Kernel ETW is the best ETW
This research focuses on the importance of native audit logs in secure-by-design software, emphasizing the need for kernel-level ETW logging over user-mode h...
20 articles
This research focuses on the importance of native audit logs in secure-by-design software, emphasizing the need for kernel-level ETW logging over user-mode h...
We're delighted to announce three major research releases from PortSwigger Research will be published at both Black Hat USA and DEF CON 32.
Most of the web already supports HTTPS: In fact, 93% of requests made by Firefox are already HTTPS. As a reminder, HTTP over TLS (HTTPS) fixes the security s...
This article guides readers through establishing an Okta threat detection lab, emphasizing the importance of securing SaaS platforms like Okta. It details cr...
This article highlights the essential contributions to the Global Threat Report from the Security Intelligence team, and describes three major phenomena impa...
In this research publication, we'll learn about upcoming improvements to the Windows Code Integrity subsystem that will make it harder for malware to tamper ...
Explore the technical implementation of the Detonate system, including sandbox creation, the supporting technology, telemetry collection, and how to blow stu...
In this research article, we will take a look at a collection of UAC bypasses, investigate some of the key primitives they depend on, and explore detection o...
Check out the newest report from Elastic Security Labs, which explores how you can protect your organization from LLM threats.
This week, we’re publishing a new version of this report that’s online and interactive, which includes additional data covering the remainder of 2022, writte...
Each month, the Elastic Security Labs team dissects a different trend or correlation from the Elastic Global Threat Report. This post provides an overview of...
Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configurat...
Threat intelligence resources like the 2022 Elastic Global Threat Report are critical to helping teams evaluate their organizational visibility, capabilities...
As companies migrate to cloud, so too do opportunist adversaries. That's why our Elastic Security team members have created free detection rules for protecti...
With the release of our first Global Threat Report at Elastic, customers, partners, and the security community at large are able to identify many of the focu...
What was our approach and process for creating a global threat report?
A significant percentage of all cyber threats achieve a degree of success against technical, procedural, and human mitigations. So what is a company to do in...
Discover our latest findings & strategic recommendations to better stay informed of potential directions threat actors may focus on.
The Deimos implant was first reported in 2020 and has been in active development; employing advanced analysis countermeasures to frustrate analysis. This pos...
By formalizing stateful detection in your rules, as well as your engineering process, you increase your detection coverage over future and past matches. In t...