What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
ID: 3895e4b1-683a-52b7-ad64-b915ccb6091a
STIX ID: report--3895e4b1-683a-52b7-ad64-b915ccb6091a
Feed Name: Elastic Security Labs
Elastic Security describes three endpoint enhancements: continuous monitoring of public vulnerable-driver disclosures with automatic generation and open publishing of detection rules to counter BYOVD (Bring Your Own Vulnerable Driver) attacks; an Automatic Troubleshooting skill in Elastic Agent Builder to speed diagnosis and remediation; and expanded Elastic Defend coverage for Windows on ARM devices. The write-up explains how BYOVD enables kernel-level bypasses commonly abused by ransomware, the public sources monitored (VirusTotal, LOLDrivers, Microsoft blocklist), and that protections are published openly and deployed continuously to reduce the window of exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
