logo

DFIR: From alert to root cause using Osquery without leaving Elastic Security

ID: 3c6c93b5-0680-5701-b009-c5736d4f92fd

STIX ID: report--3c6c93b5-0680-5701-b009-c5736d4f92fd

Feed Name: Elastic Security Labs

Threat Score
45/100

Date Published: 2026-05-01

Date Updated: 2026-08-27

Author: Raquel Tabuyo

...
...

This report explains a modern, query-driven DFIR approach using Osquery and Elastic Defend to perform live, fleet-scale forensics and detection; it demonstrates the workflow with a phishing-to-Mimikatz example showing how browser history, file lookups, Shellbags, Shimcache, UserAssist, and Prefetch evidence are used to reconstruct an attack and generate IoCs and detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.