Call Stacks: No More Free Passes For Malware
ID: 874c765b-2027-5f0c-bcc6-c9aef9e4361a
STIX ID: report--874c765b-2027-5f0c-bcc6-c9aef9e4361a
Feed Name: Elastic Security Labs
Elastic Security Labs technical overview of Windows call stacks: explains how call stacks are recovered (stack walking vs CPU tracing), how addresses are enriched with module exports or public symbols, common malware evasion techniques (tail calls, trampoline frames, return-address spoofing), and the heuristics Elastic uses (e.g., proxy_call, shellcode, unbacked_rwx) to surface and triage suspicious activity from endpoint telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
