logo

Upping the Ante: Detecting In-Memory Threats with Kernel Call Stacks

ID: a23e193f-63fd-5859-906c-02f91f99c814

STIX ID: report--a23e193f-63fd-5859-906c-02f91f99c814

Feed Name: Elastic Security Labs

Date Published: 2023-05-31

Date Updated: 2026-04-27

...
...

Elastic Security 8.8 introduces kernel call stack–based detections that enrich process, file, registry, and library events to more accurately detect in-memory tradecraft and reduce false positives; the update ships with 30+ behavior rules targeting techniques such as direct syscalls, callback-based evasion, module stomping, unbacked memory execution, and malicious Office macro activity, and provides example EQL queries for hunting and tuning, while also highlighting improved coverage of C2 frameworks like Nighthawk, Brute Ratel, Cobalt Strike, and APT41’s StealthVector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.