Skip to content

[Rule Tuning] Potential Data Exfiltration Through Curl - #6520

Open
Mikaayenson wants to merge 1 commit into
mainfrom
tuning/be70614d-4295-473c-a953-582aef41c865
Open

[Rule Tuning] Potential Data Exfiltration Through Curl#6520
Mikaayenson wants to merge 1 commit into
mainfrom
tuning/be70614d-4295-473c-a953-582aef41c865

Conversation

@Mikaayenson

Copy link
Copy Markdown
Contributor

Resolves elastic/ia-trade-team#1047

Fixes a broken oracle/retina monitoring exclusion that matched on parent executable path instead of parent command line, broadens the clevis disk-encryption parent filter to cover all clevis-* variants, and adds exclusions for Cloudamize agent registration, curl calls over local unix sockets, and Mozilla Firefox crash reporter telemetry uploads. Together these changes reduce false positive volume by approximately 90% while preserving detection of actual suspicious curl data uploads across 56 clusters.


Full telemetry triage, analytics links, and KQL verification: see linked ia-trade-team issue.

Copilot AI review requested due to automatic review settings July 29, 2026 09:18
@Mikaayenson Mikaayenson added Rule: Tuning tweaking or tuning an existing rule genai-tradecraft labels Jul 29, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

  • Detailed description of the suggested changes.
  • Provide example JSON data or screenshots.
  • Provide evidence of reducing benign events mistakenly identified as threats (False Positives).
  • Provide evidence of enhancing detection of true threats that were previously missed (False Negatives).
  • Provide evidence of optimizing resource consumption and execution time of detection rules (Performance).
  • Provide evidence of specific environment factors influencing customized rule tuning (Contextual Tuning).
  • Provide evidence of improvements made by modifying sensitivity by changing alert triggering thresholds (Threshold Adjustments).
  • Provide evidence of refining rules to better detect deviations from typical behavior (Behavioral Tuning).
  • Provide evidence of improvements of adjusting rules based on time-based patterns (Temporal Tuning).
  • Provide reasoning of adjusting priority or severity levels of alerts (Severity Tuning).
  • Provide evidence of improving quality integrity of our data used by detection rules (Data Quality).
  • Ensure the tuning includes necessary updates to the release documentation and versioning.

Rule Metadata Checks

  • updated_date matches the date of tuning PR merged.
  • min_stack_version should support the widest stack versions.
  • name and description should be descriptive and not include typos.
  • query should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.

Testing and Validation

  • Validate that the tuned rule's performance is satisfactory and does not negatively impact the stack.
  • Ensure that the tuned rule has a low false positive rate.

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Jul 29, 2026

Copy link
Copy Markdown

⛔️ Test failed

Results
  • ❌ Potential Data Exfiltration Through Curl (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tunes the existing EQL detection rule “Potential Data Exfiltration Through Curl” to reduce false positives by refining and adding additional benign-use exclusions while keeping the core curl upload/exfiltration detection logic intact.

Changes:

  • Updates updated_date to reflect the tuning date.
  • Fixes/adjusts exclusion logic for known benign curl usage (Oracle/Retina, clevis variants, Cloudamize registration, unix-socket usage, Mozilla telemetry).
  • Expands existing parent/argument-based filters to reduce alert volume.

Comment on lines +134 to 136
process.args == "--unix-socket" or
process.parent.name like "clevis*" or
process.parent.executable in ("/usr/bin/clevis-decrypt-tang", "/bin/clevis-decrypt-tang") or
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport: auto genai-tradecraft Rule: Tuning tweaking or tuning an existing rule

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants