# Integrations & Tools

Published articles for Integrations & Tools.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

DevFeed: [Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here](<https://devfeed.tech/articles/stop-rewriting-detection-rules-by-hand-automatic-sentinel-to-elastic-migration-is-here-48932.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/sentinel-detection-rules-migration>)

Author: Charles Davison

Published: 2026-07-29T00:00:00Z

Content type: release

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [migration](<https://devfeed.tech/topics/migration.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [detection](<https://devfeed.tech/tags/detection.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [llm](<https://devfeed.tech/tags/llm.md>), [migration](<https://devfeed.tech/tags/migration.md>), [rules](<https://devfeed.tech/tags/rules.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>)

### AI overview

Elastic introduces an automatic migration path for Microsoft Sentinel detection rules into Elastic Security. The feature translates supported Scheduled and Near Real Time analytics rules, carries over watchlists and severity mappings, and is available in Tech Preview in Elastic 9.5 across multiple cloud providers and regions.

### Source excerpt

Elastic's first automatic migration from a modern SIEM. Translate your Sentinel detection rules into Elastic Security without rebuilding them.

## From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

DevFeed: [From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence](<https://devfeed.tech/articles/from-api-key-to-live-threat-detections-in-minutes-how-elastic-security-ingests-google-threat-intelligence-48877.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/elastic-security-google-threat-intelligence>)

Author: Jamie Hynds,Mia LaVada

Published: 2026-06-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Google](<https://devfeed.tech/topics/google.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [agentic workflows](<https://devfeed.tech/topics/agentic-workflows.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [agentic-workflows](<https://devfeed.tech/tags/agentic-workflows.md>), [api](<https://devfeed.tech/tags/api.md>), [google](<https://devfeed.tech/tags/google.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

This tutorial explains how Elastic Security ingests Google Threat Intelligence using an API key and data streams to support continuous detection and historical hunting. It also describes AI-driven workflows that query VirusTotal, enrich alerts, correlate them with telemetry, and summarize findings during investigations.

### Source excerpt

Find out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.

## Monitoring Claude Code/Cowork at scale with OTel in Elastic

DevFeed: [Monitoring Claude Code/Cowork at scale with OTel in Elastic](<https://devfeed.tech/articles/monitoring-claude-code-cowork-at-scale-with-otel-in-elastic-48856.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/claude-code-cowork-monitoring-otel-elastic>)

Author: Spencer Niemi

Published: 2026-04-25T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [infosec](<https://devfeed.tech/topics/infosec.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [claude-code](<https://devfeed.tech/tags/claude-code.md>), [claude-cowork](<https://devfeed.tech/tags/claude-cowork.md>), [cli](<https://devfeed.tech/tags/cli.md>), [delivery](<https://devfeed.tech/tags/delivery.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>)

### AI overview

Elastic's InfoSec team built a monitoring pipeline for Claude Code and Claude Cowork using native OpenTelemetry exports and Elastic's ingestion infrastructure. The article covers telemetry, gateway deployment, Elasticsearch mappings, ingest pipelines, configuration delivery, and security use cases including threat detection, incident response, and compliance.

### Source excerpt

How Elastic's InfoSec team built a monitoring pipeline for Claude Code and Claude Cowork using their native OTel export capabilities and Elastic's OTel ingestion infrastructure.

## Managing Elastic Security Detection Rules with Terraform

DevFeed: [Managing Elastic Security Detection Rules with Terraform](<https://devfeed.tech/articles/managing-elastic-security-detection-rules-with-terraform-48919.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/managing-rules-with-terraform>)

Author: Kseniia Ignatovych,Omer Kushmaro,Stuart Moorhouse,Marc-Antoine Leclercq

Published: 2026-03-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Terraform](<https://devfeed.tech/topics/terraform.md>), [Security](<https://devfeed.tech/topics/security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [deploy](<https://devfeed.tech/tags/deploy.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devops](<https://devfeed.tech/tags/devops.md>), [exceptions](<https://devfeed.tech/tags/exceptions.md>), [hcl](<https://devfeed.tech/tags/hcl.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [security](<https://devfeed.tech/tags/security.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

A tutorial on managing Elastic Security detection rules and exceptions as code with the Elastic Stack Terraform Provider. It explains how to define and deploy detection artifacts, compares the provider with the detection-rules repository, and shows how Elastic's AI Agent can help create Terraform configuration.

### Source excerpt

Learn to define and deploy Elastic Security detection rules and exceptions using the Elastic Stack Terraform Provider vs detection-rules repository DaC capabilities.

## Manage your Elastic security stack as code with the Elastic Stack Terraform provider

DevFeed: [Manage your Elastic security stack as code with the Elastic Stack Terraform provider](<https://devfeed.tech/articles/manage-your-elastic-security-stack-as-code-with-the-elastic-stack-terraform-provider-48918.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/manage-elastic-with-terraform>)

Author: Omer Kushmaro

Published: 2026-02-27T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [terraform provider](<https://devfeed.tech/topics/terraform-provider.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Security](<https://devfeed.tech/topics/security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [configuration-drift](<https://devfeed.tech/tags/configuration-drift.md>), [git](<https://devfeed.tech/tags/git.md>), [hashicorp](<https://devfeed.tech/tags/hashicorp.md>), [hcl](<https://devfeed.tech/tags/hcl.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [ml](<https://devfeed.tech/tags/ml.md>), [observability](<https://devfeed.tech/tags/observability.md>), [security](<https://devfeed.tech/tags/security.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>)

### AI overview

Elastic's Terraform provider lets teams manage security detection rules, exception lists, prebuilt rules, machine-learning anomaly detection jobs, synthetics monitors, and AI connectors as version-controlled infrastructure-as-code. This brings these configurations into Git-based, peer-reviewed workflows and helps reduce configuration drift while improving auditability and reproducibility across environments.

### Source excerpt

From detection rules to AI connectors - the latest Terraform provider releases bring security, observability, and ML capabilities to your infrastructure-as-code workflows.

## Automating GOAD and Live Malware Labs

DevFeed: [Automating GOAD and Live Malware Labs](<https://devfeed.tech/articles/automating-goad-and-live-malware-labs-48849.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/automating-goad-and-live-malware-labs>)

Author: Nic Palmer,Adrian Chen

Published: 2026-02-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Elastic Cloud](<https://devfeed.tech/topics/elastic-cloud.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [workload protection](<https://devfeed.tech/topics/workload-protection.md>)

Tags: [automate](<https://devfeed.tech/tags/automate.md>), [detection](<https://devfeed.tech/tags/detection.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [elastic-cloud](<https://devfeed.tech/tags/elastic-cloud.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>), [security-analytics](<https://devfeed.tech/tags/security-analytics.md>)

### AI overview

A guide to automating a Purple Team range with Ludus and Elastic Security. It explains how to provision instrumented infrastructure, execute attacks, and continuously validate detection rules in a repeatable workflow.

### Source excerpt

Stop building labs by hand. Automate the deployment of a fully instrumented Purple Team range using Ludus and Elastic Security. Spin up infrastructure, execute attacks, and validate detection rules in a single, repeatable workflow.

## From Qradar to Elastic: Automate your Detection Rule Migration

DevFeed: [From Qradar to Elastic: Automate your Detection Rule Migration](<https://devfeed.tech/articles/from-qradar-to-elastic-automate-your-detection-rule-migration-48898.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/from-qradar-to-elastic>)

Author: Charles Davidson

Published: 2026-02-03T00:00:00Z

Content type: release

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Security](<https://devfeed.tech/topics/security.md>), [XML](<https://devfeed.tech/topics/xml.md>), [Network](<https://devfeed.tech/topics/network.md>), [JOIN](<https://devfeed.tech/topics/join.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [automate](<https://devfeed.tech/tags/automate.md>), [capabilities](<https://devfeed.tech/tags/capabilities.md>), [changes](<https://devfeed.tech/tags/changes.md>), [cost](<https://devfeed.tech/tags/cost.md>), [custom](<https://devfeed.tech/tags/custom.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [mapping](<https://devfeed.tech/tags/mapping.md>), [migration](<https://devfeed.tech/tags/migration.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [network](<https://devfeed.tech/tags/network.md>), [preview](<https://devfeed.tech/tags/preview.md>), [reference](<https://devfeed.tech/tags/reference.md>), [running](<https://devfeed.tech/tags/running.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations](<https://devfeed.tech/tags/security-operations.md>), [siem](<https://devfeed.tech/tags/siem.md>), [splunk](<https://devfeed.tech/tags/splunk.md>)

### AI overview

Elastic Security 9.3 introduces Tech Preview support for automatically migrating QRadar detection rules, alongside existing Splunk translation capabilities. The feature translates supported event, flow, and common rules into Elastic-native logic while preserving reference sets, MITRE mappings, and building block rules.

### Source excerpt

Today, we are excited to announce a major expansion to our Automatic Migration feature that changes that narrative. In Elastic Security 9.3, we are introducing Automatic Migration support for QRadar detection rules (now in Tech Preview), joining our existing Splunk translation capabilities to further expedite your journey to Elastic Security. Let's take a closer look at what's supported.

## Elastic and Keep join forces to help users manage alerts and automate workflows

DevFeed: [Elastic and Keep join forces to help users manage alerts and automate workflows](<https://devfeed.tech/articles/elastic-and-keep-join-forces-to-help-users-manage-alerts-and-automate-workflows-48873.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/elastic-and-keep-join-forces>)

Author: Ken Exner

Published: 2025-05-07T00:00:00Z

Content type: release

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [AIOps](<https://devfeed.tech/topics/aiops.md>), [workflow automation](<https://devfeed.tech/topics/workflow-automation.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [kibana](<https://devfeed.tech/topics/kibana.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [aiops](<https://devfeed.tech/tags/aiops.md>), [automation](<https://devfeed.tech/tags/automation.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [kibana](<https://devfeed.tech/tags/kibana.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

Elastic announces an agreement to acquire Keep Alerting, an open source AIOps company whose platform unifies, deduplicates, correlates, and prioritizes alerts while automating incident remediation. Keep will integrate with Elasticsearch and Kibana and remain open source.

### Source excerpt

Elastic announces the acquisition of Keep Alerting

## WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables

DevFeed: [WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables](<https://devfeed.tech/articles/winvisor-a-hypervisor-based-emulator-for-windows-x64-user-mode-executables-48958.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/winvisor-hypervisor-based-emulator>)

Author: Elastic Security Labs

Published: 2025-01-24T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Emulator](<https://devfeed.tech/topics/emulator.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [API](<https://devfeed.tech/topics/api.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Oracle-VM-VirtualBox](<https://devfeed.tech/topics/vm-box.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [code](<https://devfeed.tech/tags/code.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [emulator](<https://devfeed.tech/tags/emulator.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [logging](<https://devfeed.tech/tags/logging.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [virtualbox](<https://devfeed.tech/tags/virtualbox.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

WinVisor is a hypervisor-based emulator for Windows x64 user-mode executables. It uses the Windows Hypervisor Platform API to create a virtualized environment for syscall logging and memory introspection, while explicitly leaving comprehensive sandbox security outside the project's scope.

### Source excerpt

WinVisor is a hypervisor-based emulator for Windows x64 user-mode executables that leverages the Windows Hypervisor Platform API to provide a virtualized environment for logging syscalls and enabling memory introspection.

## Streamlining Security: Integrating Amazon Bedrock with Elastic

DevFeed: [Streamlining Security: Integrating Amazon Bedrock with Elastic](<https://devfeed.tech/articles/streamlining-security-integrating-amazon-bedrock-with-elastic-48943.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/streamlining-security-integrating-amazon-bedrock>)

Author: Shashank K S

Published: 2024-11-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Amazon Bedrock](<https://devfeed.tech/topics/amazon-bedrock.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [aws](<https://devfeed.tech/tags/aws.md>), [bedrock](<https://devfeed.tech/tags/bedrock.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [integration](<https://devfeed.tech/tags/integration.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations](<https://devfeed.tech/tags/security-operations.md>)

### AI overview

A tutorial on integrating Amazon Bedrock with Elastic to improve cloud security monitoring and compliance. It covers setup prerequisites, AWS integration, prebuilt detection rules, misconduct-block detection, and a Python-based exploit test scenario.

### Source excerpt

This article will guide you through the process of setting up the Amazon Bedrock integration and enabling Elastic's prebuilt detection rules to streamline your security operations.

## STIXy Situations: ECSaping your threat data

DevFeed: [STIXy Situations: ECSaping your threat data](<https://devfeed.tech/articles/stixy-situations-ecsaping-your-threat-data-48939.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/stixy-situations-ecsaping-your-threat-data>)

Author: Cyril François,Andrew Pease

Published: 2024-02-09T00:00:00Z

Content type: release

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [Security](<https://devfeed.tech/topics/security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Temporian](<https://devfeed.tech/topics/temporian.md>), [Development](<https://devfeed.tech/topics/development.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Structured-data](<https://devfeed.tech/topics/structured-data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [json](<https://devfeed.tech/tags/json.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [script](<https://devfeed.tech/tags/script.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Elastic describes a released Python tool that converts STIX 2.x threat-data documents into Elastic Common Schema format for analysis and threat detection in Elasticsearch. The tool can output JSON to standard output, create an NDJSON file, or send data directly to an Elasticsearch cluster.

### Source excerpt

Structured threat data is commonly formatted using STIX. To help get this data into Elasticsearch, we're releasing a Python script that converts STIX to an ECS format to be ingested into your stack.

## Streamlining ES|QL Query and Rule Validation: Integrating with GitHub CI

DevFeed: [Streamlining ES|QL Query and Rule Validation: Integrating with GitHub CI](<https://devfeed.tech/articles/streamlining-es-ql-query-and-rule-validation-integrating-with-github-ci-48942.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/streamlining-esql-query-and-rule-validation>)

Author: Mika Ayenson,Eric Forte

Published: 2023-11-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [ci](<https://devfeed.tech/topics/ci.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [kibana](<https://devfeed.tech/topics/kibana.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [github](<https://devfeed.tech/tags/github.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [kibana](<https://devfeed.tech/tags/kibana.md>), [security](<https://devfeed.tech/tags/security.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

Elastic Security Labs explains how to validate ES|QL queries and Detection Engine rules using Kibana, Elasticsearch, and GitHub CI. It covers manual validation, syntax and unknown-column errors, field mappings, and warnings versus hard failures.

### Source excerpt

ES|QL is Elastic's new piped query language. Taking full advantage of this new feature, Elastic Security Labs walks through how to run validation of ES|QL rules for the Detection Engine.

## Click, Click... Boom! Automating Protections Testing with Detonate

DevFeed: [Click, Click... Boom! Automating Protections Testing with Detonate](<https://devfeed.tech/articles/click-click-boom-automating-protections-testing-with-detonate-48857.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/click-click-boom-automating-protections-testing-with-detonate>)

Author: Jessica David,Hez Carty,Sergey Polzunov

Published: 2023-05-04T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Testing](<https://devfeed.tech/topics/testing.md>), [Security research](<https://devfeed.tech/topics/security-research.md>), [Security](<https://devfeed.tech/topics/security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [sha256](<https://devfeed.tech/topics/sha256.md>), [Network Configuration](<https://devfeed.tech/topics/network-configuration.md>)

Tags: [automate](<https://devfeed.tech/tags/automate.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network-configuration](<https://devfeed.tech/tags/network-configuration.md>), [operating-systems](<https://devfeed.tech/tags/operating-systems.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [system](<https://devfeed.tech/tags/system.md>), [testing](<https://devfeed.tech/tags/testing.md>), [virtual-machine](<https://devfeed.tech/tags/virtual-machine.md>), [vm](<https://devfeed.tech/tags/vm.md>)

### AI overview

Elastic Security researchers describe Detonate, an automated system for testing malware protections at scale. It runs potentially malicious software in sandboxed virtual machines, collects execution data, and measures protection efficacy.

### Source excerpt

To automate this process and test our protections at scale, we built Detonate, a system that is used by security research engineers to measure the efficacy of our Elastic Security solution in an automated fashion.

## Unpacking ICEDID

DevFeed: [Unpacking ICEDID](<https://devfeed.tech/articles/unpacking-icedid-48951.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/unpacking-icedid>)

Author: Cyril François

Published: 2023-05-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [library](<https://devfeed.tech/tags/library.md>), [malware](<https://devfeed.tech/tags/malware.md>), [python](<https://devfeed.tech/tags/python.md>), [python-3-10](<https://devfeed.tech/tags/python-3-10.md>), [repository](<https://devfeed.tech/tags/repository.md>), [security](<https://devfeed.tech/tags/security.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This tutorial explains how to unpack ICEDID malware that uses custom file formats and encryption. It introduces Elastic Security Labs tools, including the nightMARE module, and demonstrates analysis of a fake GZip sample in a controlled Windows and Python environment.

### Source excerpt

ICEDID is known to pack its payloads using custom file formats and a custom encryption scheme. We are releasing a set of tools to automate the unpacking process and help analysts and the community respond to ICEDID.

## Ingesting threat data with the Threat Intel Filebeat module

DevFeed: [Ingesting threat data with the Threat Intel Filebeat module](<https://devfeed.tech/articles/ingesting-threat-data-with-the-threat-intel-filebeat-module-48913.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/ingesting-threat-data-with-the-threat-intel-filebeat-module>)

Author: Andrew Pease,Marius Iversen

Published: 2023-03-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [kibana](<https://devfeed.tech/topics/kibana.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [kibana](<https://devfeed.tech/tags/kibana.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

A tutorial on using the Threat Intel Filebeat module to ingest open-source threat intelligence feeds into the Elastic Stack. It explains how the module loads data into Elasticsearch, normalizes it into the Threat ECS fieldset, and supports analysis through Kibana dashboards and visualizations.

### Source excerpt

Tutorial that walks through setting up Filebeat to push threat intelligence feeds into your Elastic Stack.

## The Elastic Container Project for Security Research

DevFeed: [The Elastic Container Project for Security Research](<https://devfeed.tech/articles/the-elastic-container-project-for-security-research-48947.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/the-elastic-container-project>)

Author: Andrew Pease,Colson Wilhoit,Derek Ditch

Published: 2023-03-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security research](<https://devfeed.tech/topics/security-research.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [kibana](<https://devfeed.tech/topics/kibana.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [container](<https://devfeed.tech/tags/container.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [docker](<https://devfeed.tech/tags/docker.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [kibana](<https://devfeed.tech/tags/kibana.md>), [malware](<https://devfeed.tech/tags/malware.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [script](<https://devfeed.tech/tags/script.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [shell](<https://devfeed.tech/tags/shell.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

A tutorial introduces the Elastic Container Project, a shell script that deploys and manages a local, TLS-secured Elastic Stack with Docker for testing and security research. It covers the stack's components, project usage, and Kibana-based security workflows.

### Source excerpt

The Elastic Container Project provides a single shell script that will allow you to stand up and manage an entire Elastic Stack using Docker. This open source project enables rapid deployment for testing use cases.

## NETWIRE Dynamic Configuration Extraction

DevFeed: [NETWIRE Dynamic Configuration Extraction](<https://devfeed.tech/articles/netwire-dynamic-configuration-extraction-48922.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/netwire-dynamic-configuration-extraction>)

Author: Seth Goodwin,Salim Bitam

Published: 2023-01-30T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Assembly](<https://devfeed.tech/topics/assembly.md>), [Code](<https://devfeed.tech/topics/code.md>), [.env](<https://devfeed.tech/topics/dotenv.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [decrypt](<https://devfeed.tech/tags/decrypt.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [rat](<https://devfeed.tech/tags/rat.md>), [reversing](<https://devfeed.tech/tags/reversing.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [tool](<https://devfeed.tech/tags/tool.md>), [trojan](<https://devfeed.tech/tags/trojan.md>), [yara](<https://devfeed.tech/tags/yara.md>)

### AI overview

Elastic Security Labs examines the NETWIRE remote access trojan and releases a tool for dynamically extracting its encrypted configuration from files and memory dumps. The article describes the malware's RC4-protected configuration, relevant functions and assembly patterns, and YARA rules for locating keys and encrypted values.

### Source excerpt

Elastic Security Labs discusses the NETWIRE trojan and is releasing a tool to dynamically extract configuration files.

## NETWIRE Configuration Extractor

DevFeed: [NETWIRE Configuration Extractor](<https://devfeed.tech/articles/netwire-configuration-extractor-48921.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/netwire-configuration-extractor>)

Author: Elastic Security Labs

Published: 2023-01-27T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Python](<https://devfeed.tech/topics/python.md>), [Script](<https://devfeed.tech/topics/script.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [payload](<https://devfeed.tech/topics/payload.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [docker](<https://devfeed.tech/tags/docker.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [script](<https://devfeed.tech/tags/script.md>)

### AI overview

A Python-based NETWIRE configuration extractor analyzes malware samples and can extract encryption keys, command-and-control information, wide-character strings, and ASCII strings. The project supports Docker-based execution and local setup with Poetry.

### Source excerpt

Python script to extract the configuration from NETWIRE samples.

## BPFDoor Configuration Extractor

DevFeed: [BPFDoor Configuration Extractor](<https://devfeed.tech/articles/bpfdoor-configuration-extractor-48853.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/bpfdoor-configuration-extractor>)

Author: Elastic Security Labs

Published: 2022-12-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>), [Python](<https://devfeed.tech/topics/python.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A Python module and command-line tool extracts hardcoded passwords from BPFDoor malware samples. The document explains how to run the extractor with Docker or locally using Poetry, including support for scanning individual samples or directories.

### Source excerpt

Configuration extractor to dump out hardcoded passwords with BPFDoor.

## ICEDID Configuration Extractor

DevFeed: [ICEDID Configuration Extractor](<https://devfeed.tech/articles/icedid-configuration-extractor-48911.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/icedid-configuration-extractor>)

Author: Elastic Security Labs

Published: 2022-12-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Python](<https://devfeed.tech/topics/python.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Script](<https://devfeed.tech/topics/script.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>), [payload](<https://devfeed.tech/topics/payload.md>), [execution](<https://devfeed.tech/topics/execution.md>)

Tags: [docker](<https://devfeed.tech/tags/docker.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [execution](<https://devfeed.tech/tags/execution.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [script](<https://devfeed.tech/tags/script.md>)

### AI overview

A Python-based configuration extractor for ICEDID malware samples. The project can be run in Docker or locally with Poetry, accepts individual samples or directories, and collects extracted configurations.

### Source excerpt

Python script to extract the configuration from ICEDID samples.

## QBOT Configuration Extractor

DevFeed: [QBOT Configuration Extractor](<https://devfeed.tech/articles/qbot-configuration-extractor-48929.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/qbot-configuration-extractor>)

Author: Elastic Security Labs

Published: 2022-12-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Script](<https://devfeed.tech/topics/script.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [script](<https://devfeed.tech/tags/script.md>)

### AI overview

A Python module and command-line tool extracts configurations from QBOT malware samples. The document explains running it with Docker or locally using Poetry.

### Source excerpt

Python script to extract the configuration from QBOT samples.

## PARALLAX Payload Extractor

DevFeed: [PARALLAX Payload Extractor](<https://devfeed.tech/articles/parallax-payload-extractor-48924.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/parallax-payload-extractor>)

Author: Elastic Security Labs

Published: 2022-12-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Script](<https://devfeed.tech/topics/script.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>)

Tags: [docker](<https://devfeed.tech/tags/docker.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [script](<https://devfeed.tech/tags/script.md>)

### AI overview

A guide to using a Python script to extract payloads from PARALLAX malware samples. It explains running the extractor in Docker or locally with Poetry, including options for processing individual samples or directories and selecting an output directory.

### Source excerpt

Python script to extract the payload from PARALLAX samples.

## BPFDoor Scanner

DevFeed: [BPFDoor Scanner](<https://devfeed.tech/articles/bpfdoor-scanner-48854.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/bpfdoor-scanner>)

Author: Elastic Security Labs

Published: 2022-12-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Python](<https://devfeed.tech/topics/python.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [docker](<https://devfeed.tech/tags/docker.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [udp](<https://devfeed.tech/tags/udp.md>)

### AI overview

A practical guide to using a Python-based scanner to identify hosts infected with BPFDoor malware. It covers required Linux permissions, Docker execution, UDP port configuration, and running the tool locally with Poetry.

### Source excerpt

Python script to identify hosts infected with the BPFDoor malware.

## EMOTET Configuration Extractor

DevFeed: [EMOTET Configuration Extractor](<https://devfeed.tech/articles/emotet-configuration-extractor-48884.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/emotet-configuration-extractor>)

Author: Elastic Security Labs

Published: 2022-12-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Python](<https://devfeed.tech/topics/python.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>), [Hackathon-Kit](<https://devfeed.tech/topics/hackathon-kit.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [docker](<https://devfeed.tech/tags/docker.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [malware](<https://devfeed.tech/tags/malware.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>)

### AI overview

This guide presents a Python-based extractor for retrieving configuration data from EMOTET malware samples. It explains how to run the tool in Docker or locally with Poetry, and describes options for extracting encryption keys, C2 information, wide-character strings, and ASCII strings.

### Source excerpt

Python script to extract the configuration from EMOTET samples.

[Next page](<https://devfeed.tech/tags/integrations-tools.md?cursor=WyIyMDIyLTEyLTA2VDAwOjAwOjAwKzAwOjAwIiwgIjY5ZDI0NWZlLTNiZjYtNDljOS1hYjhjLTVlNTkxNGE2MDEzNyJd>)