Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks
ID: 32cd6bb8-a1c6-5f17-bbb3-d9542840e961
STIX ID: report--32cd6bb8-a1c6-5f17-bbb3-d9542840e961
Feed Name: Elastic Security Labs
Elastic details new Windows in-memory threat visibility and behavior-based detections in Elastic Defend 8.11, leveraging kernel Threat-Intelligence ETW to monitor high-risk APIs (e.g., VirtualAlloc/VirtualProtect, WriteProcessMemory) and enriched behaviors (direct syscalls, proxying, shellcode, memory protection fluctuations). The release adds host-processed, SIEM-optional API events and rules to detect techniques like threadless injection, indirect and direct syscalls, image hollowing, AMSI/WLDP and ETW patching, and remote module hooking—aimed at improving detection fidelity while controlling telemetry volume.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
