EL

Elastic Security Labs

Articles by Elastic Security Labs

SolarWinds Web Help Desk Exploitation - February 2026

Elastic Security detection and prevention capabilities for the recently-disclosed SolarWinds Web Help Desk vulnerabilities.

Elastic Security Labs

DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector

Learn how Elastic Defend's ransomware protection successfully detects and prevents DYNOWIPER execution using canary file monitoring.

Elastic Security Labs

WinVisor – A hypervisor-based emulator for Windows x64 user-mode executables

WinVisor is a hypervisor-based emulator for Windows x64 user-mode executables that leverages the Windows Hypervisor Platform API to provide a virtualized environment for logging syscalls and enabling memory introspection.

Elastic Security Labs

NETWIRE Configuration Extractor

Python script to extract the configuration from NETWIRE samples.

Elastic Security Labs

QBOT Configuration Extractor

Python script to extract the configuration from QBOT samples.

Elastic Security Labs

ICEDID Configuration Extractor

Python script to extract the configuration from ICEDID samples.

Elastic Security Labs

BPFDoor Configuration Extractor

Configuration extractor to dump out hardcoded passwords with BPFDoor.

Elastic Security Labs

PARALLAX Payload Extractor

Python script to extract the payload from PARALLAX samples.

Elastic Security Labs

BPFDoor Scanner

Python script to identify hosts infected with the BPFDoor malware.

Elastic Security Labs

Cobalt Strike Beacon Extractor

Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beacon, and writes the data back to Elasticsearch.

Elastic Security Labs

EMOTET Configuration Extractor

Python script to extract the configuration from EMOTET samples.

Elastic Security Labs

BLISTER Configuration Extractor

Python script to extract the configuration and payload from BLISTER samples.

Elastic Security Labs

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

Elastic Security Labs

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Every stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection.

Elastic Security Labs

Investigating a Mysteriously Malformed Authenticode Signature

An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.

Elastic Security Labs

MaaS Appeal: An Infostealer Rises From The Ashes

NOVABLIGHT is a NodeJS infostealer developed and sold as a MaaS offering; it is used primarily to steal credentials and compromise cryptowallets.

Jia Yu Chan

Beyond the wail: deconstructing the BANSHEE infostealer

The BANSHEE malware is a macOS-based infostealer that targets system information, browser data, and cryptocurrency wallets.

Elastic Security Labs