logo

Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks

ID: 32cd6bb8-a1c6-5f17-bbb3-d9542840e961

STIX ID: report--32cd6bb8-a1c6-5f17-bbb3-d9542840e961

Feed Name: Elastic Security Labs

Date Published: 2024-01-09

Date Updated: 2026-04-27

...
...

Elastic details new Windows in-memory threat visibility and behavior-based detections in Elastic Defend 8.11, leveraging kernel Threat-Intelligence ETW to monitor high-risk APIs (e.g., VirtualAlloc/VirtualProtect, WriteProcessMemory) and enriched behaviors (direct syscalls, proxying, shellcode, memory protection fluctuations). The release adds host-processed, SIEM-optional API events and rules to detect techniques like threadless injection, indirect and direct syscalls, image hollowing, AMSI/WLDP and ETW patching, and remote module hooking—aimed at improving detection fidelity while controlling telemetry volume.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.