, run preconfigured anomaly detection jobs, and enable rules), highlights how anomaly detection reduces false positives, and offers options to trial and get support via Elastic Cloud and community resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
