Suricata and Elastic Defend Network Correlation
Description
This detection correlates Suricata alerts with Elastic Defend network events to identify the source process performing the network activity.
Query · eql
sequence by source.port, source.ip, destination.ip with maxspan=5s
[network where data_stream.dataset == "suricata.eve" and event.kind == "alert" and
event.severity != 3 and source.ip != null and destination.ip != null and
not source.domain : ("*nessusscan*", "SCCMPS*") and
not rule.name in ("ET INFO SMB2 NT Create AndX Request For a Powershell .ps1 File", "ET SCAN MS Terminal Server Traffic on Non-standard Port")]
[network where event.module == "endpoint" and event.action in ("disconnect_received", "connection_attempted") and
not process.executable in ("System", "C:\\Program Files (x86)\\Admin Arsenal\\PDQ Inventory\\PDQInventoryService.exe") and
not process.executable : "C:\\Windows\\AdminArsenal\\PDQInventory-Scanner\\service-*\\exec\\PDQInventoryScanner.exe"]
Analyst notes
Investigating Suricata and Elastic Defend Network Correlation
Possible investigation steps
- Investigate in the Timeline feature the two events matching this correlation (Suricata and Elastic Defend).
- Review the process details like command_line, privileges, global relevance and reputation.
- Assess the destination.ip reputation and global relevance.
- Review the parent process execution details like command_line, global relevance and reputation.
- Examine all network connection details performed by the process during last 48h.
- Correlate the alert with other security events or logs to identify any patterns or additional indicators of compromise related to the same process or network activity.
False positive analysis
- Trusted system or third party processes performing network activity that looks like beaconing.
Response and remediation
- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration.
- Terminate the suspicious processes and all associated children and parents.
- Implement network-level controls to block traffic to the destination.ip.
- Conduct a thorough review of the system's configuration files to identify unauthorized changes.
- Reset credentials for any accounts associated with the source machine.
- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to determine if additional systems are affected.