BPFDoor Scanner
Python script to identify hosts infected with the BPFDoor malware.
20 articles
Python script to identify hosts infected with the BPFDoor malware.
Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beac...
Python script to extract the configuration from EMOTET samples.
Python script to extract the configuration and payload from BLISTER samples.
Elastic Security verifies new destructive malware targeting Ukraine: Operation Bleeding Bear
The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.
Elastic Security Labs discusses the EMOTET trojan and is releasing a tool to dynamically extract configuration files using code emulators.
As companies migrate to cloud, so too do opportunist adversaries. That's why our Elastic Security team members have created free detection rules for protecti...
In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.
With the release of our first Global Threat Report at Elastic, customers, partners, and the security community at large are able to identify many of the focu...
This is the first in a series focused on the Time Travel Debugging (TTD) technology developed by Microsoft that was explored in detail during a recent indepe...
KNOTWEED deploys the Subzero spyware through the use of 0-day exploits for Adobe Reader and the Windows operating system. Once initial access is gained, it u...
What was our approach and process for creating a global threat report?
A significant percentage of all cyber threats achieve a degree of success against technical, procedural, and human mitigations. So what is a company to do in...
Discover our latest findings & strategic recommendations to better stay informed of potential directions threat actors may focus on.
Elastic Security Labs has compiled the 2022 Global Threat Report to share trends and tactics adversaries and attack groups use, as observed by our threat res...
The SIGRed vulnerability impacts all systems leveraging the Windows DNS server service (Windows 2003+). To defend your environment, we recommend implementing...
This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active exploitation of the vulnerability in t...
Provide executive-level details about CVE-2022-22965, a recently-disclosed remote code execution (RCE) vulnerability also known as “Spring4Shell”.
Elastic Security Labs outlines the steps collect and analyze the various stages of the REF4526 intrusion set. This intrusion set uses a creative approach of ...