Spacebar Campaigns

HFE-002 Sequential Correlator Alert

Source Alias:
ELK-002
발생 위치:
ELK 서버 elk-langflow-correlator
저장 index:
langflow-alerts-*
주요 event.action:
langflow_rce_confirmed_sequence, langflow_rce_to_collection_sequence, langflow_recon_to_exploit_sequence
주요 필드:
hanguel.alert_type, hanguel.risk_score, related.events, threat.technique
커버 Technique:
T1190 + T1059 + T1005/T1105 등 복합 시나리오

분석 포인트

KQL

_index : "langflow-alerts-*" and event.action : "langflow_rce_confirmed_sequence"