Automating the Security Protections rapid response to malware
See how we’ve been improving the processes that allow us to make updates quickly in response to new information and propagate those protections to our users,...
See how we’ve been improving the processes that allow us to make updates quickly in response to new information and propagate those protections to our users,...
This article demonstrates a flaw that allows attackers to bypass a Windows security mechanism which protects anti-malware products from various forms of attack.
Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configurat...
Elastic Security has performed a deep technical analysis of the CUBA ransomware family. This includes malware capabilities as well as defensive countermeasures.
Elastic Security Labs is providing an update to the REF2924 research published in December of 2022. This update includes malware analysis of the implants, ad...
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
Python script to identify hosts infected with the BPFDoor malware.
Elastic Security verifies new destructive malware targeting Ukraine: Operation Bleeding Bear
Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.
Analysis of the HERMETICWIPER malware targeting Ukranian organizations.
In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.
Elastic Security has identified active intrusions leveraging the newly identified BLISTER malware loader utilizing valid code-signing certificates to evade d...
The Mozi botnet is an ongoing malware campaign targeting unsecured and vulnerable networking devices. This post will showcase the analyst journey of collecti...