An Elastic approach to large-scale dynamic malware analysis
ID: 8d033020-e973-5605-995e-35dc823d7c58
STIX ID: report--8d033020-e973-5605-995e-35dc823d7c58
Feed Name: Elastic Security Labs
Elastic Security Labs presents a workflow for large-scale dynamic malware analysis using the Detonate sandbox and chained Elasticsearch ingest pipelines to normalize events, compute fingerprints, create enrich policies of known benign telemetry, and filter noise; they provide automation scripts and report that after detonating 332 samples the pipeline reduced benign/duplicate telemetry by ~96.8% while exposing malicious behaviors such as ransomware file activity and C2 connection attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
