Category: Threat Hunting

Articles tagged Threat Hunting

Subscribe
Filters
Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass
Security Labs

Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass

We reproduced this java deserialization vulnerability against official Log4j 2.26.1 JARs. Getting to command execution took two more things that Log4j itself does not ship. Here is how the bypass works, which versions carry it, and what to hunt for.

Ruben Groenewoud
Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response
Security Labs

Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

This article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.

Erik-Jan de Kruijf
Prioritizing Alerts Triage with Higher-Order Detection Rules
Security Labs

Prioritizing Alerts Triage with Higher-Order Detection Rules

Scaling SOC efficiency through multi-signal correlation and higher-order detection patterns.

Samir Bousseaden
Elastic releases detections for the Axios supply chain compromise
Security Labs

Elastic releases detections for the Axios supply chain compromise

Hunting and detection rules for the Elastic-discovered Axios supply chain compromise.

Ruben Groenewoud
SolarWinds Web Help Desk Exploitation - February 2026
Security Labs

SolarWinds Web Help Desk Exploitation - February 2026

Elastic Security detection and prevention capabilities for the recently-disclosed SolarWinds Web Help Desk vulnerabilities.

Elastic Security Labs
From Hypothesis to Action: Proactive Threat Hunting with Elastic Security
Security Labs

From Hypothesis to Action: Proactive Threat Hunting with Elastic Security

Elastic Security is designed to enable hypothesis-driven threat hunting at speed and scale. By unifying security telemetry and enabling analytics across clusters, threat hunters can ask complex questions across all their data, correlate signals, and validate hypotheses quickly without manual data stitching.

Paul Ewing
Elevate Your Threat Hunting with Elastic
Security Labs

Elevate Your Threat Hunting with Elastic

Elastic is releasing a threat hunting package designed to aid defenders with proactive detection queries to identify actor-agnostic intrusions.

Terrance DeJesus
Storm on the Horizon: Inside the AJCloud IoT Ecosystem
Security Labs

Storm on the Horizon: Inside the AJCloud IoT Ecosystem

Wi-Fi cameras are popular due to their affordability and convenience but often have security vulnerabilities that can be exploited.

Mark Mager
Linux detection engineering with Auditd
Security Labs

Linux detection engineering with Auditd

In this article, learn more about using Auditd and Auditd Manager for detection engineering.

Ruben Groenewoud
Exploring the Future of Security with ChatGPT
Security Labs

Exploring the Future of Security with ChatGPT

Recently, OpenAI announced APIs for engineers to integrate ChatGPT and Whisper models into their apps and products. For some time, engineers could use the REST API calls for older models and otherwise use the ChatGPT interface through their website.

Mika Ayenson
Identifying beaconing malware using Elastic
Security Labs

Identifying beaconing malware using Elastic

In this blog, we walk users through identifying beaconing malware in their environment using our beaconing identification framework.

Apoorva Joshi
Hunting for Lateral Movement using Event Query Language
Security Labs

Hunting for Lateral Movement using Event Query Language

Elastic Event Query Language (EQL) correlation capabilities enable practitioners to capture complex behavior for adversary Lateral Movement techniques. Learn how to detect a variety of such techniques in this blog post.

Samir Bousseaden