# EQL rules are wrong, God help me

**URL:** <https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606>\
**Category:** Elastic Security\
**Created:** [September 17, 2022, 3:11am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606 "2022-09-17T03:11:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhixiang\_hao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhixiang_hao/32/101559_2.png) [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Post date:** [September 17, 2022, 3:11am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/1 "2022-09-17T03:11:49Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f623846bb21707fb54054d2b37dfdfc03f97000.png)  
sequence by process.entity\_id with maxspan = 30s  
[process where event.type in ("start", "process\_started") and process.name:("powershell.exe", "pwsh.exe","cmd.exe","wmic.exe","excel.exe") and process.command\_line:("_HP_", "_Connect.Service_", "_hidden_","_LoadFile_")]  
[file where event.type != "deletion" and file.path :("C:\ProgramData\KPIPrinter1259.ico")]  
This is the behavior of an office malicious program. There are 2 items in it. There is no problem with each individual test, but after using the sequence keyword, there is no alarm. I really don’t know what is going on. I ask the teacher for help.

---

<div class="post-metadata">

**Author:** ![justin\_ibarra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_ibarra/32/110828_2.png) [@justin\_ibarra](https://discuss.elastic.co/u/justin_ibarra)\
**Post date:** [September 20, 2022, 3:41pm UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/2 "2022-09-20T15:41:28Z")

</div>

Hi 👋 , hopefully I can help. You stated that each individual query successfully returns the respective event.

Have you verified that the events occur within 30s, per the defined `maxspan`? The other thing to verify would be the `process.entity_id` of the two events, ensuring they match.

Lastly, though this would be extremely rare, on occasion, the timestamp of the file event could mistakenly precede the process event, which would result in the sequence not matching.

Hope this helps. If not, you could share a sanitized version of the two docs to dig deeper.

---

<div class="post-metadata">

**Author:** ![zhixiang\_hao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhixiang_hao/32/101559_2.png) [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Post date:** [September 21, 2022, 1:45am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/3 "2022-09-21T01:45:11Z")

</div>

> [@justin\_ibarra](#):
>
> 可以帮助。如果没有，您可以共享这两个文档的

Thank you for your reply, I confirmed that this event can happen within a few seconds, I also tried to remove process.entity\_id but it still doesn't work, they are generated by a process powershell, will the timestamp be the same and cause no alarm

---

<div class="post-metadata">

**Author:** ![justin\_ibarra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_ibarra/32/110828_2.png) [@justin\_ibarra](https://discuss.elastic.co/u/justin_ibarra)\
**Post date:** [September 21, 2022, 2:07am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/4 "2022-09-21T02:07:49Z")

</div>

Are you able to share the two target events (with all sensitive data sanitized)? It would help to assess the issue.

---

<div class="post-metadata">

**Author:** ![zhixiang\_hao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhixiang_hao/32/101559_2.png) [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Post date:** [September 21, 2022, 7:08am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/5 "2022-09-21T07:08:52Z")

</div>

> [@justin\_ibarra](#):
>
> Are you able to share the two target events (with all sensitive data sanitized)? It would help to assess the issue.

password:SAHAEXPO22

file creation  
C:\ProgramData\KPIPrinter1259  
12:43:54:420, powershell.exe, 8920:9180, 0, FILE\_truncate, C:\Users\diguoji\AppData\Local\Temp\WindowsTemp.txt

reg msedge.exe   
S-1-5-21-3207859999-3463009947-1583894364-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

powershell  
host && Powershell -WindowStyle hidden [Reflection.Assembly]::LoadFile('C:\ProgramData\KPIPrinter1259.ico');$Connect = New-Object HP.Program;$Connect.Service();

http network  
get ip address  
[http://api.geoiplookup.net/?query](http://api.geoiplookup.net/?query)

C2：  
cloud.mofa-kpi-update.link  
ip：  
104.21.91.90  
172.67.214.197  
name server:

> **[Cloudflare DNS | Authoritative and Secondary DNS](https://www.cloudflare.com/application-services/products/dns/)**
>
> With Cloudflare DNS you have the fastest response time of any DNS provider. Our DNS has unparalleled redundancy and built-in security.

> **[Cloudflare DNS | Authoritative and Secondary DNS](https://www.cloudflare.com/application-services/products/dns/)**
>
> With Cloudflare DNS you have the fastest response time of any DNS provider. Our DNS has unparalleled redundancy and built-in security.

location:  
REDACTED FOR PRIVACY, REDACTED FOR PRIVACY, AZ, REDACTED FOR PRIVACY, United States  
username:  
mofa-kpi-update  
sec:  
cloudflare

dll

> **[VirusTotal](https://www.virustotal.com/gui/file/374f97831b6ecbc979080717a8d21c1739c139e44184d72e65e4163afdaa6ae3/behavior)**
>
> VirusTotal

sandbox

> **[Analysis 1-nopass.xlsm (MD5: BE4B1510D65D8234018B734F4E5927B4) Malicious...](https://app.any.run/tasks/6d4fd063-7b1c-4bff-a8c4-ee63c843e073/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

---

<div class="post-metadata">

**Author:** ![justin\_ibarra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_ibarra/32/110828_2.png) [@justin\_ibarra](https://discuss.elastic.co/u/justin_ibarra)\
**Post date:** [September 21, 2022, 1:53pm UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/6 "2022-09-21T13:53:11Z")

</div>

Are you able to provide the actual _sanitized_ elasticsearch documents for the two events to better analyze your query.

(Please do not include any sensitive information. The main fields we need are those referenced in the query)

---

<div class="post-metadata">

**Author:** ![zhixiang\_hao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zhixiang_hao/32/101559_2.png) [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Post date:** [September 22, 2022, 2:19am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/7 "2022-09-22T02:19:11Z")

</div>

I'm sorry that I used elastic for too short time, and I still don't understand what you mean, but I still want to know if the command line of the same process performs multiple operations, it must be written as one item, or can write multiple items

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2022, 2:19am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606/8 "2022-10-20T02:19:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
