Peeling back the curtain with call stacks
ID: 11f733d0-68d2-5eaf-b55b-a3a4ca139e92
STIX ID: report--11f733d0-68d2-5eaf-b55b-a3a4ca139e92
Feed Name: Elastic Security Labs
This article explains how Elastic Defend’s kernel call stack enrichments improve detection fidelity and interpretability of EDR events, illustrating investigations (e.g., WMI consumer launches, scheduled tasks, ZIP shell extension execution) and advanced detections for techniques like process reflection (Dirty Vanity), direct syscalls, OLE-embedded payload drops, ransomware-style renames from injected processes, rogue service DLLs, unsigned print monitors, ROP-based DLL loads, LdrpKernel32 bootstrap hijack, and remote registry modifications, with actionable EQL/KQL examples to operationalize these detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
