Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Jan 19

Vulnerability summary: Follina, CVE-2022-30190

Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.

1 IOC

Elastic Security Labs → Details

Elastic Security Labs research Jan 4

FLARE-ON 9 Solutions:

This year's FLARE-ON consisted of 11 different reverse engineering challenges with a range of interesting binaries. We really enjoyed working on these challe...

Elastic Security Labs → Details

Elastic Security Labs research Google Jan 3

Google Workspace Attack Surface

During this multipart series, we’ll help you understand what GW is and some of the common risks to be aware of, while encouraging you to take control of your...

Elastic Security Labs → Details

Elastic Security Labs research Google Jan 3

Google Workspace Attack Surface

During part two of this multipart series, we’ll help you understand how to setup a GW lab for threat detection and research.

Elastic Security Labs → Details

Elastic Security Labs research Dec 16

SiestaGraph: New implant uncovered in ASEAN member foreign ministry

Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant...

T1190 T1041

Elastic Security Labs → Details

Elastic Security Labs research Intel Dec 8

Elastic’s 2022 Global Threat Report: A roadmap for navigating today’s growing threatscape

Threat intelligence resources like the 2022 Elastic Global Threat Report are critical to helping teams evaluate their organizational visibility, capabilities...

Elastic Security Labs → Details

Elastic Security Labs research Dec 7

Get-InjectedThreadEx – Detecting Thread Creation Trampolines

In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-Injecte...

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

QBOT Configuration Extractor

Python script to extract the configuration from QBOT samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

ICEDID Configuration Extractor

Python script to extract the configuration from ICEDID samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

BPFDoor Configuration Extractor

Configuration extractor to dump out hardcoded passwords with BPFDoor.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

PARALLAX Payload Extractor

Python script to extract the payload from PARALLAX samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

BPFDoor Scanner

Python script to identify hosts infected with the BPFDoor malware.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

Cobalt Strike Beacon Extractor

Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beac...

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

EMOTET Configuration Extractor

Python script to extract the configuration from EMOTET samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

BLISTER Configuration Extractor

Python script to extract the configuration and payload from BLISTER samples.

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

Operation Bleeding Bear

Elastic Security verifies new destructive malware targeting Ukraine: Operation Bleeding Bear

T1529

Elastic Security Labs → Details

Elastic Security Labs research Dec 6

Exploring the REF2731 Intrusion Set

The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.

Elastic Security Labs → Details

Elastic Security Labs research Dec 1

EMOTET Dynamic Configuration Extraction

Elastic Security Labs discusses the EMOTET trojan and is releasing a tool to dynamically extract configuration files using code emulators.

Elastic Security Labs → Details

Elastic Security Labs research Amazon Okta Nov 30

Security operations: Cloud monitoring and detection with Elastic Security

As companies migrate to cloud, so too do opportunist adversaries. That's why our Elastic Security team members have created free detection rules for protecti...

Elastic Security Labs → Details

Elastic Security Labs research Nov 30

Analysis of Log4Shell vulnerability & CVE-2021-45046

In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.

2 IOCs

Elastic Security Labs → Details

«Previous page 1 ... 32 33 34 35 36 37 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA