Threat Intel IP Address Indicator Match

edit

This rule is triggered when an IP address indicator from the Threat Intel Filebeat module or integrations has a match against a network event.

Rule type: threat_match

Rule indices:

  • auditbeat-*
  • endgame-*
  • filebeat-*
  • logs-*
  • packetbeat-*
  • winlogbeat-*

Severity: critical

Risk score: 99

Runs every: 1h

Searches indices from: now-65m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • OS: Windows
  • Data Source: Elastic Endgame
  • Rule Type: Indicator Match

Version: 1

Rule authors:

  • Elastic

Rule license: Elastic License v2

Rule query

edit
source.ip:* or destination.ip:*