LoFP LoFP / backup deduplication engines, migration utilities, and filesystem sync tools can generate high volumes of legitimate nfs writes. validate the source against known backup or storage-management hosts before escalating.

Techniques

Sample rules

Potential NFS Destructive Operation Burst

Description

Identifies a burst of successful NFS write activity combined with destructive REMOVE or RENAME operations from a single client to one export server within a one-minute window. Ransomware and destructive actors often encrypt, delete, or rename large numbers of files on mounted NFS shares; this aggregation surfaces that behavior using NFS opcode telemetry when file paths are not available on the wire.

Detection logic

from logs-network_traffic.nfs-*, packetbeat-* metadata _source
| eval
    Esql.opcode = TO_UPPER(COALESCE(
        JSON_EXTRACT(_source, "network_traffic.nfs.opcode"),
        JSON_EXTRACT(_source, "nfs.opcode")
    )),
    Esql.status = TO_UPPER(COALESCE(
        JSON_EXTRACT(_source, "network_traffic.nfs.status"),
        JSON_EXTRACT(_source, "nfs.status")
    ))
| where Esql.opcode in ("WRITE", "REMOVE", "RENAME") and Esql.status == "NFS_OK" and
    source.ip is not null and destination.ip is not null
| eval Esql.time_window = DATE_TRUNC(1 minutes, @timestamp)
| eval Esql.is_write = CASE(Esql.opcode == "WRITE", 1, 0),
    Esql.is_destructive = CASE(Esql.opcode == "REMOVE" or Esql.opcode == "RENAME", 1, 0)
| stats
    Esql.mutating_ops = COUNT(*),
    Esql.write_ops = SUM(Esql.is_write),
    Esql.destructive_ops = SUM(Esql.is_destructive),
    Esql.values_opcodes = VALUES(Esql.opcode)
  by Esql.time_window, source.ip, destination.ip
| where Esql.mutating_ops >= 100 and Esql.write_ops > 0 and Esql.destructive_ops >= 20
| keep source.ip, destination.ip, Esql.*