CW

Colson Wilhoit

Inscreva-se
Artigos de Colson Wilhoit
Elastic releases detections for the Axios supply chain compromise
Security Labs

Elastic releases detections for the Axios supply chain compromise

Hunting and detection rules for the Elastic-discovered Axios supply chain compromise.

Ruben Groenewoud
Inside the Axios supply chain compromise - one RAT to rule them all
Security Labs

Inside the Axios supply chain compromise - one RAT to rule them all

Elastic Security Labs analyzes a supply chain compromise of the axios npm package delivering a unified cross-platform RAT

Ruben Groenewoud
Bit ByBit - emulation of the DPRK's largest cryptocurrency heist
Security Labs

Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

A high-fidelity emulation of the DPRK's largest cryptocurrency heist via a compromised macOS developer and AWS pivots.

Colson Wilhoit
Code of Conduct: DPRK’s Python-fueled intrusions into secured networks
Security Labs

Code of Conduct: DPRK’s Python-fueled intrusions into secured networks

Investigating the DPRK’s strategic use of Python and carefully crafted social engineering, this publication sheds light on how they breach highly secure networks with evolving and effective cyber attacks.

Colson Wilhoit
Sinking macOS Pirate Ships with Elastic Behavior Detections
Security Labs

Sinking macOS Pirate Ships with Elastic Behavior Detections

This research looks at a recently found macOS malware campaign using the macOS Endpoint Security Framework paired with the Elastic Agent to hunt and detect the behaviors this malware exhibits.

Colson Wilhoit
Elastic catches DPRK passing out KANDYKORN
Security Labs

Elastic catches DPRK passing out KANDYKORN

Elastic Security Labs exposes an attempt by the DPRK to infect blockchain engineers with novel macOS malware.

Colson Wilhoit
The DPRK strikes using a new variant of RUSTBUCKET
Security Labs

The DPRK strikes using a new variant of RUSTBUCKET

Watch out! We’ve recently discovered a variant of RUSTBUCKET. Read this article to understand the new capabilities we’ve observed, as well as how to identify it in your own network.

Salim Bitam
Initial research exposing JOKERSPY
Security Labs

Initial research exposing JOKERSPY

Explore JOKERSPY, a recently discovered campaign that targets financial institutions with Python backdoors. This article covers reconnaissance, attack patterns, and methods of identifying JOKERSPY in your network.

Colson Wilhoit
The Elastic Container Project for Security Research
Security Labs

The Elastic Container Project for Security Research

The Elastic Container Project provides a single shell script that will allow you to stand up and manage an entire Elastic Stack using Docker. This open source project enables rapid deployment for testing use cases.

Andrew Pease
Detecting and responding to Dirty Pipe with Elastic
Security Labs

Detecting and responding to Dirty Pipe with Elastic

Elastic Security is releasing detection logic for the Dirty Pipe exploit.

Colson Wilhoit
A peek behind the BPFDoor
Security Labs

A peek behind the BPFDoor

In this research piece, we explore BPFDoor — a backdoor payload specifically crafted for Linux in order to gain re-entry into a previously or actively compromised target environment.

Jake King