heroui logo

First Seen External MQTT Broker Connection

Elastic Detection Rules

View Source
Summary
Detects the first MQTT protocol relationship from an internal source to an external MQTT broker that has not been observed in the prior 14 days, leveraging a 14-day history window (new_terms). The rule aggregates data from Suricata, Zeek, and PAN-OS logs to surface plaintext MQTT traffic (or decrypted MQTT) that represents a client-to-broker exchange, and flags potential command-and-control activity via a publish/subscribe pattern. In MITRE ATT&CK terms, it aligns with T1071.005 (Publish/Subscribe Protocols) under TA0011 (Command and Control). The alert signals a potential anomaly, not definitive malware, and requires follow-up to assess legitimacy, especially given the possibility of legitimate onboarding, broker migrations, or temporary test environments. False positives may arise from new or infrequently used IoT devices, telemetry agents, or vendor-managed services. Recommended actions include isolating the source if suspicious, blocking unauthorized broker access, preserving MQTT transactions and endpoint evidence, rotating credentials, and compiling an inventory of approved MQTT clients, brokers, and topics to constrain outbound MQTT where feasible.
Categories
  • Network
Data Sources
  • Network Traffic
  • Firewall
ATT&CK Techniques
  • T1071
  • T1071.005
Created: 2026-09-16