Detecting Living-off-the-land attacks with new Elastic Integration
We added a Living off the land (LotL) detection package to the Integrations app in Kibana. In a single click, you can install and start using the ProblemChil...
Aggregating 4881 articles from trusted cybersecurity sources
We added a Living off the land (LotL) detection package to the Integrations app in Kibana. In a single click, you can install and start using the ProblemChil...
Elastic Endpoint Security provides events that enable defenders with visibility on techniques and procedures which are commonly leveraged to access sensitive...
Learn more about discovering threats by hunting through DLL load events, one way to reveal the presence of known and unknown malware in noisy process event d...
Tutorial that walks through setting up Filebeat to push threat intelligence feeds into your Elastic Stack.
See how we’ve been improving the processes that allow us to make updates quickly in response to new information and propagate those protections to our users,...
Elastic Security Labs discusses the NETWIRE trojan and is releasing a tool to dynamically extract configuration files.
Python script to extract the configuration from NETWIRE samples.
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
Threat intelligence resources like the 2022 Elastic Global Threat Report are critical to helping teams evaluate their organizational visibility, capabilities...
Python script to extract the configuration from QBOT samples.
Python script to extract the configuration from ICEDID samples.
Configuration extractor to dump out hardcoded passwords with BPFDoor.
No articles found.