Detect domain generation algorithm (DGA) activity with new Kibana integration
ID: ec55903e-3b04-56b6-aefd-edb03152c6b7
STIX ID: report--ec55903e-3b04-56b6-aefd-edb03152c6b7
Feed Name: Elastic Security Labs
This post introduces Elastic’s DGA detection package in the Kibana Integrations app and provides step-by-step guidance to deploy the trained model, configure ingest pipelines to enrich DNS events with `ml_is_dga.malicious_prediction` and `ml_is_dga.malicious_probability`, run a preconfigured anomaly detection job to flag unusual DGA-scoring activity, and enable complementary detection rules for alerting. It includes pointers for testing via the simulate pipeline API and managing components in Stack Management, positioning the package as a quick way to operationalize DGA detection within Elastic Security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
