Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Intel Mar 1

Ingesting threat data with the Threat Intel Filebeat module

Tutorial that walks through setting up Filebeat to push threat intelligence feeds into your Elastic Stack.

Elastic Security Labs → Details

Elastic Security Labs research Mar 1

Automating the Security Protections rapid response to malware

See how we’ve been improving the processes that allow us to make updates quickly in response to new information and propagate those protections to our users,...

Elastic Security Labs → Details

Elastic Security Labs research Feb 27

Twice around the dance floor - Elastic discovers the PIPEDANCE backdoor

Elastic Security Labs is tracking an active intrusion into a Vietnamese organization using a recently discovered triggerable, multi-hop backdoor we are calli...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Feb 21

Sandboxing Antimalware Products for Fun and Profit

This article demonstrates a flaw that allows attackers to bypass a Windows security mechanism which protects anti-malware products from various forms of attack.

Elastic Security Labs → Details

Elastic Security Labs research Feb 14

QBOT Malware Analysis

Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configurat...

Elastic Security Labs → Details

Elastic Security Labs research Feb 14

CUBA Ransomware Malware Analysis

Elastic Security has performed a deep technical analysis of the CUBA ransomware family. This includes malware capabilities as well as defensive countermeasures.

Elastic Security Labs → Details

Elastic Security Labs research Feb 7

Update to the REF2924 intrusion set and related campaigns

Elastic Security Labs is providing an update to the REF2924 research published in December of 2022. This update includes malware analysis of the implants, ad...

Elastic Security Labs → Details

Elastic Security Labs research Jan 30

NETWIRE Dynamic Configuration Extraction

Elastic Security Labs discusses the NETWIRE trojan and is releasing a tool to dynamically extract configuration files.

Elastic Security Labs → Details

Elastic Security Labs research Jan 27

NETWIRE Configuration Extractor

Python script to extract the configuration from NETWIRE samples.

Elastic Security Labs → Details

Elastic Security Labs research Jan 26

Finding Truth in the Shadows

Let's discuss three benefits that Hardware Stack Protections brings beyond the intended exploit mitigation capability, and explain some limitations.

Elastic Security Labs → Details

Elastic Security Labs research Jan 19

Vulnerability summary: Follina, CVE-2022-30190

Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.

1 IOC

Elastic Security Labs → Details

Elastic Security Labs research Jan 4

FLARE-ON 9 Solutions:

This year's FLARE-ON consisted of 11 different reverse engineering challenges with a range of interesting binaries. We really enjoyed working on these challe...

Elastic Security Labs → Details

Elastic Security Labs research Google Jan 3

Google Workspace Attack Surface

During this multipart series, we’ll help you understand what GW is and some of the common risks to be aware of, while encouraging you to take control of your...

Elastic Security Labs → Details

Elastic Security Labs research Google Jan 3

Google Workspace Attack Surface

During part two of this multipart series, we’ll help you understand how to setup a GW lab for threat detection and research.

Elastic Security Labs → Details

Elastic Security Labs research Dec 16

SiestaGraph: New implant uncovered in ASEAN member foreign ministry

Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant...

T1190 T1041

Elastic Security Labs → Details

Elastic Security Labs research Intel Dec 8

Elastic’s 2022 Global Threat Report: A roadmap for navigating today’s growing threatscape

Threat intelligence resources like the 2022 Elastic Global Threat Report are critical to helping teams evaluate their organizational visibility, capabilities...

Elastic Security Labs → Details

Elastic Security Labs research Dec 7

Get-InjectedThreadEx – Detecting Thread Creation Trampolines

In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-Injecte...

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

QBOT Configuration Extractor

Python script to extract the configuration from QBOT samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

ICEDID Configuration Extractor

Python script to extract the configuration from ICEDID samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

BPFDoor Configuration Extractor

Configuration extractor to dump out hardcoded passwords with BPFDoor.

Elastic Security Labs → Details

«Previous page 1 ... 33 34 35 36 37 38 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA