Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
b499e0c
Packaging network beaconing
sodhikirti07 Jul 28, 2023
b573178
README for beaconing
sodhikirti07 Aug 15, 2023
65ea1f7
Added dashboards for beaconing
sodhikirti07 Aug 15, 2023
625b309
Added search object for beaconing drilldown
sodhikirti07 Aug 16, 2023
6370376
Transform freq change
sodhikirti07 Aug 16, 2023
28ff3a4
Updated CODEOWNERS
sodhikirti07 Aug 16, 2023
4e8355f
Updated changelog
sodhikirti07 Aug 16, 2023
f5922dd
Update packages/beaconing/docs/README.md
sodhikirti07 Aug 16, 2023
e1b6564
Update packages/beaconing/docs/README.md
sodhikirti07 Aug 16, 2023
e553979
Removed ML licensing requirements
sodhikirti07 Aug 16, 2023
a48f7db
Update packages/beaconing/docs/README.md
sodhikirti07 Aug 22, 2023
5315778
Update packages/beaconing/docs/README.md
sodhikirti07 Aug 22, 2023
1c963cc
Update packages/beaconing/docs/README.md
sodhikirti07 Aug 22, 2023
023da85
Update packages/beaconing/docs/README.md
sodhikirti07 Aug 22, 2023
cce5734
Update packages/beaconing/kibana/dashboard/beaconing-7a2c6260-2d65-11…
sodhikirti07 Aug 22, 2023
0e649ac
Update README.md
sodhikirti07 Aug 22, 2023
48ffd72
Changed destination index name in transform.yml
sodhikirti07 Aug 22, 2023
74d0260
Update package name in manifest.yml
sodhikirti07 Aug 22, 2023
fe43bc1
Changed index name in dashboards and minor correction to README
sodhikirti07 Aug 22, 2023
867d9f3
Added version and aliases for dest index
sodhikirti07 Aug 23, 2023
ad2c3a4
Added alias info in README
sodhikirti07 Aug 23, 2023
350c18e
Updated format version
sodhikirti07 Aug 23, 2023
d82a811
Updated kibana version in manifest.yml
sodhikirti07 Oct 3, 2023
73c7722
Update manifest to work with serverless
sodhikirti07 Oct 3, 2023
8481c33
Changed format version and added filter to avoid validation errors
sodhikirti07 Oct 4, 2023
6b4343d
Update packages/beaconing/manifest.yml
sodhikirti07 Oct 4, 2023
20441ad
Update packages/beaconing/docs/README.md
sodhikirti07 Oct 4, 2023
5ce96cd
Update packages/beaconing/changelog.yml
sodhikirti07 Oct 4, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@
/packages/azure_metrics @elastic/obs-cloud-monitoring
/packages/barracuda @elastic/security-external-integrations
/packages/barracuda_cloudgen_firewall @elastic/security-external-integrations
/packages/beaconing @elastic/ml-ui @elastic/sec-applied-ml
/packages/beat @elastic/infra-monitoring-ui
/packages/bitdefender @elastic/security-external-integrations
/packages/bitwarden @elastic/security-external-integrations
Expand Down
5 changes: 5 additions & 0 deletions packages/beaconing/changelog.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
- version: "1.0.0"
changes:
- description: Initial release of package (with Serverless support)
type: enhancement
link: https://github.com/elastic/integrations/pull/7418
33 changes: 33 additions & 0 deletions packages/beaconing/docs/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# Network Beaconing Identification

The Network Beaconing Identification package consists of a framework to identify beaconing activity in your environment. The framework surfaces significant indicators of compromise (IoCs) for threat hunters and analysts to use as a starting point for an investigation in addition to helping them monitor network traffic for beaconing activities.
This package is licensed under Elastic License 2.0.

## Installation

You can install the Network Beaconing Identification package via **Management > Integrations > Network Beaconing Identification**.

To inspect the installed assets, you can navigate to **Stack Management > Data > Transforms**.

| Transform name | Purpose| Source index | Destination index | Alias |
|---------------------------|--------|----------------|-------------------------|------------|
| beaconing.pivot_transform | Flags beaconing activity in your environment| logs-* | ml_beaconing-[version] | ml_beaconing.all |

For additional information on the transform's inner workings and the signals it generates, refer to [this blog post](https://www.elastic.co/security-labs/identifying-beaconing-malware-using-elastic).

**Note**: When querying the destination index to enquire about beaconing activities, we advise using the alias for the destination index (`ml_beaconing.all`). In the event that the underlying package is upgraded, the alias will aid in maintaining the previous findings.
Comment thread
sodhikirti07 marked this conversation as resolved.

## Dashboards

The **Network Beaconing Identification** has three dashboards:
* **Network Beaconing**: The main dashboard to monitor beaconing activity
* **Beaconing Drilldown**: Drilldown into relevant event logs and some statistics related to the beaconing activity
* **Hosts Affected Over Time By Process Name**: Monitor the spread of beaconing processes across hosts in your environment

For the dashboards to work as expected, the following settings need to be configured in Kibana.
1. Ensure the pivot transform is installed and running.
2. Go to **Management > Stack Management > Kibana > Data Views**. Click on **Create data view** button and enable **Allow hidden and system indices** under the **Show Advanced settings**.
3. Create a data view with the following settings:
- Index pattern : `ml_beaconing.all`
- Name: `ml_beaconing`
- Custom data view ID: `ml_beaconing`
Comment thread
sodhikirti07 marked this conversation as resolved.
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
processors:
- fingerprint:
fields:
- '@timestamp'
- _id
method: SHA-256
target_field: _id
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
- name: host.name
type: keyword
- name: process.name
type: keyword
- name: beacon_stats.autocovariance
type: float
- name: beacon_stats.beaconing_score
type: long
- name: beacon_stats.counts_percentiles
type: float
- name: beacon_stats.destination_bytes_percentiles
type: float
- name: beacon_stats.destination_ips
type: keyword
- name: beacon_stats.interval
type: long
- name: beacon_stats.is_beaconing
type: boolean
- name: beacon_stats.low_count_variation
type: boolean
- name: beacon_stats.low_destination_bytes_variation
type: boolean
- name: beacon_stats.low_source_bytes_variation
type: boolean
- name: beacon_stats.max_autocovariance_period
type: long
- name: beacon_stats.mean_counts
type: float
- name: beacon_stats.mean_destination_bytes
type: float
- name: beacon_stats.mean_source_bytes
type: float
- name: beacon_stats.non_empty_buckets
type: long
- name: beacon_stats.periodic
type: boolean
- name: beacon_stats.source_bytes_percentiles
type: float
- name: beacon_stats.std_dev_destination_bytes
type: float
- name: beacon_stats.std_dev_source_bytes
type: float
- name: beacon_stats.variance_counts
type: float
- name: '@timestamp'
type: date
Loading