elastic-logo.svg
  • Platform
  • Use cases
  • Pricing
  • Customers
  • Resources
  • Company
logo-cloud-32-color.svg
Elastic Cloud
Maximize value and optimize your experience

Deploy everything Elastic has to offer across any cloud, in minutes.

Learn more

    Additional Resources
  • icon-price-16-blue.svgView pricing
  • icon-download-16-blue.svgFree trial and downloads
  • icon-integration-16-blue.svgView all integrations
Use Elastic For
  • logo-enterprise-search-32-color.svg
    Enterprise Search

    Search and discovery experiences

  • logo-observability-32-color.svg
    Observability

    Unified logs, metrics, and traces

  • logo-security-32-color.svg
    Security

    SIEM, endpoint, and cloud

  • logo-cloud-32-color.svg
    Elastic Cloud

    Deploy and scale in any cloud

  • logo-stack-32-color.svg
    Elastic (ELK) Stack

    Elasticsearch, Kibana, and integrations

View platform overview
What's New
  • Elastic 8.7 released

    See the latest enhancements

  • Upgrade the Elastic Stack

    Expert tips when upgrading

  • Documentation

    Read latest product guides

  • ElasticON Global 2023

    Register now for free

  • We're hiring

    Join a global, distributed team

  • By Topic
    • Power of Elastic
    • Improving digital customer experiences
    • Evolving the DevOps lifecycle
    • Security without limits
    View all topics
  • By Industry
    • Public Sector
    • Financial Services
    • Telecommunications
    • Healthcare
    • Technology
    • Retail and Ecommerce
    • Media and Entertainment
    • Manufacturing and Automotive
    View all industries
  • Featured
    SIEM buyer's guide for the modern SOC

    Key considerations for evaluating and selecting a SIEM solution

    Download the guide

Stories By Use Case
  • Enterprise Search

    Search applications of all kinds

  • Observability

    Logs, metrics, APM, and more

  • Security

    SIEM, endpoint, cloud, and XDR

Help Center
  • Getting started

    Guidance to get started

  • Support

    Get help and customer resources

  • Contact us

    Have questions? Get in touch

Featured Customers
  • logo-nav-dropdown-48x48-jaguar.png
    Jaguar Land Rover

    Vehicle intelligence

  • logo-nav-dropdown-48x48-emirates-nbd.png
    Emirates NBD

    Secured billions in assets

  • logo-nav-dropdown-48x48-zurich.png
    Zurich Insurance

    Increased customer trust

View all case studies

Learn
  • Documentation

    Product guides

  • Blogs

    Tech topics, innovation, news

  • Training

    Skill building and certification

Engage
  • Events

    ElasticON, meetups, virtual events

  • Community

    Groups, forums, code

  • Consulting

    Outcome-based services

Featured
  • icon-blog-pencil-32-color.svg
    Driving quantified success with Elastic Enterprise Search
  • icon-training-on-demand-32-color.svg
    Get started with Elasticsearch
  • icon-certificate-award-32-color.svg
    Observability Engineer training

View all resources

  • About Elastic
    • About

      Our story and leadership

    • Careers

      Peruse our opportunities

    • Press

      Elastic news

    • Partners

      Find or become a partner

    • Investor Relations

      Results, filings, resources

    • Elastic Excellence Awards

      See remarkable work

  • Featured
    Why now is the time to move critical databases to the cloud

    Read more

ContactLogin
Try freeicon-magnifying-glass-24-blue.svg
elastic-logo.svg
icon-magnifying-glass-24-blue.svgicon-magnifying-glass-24-blue.svg
  • Platform
  • Use cases
  • Pricing
  • Customers
  • Resources
  • Company
Platform
Featured
  • logo-cloud-32-color.svgElastic Cloud
  • icon-price-16-blue.svgView pricing
  • icon-download-16-blue.svgFree trial and downloads
  • icon-integration-16-blue.svgView all integrations
Use Elastic For
  • logo-enterprise-search-32-color.svg
    Enterprise Search

    Search and discovery experiences

  • logo-observability-32-color.svg
    Observability

    Unified logs, metrics, and traces

  • logo-security-32-color.svg
    Security

    SIEM, endpoint, and cloud

  • logo-cloud-32-color.svg
    Elastic Cloud

    Deploy and scale in any cloud

  • logo-stack-32-color.svg
    Elastic (ELK) Stack

    Elasticsearch, Kibana, and integrations

View platform overview
What's New
  • Elastic 8.7 released

    See the latest enhancements

  • Upgrade the Elastic Stack

    Expert tips when upgrading

  • Documentation

    Read latest product guides

  • ElasticON Global 2023

    Register now for free

  • We're hiring

    Join a global, distributed team

Use cases
By Topic
Power of Elastic
Improving digital customer experiences
Evolving the DevOps lifecycle
Security without limits
View all topics
By Industry
Public Sector
Financial Services
Telecommunications
Healthcare
Technology
Retail and Ecommerce
Media and Entertainment
Manufacturing and Automotive
View all industries
FeaturedSIEM buyer's guide for the modern SOC
Customers
Stories By Use Case
  • Enterprise Search

    Search applications of all kinds

  • Observability

    Logs, metrics, APM, and more

  • Security

    SIEM, endpoint, cloud, and XDR

Help Center
  • Getting started

    Guidance to get started

  • Support

    Get help and customer resources

  • Contact us

    Have questions? Get in touch

Featured Customers
  • logo-nav-dropdown-48x48-jaguar.png
    Jaguar Land Rover

    Vehicle intelligence

  • logo-nav-dropdown-48x48-emirates-nbd.png
    Emirates NBD

    Secured billions in assets

  • logo-nav-dropdown-48x48-zurich.png
    Zurich Insurance

    Increased customer trust

View all case studies

Resources
Learn
  • Documentation

    Product guides

  • Blogs

    Tech topics, innovation, news

  • Training

    Skill building and certification

Engage
  • Events

    ElasticON, meetups, virtual events

  • Community

    Groups, forums, code

  • Consulting

    Outcome-based services

Featured
  • icon-blog-pencil-32-color.svg
    Driving quantified success with Elastic Enterprise Search
  • icon-training-on-demand-32-color.svg
    Get started with Elasticsearch
  • icon-certificate-award-32-color.svg
    Observability Engineer training

View all resources

Company
About Elastic
About

Our story and leadership

Careers

Peruse our opportunities

Press

Elastic news

Partners

Find or become a partner

Investor Relations

Results, filings, resources

Elastic Excellence Awards

See remarkable work

FeaturedWhy now is the time to move critical databases to the cloud
Try free

Have questions?

Contact us

Already have an account?

Log in
Security Labs
    About
    Topics
    • Security Research
    • Malware Analysis
    • Campaign
    • Groups & Tactics
    • Detection Science
    Vuln updates
    Reports
    Tools

Topics

Groups and Tactics

avatar

REF2924: how to maintain persistence as an (advanced?) threat

Elastic Security Labs describes new persistence techniques used by the group behind SIESTAGRAPH, NAPLISTENER, and SOMNIRECORD.

By
Remco Sprooten

Update to the REF2924 intrusion set and related campaigns

Elastic Security Labs is providing an update to the REF2924 research published in December of 2022. This update includes malware analysis of the implants, additional findings, and associations with other intrusions.

By
Salim Bitam
Remco Sprooten
...

SiestaGraph: New implant uncovered in ASEAN member foreign ministry

Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant to achieve and maintain access, escalate privilege, and exfiltrate targeted data.

By
Samir Bousseaden
Andrew Pease
...

Doing time with the YIPPHB dropper

Elastic Security Labs outlines the steps collect and analyze the various stages of the REF4526 intrusion set. This intrusion set uses a creative approach of Unicode icons in Powershell scripts to install a loader, a dropper, and RAT implants.

By
Seth Goodwin
Derek Ditch
...

More on Adversary + Attack Pattern + Activity Group

Videos

ICEDIDs network infrastructure is alive and well

Elastic Security Labs details the use of open source data collection and the Elastic Stack to analyze the ICEDID botnet C2 infrastructure.

By
Daniel Stepanic
Seth Goodwin
...
31 October 2022
Videos

Exploring the REF2731 Intrusion Set

The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.

By
Salim Bitam
Daniel Stepanic
...
30 September 2022
Videos

LUNA Ransomware Attack Pattern Analysis

In this research publication, we'll explore the LUNA attack pattern — a cross-platform ransomware variant.

By
Salim Bitam
Seth Goodwin
...
31 August 2022
Videos

Exploring the QBOT Attack Pattern

In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.

By
Cyril François
Seth Goodwin
...
27 July 2022
Videos

A peek behind the BPFDoor

In this research piece, we explore BPFDoor — a backdoor payload specifically crafted for Linux in order to gain re-entry into a previously or actively compromised target environment.

By
Jake King
Colson Wilhoit
17 May 2022
Videos

Okta and LAPSUS$: What you need to know

The latest organization under the microscope of the LAPSUS$ group is Okta. Threat hunt for the recent breach targeting Okta users using these simple steps in Elastic

By
Jake King
22 March 2022
Videos

Collecting Cobalt Strike Beacons with the Elastic Stack

Part 1 - Processes and technology needed to extract Cobalt Strike implant beacons

By
Derek Ditch
Daniel Stepanic
...
19 January 2022
Videos

Elastic Security uncovers BLISTER malware campaign

Elastic Security has identified active intrusions leveraging the newly identified BLISTER malware loader utilizing valid code-signing certificates to evade detection. We are providing detection guidance for security teams to protect themselves.

By
Joe Desimone
Samir Bousseaden
22 December 2021
Videos

Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)

Learn how Elastic Endpoint Security and Elastic SIEM can be used to hunt for and detect malicious persistence techniques at scale.

By
Brent Murphy
David French
...
07 April 2020
View more posts
  • Follow us:
    TwitterLinkedInFacebook
  • Detections Repo
  • Discuss
  • Security Slack
Subscribe to our newsletter
Follow us
  • Follow us on Twitter
  • Follow us on Facebook
  • Follow us on Youtube
  • Follow us on LinkedIn

Products & Solutions

  • Enterprise Search
  • Observability
  • Security
  • Elastic Stack
  • Elasticsearch
  • Kibana
  • Integrations
  • Subscriptions
  • Pricing

Company

  • Careers
  • Board of Directors
  • Contact

Resources

  • Documentation
  • What is the ELK Stack?
  • What is Elasticsearch?
  • Migrating from Splunk
  • OpenSearch vs. Elasticsearch
  • Public Sector
Follow us

Language

English
Elastic
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© . Elasticsearch B.V. All Rights Reserved

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries.

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.

© . Elasticsearch B.V. All Rights Reserved

Elastic