Skip to content

Commit 8c71bc7

Browse files
committed
Update rare scripts docs
1 parent 4e0ad68 commit 8c71bc7

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

docs/en/stack/ml/anomaly-detection/ootb-ml-jobs-siem.asciidoc

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -415,6 +415,11 @@ they are listed for each job.
415415
|https://github.com/elastic/kibana/blob/{branch}/x-pack/plugins/ml/server/models/data_recognizer/modules/security_windows/ml/v3_windows_rare_user_type10_remote_login.json[image:images/link.svg[A link icon]]
416416
|https://github.com/elastic/kibana/blob/{branch}/x-pack/plugins/ml/server/models/data_recognizer/modules/security_windows/ml/datafeed_v3_windows_rare_user_type10_remote_login.json[image:images/link.svg[A link icon]]
417417

418+
|v3_windows_rare_script
419+
|Looks for rare powershell scripts that may indicate execution of malware, or persistence mechanisms via hash.
420+
|https://github.com/elastic/kibana/blob/{branch}/x-pack/plugins/ml/server/models/data_recognizer/modules/security_windows/ml/v3_windows_rare_script.json[image:images/link.svg[A link icon]]
421+
|https://github.com/elastic/kibana/blob/{branch}/x-pack/plugins/ml/server/models/data_recognizer/modules/security_windows/ml/datafeed_v3_windows_rare_script.json[image:images/link.svg[A link icon]]
422+
418423
|===
419424
// end::security-windows-jobs[]
420425

0 commit comments

Comments
 (0)