Techniques
Sample rules
Potential NFS Destructive Operation Burst
- source: elastic
- technicques:
- T1486
Description
Identifies a burst of successful NFS write activity combined with destructive REMOVE or RENAME operations from a single client to one export server within a one-minute window. Ransomware and destructive actors often encrypt, delete, or rename large numbers of files on mounted NFS shares; this aggregation surfaces that behavior using NFS opcode telemetry when file paths are not available on the wire.
Detection logic
from logs-network_traffic.nfs-*, packetbeat-* metadata _source
| eval
Esql.opcode = TO_UPPER(COALESCE(
JSON_EXTRACT(_source, "network_traffic.nfs.opcode"),
JSON_EXTRACT(_source, "nfs.opcode")
)),
Esql.status = TO_UPPER(COALESCE(
JSON_EXTRACT(_source, "network_traffic.nfs.status"),
JSON_EXTRACT(_source, "nfs.status")
))
| where Esql.opcode in ("WRITE", "REMOVE", "RENAME") and Esql.status == "NFS_OK" and
source.ip is not null and destination.ip is not null
| eval Esql.time_window = DATE_TRUNC(1 minutes, @timestamp)
| eval Esql.is_write = CASE(Esql.opcode == "WRITE", 1, 0),
Esql.is_destructive = CASE(Esql.opcode == "REMOVE" or Esql.opcode == "RENAME", 1, 0)
| stats
Esql.mutating_ops = COUNT(*),
Esql.write_ops = SUM(Esql.is_write),
Esql.destructive_ops = SUM(Esql.is_destructive),
Esql.values_opcodes = VALUES(Esql.opcode)
by Esql.time_window, source.ip, destination.ip
| where Esql.mutating_ops >= 100 and Esql.write_ops > 0 and Esql.destructive_ops >= 20
| keep source.ip, destination.ip, Esql.*