Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Dec 6

BPFDoor Scanner

Python script to identify hosts infected with the BPFDoor malware.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

Cobalt Strike Beacon Extractor

Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beac...

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

EMOTET Configuration Extractor

Python script to extract the configuration from EMOTET samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

BLISTER Configuration Extractor

Python script to extract the configuration and payload from BLISTER samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

Operation Bleeding Bear

Elastic Security verifies new destructive malware targeting Ukraine: Operation Bleeding Bear

T1529

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

Exploring the REF2731 Intrusion Set

The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.

Elastic Security Labs → Details

Elastic Security Labs research Dec 1

EMOTET Dynamic Configuration Extraction

Elastic Security Labs discusses the EMOTET trojan and is releasing a tool to dynamically extract configuration files using code emulators.

Elastic Security Labs → Details

Elastic Security Labs research Amazon Okta Nov 30

Security operations: Cloud monitoring and detection with Elastic Security

As companies migrate to cloud, so too do opportunist adversaries. That's why our Elastic Security team members have created free detection rules for protecti...

Elastic Security Labs → Details

Elastic Security Labs research Nov 30

Analysis of Log4Shell vulnerability & CVE-2021-45046

In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.

2 IOCs

Elastic Security Labs → Details

Elastic Security Labs research Nov 30

Forecast and Recommendations: 2022 Elastic Global Threat Report

With the release of our first Global Threat Report at Elastic, customers, partners, and the security community at large are able to identify many of the focu...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Nov 30

Deep dive into the TTD ecosystem

This is the first in a series focused on the Time Travel Debugging (TTD) technology developed by Microsoft that was explored in detail during a recent indepe...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Adobe Nov 30

KNOTWEED Assessment Summary

KNOTWEED deploys the Subzero spyware through the use of 0-day exploits for Adobe Reader and the Windows operating system. Once initial access is gained, it u...

Elastic Security Labs → Details

Elastic Security Labs research Nov 30

Behind the scenes: The making of a Global Threat Report

What was our approach and process for creating a global threat report?

Elastic Security Labs → Details

Elastic Security Labs research Nov 30

2022 Elastic Global Threat Report: Helping security leaders navigate today’s threat landscape

A significant percentage of all cyber threats achieve a degree of success against technical, procedural, and human mitigations. So what is a company to do in...

Elastic Security Labs → Details

Elastic Security Labs research Nov 30

2022 Elastic Global Threat Report Announcement

Discover our latest findings & strategic recommendations to better stay informed of potential directions threat actors may focus on.

Elastic Security Labs → Details

Elastic Security Labs research Nov 29

Sneak Peek: Elastic’s 2022 Global Threat Report

Elastic Security Labs has compiled the 2022 Global Threat Report to share trends and tactics adversaries and attack groups use, as observed by our threat res...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Nov 22

Detection rules for SIGRed vulnerability

The SIGRed vulnerability impacts all systems leveraging the Windows DNS server service (Windows 2003+). To defend your environment, we recommend implementing...

Elastic Security Labs → Details

Elastic Security Labs research Apache Nov 22

Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security

This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active exploitation of the vulnerability in t...

1 IOC

Elastic Security Labs → Details

Elastic Security Labs research Nov 22

Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965)

Provide executive-level details about CVE-2022-22965, a recently-disclosed remote code execution (RCE) vulnerability also known as “Spring4Shell”.

T1190 1 IOC

Elastic Security Labs → Details

Elastic Security Labs research Nov 21

Doing time with the YIPPHB dropper

Elastic Security Labs outlines the steps collect and analyze the various stages of the REF4526 intrusion set. This intrusion set uses a creative approach of ...

Elastic Security Labs → Details

«Previous page 1 ... 34 35 36 37 38 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA