Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Apr 25

Embedding Security in LLM Workflows: Elastic's Proactive Approach

Dive into Elastic's exploration of embedding security directly within Large Language Models (LLMs). Discover our strategies for detecting and mitigating seve...

Elastic Security Labs → Details

Elastic Security Labs research Apr 24

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One

This malware research article describes the REMCOS implant at a high level, and provides background for future articles in this multipart series.

Elastic Security Labs → Details

Elastic Security Labs research Linux Apr 9

Linux detection engineering with Auditd

In this article, learn more about using Auditd and Auditd Manager for detection engineering.

Elastic Security Labs → Details

Elastic Security Labs research Apr 5

500ms to midnight: XZ A.K.A. liblzma backdoor

Elastic Security Labs is releasing an initial analysis of the XZ Utility backdoor, including YARA rules, osquery, and KQL searches to identify potential comp...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Mar 29

In-the-Wild Windows LPE 0-days: Insights & Detection Strategies

This article will evaluate detection methods for Windows local privilege escalation techniques based on dynamic behaviors analysis using Elastic Defend featu...

T1548 T1068

Elastic Security Labs → Details

Elastic Security Labs research Linux Mar 27

Unlocking Power Safely: Privilege Escalation via Linux Process Capabilities

Organizations need to understand how Linux features contribute to their attack surface via privilege escalation and how to effectively monitor intrusion atte...

T1548

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Mar 20

Unveiling malware behavior trends

An analysis of a diverse dataset of Windows malware extracted from more than 100,000 samples revealing insights into the most prevalent tactics, techniques, ...

Elastic Security Labs → Details

PortSwigger Research research Mar 19

Making desync attacks easy with TRACE

Have you ever found an HTTP desync vulnerability that seemed impossible to exploit due to its complicated constraints?

PortSwigger Research → Details

Elastic Security Labs research Apple Mar 15

Sinking macOS Pirate Ships with Elastic Behavior Detections

This research looks at a recently found macOS malware campaign using the macOS Endpoint Security Framework paired with the Elastic Agent to hunt and detect t...

Elastic Security Labs → Details

PortSwigger Research research Mar 5

Using form hijacking to bypass CSP

In this post we'll show you how to bypass CSP by using an often overlooked technique that can enable password theft in a seemingly secure configuration. What...

PortSwigger Research → Details

Elastic Security Labs research Feb 24

PIKABOT, I choose you!

Elastic Security Labs observed new PIKABOT campaigns, including an updated version. PIKABOT is a widely deployed loader malicious actors utilize to distribut...

Elastic Security Labs → Details

Elastic Security Labs research Okta Feb 23

Monitoring Okta threats with Elastic Security

This article guides readers through establishing an Okta threat detection lab, emphasizing the importance of securing SaaS platforms like Okta. It details cr...

Elastic Security Labs → Details

Elastic Security Labs research Feb 23

Ransomware in the honeypot: how we capture keys with sticky canary files

This article describes the process of capturing encryption keys from ransomware using Elastic Defend ransomware protection.

Elastic Security Labs → Details

PortSwigger Research research Feb 19

Top 10 web hacking techniques of 2023

Welcome to the Top 10 Web Hacking Techniques of 2023, the 17th edition of our annual community-powered effort to identify the most innovative must-read web s...

PortSwigger Research → Details

Elastic Security Labs research Feb 14

Introduction to Hex-Rays decompilation internals

In this publication, we delve into Hex-Rays microcode and explore techniques for manipulating the generated CTree to deobfuscate and annotate decompiled code.

Elastic Security Labs → Details

Elastic Security Labs research SAP Feb 9

STIXy Situations: ECSaping your threat data

Structured threat data is commonly formatted using STIX. To help get this data into Elasticsearch, we’re releasing a Python script that converts STIX to an E...

Elastic Security Labs → Details

Elastic Security Labs research Jan 31

Unmasking a Financial Services Intrusion: REF0657

Elastic Security Labs details an intrusion leveraging open-source tooling and different post-exploitation techniques targeting the financial services industr...

Elastic Security Labs → Details

PortSwigger Research research Oracle Jan 23

Hiding payloads in Java source code strings

In this post we'll show you how Java handles unicode escapes in source code strings in a way you might find surprising - and how you can abuse them to concea...

PortSwigger Research → Details

Elastic Security Labs research Okta Jan 23

Starter guide to understanding Okta

This article delves into Okta's architecture and services, laying a solid foundation for threat research and detection engineering. Essential reading for tho...

Elastic Security Labs → Details

PortSwigger Research research Jan 9

Top 10 web hacking techniques of 2023 - nominations open

Update: The results are in!

PortSwigger Research → Details

«Previous page 1 ... 28 29 30 31 32 ... 37 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA