Corelight
Telemetry Evidence
These values show how indexed rules identify Corelight telemetry.Elastic
logs-corelight.* corelight Kusto
corelight_conn corelight_conn_red corelight_dns corelight_dns_red corelight_http corelight_smtp YARA-L
crowdstrike, gcp firewall, microsoft sysmon, gcp scc, microsoft defender atp, corelight zeek, microsoft windows events
Detection Rules
Elastic #
- Abnormally Large DNS Response source medium: Specially crafted DNS requests can manipulate a known overflow vulnerability in some Windows DNS servers, resulting in Remote Code Execution (RCE) or a Denial of Service (DoS) from crashing the service.
T1210,T1499,T1499.004 - RDP (Remote Desktop Protocol) from the Internet source medium: This rule detects network events that may indicate the use of RDP traffic from the Internet. RDP is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
T1021,T1021.001,T1133,T1190 - RPC (Remote Procedure Call) from the Internet source high: This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
T1133,T1190 - RPC (Remote Procedure Call) to the Internet source high: This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
T1021,T1021.003,T1190 - SMB (Windows File Sharing) Activity from the Internet source high: This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities.
T1133,T1190 - SMB (Windows File Sharing) Activity to the Internet source medium: This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration.
T1048,T1190 - SMTP to the Internet on Port 26/TCP source low: This rule detects events that may indicate use of SMTP on TCP port 26 from an internal host to an external destination. This port is commonly used by several popular mail transfer agents to deconflict with the default SMTP port 25. This port has also been used by a malware family called BadPatch for command and control of Windows systems. The rule is scoped to outbound traffic (internal source to external destination) to focus on the command and control and exfiltration use cases, rather than benign internal mail relays or unrelated transit traffic observed by the sensor.
T1048,T1071,T1071.003,T1571
Kusto #
- Corelight - C2 DGA Detected Via Repetitive Failures source medium: 'Detects large amounts of DNS resolution failures.'
T1568 - Corelight - External Proxy Detected source low: 'Detects external proxy usage.'
T1090 - Corelight - Forced External Outbound SMB source medium: 'Detects SMB requests that originate internally and communicate with an external IP address.'
T1187 - Corelight - Multiple Compressed Files Transferred over HTTP source medium: 'Detects compressed archives transferre over HTTP.'
T1567 - Corelight - Multiple files sent over HTTP with abnormal requests source medium: 'Detects sources sending multiple compressed files greater than 10MBs sent over HTTP in a short amount of time.'
T1030 - Corelight - Network Service Scanning Multiple IP Addresses source medium: 'Identify scanning of services that may be available on the internal network.'
T1566 - Corelight - Possible Typo Squatting or Punycode Phishing HTTP Request source medium: 'Detects when an HTTP request was made to a domain that was using unicode/punycode.'
T1566 - Corelight - Possible Webshell source medium: 'Detects post requests to unusual extensions.'
T1505 - Corelight - Possible Webshell (Rare PUT or POST) source medium: 'Detects rare post requests to a single webserver location.'
T1505 - Corelight - SMTP Email containing NON Ascii Characters within the Subject source low: 'Detects where an emails contain non ascii characters within the Subject.'
T1566
YARA-L #
- IP Target Prevalence source low: Detect events that are communicating to IP addresses that have a low rolling max prevalence.
Compatible Rules
These rules declare Corelight connector or schema compatibility without a product-specific query filter.Kusto #
T1030, T1046, T1071, T1095, T1210T1059, T1095, T1190, T1203T1059, T1095, T1190, T1203T1496T1048T1499T1008, T1568T1071T1071T1046, T1590T1046T1071, T1571T1008, T1568T1071T1071T1071T1071T1071T1071