Building effective threat hunting and detection rules in Elastic Security

Learn to create custom detection rules in Elastic Security. We cover best practices for using ES|QL and Elastic AI Assistant for threat detection to add vital context. Discover how to preview, test, a...

Elastic Blog
Elastic response to blog ‘EDR 0-Day Vulnerability’

Elastic’s Security Engineering team has found no evidence supporting the claims of a vulnerability bypassing EDR monitoring and enables remote code execution. We'll continue to investigate and provide...

Elastic Blog

I spent too much time banging my head against the wall getting #ElasticSecurity and #Kolide to run well on #immutable #Linux distros like #Fedora #SilverBlue

Here's the first article:

https://unfinished.bike/elastic-agent-on-fedora-silverblue

Linux distro's heading to where macOS today: where the root filesystem is mostly immutable, but not entirely. #ChromeOS arrived there a decade ago, but everyone seems to be moving in the same direction.

Elastic Agent on Fedora SilverBlue

This is a small technical article to save other adventurous people some pain. The Elastic Agent installer fails to install on immutable ...

unfinished.bike
Question for Elasticsearch experts. Well, specifically, Elastic Security experts.

How do you cope with the fact that Elastic Security does not have traditional on-demand/scheduled AV scanning?

Companies often ask questions about AV scans in their vendor "security questionnaires" and I've never seen a good answer that explains why/how next-gen AV/EDR doesn't do "scanning."

What do you tell people? How do you get this past ancient regulatory requirements and/or companies who don't know what "EDR" means?

[Boosts appreciated.
🚀]

[Edit: I guess this is a question for anyone using any "next-gen av" or EDR like
#Crowdstrike or #SentinelOne ]

#Cybersecurity #InformationSecurity #Elastic #Elasticsearch #ElasticSecurity #EndpointProtection #EDR

As we close out 2023,
Check ✅️ out my Elastic Advent Calendar entry "How to investigate a Malicious Alert for Threat Hunting in Elastic Security"

https://discuss.elastic.co/t/dec-25th-2023-en-how-to-investigate-a-malicious-alert-for-threat-hunting-in-elastic-security/347618

#threathunting #elasticsecurity #incidentresponse #elastic

Dec 25th, 2023: [EN] How to investigate a Malicious Alert for Threat Hunting in Elastic Security

Introduction When investigating malicious alerts in Elastic Security, it is essential to determine the type of malicious activity that is detected from an alert for response and remediation. There are many methods to perform for malicious alert investigation. The first step in the malicious alert investigation is identification. As the user, you will need to identify the alert and the rule that triggered the alert. Identification of the alert encompasses the following: Type of alert: Malic...

Discuss the Elastic Stack

Join me for an Elastic Security Community virtual event. I will be giving a tech talk on my Journey Into Malware Research and Reverse Engineering.

Hope to see you there! 🤩🙌

Date: Thursday, October 19
Time: 8am PST/11am EST

#Elastic #ElasticSecurity #reverseengineering #malwareresearch #securityresearch
#womenincyber #womenincybersecurity

Meetup link:
https://www.meetup.com/elastic-united-states-and-canada-virtual/events/296510147/

Session will be recorded and shared on the YouTube Elastic Community page for those who are unable to attend.

Journey Into Malware Research and Reverse Engineering, Thu, Oct 19, 2023, 8:00 AM | Meetup

Women In Security Summit presents: Journey Into Malware Research and Reverse Engineering **Date and Time:** Thursday, October 19 at 8am PST/ 11am EST **Event Details:** J

Meetup
3CX Breach Was a Double Supply Chain Compromise – Krebs on Security

3CX Breach Was a Double Supply Chain Compromise – Krebs on Security

My entry for the Elastic Advent Calendar 2022 is now available 🤩:
"How to build a cluster for Elastic Security: Best practices for creating and generating security data in Elastic Cloud"

Happy Holidays everyone! ❄️☃️😊

https://discuss.elastic.co/t/321832

#infosec #elasticsecurity #elastic #cloud #elasticcloud #elasticadventcalendar

Dec 25th, 2022: [EN] How to build a cluster for Elastic Security: Best practices for creating and generating security data in Elastic Cloud

Introduction When building a cluster for Elastic Security in Elastic Cloud, there are different methods to add security data. The easiest method for adding and shipping security data to Elastic Cloud is with using the Elastic Agent Integration. There are a number of factors that need to be considered prior to creation and building a cluster for Elastic Security: ✅ Determine the type of data that is best suited for the use case scenario - Data architecture and design ...

Discuss the Elastic Stack

Just added: YAML Config Snippet of JPCERT Lateral Movement Events to Monitor (Windows) https://hannahsuarez.github.io/2021/YAML_Lateral_Movement_Events_to_Monitor/

#security #cybersecurity #infosec #elasticsecurity #blueteam

YAML Config Snippet of JPCERT Lateral Movement Events to Monitor (Windows) | Articles, Notes and Other Work by hcs0

YAML Config Snippet of JPCERT Lateral Movement Events to Monitor (Windows)