heroui logo

Suspicious Linux Process Connection to Bulletproof Hosting ASN

Elastic Detection Rules

View Source
Summary
This Elastic EQL rule detects suspicious outbound connections from Linux processes to bulletproof hosting ASNs. It triggers when a Linux host starts a network connection and the originating process appears from unusual locations (e.g., /tmp, /dev/shm, web directories, memfd) or when the process is a downloader, shell, or interpreter commonly used to fetch and execute payloads (e.g., curl, wget, python, bash). The rule explicitly flags connections whose destination ASN corresponds to operators known for abuse (e.g., Storm Industries, Ecatel/IP Volume, Aeza, Proton66, etc.), helping identify beacons to infrastructure that may ignore abuse reports. ASN enrichment is applied at ingest to augment destination ASN data, since endpoint agents may not populate these fields natively. The query correlates process context with network destination ASN to surface potential command-and-control traffic, leveraging MITRE ATT&CK mappings (T1071 - Application Layer Protocol; T1059 - Command and Scripting Interpreter with Unix Shell). A detailed triage guide covers investigation steps, false positives, and remediation actions, including isolating the host, collecting forensic evidence, removing attacker footholds, and rebuilding from trusted images. This rule is designed for Elastic Defend on Linux endpoints and integrates with Fleet-based Elastic Agent deployments. Severity is high, reflecting the potential impact of beaconing to bulletproof hosting infrastructure and possible follow-on activity across hosts. It also provides a practitioner-oriented response workflow, suggesting enrichment, correlation, containment, and remediation steps to support incident response efforts.
Categories
  • Endpoint
  • Network
Data Sources
  • Process
  • Network Traffic
ATT&CK Techniques
  • T1071
  • T1059
  • T1059.004
Created: 2026-09-17