logo

Detect domain generation algorithm (DGA) activity with new Kibana integration

ID: ec55903e-3b04-56b6-aefd-edb03152c6b7

STIX ID: report--ec55903e-3b04-56b6-aefd-edb03152c6b7

Feed Name: Elastic Security Labs

Date Published: 2023-05-17

Date Updated: 2026-04-27

...
...

This post introduces Elastic’s DGA detection package in the Kibana Integrations app and provides step-by-step guidance to deploy the trained model, configure ingest pipelines to enrich DNS events with `ml_is_dga.malicious_prediction` and `ml_is_dga.malicious_probability`, run a preconfigured anomaly detection job to flag unusual DGA-scoring activity, and enable complementary detection rules for alerting. It includes pointers for testing via the simulate pipeline API and managing components in Stack Management, positioning the package as a quick way to operationalize DGA detection within Elastic Security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.