Upping the Ante: Detecting In-Memory Threats with Kernel Call Stacks
ID: a23e193f-63fd-5859-906c-02f91f99c814
STIX ID: report--a23e193f-63fd-5859-906c-02f91f99c814
Feed Name: Elastic Security Labs
Elastic Security 8.8 introduces kernel call stack–based detections that enrich process, file, registry, and library events to more accurately detect in-memory tradecraft and reduce false positives; the update ships with 30+ behavior rules targeting techniques such as direct syscalls, callback-based evasion, module stomping, unbacked memory execution, and malicious Office macro activity, and provides example EQL queries for hunting and tuning, while also highlighting improved coverage of C2 frameworks like Nighthawk, Brute Ratel, Cobalt Strike, and APT41’s StealthVector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
