DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector
Learn how Elastic Defend's ransomware protection successfully detects and prevents DYNOWIPER execution using canary file monitoring.
20 articles
Learn how Elastic Defend's ransomware protection successfully detects and prevents DYNOWIPER execution using canary file monitoring.
Stop building labs by hand. Automate the deployment of a fully instrumented Purple Team range using Ludus and Elastic Security.
This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highligh...
Attempting to chase individual alerts is a losing strategy. To succeed, we have to move beyond simple automation scripts and into the era of Agentic AI.
Today, we are excited to announce a major expansion to our Automatic Migration feature that changes that narrative. In Elastic Security 9.
This article details the internal Elastic Infosec team's process to optimize our endpoint data collection using Event Filtering and Advanced Policy Settings ...
Elastic Security is designed to enable hypothesis-driven threat hunting at speed and scale. By unifying security telemetry and enabling analytics across clus...
The fully-featured backdoor we call NANOREMOTE shares characteristics with malware described in REF7707 and is similar to the FINALDRAFT implant.
Learn how to automate detection rule tuning requests in Elastic Security. This guide shows how to add custom fields to Cases, create a rule to detect tuning ...
Elastic Security Labs uncovers RONINGLOADER, a multi-stage loader deploying DragonBreath’s updated gh0st RAT variant. The campaign weaponizes signed drivers,...
Learn how to monitor your enterprise for TOR exit node activity.
In this article, we describe how we applied survival analysis to vulnerability management (VM) data from Qualys VMDR, using the Elastic Stack.
REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally.
This article describes nightMARE, a python-based library for malware researchers that was developed by Elastic Security Labs to help scale analysis. It descr...
The 2025 Elastic Global Threat Report provides current insights on adversary trends and defender strategies derived from real-world telemetry.
A year later: Elastic Security Labs re-examines the WARMCOOKIE backdoor.
FlipSwitch offers a fresh look at bypassing Linux kernel defenses, revealing a new technique in the ongoing battle between cyber attackers and defenders.
Elastic shares results of the 2025 AV Comparatives EPR test
This research examines how Model Context Protocol (MCP) tools expand the attack surface for autonomous agents, detailing exploit vectors such as tool poisoni...
An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.