Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Linux Jan 9

Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks

With Elastic Security 8.11, we added further kernel telemetry call stack-based detections to increase efficacy against in-memory threats.

Elastic Security Labs → Details

Elastic Security Labs research Google Dec 14

Google Cloud for Cyber Data Analytics

This article explains how we conduct comprehensive cyber threat data analysis using Google Cloud, from data extraction and preprocessing to trend analysis an...

Elastic Security Labs → Details

PortSwigger Research research Dec 12

Finding that one weird endpoint, with Bambdas

Security research involves a lot of failure.

PortSwigger Research → Details

Elastic Security Labs research Dec 6

Getting gooey with GULOADER: deobfuscating the downloader

Elastic Security Labs walks through the updated GULOADER analysis countermeasures.

Elastic Security Labs → Details

Elastic Security Labs research Nov 28

Signaling from within: how eBPF interacts with signals

This article explores some of the semantics of UNIX signals when generated from an eBPF program.

Elastic Security Labs → Details

Elastic Security Labs research GitHub Nov 17

Streamlining ES|QL Query and Rule Validation: Integrating with GitHub CI

ES|QL is Elastic's new piped query language. Taking full advantage of this new feature, Elastic Security Labs walks through how to run validation of ES|QL ru...

Elastic Security Labs → Details

Elastic Security Labs research Apple Nov 1

Elastic catches DPRK passing out KANDYKORN

Elastic Security Labs exposes an attempt by the DPRK to infect blockchain engineers with novel macOS malware.

Elastic Security Labs → Details

Elastic Security Labs research Oct 27

GHOSTPULSE haunts victims using defense evasion bag o' tricks

Elastic Security Labs reveals details of a new campaign leveraging defense evasion capabilities to infect victims with malicious MSIX executables.

Elastic Security Labs → Details

Elastic Security Labs research Intel Oct 19

Fall 2023 Global Threat Report Outro

This article highlights the essential contributions to the Global Threat Report from the Security Intelligence team, and describes three major phenomena impa...

Elastic Security Labs → Details

Elastic Security Labs research F5 Oct 13

Disclosing the BLOODALCHEMY backdoor

BLOODALCHEMY is a new, actively developed, backdoor that leverages a benign binary as an injection vehicle, and is a part of the REF5961 intrusion set.

Elastic Security Labs → Details

Elastic Security Labs research Oct 5

Dancing the night away with named pipes - PIPEDANCE client release

In this publication, we will walk through this client application’s functionality and how to get started with the tool.

Elastic Security Labs → Details

Elastic Security Labs research F5 Oct 4

Introducing the REF5961 intrusion set

The REF5961 intrusion set discloses three new malware families targeting ASEAN members. The threat actor leveraging this intrusion set continues to develop a...

Elastic Security Labs → Details

Elastic Security Labs research Sep 29

Accelerating Elastic detection tradecraft with LLMs

Learn more about how Elastic Security Labs has been focused on accelerating our detection engineering workflows by tapping into more generative AI capabilities.

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 19

Using LLMs and ESRE to find similar user sessions

In our previous article, we explored using the GPT-4 Large Language Model (LLM) to condense Linux user sessions. In the context of the same experiment, we de...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Sep 15

Inside Microsoft's plan to kill PPLFault

In this research publication, we'll learn about upcoming improvements to the Windows Code Integrity subsystem that will make it harder for malware to tamper ...

Elastic Security Labs → Details

Elastic Security Labs research Sep 13

Peeling back the curtain with call stacks

In this article, we'll show you how we contextualize rules and events, and how you can leverage call stacks to better understand any alerts you encounter in ...

Elastic Security Labs → Details

Elastic Security Labs research Sep 11

Using LLMs to summarize user sessions

In this publication, we will talk about lessons learned and key takeaways from our experiments using GPT-4 to summarize user sessions.

Elastic Security Labs → Details

Elastic Security Labs research Linux Aug 25

Forget vulnerable drivers - Admin is all you need

Bring Your Own Vulnerable Driver (BYOVD) is an increasingly popular attacker technique whereby a threat actor brings a known-vulnerable signed driver alongsi...

T1598

Elastic Security Labs → Details

Elastic Security Labs research Aug 24

Revisiting BLISTER: New development of the BLISTER loader

Elastic Security Labs dives deep into the recent evolution of the BLISTER loader malware family.

Elastic Security Labs → Details

Elastic Security Labs research Jul 31

An Elastic approach to large-scale dynamic malware analysis

This research reveals insights into some of the large-scale malware analysis performed by Elastic Security Labs, and complements research related to the Deto...

Elastic Security Labs → Details

«Previous page 1 ... 29 30 31 32 33 ... 37 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA