logo

Elastic Security Labs

ID: 3b67b5ad-2c09-590d-9457-06e4d7970a2f

STIX ID: identity--3b67b5ad-2c09-590d-9457-06e4d7970a2f

Feed Type: rss

Earliest post: 2020-05-30

Latest post: 2026-05-26

Advanced threat research, detection engineering insights, and security analysis from the Elastic Security Labs team — covering adversary techniques, anomaly detection, malware behavior, and defensive strategies powered by Elastic data.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace2026-05-26TrueTrue
Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild2026-05-09TrueTrue
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook2026-05-07TrueTrue
DFIR: From alert to root cause using Osquery without leaving Elastic Security2026-05-01TrueTrue
CI/CD pipeline abuse: the problem no one is watching2026-04-29TrueTrue
The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation2026-04-21TrueTrue
Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT2026-04-14TrueTrue
How we caught the Axios supply chain attack2026-04-02TrueTrue
Hooked on Linux: Rootkit Detection Engineering2026-04-02TrueTrue
Inside the Axios supply chain compromise - one RAT to rule them all2026-04-01TrueTrue
Elastic releases detections for the Axios supply chain compromise2026-04-01TrueTrue
Fake Installers to Monero: A Multi-Tool Mining Operation2026-03-31TrueTrue
Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER2026-03-27TrueTrue
Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework2026-03-26TrueTrue
Supercharge Your SOC2026-03-24TrueTrue
Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario2026-03-20TrueTrue
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect2026-03-19TrueTrue
Patch diff to SYSTEM2026-03-06TrueTrue
Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft2026-03-05TrueTrue
The Immutable Illusion: Pwning Your Kernel with Cloud Files2026-02-20TrueTrue
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites2026-02-20TrueTrue
Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder2026-02-18TrueTrue
BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign2026-02-11TrueTrue
SolarWinds Web Help Desk Exploitation - February 20262026-02-10TrueTrue
DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector2026-02-06TrueTrue
Automating GOAD and Live Malware Labs2026-02-05TrueTrue
NANOREMOTE, cousin of FINALDRAFT2025-12-11TrueTrue
RONINGLOADER: DragonBreath’s New Path to PPL Abuse2025-11-15TrueTrue
TOLLBOOTH: What's yours, IIS mine2025-10-22TrueTrue
NightMARE on 0xelm Street, a guided tour2025-10-14TrueTrue
What the 2025 Elastic Global Threat Report reveals about the evolving threat landscape2025-10-08TrueTrue
WARMCOOKIE One Year Later: New Features and Fresh Insights2025-10-01TrueTrue
FlipSwitch: a Novel Syscall Hooking Technique2025-09-30TrueTrue
MCP Tools: Attack Vectors and Defense Recommendations for Autonomous Agents2025-09-19TrueTrue
MaaS Appeal: An Infostealer Rises From The Ashes2025-07-29TrueTrue
Taking SHELLTER: a commercial evasion framework abused in-the-wild 2025-07-03TrueTrue
Microsoft Entra ID OAuth Phishing and Detections2025-06-25TrueTrue
A Wretch Client: From ClickFix deception to information stealer deployment2025-06-18TrueTrue
Chasing Eddies: New Rust-based InfoStealer used in CAPTCHA campaigns2025-05-30TrueTrue
De-obfuscating ALCATRAZ2025-05-23TrueTrue
Bit ByBit - emulation of the DPRK's largest cryptocurrency heist2025-05-06TrueTrue
Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective2025-04-01TrueTrue
The Shelby Strategy2025-03-26TrueTrue
Shedding light on the ABYSSWORKER driver2025-03-20TrueTrue
Detecting Hotkey-Based Keyloggers Using an Undocumented Kernel Data Structure2025-03-04TrueTrue
未公開のカーネルデータ構造を使ったホットキー型キーロガーの検知2025-03-04TrueTrue
From South America to Southeast Asia: The Fragile Web of REF77072025-02-13TrueTrue
You've Got Malware: FINALDRAFT Hides in Your Drafts2025-02-13TrueTrue
Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite2024-12-13TrueTrue
Declawing PUMAKIT2024-12-12TrueTrue

1–50 of 148