Vulnerability summary: Follina, CVE-2022-30190
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
20 articles
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
This year's FLARE-ON consisted of 11 different reverse engineering challenges with a range of interesting binaries. We really enjoyed working on these challe...
During this multipart series, we’ll help you understand what GW is and some of the common risks to be aware of, while encouraging you to take control of your...
During part two of this multipart series, we’ll help you understand how to setup a GW lab for threat detection and research.
Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant...
Threat intelligence resources like the 2022 Elastic Global Threat Report are critical to helping teams evaluate their organizational visibility, capabilities...
In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-Injecte...
Python script to extract the configuration from QBOT samples.
Python script to extract the configuration from ICEDID samples.
Configuration extractor to dump out hardcoded passwords with BPFDoor.
Python script to extract the payload from PARALLAX samples.
Python script to identify hosts infected with the BPFDoor malware.
Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beac...
Python script to extract the configuration from EMOTET samples.
Python script to extract the configuration and payload from BLISTER samples.
Elastic Security verifies new destructive malware targeting Ukraine: Operation Bleeding Bear
The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.
Elastic Security Labs discusses the EMOTET trojan and is releasing a tool to dynamically extract configuration files using code emulators.
As companies migrate to cloud, so too do opportunist adversaries. That's why our Elastic Security team members have created free detection rules for protecti...
In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.