logo

An Elastic approach to large-scale dynamic malware analysis

ID: 8d033020-e973-5605-995e-35dc823d7c58

STIX ID: report--8d033020-e973-5605-995e-35dc823d7c58

Feed Name: Elastic Security Labs

Threat Score
15/100

Date Published: 2023-07-31

Date Updated: 2026-04-27

...
...

Elastic Security Labs presents a workflow for large-scale dynamic malware analysis using the Detonate sandbox and chained Elasticsearch ingest pipelines to normalize events, compute fingerprints, create enrich policies of known benign telemetry, and filter noise; they provide automation scripts and report that after detonating 332 samples the pipeline reduced benign/duplicate telemetry by ~96.8% while exposing malicious behaviors such as ransomware file activity and C2 connection attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.