Elastic Global Threat Report Multipart Series Overview
Blog Each month, the Elastic Security Labs team dissects a different trend or correlation from the Elastic Global Threat Report. This post provides an overview…
Blog Each month, the Elastic Security Labs team dissects a different trend or correlation from the Elastic Global Threat Report. This post provides an overview…
Preamble ICEDID is a malware family discoveredin 2017 by IBM X-force researchers and is associated with the theft of login credentials, banking information, and other…
Preamble Imagine you are an Endpoint artifact developer. After you put in the work to ensure protection against conventional shellcode injections or ransomware innovations, how…
Searching for a way to help protect your network from potential domain generation algorithm (DGA) attacks? Look no further — a DGA detection package is…
Introduction Bring Your Own Vulnerable Driver (BYOVD) is an increasingly popular attacker technique wherein a threat actor brings a known-vulnerable signed driver alongside their malware,…
Using LLMs to summarize user sessions With the introduction of the AI Assistant into the Security Solution in 8.8, the Security Machine Learning team at…
Using LLMs and ESRE to find similar user sessions In our previous article, we explored using the GPT-4 Large Language Model (LLM) to condense complex…
One of the amazing, recently premiered 8.11.0 features, is the Elasticsearch Query Language (ES|QL). As highlighted in an earlier post by Costin Leau, it’s a…
Your security data is the most important asset in your SOC. Not the dashboards, not the detections, not the AI features on the roadmap slide.…
Preamble Organizations that use threat indicators or observables consume, create, and/or (ideally) publish threat data. This data can be used internally or externally as information…
Preamble When prioritizing detection engineering efforts, it’s essential to understand the most prevalent tactics, techniques, and procedures (TTPs) observed in the wild. This knowledge helps…
Preamble A critical feature of secure-by-design software is the generation of audit logs when privileged operations are performed. These native audit logs can include details…