Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Elastic Security Labs

20 articles

Elastic Security Labs research Linux Mar 4

Detecting Hotkey-Based Keyloggers Using an Undocumented Kernel Data Structure

In this article, we explore what hotkey-based keyloggers are and how to detect them. Specifically, we explain how these keyloggers intercept keystrokes, then...

Elastic Security Labs → Details

Elastic Security Labs research Linux Feb 27

Linux Detection Engineering - The Grand Finale on Linux Persistence

By the end of this series, you'll have a robust knowledge of both common and rare Linux persistence techniques; and you'll understand how to effectively engi...

Elastic Security Labs → Details

Elastic Security Labs research Amazon Feb 20

Emulating AWS S3 SSE-C Ransom for Threat Detection

In this article, we’ll explore how threat actors leverage Amazon S3’s Server-Side Encryption with Customer-Provided Keys (SSE-C) for ransom/extortion operati...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Feb 13

You've Got Malware: FINALDRAFT Hides in Your Drafts

During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and ...

T1071

Elastic Security Labs → Details

Elastic Security Labs research Feb 13

From South America to Southeast Asia: The Fragile Web of REF7707

REF7707 targeted a South American foreign ministry using novel malware families. Inconsistent evasion tactics and operational security missteps exposed addit...

Elastic Security Labs → Details

Elastic Security Labs research Linux Feb 11

Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms

Building on foundational concepts and techniques explored in the previous publications, this post discusses some creative and/or complex persistence mechanisms.

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Jan 29

Announcing the Elastic Bounty Program for Behavior Rule Protections

Elastic is launching an expansion of its security bounty program, inviting researchers to test its SIEM and EDR rules for evasion and bypass techniques, star...

Elastic Security Labs → Details

Elastic Security Labs research Linux Jan 27

Linux Detection Engineering - A Continuation on Persistence Mechanisms

This document continues the exploration of Linux detection engineering, emphasizing advancements in monitoring persistence mechanisms. By building on past pr...

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Jan 24

WinVisor – A hypervisor-based emulator for Windows x64 user-mode executables

WinVisor is a hypervisor-based emulator for Windows x64 user-mode executables that leverages the Windows Hypervisor Platform API to provide a virtualized env...

Elastic Security Labs → Details

Elastic Security Labs research Jan 9

Detonating Beacons to Illuminate Detection Gaps

Learn how Elastic Security leveraged open-source BOFs to achieve detection engineering goals during our most recent ON week.

Elastic Security Labs → Details

Elastic Security Labs research Dec 13

Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite

Elastic Security Labs share details about the SADBRIDGE loader and GOSAR backdoor, malware used in campaigns targeting Chinese-speaking victims.

Elastic Security Labs → Details

Elastic Security Labs research Linux Dec 12

Declawing PUMAKIT

PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with...

Elastic Security Labs → Details

Elastic Security Labs research Apple Amazon Dec 10

Exploring AWS STS AssumeRoot

Explore AWS STS AssumeRoot, its risks, detection strategies, and practical scenarios to secure against privilege escalation and account compromise using Elas...

T1548

Elastic Security Labs → Details

Elastic Security Labs research Amazon Nov 14

Streamlining Security: Integrating Amazon Bedrock with Elastic

This article will guide you through the process of setting up the Amazon Bedrock integration and enabling Elastic's prebuilt detection rules to streamline yo...

Elastic Security Labs → Details

Elastic Security Labs research Google Oct 28

Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses

Elastic Security Labs breaks down bypass implementations from the infostealer ecosystem’s reaction to Chrome 127's Application-Bound Encryption scheme.

Elastic Security Labs → Details

Elastic Security Labs research Oct 19

Tricks and Treats: GHOSTPULSE’s new pixel-level deception

The updated GHOSTPULSE malware has evolved to embed malicious data directly within pixel structures, making it harder to detect and requiring new analysis an...

Elastic Security Labs → Details

Elastic Security Labs research Oct 18

Elevate Your Threat Hunting with Elastic

Elastic is releasing a threat hunting package designed to aid defenders with proactive detection queries to identify actor-agnostic intrusions.

Elastic Security Labs → Details

Elastic Security Labs research Oct 1

Elastic publishes 2024 Global Threat Report

Elastic Security Labs has released the 2024 Elastic Global Threat Report, surfacing the most pressing threats, trends, and recommendations to help keep organ...

Elastic Security Labs → Details

Elastic Security Labs research Google Apple Linux Sep 28

Cups Overflow: When your printer spills more than Ink

Elastic Security Labs discusses detection and mitigation strategies for vulnerabilities in the CUPS printing system, which allow unauthenticated attackers to...

T1190

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 27

Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse

The REF6138 campaign involved cryptomining, DDoS attacks, and potential money laundering via gambling APIs, highlighting the attackers' use of evolving malwa...

T1498

Elastic Security Labs → Details

«Previous page 1 ... 7 8 9 10 11 ... 17 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA