# Is this even Possible?

**URL:** <https://discuss.elastic.co/t/is-this-even-possible/367256>\
**Category:** Kibana\
**Tags:** elastic-stack-security, detection-rules\
**Created:** [September 27, 2024, 5:08pm UTC](https://discuss.elastic.co/t/is-this-even-possible/367256 "2024-09-27T17:08:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gisselle-Guzman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gisselle-guzman/32/137926_2.png) [@Gisselle-Guzman](https://discuss.elastic.co/u/Gisselle-Guzman)\
**Post date:** [September 27, 2024, 5:08pm UTC](https://discuss.elastic.co/t/is-this-even-possible/367256/1 "2024-09-27T17:08:00Z")

</div>

Hi all ! I have been a pentester but now I'm working on the blue side of things. So anyways I know all the malicious commands, the programs, and what an attacker will type, say into powershell or into their attack machine.

Anyways we have ELK. Looking into Kibana. I can see there are pre-built rules and I can duplicate them and make edits in the custom query. But the custom query looks like it's the output of how Windows will react when something malicious occurs. But what I want to do is add a custom query of common pentesting commands and if they are type & entered then an alert happens.

Like take for instance , basic , like a query for nmap for network scanning , sudo nmap -sC -sV -O -A , etc. I know there is already a pre-built rule for this, but this is just an example. Is there a way in Kibana to write an alert for powershell terminal commands a malicious threat will use directly ? Instead of formatting the custom query on how Windows process take place , etc when an attack happens?

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [September 30, 2024, 8:17pm UTC](https://discuss.elastic.co/t/is-this-even-possible/367256/2 "2024-09-30T20:17:29Z")

</div>

I'm afraid the answer is no. Elastic Defend only monitors process execution, but does not perform deep PowerShell inspection at runtime. When you open a Powershell window, all typed commands are interpreted and executed by the shell. Elastic Defend does not see them unless new processes are created.
