Repeater Strike: manual testing, amplified
Manual testing doesn't have to be repetitive.
20 articles
Manual testing doesn't have to be repetitive.
Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to dep...
Contextual search brings clarity, speed, and insight to defence security teams
This article explores OAuth phishing and token-based abuse in Microsoft Entra ID. Through emulation and analysis of tokens, scope, and device behavior during...
Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.
We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the ar...
Elastic Security nailed it with a perfect score of 100% in the most recent AV-Comparatives Business Security Test.
Elastic Security Labs walks through EDDIESTEALER, a lightweight commodity infostealer used in emerging CAPTCHA-based campaigns.
An exploration of techniques used by the obfuscator ALCATRAZ.
We explore the concept of Execution Modality and how modality-focused detections can complement behaviour-focused ones.
Elastic announces the acquisition of Keep Alerting
Learn more about Elastic's AI-driven security analytics
A high-fidelity emulation of the DPRK's largest cryptocurrency heist via a compromised macOS developer and AWS pivots.
Control characters like SOH, STX, EOT and ETX were never meant to run your code - but in the world of modern terminal emulators, they sometimes do.
Financial services can’t rely on manual review alone. Discover how unified data and explainable AI are helping firms detect risk, reduce cost, and stay ahead...
The 2025 State of Detection Engineering at Elastic explores how we create, maintain, and assess our SIEM and EDR rulesets.
Tired of repeating yourself? Automate your web security audit trail.
Outlaw is a persistent Linux malware leveraging simple brute-force and mining tactics to maintain a long-lasting botnet.
An analysis of REF8685's abuse of GitHub for C2 to evade defenses.
Elastic Security Labs describes ABYSSWORKER, a malicious driver used with the MEDUSA ransomware attack-chain to disable anti-malware tools.