Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Elastic Security Labs

20 articles

Elastic Security Labs research 1d ago

Cloud Threat Emulation on Autopilot: Context is Everything

Cloud threat emulation is more than detonation. A plan-first methodology for cloud detection engineering: scope, victim model, telemetry, coverage, cleanup.

Elastic Security Labs → Details

Elastic Security Labs research 4d ago

One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless

We linked one Elastic Security project to 100 others and ran the full prebuilt detection catalog from the origin, with all the ingest landing in the linked p...

Elastic Security Labs → Details

Elastic Security Labs research Google Sep 14

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart cont...

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 11

Linux Detection Engineering - Local Privilege Escalation

Seven of the thirteen Linux privilege escalation CVEs we tracked in 2026 turned out to be the same copy-on-write bug pointed at different kernel interfaces. ...

T1548 T1068

Elastic Security Labs → Details

Elastic Security Labs research Sep 4

Data access: the hidden cost of security vendor lock-in

Getting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the ev...

Elastic Security Labs → Details

Elastic Security Labs research Docker Kubernetes Sep 3

How to correlate Kubernetes audit logs with container runtime data

Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.

Elastic Security Labs → Details

Elastic Security Labs research Sep 2

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts.

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 1

Linux Detection Engineering - Fileless Execution

We reproduced five Linux fileless execution patterns with FENIX, including memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kern...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Aug 28

From 88 lines to 1: Detecting DLL hijacking with Elastic Defend

The ClickFix campaign that sideloads a malicious mscoree.dll also ships a driver to kill Elastic Endpoint.

Elastic Security Labs → Details

Elastic Security Labs research Aug 25

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now cl...

Elastic Security Labs → Details

Elastic Security Labs research Aug 25

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now cl...

Elastic Security Labs → Details

Elastic Security Labs research Aug 24

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Inside Elastic Security, background jobs called maintainers each own one piece of every user, host and service record, from building entities out of raw logs...

Elastic Security Labs → Details

Elastic Security Labs research Aug 24

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Inside Elastic Security, background jobs called maintainers each own one piece of every user, host and service record, from building entities out of raw logs...

Elastic Security Labs → Details

Elastic Security Labs research Aug 11

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

Elastic Security Labs → Details

Elastic Security Labs research Aug 11

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

Elastic Security Labs → Details

Elastic Security Labs research Aug 7

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when t...

Elastic Security Labs → Details

Elastic Security Labs research Aug 7

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

A 40-line CEL integration snapshots .npmrc files every 6 hours to catch cooldown removals.

Elastic Security Labs → Details

Elastic Security Labs research Aug 7

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

A 40-line CEL integration snapshots .npmrc files every 6 hours to catch cooldown removals.

Elastic Security Labs → Details

Elastic Security Labs research Aug 7

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when t...

Elastic Security Labs → Details

Elastic Security Labs research Aug 6

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm cred...

Elastic Security Labs → Details

1 2 3 ... 17 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA