| elastic |
Unix Socket Connection |
production |
2026-09-18 |
| elastic |
BPF filter applied using TC |
production |
2026-09-18 |
| elastic |
System Binary Path File Permission Modification |
production |
2026-09-18 |
| elastic |
XDG-Open Command Execution |
production |
2026-09-18 |
| elastic |
Pod or Container Creation with Suspicious Command-Line |
production |
2026-09-18 |
| elastic |
Suspicious Named Pipe Creation |
production |
2026-09-18 |
| elastic |
Privilege Escalation via CAP_SETUID/SETGID Capabilities |
production |
2026-09-18 |
| elastic |
Suspicious Mining Process Creation Event |
production |
2026-09-18 |
| elastic |
Suspicious System Commands Executed by Previously Unknown Executable |
production |
2026-09-18 |
| elastic |
Suspicious Content Extracted or Decompressed via Funzip |
production |
2026-09-18 |
| elastic |
Potential Reverse Shell via UDP |
production |
2026-09-18 |
| elastic |
Potential Reverse Shell |
production |
2026-09-18 |
| elastic |
Potential Reverse Shell via Suspicious Binary |
production |
2026-09-18 |
| elastic |
Potential Meterpreter Reverse Shell |
production |
2026-09-18 |
| elastic |
Potential Reverse Shell via Suspicious Child Process |
production |
2026-09-18 |
| elastic |
Potential Reverse Shell via Child |
production |
2026-09-18 |
| elastic |
Potential Reverse Shell via Background Process |
production |
2026-09-18 |
| elastic |
Openssl Client or Server Activity |
production |
2026-09-18 |
| elastic |
Direct Process Execution via Background Utility |
production |
2026-09-18 |
| elastic |
Potential Code Execution via Postgresql |
production |
2026-09-18 |
| elastic |
Web Server Spawned via Python |
production |
2026-09-18 |
| elastic |
Interactive Terminal Spawned via Python |
production |
2026-09-18 |
| elastic |
Binary Executed from Shared Memory Directory |
production |
2026-09-18 |
| elastic |
Process Started from Process ID (PID) File |
production |
2026-09-18 |
| elastic |
Process Backgrounded by Unusual Parent |
production |
2026-09-18 |
| elastic |
Privileged Docker Container Creation |
production |
2026-09-18 |
| elastic |
Potential Linux Hack Tool Launched |
production |
2026-09-18 |
| elastic |
Interactive Terminal Spawned via Perl |
production |
2026-09-18 |
| elastic |
Payload Downloaded by Interpreter and Piped to Interpreter |
production |
2026-09-18 |
| elastic |
File Downloaded by Curl/Wget and Piped to Interpreter |
production |
2026-09-18 |
| elastic |
Network Connection via Recently Compiled Executable |
production |
2026-09-18 |
| elastic |
Network Connection from Binary with RWX Memory Region |
production |
2026-09-18 |
| elastic |
Netcat Listener Established via rlwrap |
production |
2026-09-18 |
| elastic |
Kubectl Apply Pod from URL |
production |
2026-09-18 |
| elastic |
Potential Upgrade of Non-interactive Shell |
production |
2026-09-18 |
| elastic |
File Transfer or Listener Established via Netcat |
production |
2026-09-18 |
| elastic |
Suspicious File Made Executable via Chmod Inside A Container |
production |
2026-09-18 |
| elastic |
File Creation, Execution and Self-Deletion in Suspicious Directory |
production |
2026-09-18 |
| elastic |
Process Started with Executable Stack |
production |
2026-09-18 |
| elastic |
Egress Connection from Entrypoint in Container |
production |
2026-09-18 |