Get-InjectedThreadEx – Detecting Thread Creation Trampolines
In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-Injecte...
Aggregating 7517 articles from trusted cybersecurity sources
In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-Injecte...
Python script to extract the configuration from QBOT samples.
Python script to extract the configuration from ICEDID samples.
Configuration extractor to dump out hardcoded passwords with BPFDoor.
Python script to extract the payload from PARALLAX samples.
Python script to identify hosts infected with the BPFDoor malware.
Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beac...
Python script to extract the configuration from EMOTET samples.
Python script to extract the configuration and payload from BLISTER samples.
Elastic Security verifies new destructive malware targeting Ukraine: Operation Bleeding Bear
The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.
Elastic Security Labs discusses the EMOTET trojan and is releasing a tool to dynamically extract configuration files using code emulators.
No articles found.