elastic security labs logo
About
Vulnerability updatesReportsTools
SubscribeStart free trialContact sales

Author

Ruben Groenewoud

Security Research Engineer, Elastic

Subscribe

Articles

Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse
27 September 2024

Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse

The REF6138 campaign involved cryptomining, DDoS attacks, and potential money laundering via gambling APIs, highlighting the attackers' use of evolving malware and stealthy communication channels.

Linux Detection Engineering - A Sequel on Persistence Mechanisms
30 August 2024

Linux Detection Engineering - A Sequel on Persistence Mechanisms

In this final part of this Linux persistence series, we'll continue exploring persistence mechanisms on Linux systems, focusing on more advanced techniques and how to detect them.

Linux Detection Engineering - A primer on persistence mechanisms
21 August 2024

Linux Detection Engineering - A primer on persistence mechanisms

In this second part of the Linux Detection Engineering series, we map multiple Linux persistence mechanisms to the MITRE ATT&CK framework, explain how they work, and how to detect them.

Linux detection engineering with Auditd
9 April 2024

Linux detection engineering with Auditd

In this article, learn more about using Auditd and Auditd Manager for detection engineering.

An Elastic approach to large-scale dynamic malware analysis
31 July 2023

An Elastic approach to large-scale dynamic malware analysis

This research reveals insights into some of the large-scale malware analysis performed by Elastic Security Labs, and complements research related to the Detonate framework.

  • Sitemap
  • Elastic.co
  • @elasticseclabs

© 2024. Elasticsearch B.V. All Rights Reserved.