Výsledky hledání

výrobce: Elastic× téma: malware× v celém archivu zrušit filtry

4 karet z 4 položek CZ · EN/orig

1

Linux Detection Engineering - Fileless Execution

Fileless execution on Linux has moved from niche tradecraft into real-world intrusion chains. By executing payloads from memory or anonymous file descriptors, attackers can reduce on-disk artifacts and weaken controls that rely heavily on file inspection.In our own analysis of VoidLink, we observed how fileless execution can be paired with a rootkit. The loader scans for processes running from memfd and passes their PIDs to the rootkit, allowing an already running fileless implant to be hidden…

Elastic US

tg: rozbor tg: propagace tp: malware tp: AI

Elastic Security ·

1

From 88 lines to 1: Detecting DLL hijacking with Elastic Defend

Elastic Defend 9.5.0 detects dynamic link library (DLL) search-order hijacking [1] in a single field. Writing that rule before 9.5.0 took about 88 lines, covering approximately 2,600 named libraries, 10 excluded Windows system paths, signature checks, and a drop-to-load time window. It now takes one: dll.Ext.defense_evasions: "DLL Hijack: Masquerading".DLL search-order hijacking, which Defend labels Masquerading, runs attacker code inside a legitimate process by abusing the order that Windows…

Elastic US

tg: rozbor tg: novinka v produktu tg: propagace tp: malware

Elastic Security ·

2

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

We know you’re tired of hearing how every vendor is going to finally help you solve alert fatigue. Well, one way we’re improving alert fatigue is from a slightly different angle, better prevention at the endpoint. Because stopping more at the endpoint means fewer alerts ever raised. We have three endpoint enhancements, all contributing to better endpoint prevention: To be even more proactive about Bring Your Own Vulnerable Driver (BYOVD) attacks, we’re continuously monitoring public vulnerable…

Elastic US

tg: novinka v produktu tg: propagace tp: malware

Elastic Security ·

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

We know you’re tired of hearing how every vendor is going to finally help you solve alert fatigue. Well, one way we’re improving alert fatigue is from a slightly different angle, better prevention at the endpoint. Because stopping more at the endpoint means fewer alerts ever raised. We have three endpoint enhancements, all contributing to better endpoint prevention: To be even more proactive about Bring Your Own Vulnerable Driver (BYOVD) attacks, we’re continuously monitoring public vulnerable…

Elastic US

tg: novinka v produktu tg: propagace tp: malware

Elastic Security ·