Credential Access (TA0006)(external, opens in a new tab or window)
text code block:event.category: network and host.os.type: (linux or windows) and destination.ip: "168.63.129.16" and destination.port: (80 or 32526) and ( process.name: ( bash or dash or sh or tcsh or csh or zsh or ksh or fish or mksh or busybox or bun or bun.exe or node or node.exe or nodejs or deno or deno.exe or java or java.exe or javaw or javaw.exe or curl or curl.exe or wget or wget.exe or powershell.exe or pwsh.exe or pwsh or cmd.exe or certutil.exe or bitsadmin.exe or mshta.exe or rundll32.exe or wscript.exe or cscript.exe or regsvr32.exe or openssl or openssl.exe or nc or ncat or netcat or socat or python.exe or pythonw.exe or perl or perl.exe or ruby or ruby.exe or php or php.exe or lua or lua.exe ) or process.executable: ( ./* or /tmp/* or /var/tmp/* or /dev/shm/* or /run/* or /var/run/* or /home/*/* or /root/* or *\:\\Users\\* or *\:\\ProgramData\\* ) ) and not process.executable: ( /usr/sbin/waagent or /usr/bin/waagent or /usr/bin/python3* or /usr/lib/systemd/systemd-resolved or /lib/systemd/systemd-resolved or *\:\\WindowsAzure\\Packages\\* or *\:\\WindowsAzure\\GuestAgent*\\* or *\:\\WindowsAzure\\SecAgent\\* )
Install detection rules in Elastic Security
Detect Azure WireServer Unusual Process Connection in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).