Elevate Your Threat Hunting with Elastic
ID: 31ad0d62-792b-5f0b-aa91-413849cfc3f7
STIX ID: report--31ad0d62-792b-5f0b-aa91-413849cfc3f7
Feed Name: Elastic Security Labs
Elastic announces a new Hunting package in the Detection Rules repository that delivers curated, MITRE ATT&CK-mapped hunting queries across endpoints, cloud, network, and other integrations, plus CLI tooling to generate, search, run, and manage hunts. The resource aims to complement SIEM/EDR detections, offering standardized TOML/Markdown queries in multiple languages (ES|QL, EQL, KQL, OsQuery, YARA), and includes an example hunt for suspicious Okta OAuth client-credentials activity, with guidance on creating, indexing, and executing hunts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
