heroui logo

First Seen Network Flow Exporter Followed by Suspicious Source Activity

Elastic Detection Rules

View Source
Summary
Correlation rule that binds two alerts to provide stronger evidence of potentially unauthorized or compromised NetFlow exporters. It links a previously observed NetFlow/IPFIX/sFlow exporter (First Seen Network Flow Exporter) with a later detection alert that has medium-or-higher severity or an elevated risk score within a 30-minute window. The correlation requires the first alert's observer.ip (exporter address) to equal the second alert's source.ip and mandates both alerts share the same data_stream.namespace. The rule uses NetFlow/IPFIX/sFlow data ingested via Elastic NetFlow (netflow.log) or GoFlow2 (goflow2.sflow) and is designed to help distinguish routine exporter onboarding from defense-evasion activity. It explicitly notes that correlation alone does not prove telemetry injection or exporter compromise. The rule includes guidance for triage, false-positive considerations, and remediation steps to verify and respond to potential threats across the exporter and its activity in the same namespace.
Categories
  • Network
Data Sources
  • Network Traffic
ATT&CK Techniques
  • T1562
Created: 2026-08-24