Author
Articles by Justin Higdon
Principal Solutions Architect

Hunting with Elastic Security: Detecting command and scripting interpreter execution
Uncover malicious script execution with ES|QL. This blog walks through detecting interpreter abuse (PowerShell, Bash, Python) using ECS-aligned data and practical queries. Start your threat hunting journey with the power of the Search AI Platform.

Hunting with Elastic Security: Unmasking concealed artifacts with Elastic Stack insights
Explore how to detect hidden threats with ELK Stack. Learn how adversaries are leveraging T1564 - Hide Artifacts to conceal files, processes, and more. Strengthen your defenses against with actionable insights and tailored ES|QL queries.

Hunting with Elastic Security: Detecting credential dumping with ES|QL
Discover how to detect OS Credential Dumping (T1003) in this comprehensive guide. Learn how to unmask adversaries, protect your credentials, and fortify your defenses with actionable insights and ES|QL queries tailored for detection.
Sign up for Elastic Cloud free trial
Spin up a fully loaded deployment on the cloud provider you choose. As the company behind Elasticsearch, we bring our features and support to your Elastic clusters in the cloud.