Repository navigation
[Beaconing] Packaging Network Beaconing Detection #7418
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
28 commits
Select commit
Hold shift + click to select a range
b499e0c
Packaging network beaconing
sodhikirti07 b573178
README for beaconing
sodhikirti07 65ea1f7
Added dashboards for beaconing
sodhikirti07 625b309
Added search object for beaconing drilldown
sodhikirti07 6370376
Transform freq change
sodhikirti07 28ff3a4
Updated CODEOWNERS
sodhikirti07 4e8355f
Updated changelog
sodhikirti07 f5922dd
Update packages/beaconing/docs/README.md
sodhikirti07 e1b6564
Update packages/beaconing/docs/README.md
sodhikirti07 e553979
Removed ML licensing requirements
sodhikirti07 a48f7db
Update packages/beaconing/docs/README.md
sodhikirti07 5315778
Update packages/beaconing/docs/README.md
sodhikirti07 1c963cc
Update packages/beaconing/docs/README.md
sodhikirti07 023da85
Update packages/beaconing/docs/README.md
sodhikirti07 cce5734
Update packages/beaconing/kibana/dashboard/beaconing-7a2c6260-2d65-11…
sodhikirti07 0e649ac
Update README.md
sodhikirti07 48ffd72
Changed destination index name in transform.yml
sodhikirti07 74d0260
Update package name in manifest.yml
sodhikirti07 fe43bc1
Changed index name in dashboards and minor correction to README
sodhikirti07 867d9f3
Added version and aliases for dest index
sodhikirti07 ad2c3a4
Added alias info in README
sodhikirti07 350c18e
Updated format version
sodhikirti07 d82a811
Updated kibana version in manifest.yml
sodhikirti07 73c7722
Update manifest to work with serverless
sodhikirti07 8481c33
Changed format version and added filter to avoid validation errors
sodhikirti07 6b4343d
Update packages/beaconing/manifest.yml
sodhikirti07 20441ad
Update packages/beaconing/docs/README.md
sodhikirti07 5ce96cd
Update packages/beaconing/changelog.yml
sodhikirti07 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| - version: "1.0.0" | ||
| changes: | ||
| - description: Initial release of package (with Serverless support) | ||
| type: enhancement | ||
| link: https://github.com/elastic/integrations/pull/7418 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # Network Beaconing Identification | ||
|
|
||
| The Network Beaconing Identification package consists of a framework to identify beaconing activity in your environment. The framework surfaces significant indicators of compromise (IoCs) for threat hunters and analysts to use as a starting point for an investigation in addition to helping them monitor network traffic for beaconing activities. | ||
| This package is licensed under Elastic License 2.0. | ||
|
|
||
| ## Installation | ||
|
|
||
| You can install the Network Beaconing Identification package via **Management > Integrations > Network Beaconing Identification**. | ||
|
|
||
| To inspect the installed assets, you can navigate to **Stack Management > Data > Transforms**. | ||
|
|
||
| | Transform name | Purpose| Source index | Destination index | Alias | | ||
| |---------------------------|--------|----------------|-------------------------|------------| | ||
| | beaconing.pivot_transform | Flags beaconing activity in your environment| logs-* | ml_beaconing-[version] | ml_beaconing.all | | ||
|
|
||
| For additional information on the transform's inner workings and the signals it generates, refer to [this blog post](https://www.elastic.co/security-labs/identifying-beaconing-malware-using-elastic). | ||
|
|
||
| **Note**: When querying the destination index to enquire about beaconing activities, we advise using the alias for the destination index (`ml_beaconing.all`). In the event that the underlying package is upgraded, the alias will aid in maintaining the previous findings. | ||
|
|
||
| ## Dashboards | ||
|
|
||
| The **Network Beaconing Identification** has three dashboards: | ||
| * **Network Beaconing**: The main dashboard to monitor beaconing activity | ||
| * **Beaconing Drilldown**: Drilldown into relevant event logs and some statistics related to the beaconing activity | ||
| * **Hosts Affected Over Time By Process Name**: Monitor the spread of beaconing processes across hosts in your environment | ||
|
|
||
| For the dashboards to work as expected, the following settings need to be configured in Kibana. | ||
| 1. Ensure the pivot transform is installed and running. | ||
| 2. Go to **Management > Stack Management > Kibana > Data Views**. Click on **Create data view** button and enable **Allow hidden and system indices** under the **Show Advanced settings**. | ||
| 3. Create a data view with the following settings: | ||
| - Index pattern : `ml_beaconing.all` | ||
| - Name: `ml_beaconing` | ||
| - Custom data view ID: `ml_beaconing` | ||
|
sodhikirti07 marked this conversation as resolved.
|
||
8 changes: 8 additions & 0 deletions
8
packages/beaconing/elasticsearch/ingest_pipeline/ml_beaconing_ingest_pipeline.yml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| --- | ||
| processors: | ||
| - fingerprint: | ||
| fields: | ||
| - '@timestamp' | ||
| - _id | ||
| method: SHA-256 | ||
| target_field: _id |
46 changes: 46 additions & 0 deletions
46
packages/beaconing/elasticsearch/transform/pivot_transform/fields/fields.yml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,46 @@ | ||
| - name: host.name | ||
| type: keyword | ||
| - name: process.name | ||
| type: keyword | ||
| - name: beacon_stats.autocovariance | ||
| type: float | ||
| - name: beacon_stats.beaconing_score | ||
| type: long | ||
| - name: beacon_stats.counts_percentiles | ||
| type: float | ||
| - name: beacon_stats.destination_bytes_percentiles | ||
| type: float | ||
| - name: beacon_stats.destination_ips | ||
| type: keyword | ||
| - name: beacon_stats.interval | ||
| type: long | ||
| - name: beacon_stats.is_beaconing | ||
| type: boolean | ||
| - name: beacon_stats.low_count_variation | ||
| type: boolean | ||
| - name: beacon_stats.low_destination_bytes_variation | ||
| type: boolean | ||
| - name: beacon_stats.low_source_bytes_variation | ||
| type: boolean | ||
| - name: beacon_stats.max_autocovariance_period | ||
| type: long | ||
| - name: beacon_stats.mean_counts | ||
| type: float | ||
| - name: beacon_stats.mean_destination_bytes | ||
| type: float | ||
| - name: beacon_stats.mean_source_bytes | ||
| type: float | ||
| - name: beacon_stats.non_empty_buckets | ||
| type: long | ||
| - name: beacon_stats.periodic | ||
| type: boolean | ||
| - name: beacon_stats.source_bytes_percentiles | ||
| type: float | ||
| - name: beacon_stats.std_dev_destination_bytes | ||
| type: float | ||
| - name: beacon_stats.std_dev_source_bytes | ||
| type: float | ||
| - name: beacon_stats.variance_counts | ||
| type: float | ||
| - name: '@timestamp' | ||
| type: date |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.