How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
ID: 911933f6-e799-59ab-be2d-8c264f85ee90
STIX ID: report--911933f6-e799-59ab-be2d-8c264f85ee90
Feed Name: Elastic Security Labs
This article documents a detection-engineering approach using Elastic ES|QL's COMPLETION feature (LLM inference) to triage noisy `curl` and `wget` process detections: parse and anchor destination hosts, apply deterministic allow-lists, redact secrets, aggregate by host/destination, cap rows, and ask an LLM for a structured verdict to reduce false positives and keep alerts meaningful; includes implementation examples, prompt guidance, and a seven-day QA test.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
