heroui logo

LLM-Based Wget Activity Triage via Auditd

Elastic Detection Rules

View Source
Summary
Detects non-allowlisted wget activity on Linux hosts using Linux process execution events from Auditd Manager or Auditbeat. The rule normalizes destinations, redacts sensitive command-line values, aggregates by host and destination, and invokes ES|QL COMPLETION to obtain an LLM verdict. Only high-confidence results (confidence > 0.7) that are TP or SUSPICIOUS generate alerts. Excludes common benign destinations via a deterministic allow-list, and provides triage guidance, false-positive considerations, and remediation steps. The triage outputs map to ECS fields (verdict, summary, outcome) and reference MITRE techniques such as Ingress Tool Transfer (T1105), Command and Control (TA0011), Exfiltration (T1048), and Data from Local System (T1005). Included are investigative steps, redaction safeguards, and context about host/process lineage to aid analyst review.
Categories
  • Endpoint
  • Linux
Data Sources
  • Process
ATT&CK Techniques
  • T1105
  • T1048
  • T1005
Created: 2026-07-17