Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Elastic Security Labs

20 articles

Elastic Security Labs research Aug 12

Agentic Frameworks Summary

Agentic systems require security teams to balance autonomy with alignment, ensuring that AI agents can act independently while remaining goal-consistent and ...

Elastic Security Labs → Details

Elastic Security Labs research Jul 29

MaaS Appeal: An Infostealer Rises From The Ashes

NOVABLIGHT is a NodeJS infostealer developed and sold as a MaaS offering; it is used primarily to steal credentials and compromise cryptowallets.

Elastic Security Labs → Details

Elastic Security Labs research Jul 3

Taking SHELLTER: a commercial evasion framework abused in-the-wild

Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to dep...

Elastic Security Labs → Details

Elastic Security Labs research Jul 2

How AI and contextual search enhance defence cybersecurity

Contextual search brings clarity, speed, and insight to defence security teams

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Jun 25

Microsoft Entra ID OAuth Phishing and Detections

This article explores OAuth phishing and token-based abuse in Microsoft Entra ID. Through emulation and analysis of tokens, scope, and device behavior during...

T1566

Elastic Security Labs → Details

Elastic Security Labs research Jun 18

A Wretch Client: From ClickFix deception to information stealer deployment

Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Jun 12

Call Stacks: No More Free Passes For Malware

We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the ar...

Elastic Security Labs → Details

Elastic Security Labs research Jun 9

Elastic Security scores 100% in AV-Comparatives Business Security Test

Elastic Security nailed it with a perfect score of 100% in the most recent AV-Comparatives Business Security Test.

Elastic Security Labs → Details

Elastic Security Labs research May 30

Chasing Eddies: New Rust-based InfoStealer used in CAPTCHA campaigns

Elastic Security Labs walks through EDDIESTEALER, a lightweight commodity infostealer used in emerging CAPTCHA-based campaigns.

Elastic Security Labs → Details

Elastic Security Labs research May 23

De-obfuscating ALCATRAZ

An exploration of techniques used by the obfuscator ALCATRAZ.

Elastic Security Labs → Details

Elastic Security Labs research May 15

Misbehaving Modalities: Detecting Tools, Not Techniques

We explore the concept of Execution Modality and how modality-focused detections can complement behaviour-focused ones.

Elastic Security Labs → Details

Elastic Security Labs research May 7

Elastic and Keep join forces to help users manage alerts and automate workflows

Elastic announces the acquisition of Keep Alerting

Elastic Security Labs → Details

Elastic Security Labs research May 6

Elastic changes the SIEM game with AI-driven security analytics

Learn more about Elastic's AI-driven security analytics

Elastic Security Labs → Details

Elastic Security Labs research Apple Amazon May 6

Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

A high-fidelity emulation of the DPRK's largest cryptocurrency heist via a compromised macOS developer and AWS pivots.

Elastic Security Labs → Details

Elastic Security Labs research Apr 27

How to achieve full-spectrum financial risk detection with AI and unified data

Financial services can’t rely on manual review alone. Discover how unified data and explainable AI are helping firms detect risk, reduce cost, and stay ahead...

Elastic Security Labs → Details

Elastic Security Labs research Apr 24

Now available: the 2025 State of Detection Engineering at Elastic

The 2025 State of Detection Engineering at Elastic explores how we create, maintain, and assess our SIEM and EDR rulesets.

Elastic Security Labs → Details

Elastic Security Labs research Linux Apr 1

Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

Outlaw is a persistent Linux malware leveraging simple brute-force and mining tactics to maintain a long-lasting botnet.

Elastic Security Labs → Details

Elastic Security Labs research GitHub Mar 26

The Shelby Strategy

An analysis of REF8685's abuse of GitHub for C2 to evade defenses.

Elastic Security Labs → Details

Elastic Security Labs research Mar 20

Shedding light on the ABYSSWORKER driver

Elastic Security Labs describes ABYSSWORKER, a malicious driver used with the MEDUSA ransomware attack-chain to disable anti-malware tools.

Elastic Security Labs → Details

Elastic Security Labs research Amazon Mar 13

AWS SNS Abuse: Data Exfiltration and Phishing

During a recent internal collaboration, we dug into publicly known SNS abuse attempts and our knowledge of the data source to develop detection capabilities.

T1566 T1041

Elastic Security Labs → Details

«Previous page 1 ... 6 7 8 9 10 ... 17 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA