Phishing incident response with Elastic and Sublime Security
Critical signals still land in different security tools, so early signs of a campaign might go unnoticed. That visibility gap is getting more expensive as…
Critical signals still land in different security tools, so early signs of a campaign might go unnoticed. That visibility gap is getting more expensive as…
Summary The Microsoft 365 Defender team released a post detailing several identified vulnerabilities. These vulnerabilities allow adversarial groups to easily escalate privileges on Linux systems,…
Threat Hunters are charged with the difficult task of sifting through vast sources of diverse data to pinpoint adversarial activity at any stage in the…
Hunting-memory-hunting_in_memory_.net_1.png In past blog posts, we shared our approach to hunting for traditional in-memory attacks along with in-depth analysis of many injection techniques. As a…
The Elastic Security Intelligence & Analytics Team researches adversary innovations of many kinds, and has recently focused on an activity group that leveraged remote templates,…
Key takeaways:
Preamble In 8.3, our Elastic Stack Machine Learning team introduced a way to import third party Natural Language Processing (NLP) models into Elastic. As security…
Preamble Dirty Pipe is a local privilege escalation vulnerability that is easily exploitable with a handful of working exploit POCs already available. Its broad scope…
Please check out our previous post on how to collect Cobalt Strike beacon implants. We’ll build on that information to extract the configurations from the…
Introduction On February 23, 2022, the ESET threat research team disclosed a series of findings pertaining to a Data Wiper malware campaign, impacting hundreds of…
I’ve been fortunate to work for some truly great leaders at some amazing companies. The common thread is always the same: when culture is protected,…
On August 3, we released Protections-artifacts as part of our Openness Initiative . One of the benefits of producing open and transparent security content is…