Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Elastic Security Labs

20 articles

Elastic Security Labs research 1d ago

Introducing AlertZero: Inbox zero for your alert queue

AlertZero brings AI SOC automation to Elastic Security with four agents, one job each, so the queue stops setting your priorities. Nothing changes in your en...

Elastic Security Labs → Details

Elastic Security Labs research 4d ago

Behind the tags: How Elastic SIEM grades 1,781 detection rules on noise, speed, and threat coverage

This article explains how Elastic SIEM uses a monthly automated telemetry pipeline to score prebuilt detection rules across noise, performance, threat, and p...

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 29

No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current

Elastic InfoSec runs Linux endpoint management through Elastic Defend with a scheduled workflow that gets Cursor and Codex config onto new laptops without pi...

Elastic Security Labs → Details

Elastic Security Labs research Sep 28

Quarantined isn't contained: Agentic phishing response with Elastic and Sublime

The native Sublime Security integration sends email detections into Elastic Security, where phishing incident response can tie a quarantined email to what ha...

T1566

Elastic Security Labs → Details

Elastic Security Labs research Sep 21

Cloud Threat Emulation on Autopilot: Context is Everything

Cloud threat emulation is more than detonation. A plan-first methodology for cloud detection engineering: scope, victim model, telemetry, coverage, cleanup.

Elastic Security Labs → Details

Elastic Security Labs research Sep 18

One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless

We linked one Elastic Security project to 100 others and ran the full prebuilt detection catalog from the origin, with all the ingest landing in the linked p...

Elastic Security Labs → Details

Elastic Security Labs research Google Sep 14

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart cont...

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 11

Linux Detection Engineering - Local Privilege Escalation

Seven of the thirteen Linux privilege escalation CVEs we tracked in 2026 turned out to be the same copy-on-write bug pointed at different kernel interfaces. ...

T1548 T1068

Elastic Security Labs → Details

Elastic Security Labs research Sep 4

Data access: the hidden cost of security vendor lock-in

Getting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the ev...

Elastic Security Labs → Details

Elastic Security Labs research Docker Kubernetes Sep 3

How to correlate Kubernetes audit logs with container runtime data

Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.

Elastic Security Labs → Details

Elastic Security Labs research Sep 2

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts.

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 1

Linux Detection Engineering - Fileless Execution

We reproduced five Linux fileless execution patterns with FENIX, including memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kern...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Aug 28

From 88 lines to 1: Detecting DLL hijacking with Elastic Defend

The ClickFix campaign that sideloads a malicious mscoree.dll also ships a driver to kill Elastic Endpoint.

Elastic Security Labs → Details

Elastic Security Labs research Aug 25

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now cl...

Elastic Security Labs → Details

Elastic Security Labs research Aug 25

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now cl...

Elastic Security Labs → Details

Elastic Security Labs research Aug 24

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Inside Elastic Security, background jobs called maintainers each own one piece of every user, host and service record, from building entities out of raw logs...

Elastic Security Labs → Details

Elastic Security Labs research Aug 24

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Inside Elastic Security, background jobs called maintainers each own one piece of every user, host and service record, from building entities out of raw logs...

Elastic Security Labs → Details

Elastic Security Labs research Aug 11

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

Elastic Security Labs → Details

Elastic Security Labs research Aug 11

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

Elastic Security Labs → Details

Elastic Security Labs research Aug 7

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when t...

Elastic Security Labs → Details

1 2 3 ... 17 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA