Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Microsoft Jun 22

GrimResource - Microsoft Management Console for initial access and evasion

Elastic researchers uncovered a new technique, GrimResource, which allows full code execution via specially crafted MSC files. It underscores a trend of well...

Elastic Security Labs → Details

Elastic Security Labs research Jun 12

Dipping into Danger: The WARMCOOKIE backdoor

Elastic Security Labs observed threat actors masquerading as recruiting firms to deploy a new malware backdoor called WARMCOOKIE. This malware has standard b...

Elastic Security Labs → Details

PortSwigger Research research Apple Jun 11

onwebkitplaybacktargetavailabilitychanged?! New exotic events in the XSS cheat sheet

The power of our XSS cheat sheet is we get fantastic contributions from the web security community and this update is no exception.

PortSwigger Research → Details

Elastic Security Labs research May 30

Protecting your devices from information theft

In this article, we will introduce the keylogger and keylogging detection features added this year to Elastic Defend (starting from version 8.12), which is r...

Elastic Security Labs → Details

PortSwigger Research research May 29

Refining your HTTP perspective, with bambdas

When you open a HTTP request or response, what do you instinctively look for? Suspicious parameter names?

PortSwigger Research → Details

Elastic Security Labs research May 24

Globally distributed stealers

This article describes our analysis of the top malware stealer families, unveiling their operation methodologies, recent updates, and configurations. By unde...

Elastic Security Labs → Details

PortSwigger Research research May 22

Introducing SignSaboteur: forge signed web tokens with ease

Signed web tokens are widely used for stateless authentication and authorization throughout the web.

PortSwigger Research → Details

Elastic Security Labs research May 22

Invisible miners: unveiling GHOSTENGINE’s crypto mining operations

Elastic Security Labs has identified REF4578, an intrusion set incorporating several malicious modules and leveraging vulnerable drivers to disable known sec...

Elastic Security Labs → Details

Elastic Security Labs research May 16

Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID

Elastic Security Labs has observed an uptick in a recent emerging loader known as LATRODECTUS. This lightweight loader packs a big punch with ties to ICEDID ...

Elastic Security Labs → Details

Elastic Security Labs research May 10

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Four

In previous articles in this multipart series, malware researchers on the Elastic Security Labs team decomposed the REMCOS configuration structure and gave d...

Elastic Security Labs → Details

Elastic Security Labs research May 6

Elastic Advances LLM Security with Standardized Fields and Integrations

Discover Elastic’s latest advancements in LLM security, focusing on standardized field integrations and enhanced detection capabilities. Learn how adopting t...

Elastic Security Labs → Details

Elastic Security Labs research May 3

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three

In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, yo...

Elastic Security Labs → Details

Elastic Security Labs research Apr 30

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Two

In the previous article in this series on the REMCOS implant, we shared information about execution, persistence, and defense evasion mechanisms. Continuing ...

Elastic Security Labs → Details

Elastic Security Labs research Apr 25

Embedding Security in LLM Workflows: Elastic's Proactive Approach

Dive into Elastic's exploration of embedding security directly within Large Language Models (LLMs). Discover our strategies for detecting and mitigating seve...

Elastic Security Labs → Details

Elastic Security Labs research Apr 24

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One

This malware research article describes the REMCOS implant at a high level, and provides background for future articles in this multipart series.

Elastic Security Labs → Details

Elastic Security Labs research Linux Apr 9

Linux detection engineering with Auditd

In this article, learn more about using Auditd and Auditd Manager for detection engineering.

Elastic Security Labs → Details

Elastic Security Labs research Apr 5

500ms to midnight: XZ A.K.A. liblzma backdoor

Elastic Security Labs is releasing an initial analysis of the XZ Utility backdoor, including YARA rules, osquery, and KQL searches to identify potential comp...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Mar 29

In-the-Wild Windows LPE 0-days: Insights & Detection Strategies

This article will evaluate detection methods for Windows local privilege escalation techniques based on dynamic behaviors analysis using Elastic Defend featu...

T1548 T1068

Elastic Security Labs → Details

Elastic Security Labs research Linux Mar 27

Unlocking Power Safely: Privilege Escalation via Linux Process Capabilities

Organizations need to understand how Linux features contribute to their attack surface via privilege escalation and how to effectively monitor intrusion atte...

T1548

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Mar 20

Unveiling malware behavior trends

An analysis of a diverse dataset of Windows malware extracted from more than 100,000 samples revealing insights into the most prevalent tactics, techniques, ...

Elastic Security Labs → Details

«Previous page 1 ... 29 30 31 32 33 ... 38 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA