Ingesting threat data with the Threat Intel Filebeat module
Tutorial that walks through setting up Filebeat to push threat intelligence feeds into your Elastic Stack.
20 articles
Tutorial that walks through setting up Filebeat to push threat intelligence feeds into your Elastic Stack.
See how we’ve been improving the processes that allow us to make updates quickly in response to new information and propagate those protections to our users,...
Elastic Security Labs is tracking an active intrusion into a Vietnamese organization using a recently discovered triggerable, multi-hop backdoor we are calli...
This article demonstrates a flaw that allows attackers to bypass a Windows security mechanism which protects anti-malware products from various forms of attack.
Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configurat...
Elastic Security has performed a deep technical analysis of the CUBA ransomware family. This includes malware capabilities as well as defensive countermeasures.
Elastic Security Labs is providing an update to the REF2924 research published in December of 2022. This update includes malware analysis of the implants, ad...
Elastic Security Labs discusses the NETWIRE trojan and is releasing a tool to dynamically extract configuration files.
Python script to extract the configuration from NETWIRE samples.
Let's discuss three benefits that Hardware Stack Protections brings beyond the intended exploit mitigation capability, and explain some limitations.
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
This year's FLARE-ON consisted of 11 different reverse engineering challenges with a range of interesting binaries. We really enjoyed working on these challe...
During this multipart series, we’ll help you understand what GW is and some of the common risks to be aware of, while encouraging you to take control of your...
During part two of this multipart series, we’ll help you understand how to setup a GW lab for threat detection and research.
Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant...
Threat intelligence resources like the 2022 Elastic Global Threat Report are critical to helping teams evaluate their organizational visibility, capabilities...
In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-Injecte...
Python script to extract the configuration from QBOT samples.
Python script to extract the configuration from ICEDID samples.
Configuration extractor to dump out hardcoded passwords with BPFDoor.