TOR Exit Node Monitoring Overview
ID: b20f5c2c-2814-5174-9a61-0fb1139bcc70
STIX ID: report--b20f5c2c-2814-5174-9a61-0fb1139bcc70
Feed Name: Elastic Security Labs
This guide explains the importance of monitoring TOR exit node activity for detecting anonymized reconnaissance, C2 communications, and potential data exfiltration, and provides step-by-step instructions to implement collection in Elastic via ingest pipelines, index templates, and Elastic-Agent/Filebeat. It also outlines how to operationalize the data in SIEM for rules, dashboards, and geo-visualizations to track TOR-related interactions with internal assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
