Elastic Security Labs detailed a detection pipeline that uses ES|QL COMPLETION to reduce noise from curl and wget execution alerts tied to MITRE ATT&CK T1105 Ingress Tool Transfer, a technique widely used by threat actors to download second-stage payloads, post-exploitation tools, and ransomware from command-and-control infrastructure. The approach preserves deterministic detections, then extracts destination hosts, applies allow-lists, redacts secrets from command lines, aggregates remaining events, and submits only a small set of high-value records to an LLM for a structured verdict of true positive, false positive, or suspicious.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic described a detection-engineering workflow that uses ES|QL COMPLETION to triage noisy curl and wget execution events before they become analyst-facing alerts in cloud environments. The approach preserves deterministic rules, applies destination parsing and allow-listing, redacts secrets, and sends only limited high-value rows to an LLM for structured verdicts.
Elastic ran its wget-focused ES|QL COMPLETION triage pipeline over seven days on its own cloud fleet in June 2026. After deterministic filtering, only three destinations remained, with two classified as false positives and one as suspicious, resulting in no analyst-opened alerts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceelastic.co
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.