Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Elastic Security Labs

20 articles

Elastic Security Labs research Feb 6

DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector

Learn how Elastic Defend's ransomware protection successfully detects and prevents DYNOWIPER execution using canary file monitoring.

T1529

Elastic Security Labs → Details

Elastic Security Labs research Feb 5

Automating GOAD and Live Malware Labs

Stop building labs by hand. Automate the deployment of a fully instrumented Purple Team range using Ludus and Elastic Security.

Elastic Security Labs → Details

Elastic Security Labs research Feb 4

The Engineer's Guide to Elastic Detections as Code

This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highligh...

Elastic Security Labs → Details

Elastic Security Labs research Feb 3

From Alert Fatigue to Agentic Response: How Workflows and Agent Builder Close the Loop

Attempting to chase individual alerts is a losing strategy. To succeed, we have to move beyond simple automation scripts and into the era of Agentic AI.

Elastic Security Labs → Details

Elastic Security Labs research Splunk IBM Feb 3

From Qradar to Elastic: Automate your Detection Rule Migration

Today, we are excited to announce a major expansion to our Automatic Migration feature that changes that narrative. In Elastic Security 9.

Elastic Security Labs → Details

Elastic Security Labs research Jan 27

How Elastic Infosec Optimizes Defend for Cost and Performance

This article details the internal Elastic Infosec team's process to optimize our endpoint data collection using Event Filtering and Advanced Policy Settings ...

Elastic Security Labs → Details

Elastic Security Labs research Jan 8

From Hypothesis to Action: Proactive Threat Hunting with Elastic Security

Elastic Security is designed to enable hypothesis-driven threat hunting at speed and scale. By unifying security telemetry and enabling analytics across clus...

Elastic Security Labs → Details

Elastic Security Labs research Dec 11

NANOREMOTE, cousin of FINALDRAFT

The fully-featured backdoor we call NANOREMOTE shares characteristics with malware described in REF7707 and is similar to the FINALDRAFT implant.

Elastic Security Labs → Details

Elastic Security Labs research Dec 5

Automating detection tuning requests with Kibana cases

Learn how to automate detection rule tuning requests in Elastic Security. This guide shows how to add custom fields to Cases, create a rule to detect tuning ...

Elastic Security Labs → Details

Elastic Security Labs research Nov 15

RONINGLOADER: DragonBreath’s New Path to PPL Abuse

Elastic Security Labs uncovers RONINGLOADER, a multi-stage loader deploying DragonBreath’s updated gh0st RAT variant. The campaign weaponizes signed drivers,...

Elastic Security Labs → Details

Elastic Security Labs research Oct 27

TOR Exit Node Monitoring Overview

Learn how to monitor your enterprise for TOR exit node activity.

Elastic Security Labs → Details

Elastic Security Labs research Qualys Oct 22

Time-to-Patch Metrics: A Survival Analysis Approach Using Qualys and Elastic

In this article, we describe how we applied survival analysis to vulnerability management (VM) data from Qualys VMDR, using the Elastic Stack.

Elastic Security Labs → Details

Elastic Security Labs research Oct 22

TOLLBOOTH: What's yours, IIS mine

REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally.

1 IOC

Elastic Security Labs → Details

Elastic Security Labs research Intel Oct 14

NightMARE on 0xelm Street, a guided tour

This article describes nightMARE, a python-based library for malware researchers that was developed by Elastic Security Labs to help scale analysis. It descr...

Elastic Security Labs → Details

Elastic Security Labs research Oct 8

What the 2025 Elastic Global Threat Report reveals about the evolving threat landscape

The 2025 Elastic Global Threat Report provides current insights on adversary trends and defender strategies derived from real-world telemetry.

Elastic Security Labs → Details

Elastic Security Labs research Oct 1

WARMCOOKIE One Year Later: New Features and Fresh Insights

A year later: Elastic Security Labs re-examines the WARMCOOKIE backdoor.

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 30

FlipSwitch: a Novel Syscall Hooking Technique

FlipSwitch offers a fresh look at bypassing Linux kernel defenses, revealing a new technique in the ongoing battle between cyber attackers and defenders.

Elastic Security Labs → Details

Elastic Security Labs research Sep 22

Elastic excels in AV-Comparatives EPR Test 2025: A closer look

Elastic shares results of the 2025 AV Comparatives EPR test

Elastic Security Labs → Details

Elastic Security Labs research Sep 19

MCP Tools: Attack Vectors and Defense Recommendations for Autonomous Agents

This research examines how Model Context Protocol (MCP) tools expand the attack surface for autonomous agents, detailing exploit vectors such as tool poisoni...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Linux Sep 4

Investigating a Mysteriously Malformed Authenticode Signature

An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.

Elastic Security Labs → Details

«Previous page 1 ... 5 6 7 8 9 ... 17 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA