Log inSign up
Elastic Security Labs
605 posts
Image
user avatar
Elastic Security Labs
@elasticseclabs
Elastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
Global
elastic.co/security-labs/
Joined November 2022
727
Following
5,506
Followers
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Sep 13, 2023
    Check out this new article from @SBousseaden that explores call stacks. Understand what they are and how they can be used for detections. Learn more:
    In this article, we'll show you how we contextualize rules and events, and how you can leverage call stacks to better understand any alerts you encounter in your environment.
    Peeling back the curtain with call stacks — Elastic Security Labs
    From elastic.co
    82K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Jan 28, 2025
    We’re adding a new section to @elastic’s HackerOne Bounty Program! Today, we’re opening our SIEM and EDR rules for testing. We’re excited to have another way to thank our community for their efforts on our #detectionengineering. Get more details here:
    Elastic is launching an expansion of its security bounty program, inviting researchers to test its SIEM and EDR rules for evasion and bypass techniques, starting with Windows endpoints. This initiative strengthens collaboration with the security community, ensuring Elastic’s defenses remain robust against evolving threats.
    Announcing the Elastic Bounty Program for Behavior Rule Protections — Elastic Security Labs
    From elastic.co
    29K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Aug 5, 2024
    This new article from @dez_ reveals 4 attack techniques linked to SmartScreen and SmartAppControl. Check it out: go.es.io/4d5L2BR Will you be at #BHUSA? Stop by @elastic booth #2350 to chat with Joe or catch his lightning talk! #ElasticSecurityLabs #threattechnique
    This article will explore Windows Smart App Control and SmartScreen as a case study for researching bypasses to reputation-based systems, then demonstrate detections to cover those weaknesses.
    Dismantling Smart App Control — Elastic Security Labs
    From elastic.co
    64K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Sep 3, 2024
    #ElasticSecurityLabs is introducing HexForge, our tool that enhances #IDAPro with manipulation capabilities built into the hex and disassembly views. HexForge makes it easy to copy and patch binary data and currently supports RC4, AES, ChaCha20, and XOR:
    Image
    GitHub - elastic/HexForge: This IDA plugin extends the functionality of the assembly and hex view....
    From github.com
    19K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Oct 17, 2024
    Threat hunting just got easier! This new repo of detection rules is crafted by our veteran detection engineers and powered by different Elastic query languages. Get the details of what’s included and see the future of this repo here: go.es.io/4h2JsTX #ElasticSecurityLabs
    Elastic is releasing a threat hunting package designed to aid defenders with proactive detection queries to identify actor-agnostic intrusions.
    Elevate Your Threat Hunting with Elastic — Elastic Security Labs
    From elastic.co
    62K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Jul 3, 2025
    New research from our #ElasticSecurityLabs team: we dive into how infostealers are leveraging a stolen Shellter evasion tool to deploy data-stealing malware. Learn more & get our unpacker: go.es.io/4ldCM72 #malware #rhadamanthys #ghostpulse
    elastic.co
    Taking SHELLTER: a commercial evasion framework abused in-the-wild — Elastic Security Labs
    Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to deploy post-exploitation payloads.
    25K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Sep 5, 2024
    Detection engineering is complicated, but this new 5 tier maturity model from @stryker0x, @_xDeJesus, and @SBousseaden provides guidance for security teams: go.es.io/3MySV7l #ElasticSecurityLabs #detectionengineering #maturitymodel
    7.9K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Jun 13, 2025
    Dive deep into malware detection with the latest article by John Uhlmann: "Call Stacks: No More Free Passes for Malware." Discover how call stacks provide vital insights into malware behavior. Read more:
    We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the architectural limitations.
    Call Stacks: No More Free Passes For Malware — Elastic Security Labs
    From elastic.co
    9.7K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Feb 8, 2023
    Check out the latest #ElasticSecurityLabs research from @SBousseaden, a deep-dive into hunting for malicious DLLs for #threatdetection: go.es.io/3jMg8rL
    37K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    May 30, 2023
    Kernel-level callstack visibility is essential for in-memory #ThreatDetection of #Malware and defense evasions, #ElasticSecurityLabs researchers @dez_, @GabrielLandau, and @SBousseaden explain the research behind this capability: go.es.io/42d0Mge
    33K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Jun 21, 2024
    #ElasticSecurityLabs is exposing a new threat technique — a fresh application of MMC abuse. GRIMRESOURCE utilizes specially crafted MSC files for full code execution. Read through the breakdown from @dez_ and @SBousseaden : go.es.io/45AO0eG #threattechnique #cybersecurity
    11K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Aug 28, 2025
    #ElasticSecurityLabs continues to observe phishing campaigns leveraging Cloudflare tunnels distributing multiple malware families (#VenomRAT, #DCRat, #XWorm) simultaneously. These threat actors are abusing LLMs to produce simple Python shellcode loaders for injection
    Image
    28K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Oct 28, 2024
    The #ElasticSecurityLabs team breaks down a recent Chrome update that introduced App-Bound Encryption and how the most common #infostealers have adapted:
    Elastic Security Labs breaks down bypass implementations from the infostealer ecosystem’s reaction to Chrome 127's Application-Bound Encryption scheme.
    Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses — Elastic Security Labs
    From elastic.co
    16K
  • user avatar
    Elastic Security Labs
    @elasticseclabs
    Jun 17, 2025
    New research from #ElasticSecurityLabs uncovers a new ClickFix campaign! Learn how attackers are using GHOSTPULSE and ARECHCLIENT2 (SECTOPRAT) in multi-stage attacks to deploy RATs and steal data. Stay informed:
    Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.
    A Wretch Client: From ClickFix deception to information stealer deployment — Elastic Security Labs
    From elastic.co
    14K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement