elastic-logo.svg
  • Platform
  • Use cases
  • Pricing
  • Customers
  • Resources
  • Company
logo-cloud-32-color.svg
Elastic Cloud
Maximize value and optimize your experience

Deploy everything Elastic has to offer across any cloud, in minutes.

Learn more

    Additional Resources
  • icon-price-16-blue.svgView pricing
  • icon-download-16-blue.svgFree trial and downloads
  • icon-integration-16-blue.svgView all integrations
Use Elastic For
  • logo-enterprise-search-32-color.svg
    Enterprise Search

    Search and discovery experiences

  • logo-observability-32-color.svg
    Observability

    Unified logs, metrics, and traces

  • logo-security-32-color.svg
    Security

    SIEM, endpoint, and cloud

  • logo-cloud-32-color.svg
    Elastic Cloud

    Deploy and scale in any cloud

  • logo-stack-32-color.svg
    Elastic (ELK) Stack

    Elasticsearch, Kibana, and integrations

View platform overview
What's New
  • Elastic 8.6 released

    See the latest enhancements

  • Upgrade the Elastic Stack

    Expert tips when upgrading

  • Documentation

    Read latest product guides

  • ElasticON Global 2023

    Register now for free

  • We're hiring

    Join a global, distributed team

  • By Topic
    • Power of Elastic
    • Improving digital customer experiences
    • Evolving the DevOps lifecycle
    • Security without limits
    View all topics
  • By Industry
    • Public Sector
    • Financial Services
    • Telecommunications
    • Healthcare
    • Technology
    • Retail and Ecommerce
    • Media and Entertainment
    • Manufacturing and Automotive
    View all industries
  • Featured
    SIEM buyer's guide for the modern SOC

    Key considerations for evaluating and selecting a SIEM solution

    Download the guide

Stories By Use Case
  • Enterprise Search

    Search applications of all kinds

  • Observability

    Logs, metrics, APM, and more

  • Security

    SIEM, endpoint, cloud, and XDR

Help Center
  • Getting started

    Guidance to get started

  • Support

    Get help and customer resources

  • Contact us

    Have questions? Get in touch

Featured Customers
  • logo-nav-dropdown-48x48-jaguar.png
    Jaguar Land Rover

    Vehicle intelligence

  • logo-nav-dropdown-48x48-emirates-nbd.png
    Emirates NBD

    Secured billions in assets

  • logo-nav-dropdown-48x48-zurich.png
    Zurich Insurance

    Increased customer trust

View all case studies

Learn
  • Documentation

    Product guides

  • Blogs

    Tech topics, innovation, news

  • Training

    Skill building and certification

Engage
  • Events

    ElasticON, meetups, virtual events

  • Community

    Groups, forums, code

  • Consulting

    Outcome-based services

Featured
  • icon-blog-pencil-32-color.svg
    Driving quantified success with Elastic Enterprise Search
  • icon-training-on-demand-32-color.svg
    Get started with Elasticsearch
  • icon-certificate-award-32-color.svg
    Observability Engineer training

View all resources

  • About Elastic
    • About

      Our story and leadership

    • Careers

      Peruse our opportunities

    • Press

      Elastic news

    • Partners

      Find or become a partner

    • Investor Relations

      Results, filings, resources

    • Elastic Excellence Awards

      See remarkable work

  • Featured
    Why now is the time to move critical databases to the cloud

    Read more

ContactLogin
Try freeicon-magnifying-glass-24-blue.svg
elastic-logo.svg
icon-magnifying-glass-24-blue.svgicon-magnifying-glass-24-blue.svg
  • Platform
  • Use cases
  • Pricing
  • Customers
  • Resources
  • Company
Platform
Featured
  • logo-cloud-32-color.svgElastic Cloud
  • icon-price-16-blue.svgView pricing
  • icon-download-16-blue.svgFree trial and downloads
  • icon-integration-16-blue.svgView all integrations
Use Elastic For
  • logo-enterprise-search-32-color.svg
    Enterprise Search

    Search and discovery experiences

  • logo-observability-32-color.svg
    Observability

    Unified logs, metrics, and traces

  • logo-security-32-color.svg
    Security

    SIEM, endpoint, and cloud

  • logo-cloud-32-color.svg
    Elastic Cloud

    Deploy and scale in any cloud

  • logo-stack-32-color.svg
    Elastic (ELK) Stack

    Elasticsearch, Kibana, and integrations

View platform overview
What's New
  • Elastic 8.6 released

    See the latest enhancements

  • Upgrade the Elastic Stack

    Expert tips when upgrading

  • Documentation

    Read latest product guides

  • ElasticON Global 2023

    Register now for free

  • We're hiring

    Join a global, distributed team

Use cases
By Topic
Power of Elastic
Improving digital customer experiences
Evolving the DevOps lifecycle
Security without limits
View all topics
By Industry
Public Sector
Financial Services
Telecommunications
Healthcare
Technology
Retail and Ecommerce
Media and Entertainment
Manufacturing and Automotive
View all industries
FeaturedSIEM buyer's guide for the modern SOC
Customers
Stories By Use Case
  • Enterprise Search

    Search applications of all kinds

  • Observability

    Logs, metrics, APM, and more

  • Security

    SIEM, endpoint, cloud, and XDR

Help Center
  • Getting started

    Guidance to get started

  • Support

    Get help and customer resources

  • Contact us

    Have questions? Get in touch

Featured Customers
  • logo-nav-dropdown-48x48-jaguar.png
    Jaguar Land Rover

    Vehicle intelligence

  • logo-nav-dropdown-48x48-emirates-nbd.png
    Emirates NBD

    Secured billions in assets

  • logo-nav-dropdown-48x48-zurich.png
    Zurich Insurance

    Increased customer trust

View all case studies

Resources
Learn
  • Documentation

    Product guides

  • Blogs

    Tech topics, innovation, news

  • Training

    Skill building and certification

Engage
  • Events

    ElasticON, meetups, virtual events

  • Community

    Groups, forums, code

  • Consulting

    Outcome-based services

Featured
  • icon-blog-pencil-32-color.svg
    Driving quantified success with Elastic Enterprise Search
  • icon-training-on-demand-32-color.svg
    Get started with Elasticsearch
  • icon-certificate-award-32-color.svg
    Observability Engineer training

View all resources

Company
About Elastic
About

Our story and leadership

Careers

Peruse our opportunities

Press

Elastic news

Partners

Find or become a partner

Investor Relations

Results, filings, resources

Elastic Excellence Awards

See remarkable work

FeaturedWhy now is the time to move critical databases to the cloud
Try free

Have questions?

Contact us

Already have an account?

Log in
Security Labs
    About
    Topics
    • Security Research
    • Malware Analysis
    • Campaign
    • Groups & Tactics
    • Detection Science
    Vuln updates
    Reports
    Tools

Topics

Detection Science

avatar

Exploring the Future of Security with ChatGPT

Recently, OpenAI announced APIs for engineers to integrate ChatGPT and Whisper models into their apps and products. For some time, engineers could use the REST API calls for older models and otherwise use the ChatGPT interface through their website.

By
Mika Ayenson

Click, Click… Boom! Automating Protections Testing with Detonate

To automate this process and test our protections at scale, we built Detonate, a system that is used by security research engineers to measure the efficacy of our Elastic Security solution in an automated fashion.

By
Jessica David
Hez Carty
...

Hunting for Suspicious Windows Libraries for Execution and Defense Evasion

Learn more about discovering threats by hunting through DLL load events, one way to reveal the presence of known and unknown malware in noisy process event data.

By
Samir Bousseaden

Stopping Vulnerable Driver Attacks

This post includes a primer on kernel mode attacks, along with Elastic’s recommendations for securing users from kernel attacks leveraging vulnerable drivers.

By
Joe Desimone

More on Detection Science

Videos

The Elastic Container Project for Security Research

The Elastic Container Project provides a single shell script that will allow you to stand up and manage an entire Elastic Stack using Docker. This open source project enables rapid deployment for testing use cases.

By
Andrew Pease
Colson Wilhoit
...
30 August 2022
Videos

Automating the Security Protections rapid response to malware

See how we’ve been improving the processes that allow us to make updates quickly in response to new information and propagate those protections to our users, with the help of machine learning models.

By
Samantha Zeitlin
09 June 2022
Videos

Detect domain generation algorithm (DGA) activity with new Kibana integration

We have added a DGA detection package to the Integrations app in Kibana. In a single click, you can install and start using the DGA model and associated assets, including ingest pipeline configurations, anomaly detection jobs, and detection rules.

By
Melissa Alvarez
06 June 2022
Videos

Detecting Living-off-the-land attacks with new Elastic Integration

We added a Living off the land (LotL) detection package to the Integrations app in Kibana. In a single click, you can install and start using the ProblemChild model and associated assets including anomaly detection configurations and detection rules.

By
Melissa Alvarez
11 May 2022
Videos

Detect Credential Access with Elastic Security

Elastic Endpoint Security provides events that enable defenders with visibility on techniques and procedures which are commonly leveraged to access sensitive files and registry objects.

By
Samir Bousseaden
25 April 2022
Videos

Exploring Windows UAC Bypasses: Techniques and Detection Strategies

In this research article, we will take a look at a collection of UAC bypasses, investigate some of the key primitives they depend on, and explore detection opportunities.

By
Samir Bousseaden
07 February 2022
Videos

Identifying beaconing malware using Elastic

In this blog, we walk users through identifying beaconing malware in their environment using our beaconing identification framework.

By
Apoorva Joshi
Thomas Veasey
...
13 January 2022
Videos

Ingesting threat data with the Threat Intel Filebeat module

Tutorial that walks through setting up Filebeat to push threat intelligence feeds into your Elastic Stack.

By
Andrew Pease
Marius Iversen
01 July 2021
Videos

Hunting for Lateral Movement using Event Query Language

Elastic Event Query Language (EQL) correlation capabilities enable practitioners to capture complex behavior for adversary Lateral Movement techniques. Learn how to detect a variety of such techniques in this blog post.

By
Samir Bousseaden
18 March 2021
  • Follow us:
    TwitterLinkedInFacebook
  • Detections Repo
  • Discuss
  • Security Slack
Subscribe to our newsletter
Follow us
  • Follow us on Twitter
  • Follow us on Facebook
  • Follow us on Youtube
  • Follow us on LinkedIn

Products & Solutions

  • Enterprise Search
  • Observability
  • Security
  • Elastic Stack
  • Elasticsearch
  • Kibana
  • Integrations
  • Subscriptions
  • Pricing

Company

  • Careers
  • Board of Directors
  • Contact

Resources

  • Documentation
  • What is the ELK Stack?
  • What is Elasticsearch?
  • Migrating from Splunk
  • OpenSearch vs. Elasticsearch
  • Public Sector
Follow us

Language

English
Elastic
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© . Elasticsearch B.V. All Rights Reserved

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries.

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.

© . Elasticsearch B.V. All Rights Reserved

Elastic