Threat Command

Primary threat research from Elastic Security Labs Threat Command.

Filters
Linux Detection Engineering - Local Privilege Escalation

Linux Detection Engineering - Local Privilege Escalation

Seven of the thirteen Linux privilege escalation CVEs we tracked in 2026 turned out to be the same copy-on-write bug pointed at different kernel interfaces. We ran the public proof-of-concept for eleven exploits and two misconfigurations, and noted which rules fired.

Ruben Groenewoud
How to correlate Kubernetes audit logs with container runtime data

How to correlate Kubernetes audit logs with container runtime data

Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded.

Isai Anthony
REVSTEALER ramps up: analysis of up-and-coming infostealer

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts.

Daniel Stepanic
Linux Detection Engineering - Fileless Execution

Linux Detection Engineering - Fileless Execution

We reproduced five Linux fileless execution patterns with FENIX, including memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kernel module loads, then mapped each to the Elastic Defend rules that catch it.

Ruben Groenewoud
From 88 lines to 1: Detecting DLL hijacking with Elastic Defend

From 88 lines to 1: Detecting DLL hijacking with Elastic Defend

The ClickFix campaign that sideloads a malicious mscoree.dll also ships a driver to kill Elastic Endpoint. We rebuilt that DLL as a NativeAOT library, dropped it beside a signed Microsoft binary, and Elastic Defend 9.5.0 flagged the load.

Ian Garratt
Living off the coding agent: Two tales of tunnels and LaunchAgents

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

Mika Ayenson
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

Elastic Security Labs
Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows

Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows

Public leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execution traces, blind judging) across Agent Builder, Attack Discovery, and automatic migration.

Dhrumil Patel
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Every stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection.

Elastic Security Labs
New North Korean campaign uses fake coding interviews to steal developer credentials

New North Korean campaign uses fake coding interviews to steal developer credentials

DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.

Daniel Stepanic
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

TELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.

Cyril François
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.

Jia Yu Chan