Author
John Uhlmann
Senior Security Research Engineer, Elastic
Articles
data:image/s3,"s3://crabby-images/a8596/a859644d52f7a11f4dbe896e54a20eab87f40235" alt="Kernel ETW is the best ETW"
Kernel ETW is the best ETW
This research focuses on the importance of native audit logs in secure-by-design software, emphasizing the need for kernel-level ETW logging over user-mode hooks to enhance anti-tamper protections.
data:image/s3,"s3://crabby-images/f941c/f941c4534c8585a40fbd713b771f5d6ea8663f5f" alt="Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks"
Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks
With Elastic Security 8.11, we added further kernel telemetry call stack-based detections to increase efficacy against in-memory threats.
data:image/s3,"s3://crabby-images/64753/647535c4cf32d1485eb0649fe8958bc6a85b78c8" alt="Effective Parenting - detecting LRPC-based parent PID spoofing"
Effective Parenting - detecting LRPC-based parent PID spoofing
Using process creation as a case study, this research will outline the evasion-detection arms race to date, describe the weaknesses in some current detection approaches and then follow the quest for a generic approach to LRPC-based evasion.
data:image/s3,"s3://crabby-images/62a51/62a51b7a6d133187ba3eeeb5f9e1e16856844076" alt="Get-InjectedThreadEx – Detecting Thread Creation Trampolines"
Get-InjectedThreadEx – Detecting Thread Creation Trampolines
In this blog, we will demonstrate how to detect each of four classes of process trampolining and release an updated PowerShell detection script – Get-InjectedThreadEx