Statistical Model Detected C2 Beaconing Activity

edit

Statistical Model Detected C2 Beaconing Activity

edit

A statistical model has identified command-and-control (C2) beaconing activity. Beaconing can help attackers maintain stealthy communication with their C2 servers, receive instructions and payloads, exfiltrate data and maintain persistence in a network.

Rule type: query

Rule indices:

  • ml_beaconing.all

Severity: low

Risk score: 21

Runs every: 5m

Searches indices from: now-1h (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Domain: Network
  • Use Case: C2 Beaconing Detection
  • Tactic: Command and Control

Version: 2

Rule authors:

  • Elastic

Rule license: Elastic License v2

Rule query

edit
beacon_stats.is_beaconing: true

Framework: MITRE ATT&CKTM