# MITRE

Published articles for MITRE.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Attackers Abuse VSS, and How Huntress Detects It

DevFeed: [How Attackers Abuse VSS, and How Huntress Detects It](<https://devfeed.tech/articles/how-attackers-abuse-vss-and-how-huntress-detects-it-54632.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/vss-abuse-explained>)

Author: Shivangi Pandey; Matt Anderson

Published: 2026-09-14T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Security](<https://devfeed.tech/topics/security.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [detection](<https://devfeed.tech/tags/detection.md>), [making](<https://devfeed.tech/tags/making.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how attackers abuse Microsoft's Volume Shadow Copy Service for ransomware defense evasion, credential theft from the Active Directory database, and shadow copy manipulation. It also describes why detections must distinguish malicious activity from routine cleanup by backup and remote-management tools.

### Source excerpt

Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.

## The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

DevFeed: [The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment](<https://devfeed.tech/articles/the-fraud-ecosystem-a-transition-from-known-marketplaces-to-a-fragmented-environment-50725.md>)

Original publisher: [Read original article](<https://www.rapid7.com/blog/post/tr-fraud-ecosystem-fragmenting-marketplaces>)

Author: Gal Givon

Published: 2026-09-11T13:33:33Z

Content type: article

Language: en

Sources: [Rapid7 Cybersecurity](<https://devfeed.tech/sources/rapid7-cybersecurity-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [processing](<https://devfeed.tech/topics/processing.md>), [service](<https://devfeed.tech/topics/service.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [collaboration](<https://devfeed.tech/tags/collaboration.md>), [cybersecurity-company](<https://devfeed.tech/tags/cybersecurity-company.md>), [dark-web](<https://devfeed.tech/tags/dark-web.md>), [data](<https://devfeed.tech/tags/data.md>), [detection](<https://devfeed.tech/tags/detection.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [exposure-assessment-platform](<https://devfeed.tech/tags/exposure-assessment-platform.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [faas](<https://devfeed.tech/tags/faas.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [intelligence](<https://devfeed.tech/tags/intelligence.md>), [managed-detection-and-response](<https://devfeed.tech/tags/managed-detection-and-response.md>), [managed-security-solutions](<https://devfeed.tech/tags/managed-security-solutions.md>), [marketplaces](<https://devfeed.tech/tags/marketplaces.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [operational](<https://devfeed.tech/tags/operational.md>), [processing](<https://devfeed.tech/tags/processing.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [services](<https://devfeed.tech/tags/services.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article examines how fraud marketplaces are fragmenting across social media, dark web channels, and smaller specialized storefronts. It discusses the resulting challenges for security teams, including monitoring diverse channels, processing varied data formats, coordinating across teams, and using the MITRE Fraud framework to guide detection and prevention.

### Source excerpt

Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundreds of billions of USD, security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats--such as documents, imagery, video, and unformatted text--linked to organizational assets. The recent introduction of a new Fraud framework by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to look at. These marketplaces supply a range of services in need for the novice fraudster, encompassing server infrastructure, targeted lists, and even support for money laundering facilitated through compromised accounts across various platforms. As larger, well-known marketplaces have been dismantled, smaller, specialized shops are experiencing heightened activity from buyers seeking to engage in fraudulent endeavors. This blog post undertakes an exploration of these marketplaces and their operational modalities, illuminating the contemporary fraud economy and underscoring the enduring critical nature of robust detection and prevention initiatives. Fraud-as-a-Service (FaaS) Fraud is broadly defined as an intentional, dishonest act or misrepresentation of material facts, calculated to deceive oth

## From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

DevFeed: [From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI](<https://devfeed.tech/articles/from-vulnerability-report-to-cve-draft-in-minutes-how-elastic-automated-security-advisories-with-ai-48930.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/security-advisory-automation-rag-elastic-agent-builder>)

Author: Paul McCann

Published: 2026-06-23T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [common vulnerabilities and exposures](<https://devfeed.tech/topics/common-vulnerabilities-and-exposures.md>), [Crawler](<https://devfeed.tech/topics/crawler.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-automation](<https://devfeed.tech/tags/ai-automation.md>), [crawler](<https://devfeed.tech/tags/crawler.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cvss](<https://devfeed.tech/tags/cvss.md>), [cvss-scoring](<https://devfeed.tech/tags/cvss-scoring.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [generative](<https://devfeed.tech/tags/generative.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [rag](<https://devfeed.tech/tags/rag.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Elastic's security team built an AI agent with retrieval-augmented generation over MITRE's CWE and CAPEC catalogues. Using Elastic Agent Builder and Elasticsearch, the system drafts CVE security advisories from raw vulnerability reports, including classifications, attack methodology, CVSS scoring, and mitigation guidance.

### Source excerpt

How Elastic's security team built an AI agent with RAG against MITRE's CWE and CAPEC catalogues to draft CVE advisories from raw vulnerability reports, including the full prompt and crawler configs.

## Vulnerability management is reaching the limits of human scale

DevFeed: [Vulnerability management is reaching the limits of human scale](<https://devfeed.tech/articles/vulnerability-management-is-reaching-the-limits-of-human-scale-53286.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/vulnerability-management-is-reaching-the-limits-of-human-scale>)

Author: Sysdig Team

Published: 2026-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [.NET](<https://devfeed.tech/topics/net.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-in-cybersecurity](<https://devfeed.tech/tags/ai-in-cybersecurity.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [cloud-native-security](<https://devfeed.tech/tags/cloud-native-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [exploit-weaponization](<https://devfeed.tech/tags/exploit-weaponization.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [security](<https://devfeed.tech/tags/security.md>), [vulncheck](<https://devfeed.tech/tags/vulncheck.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-remediation-automation](<https://devfeed.tech/tags/vulnerability-remediation-automation.md>)

### AI overview

Security teams have reduced exploitable in-use vulnerabilities, but the exponential growth of vulnerabilities and increasingly rapid AI-assisted exploit weaponization are outpacing human-scale defenses. The article argues that vulnerability management requires prioritization and AI-supported capabilities with human guardrails.

### Source excerpt

Security teams reduced exploitable vulnerabilities by 75%, but exponential CVE growth and AI-powered exploits are outpacing human-scale defenses. Learn why agentic AI with human guardrails is becoming the new requirement for modern vulnerability management.

## Threat Actor Defense Evasion: How Attackers Disable AV & EDR

DevFeed: [Threat Actor Defense Evasion: How Attackers Disable AV & EDR](<https://devfeed.tech/articles/threat-actor-defense-evasion-how-attackers-disable-av-edr-54376.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/how-attackers-disable-av-edr>)

Author: Toby Bussa

Published: 2026-05-18T14:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [av](<https://devfeed.tech/tags/av.md>), [detection](<https://devfeed.tech/tags/detection.md>), [detection-and-response](<https://devfeed.tech/tags/detection-and-response.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [edr](<https://devfeed.tech/tags/edr.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [learn](<https://devfeed.tech/tags/learn.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how threat actors disable antivirus and EDR defenses using malicious firewall rules, privilege escalation, agent removal, and vulnerable drivers. These actions can suppress telemetry and create a blind spot for lateral movement, data exfiltration, and ransomware deployment.

### Source excerpt

Threat actors are actively targeting your security tools. Learn how threat actors disable antivirus and EDR through vulnerable drivers, tampering attacks, and malicious firewall rules, and how Huntress detects.

## Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

DevFeed: [Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario](<https://devfeed.tech/articles/linux-cloud-detection-engineering-teampcp-container-attack-scenario-48946.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/teampcp-container-attack-scenario>)

Author: Ruben Groenewoud

Published: 2026-03-20T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [container](<https://devfeed.tech/topics/container.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [execution](<https://devfeed.tech/topics/execution.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-detection](<https://devfeed.tech/tags/cloud-detection.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [containers](<https://devfeed.tech/tags/containers.md>), [detection](<https://devfeed.tech/tags/detection.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [discovery](<https://devfeed.tech/tags/discovery.md>), [endpoint-protection-security](<https://devfeed.tech/tags/endpoint-protection-security.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [execution](<https://devfeed.tech/tags/execution.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [lateral-movement](<https://devfeed.tech/tags/lateral-movement.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [runtime-telemetry](<https://devfeed.tech/tags/runtime-telemetry.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>)

### AI overview

A real-world walkthrough of TeamPCP's multi-stage container compromise, showing how Elastic's Defend for Containers surfaces runtime signals and detection logic across the attack chain.

### Source excerpt

This publication provides a real-world walkthrough of TeamPCP's multi-stage container compromise, demonstrating how Elastic's D4C surfaces runtime signals across each stage of the attack chain.

## Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder

DevFeed: [Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder](<https://devfeed.tech/articles/speeding-apt-attack-confirmation-with-attack-discovery-workflows-and-agent-builder-48937.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/speeding-apt-attack-discovery-confirmation-with-attack-discovery-workflows-and-agent-builder>)

Author: James Spiteri,Dhrumil Patel

Published: 2026-02-18T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [incident](<https://devfeed.tech/topics/incident.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>)

Tags: [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [ai-automation](<https://devfeed.tech/tags/ai-automation.md>), [article](<https://devfeed.tech/tags/article.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [dll-sideloading](<https://devfeed.tech/tags/dll-sideloading.md>), [incident](<https://devfeed.tech/tags/incident.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Elastic Security describes an Agentic SOC workflow that combines Attack Discovery, Workflows, and Agent Builder to correlate alerts, verify malware indicators, search logs, create cases, coordinate incident response, and generate summaries. The article uses the Chrysalis backdoor campaign as its example.

### Source excerpt

This article walks through how Elastic Security's Attack Discovery, combined with Workflows and Agent Builder, can automatically detect, correlate, and confirm APT-level attacks like Chrysalis while reducing analyst response time from hours to minutes.

## From Qradar to Elastic: Automate your Detection Rule Migration

DevFeed: [From Qradar to Elastic: Automate your Detection Rule Migration](<https://devfeed.tech/articles/from-qradar-to-elastic-automate-your-detection-rule-migration-48898.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/from-qradar-to-elastic>)

Author: Charles Davidson

Published: 2026-02-03T00:00:00Z

Content type: release

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Security](<https://devfeed.tech/topics/security.md>), [XML](<https://devfeed.tech/topics/xml.md>), [Network](<https://devfeed.tech/topics/network.md>), [JOIN](<https://devfeed.tech/topics/join.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [automate](<https://devfeed.tech/tags/automate.md>), [capabilities](<https://devfeed.tech/tags/capabilities.md>), [changes](<https://devfeed.tech/tags/changes.md>), [cost](<https://devfeed.tech/tags/cost.md>), [custom](<https://devfeed.tech/tags/custom.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrations-tools](<https://devfeed.tech/tags/integrations-tools.md>), [mapping](<https://devfeed.tech/tags/mapping.md>), [migration](<https://devfeed.tech/tags/migration.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [network](<https://devfeed.tech/tags/network.md>), [preview](<https://devfeed.tech/tags/preview.md>), [reference](<https://devfeed.tech/tags/reference.md>), [running](<https://devfeed.tech/tags/running.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations](<https://devfeed.tech/tags/security-operations.md>), [siem](<https://devfeed.tech/tags/siem.md>), [splunk](<https://devfeed.tech/tags/splunk.md>)

### AI overview

Elastic Security 9.3 introduces Tech Preview support for automatically migrating QRadar detection rules, alongside existing Splunk translation capabilities. The feature translates supported event, flow, and common rules into Elastic-native logic while preserving reference sets, MITRE mappings, and building block rules.

### Source excerpt

Today, we are excited to announce a major expansion to our Automatic Migration feature that changes that narrative. In Elastic Security 9.3, we are introducing Automatic Migration support for QRadar detection rules (now in Tech Preview), joining our existing Splunk translation capabilities to further expedite your journey to Elastic Security. Let's take a closer look at what's supported.

## STIG in Action: 4 Lessons on Automating Compliance with MITRE SAF

DevFeed: [STIG in Action: 4 Lessons on Automating Compliance with MITRE SAF](<https://devfeed.tech/articles/stig-in-action-4-lessons-on-automating-compliance-with-mitre-saf-50334.md>)

Original publisher: [Read original article](<https://anchore.com/blog/stig-in-action-4-lessons-on-automating-compliance-with-mitre-saf/>)

Author: Jono Bergquist

Published: 2026-01-06T13:00:00Z

Content type: opinion

Language: en

Sources: [Anchore](<https://devfeed.tech/sources/anchore.md>)

Topics: [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Security](<https://devfeed.tech/topics/security.md>), [container](<https://devfeed.tech/topics/container.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [anchore](<https://devfeed.tech/topics/anchore.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containerized](<https://devfeed.tech/tags/containerized.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [national-security](<https://devfeed.tech/tags/national-security.md>), [open](<https://devfeed.tech/tags/open.md>), [opinion](<https://devfeed.tech/tags/opinion.md>), [security](<https://devfeed.tech/tags/security.md>), [stig](<https://devfeed.tech/tags/stig.md>)

### AI overview

This post discusses four lessons from MITRE's Security Automation Framework about automating STIG compliance in containerized, cloud-native and DevSecOps environments. It emphasizes open, shared security validation standards and acknowledges operational realities such as drift, emergency patches and changes to running containers.

### Source excerpt

The post STIG in Action: 4 Lessons on Automating Compliance with MITRE SAF appeared first on Anchore.If you have ever tried to manually apply a Security Technical Implementation Guide (STIG) to a modern containerized environment, you know it feels like trying to fit a square peg into a round hole...while the hole is moving at 60 miles per hour. The Department of Defense's move to DevSecOps (and adoption of the DoD [...]

## Triksha - Securing AI with AI at Flipkart

DevFeed: [Triksha - Securing AI with AI at Flipkart](<https://devfeed.tech/articles/triksha-securing-ai-with-ai-at-flipkart-56672.md>)

Original publisher: [Read original article](<https://blog.flipkart.tech/triksha-securing-ai-with-ai-at-flipkart-5353da27dc33?source=rss----aea1f5a880a3---4>)

Author: Karan Arora

Published: 2025-12-15T08:34:35Z

Content type: article

Language: en

Sources: [Flipkart Tech Blog](<https://devfeed.tech/sources/flipkart-tech-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI-generated research reports](<https://devfeed.tech/topics/ai-generated-research-reports.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>)

Tags: [adversarial](<https://devfeed.tech/tags/adversarial.md>), [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [apis](<https://devfeed.tech/tags/apis.md>), [application](<https://devfeed.tech/tags/application.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attack](<https://devfeed.tech/tags/attack.md>), [attack-surface](<https://devfeed.tech/tags/attack-surface.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [core](<https://devfeed.tech/tags/core.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [genai-security](<https://devfeed.tech/tags/genai-security.md>), [guardrails](<https://devfeed.tech/tags/guardrails.md>), [llm-security](<https://devfeed.tech/tags/llm-security.md>), [manipulate](<https://devfeed.tech/tags/manipulate.md>), [markov](<https://devfeed.tech/tags/markov.md>), [markov-chain](<https://devfeed.tech/tags/markov-chain.md>), [mistral](<https://devfeed.tech/tags/mistral.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [mitre-atlas](<https://devfeed.tech/tags/mitre-atlas.md>), [owasp-top-10](<https://devfeed.tech/tags/owasp-top-10.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [red-teaming](<https://devfeed.tech/tags/red-teaming.md>), [securing-ai](<https://devfeed.tech/tags/securing-ai.md>)

### AI overview

Flipkart's Triksha is a contextual adversarial model designed to test and secure generative AI applications. It generates domain-aware attack prompts using reconnaissance, adversarial datasets, Markov-chain synthesis, and Gemini-based refinement, targeting risks such as prompt injection, data leakage, and malicious content generation.

### Source excerpt

Triksha -- Securing AI with AI at FlipkartTL;DR GenAI apps introduce a new attack surface where prompts become the primary vector of exploitation, making generic application security ineffective for real-world, fine-tuned LLMs like e-commerce support bots. Triksha, Flipkart's purpose-built contextual adversarial model, generates domain-aware attack prompts using recon, adversarial pattern datasets, Markov-chain synthesis, and Gemini-based contextual refinement. It significantly outperforms leading guardrails (LLama-Guard, Model Armor), achieving a 14.6x higher bypass rate in internal tests. Triksha strengthens security across major OWASP-LLM risks, including prompt injection, data leakage, and malicious content generation, and will expand into multimodal testing, RAG attacks, agent workflows, and MCP servers. In short: AI securing AI -- contextually, systematically, and built for how GenAI systems actually fail. Problem Statement The AI landscape is evolving rapidly, and with it comes a shift in how we build, deploy, and secure applications. Today, we're no longer just testing traditional web apps or APIs. We're in the era of GenAI-based applications, where Large Language Models (LLMs) like OpenAI's GPT, Google's Gemini, and open-source models such as LLaMA and Mistral drive core functionalities. But with this shift comes a new kind of threat surface -- and a new way of thinking about security. The New Attack Surface: The Prompt In traditional application security, we test input validation, authentication, business logic, and more, often guided by frameworks like the OWASP Top 10 and MITRE ATLAS But in GenAI applications, the primary entry point for attack is the prompt. Everything starts with a prompt: a query, an instruction, a message. If malicious actors craft the right prompt, they can manipulate a model into harmful or private outputs. That's why prompt injection is one of the most critical and emerging attack vectors today, with OWASP ranking it #1 for 2025, res

## Elastic Security reports a 99.3% detection rate in the 2025 AV-Comparatives EPR Test

DevFeed: [Elastic Security reports a 99.3% detection rate in the 2025 AV-Comparatives EPR Test](<https://devfeed.tech/articles/elastic-excels-in-av-comparatives-epr-test-2025-a-closer-look-48963.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/reports/elastic-av-comparatives-epr-test-2025>)

Author: Roxana Gheorghe

Published: 2025-09-22T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>), [Protection](<https://devfeed.tech/topics/protection.md>), [execution](<https://devfeed.tech/topics/execution.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [av](<https://devfeed.tech/tags/av.md>), [detection](<https://devfeed.tech/tags/detection.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [mitre](<https://devfeed.tech/tags/mitre.md>)

### AI overview

Elastic reports that Elastic Security achieved a 99.3% detection rate in the 2025 AV-Comparatives Endpoint Prevention and Response Test. The evaluation covered active and passive response across simulated multistage attacks.

### Source excerpt

Elastic shares results of the 2025 AV Comparatives EPR test

## Kali Linux 2025.2 Release (Kali Menu Refresh, BloodHound CE & CARsenal)

DevFeed: [Kali Linux 2025.2 Release (Kali Menu Refresh, BloodHound CE & CARsenal)](<https://devfeed.tech/articles/kali-linux-2025-2-release-kali-menu-refresh-bloodhound-ce-carsenal-47141.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-linux-2025-2-release/>)

Published: 2025-06-13T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [changelog](<https://devfeed.tech/topics/changelog.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [bloodhound](<https://devfeed.tech/tags/bloodhound.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [release](<https://devfeed.tech/tags/release.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Kali Linux 2025.2 introduces a redesigned Kali Menu organized around the MITRE ATT&CK framework, upgrades BloodHound Community Edition, adds smartwatch Wi-Fi injection support and the CARsenal car-hacking toolkit, and includes 13 new tools. The release also updates GNOME and KDE and automates menu management through a YAML-based system.

### Source excerpt

We're almost half way through 2025 already, and we've got a lot to share with you in this release, Kali 2025.2. The summary of the changelog since the 2025.1 release from March is: Desktop Updates - Kali-Menu refresh, GNOME 48 & KDE 6.3 updates BloodHound Community Edition - Major upgrade with full set of ingestors Kali NetHunter Smartwatch Wi-Fi Injection - TicWatch Pro 3 now able to de-authenticate and capture WPA2 handshakes Kali NetHunter CARsenal - Car hacking tool set! New Tools - 13 new shinny tools added (and various updates) Desktop Updates Kali Menu Refresh We've completely reworked the Kali Menu! It's now reorganized to follow the MITRE ATT&CK framework structure - which means that finding the right tool for your task should now be a lot more intuitive for red and blue teams alike. Previously the Kali menu structure followed what was in BackTrack... which followed WHAX before it. The previous structure was an in-house item, before MITRE was a thing. When our menu was first created, there wasn't as much design planning done, which we suffered for later. It meant that over time, scaling and adding new tools became difficult for us. The knock on effect was that this made it harder for you, the end-users, to discover new tools as similar tools with overlapping functions were in different places or missing entries. Yes, seasoned professionals may not use the menu to start up items, using shortcuts such as super key and typing the tool name , or via a terminal window. We see the menu as a way to discover tools. The final nail in the coffin in the setup was the fact that it was manually managed. Yes, all those entries were previously created by-hand (which also may explain a few things). As a result, we had stopped adding new tools to the menu... until now. Now, we have created a new system and automated many aspects, making it easier for us to manage, and easier for you to discover items. Win win. Over time, we hope to start to add this to kali.org/tools/. Currentl

## Credential Theft: Expanding Your Reach, Pt. II

DevFeed: [Credential Theft: Expanding Your Reach, Pt. II](<https://devfeed.tech/articles/credential-theft-expanding-your-reach-pt-ii-54259.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/credential-theft-expanding-your-reach-pt-2>)

Author: Huntress Adversary Tactics

Published: 2025-04-24T05:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Security](<https://devfeed.tech/topics/security.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Process](<https://devfeed.tech/topics/process.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [edr](<https://devfeed.tech/tags/edr.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This article explains how credential theft can use Windows LOLBins, including print.exe, to copy the Active Directory NTDS.DIT credential database from Volume Shadow Copies. It describes observed attacker activity and detection considerations using endpoint telemetry.

### Source excerpt

As with many tactics within the MITRE ATT&CK framework, credential theft consists of a number of different techniques. Showing what many of them look like on an endpoint helps other security professionals understand what to look for and how to detect and respond to similar activity.

## Cloud Logging Tip & Tricks: Getting the most value out of your cloud logs

DevFeed: [Cloud Logging Tip & Tricks: Getting the most value out of your cloud logs](<https://devfeed.tech/articles/cloud-logging-tip-tricks-getting-the-most-value-out-of-your-cloud-logs-53729.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/cloud-logging-tip-tricks-getting-the-most-value-out-of-your-cloud-logs>)

Author: Chris Champa

Published: 2024-10-08T14:12:15Z

Content type: article

Language: en

Sources: [Wiz](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [Cloud Logging](<https://devfeed.tech/topics/cloud-logging.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [control-plane](<https://devfeed.tech/topics/control-plane.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-detection](<https://devfeed.tech/tags/cloud-detection.md>), [cloud-detection-and-response](<https://devfeed.tech/tags/cloud-detection-and-response.md>), [cloud-logging](<https://devfeed.tech/tags/cloud-logging.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [cloudtrail](<https://devfeed.tech/tags/cloudtrail.md>), [control-plane](<https://devfeed.tech/tags/control-plane.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [data](<https://devfeed.tech/tags/data.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [product](<https://devfeed.tech/tags/product.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

This article explains why cloud logging is central to cloud detection and response, and previews a framework for prioritizing log collection by security use case. It discusses cloud-provider differences, configuration and cost considerations, and examples involving CloudTrail, S3 data events, and control-plane activity.

### Source excerpt

In the cloud, logs are often the only way to get real-time visibility into what's happening, making them critical to any cloud detection and response program.

## Password Spraying Tools: How Attackers Spray M365

DevFeed: [Password Spraying Tools: How Attackers Spray M365](<https://devfeed.tech/articles/password-spraying-tools-how-attackers-spray-m365-54390.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/hunting-for-m365-password-spraying>)

Author: Anton Ovrutsky; Faith Stratton

Published: 2024-10-03T00:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [password spraying](<https://devfeed.tech/topics/password-spraying.md>), [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [business](<https://devfeed.tech/tags/business.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-hunting](<https://devfeed.tech/tags/threat-hunting.md>)

### AI overview

Huntress explains how threat actors use password spraying against Microsoft 365 environments and contrasts the technique with brute-force attacks. The article describes threat-hunting approaches focused on failed authentications, IP addresses, targeted users, and effective detection strategies.

### Source excerpt

Join Huntress Threat Hunters as they unpack the password-spraying techniques of threat actors, exposing how they target everything from small businesses to giants like Microsoft.

## Linux Detection Engineering - A primer on persistence mechanisms

DevFeed: [Linux Detection Engineering - A primer on persistence mechanisms](<https://devfeed.tech/articles/linux-detection-engineering-a-primer-on-persistence-mechanisms-49099.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/primer-on-persistence-mechanisms>)

Author: Ruben Groenewoud

Published: 2024-08-21T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [detection](<https://devfeed.tech/tags/detection.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [siem](<https://devfeed.tech/tags/siem.md>)

### AI overview

This tutorial examines Linux persistence mechanisms, maps them to the MITRE ATT&CK framework, and explains how defenders can set up tests, analyze logs, hunt for persistence, and develop detection strategies. It also introduces PANIX, a tool for testing persistence detections.

### Source excerpt

In this second part of the Linux Detection Engineering series, we map multiple Linux persistence mechanisms to the MITRE ATT&CK framework, explain how they work, and how to detect them.

## Introducing the Cloud Threat Landscape, a new TI resource for cloud defenders

DevFeed: [Introducing the Cloud Threat Landscape, a new TI resource for cloud defenders](<https://devfeed.tech/articles/introducing-the-cloud-threat-landscape-a-new-ti-resource-for-cloud-defenders-53842.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/introducing-the-cloud-threat-landscape>)

Author: Alon Schindel

Published: 2024-01-24T15:28:30Z

Content type: release

Language: en

Sources: [Wiz](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Security](<https://devfeed.tech/topics/security.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-threat-intelligence](<https://devfeed.tech/tags/cloud-threat-intelligence.md>), [data-exfiltration](<https://devfeed.tech/tags/data-exfiltration.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [research](<https://devfeed.tech/tags/research.md>), [risk-assessment](<https://devfeed.tech/tags/risk-assessment.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wiz-cloud](<https://devfeed.tech/tags/wiz-cloud.md>)

### AI overview

Wiz introduces the Cloud Threat Landscape, a public threat intelligence database covering cloud security incidents, campaigns, threat actors, targeting patterns, initial access methods, and data exfiltration techniques. The resource is intended to help cloud defenders with risk assessment, threat modeling, and defensive planning.

### Source excerpt

The Cloud Threat Landscape is a threat intelligence database that summarizes cloud incidents and offers insights into targeting patterns and initial access methods.

## Exploring the Value of Indicators In Small Business Defense

DevFeed: [Exploring the Value of Indicators In Small Business Defense](<https://devfeed.tech/articles/exploring-the-value-of-indicators-in-small-business-defense-54335.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/exploring-the-value-of-indicators-in-small-business-defense>)

Author: Joe Slowik

Published: 2023-12-07T00:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [IoC (Disambiguation)](<https://devfeed.tech/topics/ioc.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [indicators-of-compromise](<https://devfeed.tech/tags/indicators-of-compromise.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [small-business](<https://devfeed.tech/tags/small-business.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

This article examines the role of technical indicators and indicators of compromise in cyber threat intelligence and information security. It distinguishes indicators from raw observables, explains their value in forensic analysis and threat hunting, and discusses their economical use in small and medium-sized business defense.

### Source excerpt

Discover how leveraging technical indicators can boost cybersecurity effectiveness and empower small business defense. Read on for practical insights.

## CUBA Ransomware Malware Analysis

DevFeed: [CUBA Ransomware Malware Analysis](<https://devfeed.tech/articles/cuba-ransomware-malware-analysis-49003.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/cuba-ransomware-malware-analysis>)

Author: Salim Bitam

Published: 2023-02-14T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [ChaCha](<https://devfeed.tech/topics/chacha-cipher.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Concurrency](<https://devfeed.tech/topics/concurrency.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [code analysis](<https://devfeed.tech/topics/code-analysis.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [detection](<https://devfeed.tech/tags/detection.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [file](<https://devfeed.tech/tags/file.md>), [file-system](<https://devfeed.tech/tags/file-system.md>), [indicators-of-compromise](<https://devfeed.tech/tags/indicators-of-compromise.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [process](<https://devfeed.tech/tags/process.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [technical](<https://devfeed.tech/tags/technical.md>), [technical-analysis](<https://devfeed.tech/tags/technical-analysis.md>), [threading](<https://devfeed.tech/tags/threading.md>)

### AI overview

Elastic Security analyzes the CUBA ransomware family, describing its capabilities, encryption of local and network-share files, multithreaded implementation, defensive countermeasures, and indicators for detection.

### Source excerpt

Elastic Security has performed a deep technical analysis of the CUBA ransomware family. This includes malware capabilities as well as defensive countermeasures.

## SiestaGraph: New implant uncovered in ASEAN member foreign ministry

DevFeed: [SiestaGraph: New implant uncovered in ASEAN member foreign ministry](<https://devfeed.tech/articles/siestagraph-new-implant-uncovered-in-asean-member-foreign-ministry-49111.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/siestagraph-new-implant-uncovered-in-asean-member-foreign-ministry>)

Author: Samir Bousseaden,Andrew Pease,Daniel Stepanic,Salim Bitam,Seth Goodwin,Devon Kerr

Published: 2022-12-16T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [API](<https://devfeed.tech/topics/api.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Process](<https://devfeed.tech/topics/process.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [exfiltration](<https://devfeed.tech/tags/exfiltration.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft-exchange](<https://devfeed.tech/tags/microsoft-exchange.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [network](<https://devfeed.tech/tags/network.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [process](<https://devfeed.tech/tags/process.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

Elastic Security Labs reports on a campaign targeting an ASEAN member's foreign ministry. The activity involved Exchange exploits, web shells, mailbox exfiltration, lateral movement, credential collection, and the newly identified SiestaGraph backdoor, which uses the Microsoft Graph API for command and control.

### Source excerpt

Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant to achieve and maintain access, escalate privilege, and exfiltrate targeted data.

## A close look at the advanced techniques used in a Malaysian-focused APT campaign

DevFeed: [A close look at the advanced techniques used in a Malaysian-focused APT campaign](<https://devfeed.tech/articles/a-close-look-at-the-advanced-techniques-used-in-a-malaysian-focused-apt-campaign-48978.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/advanced-techniques-used-in-malaysian-focused-apt-campaign>)

Author: Samir Bousseaden,Daniel Stepanic,Elastic Security Intelligence & Analytics Team

Published: 2022-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security research](<https://devfeed.tech/topics/security-research.md>), [DLL hijacking](<https://devfeed.tech/topics/dll-hijacking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [VBA](<https://devfeed.tech/topics/vba.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [dll](<https://devfeed.tech/tags/dll.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Elastic Security researchers analyze a Malaysian-focused APT campaign possibly linked to APT40. The report describes phishing with a Microsoft Word lure, remote template injection, VBA macro execution, embedded DLLs, obfuscation, and DLL search order exploitation, along with observed MITRE techniques and indicators of compromise.

### Source excerpt

Our Elastic Security research team has focused on advanced techniques used in a Malaysian-focused APT campaign. Learn who's behind it, how the attack works, observed MITRE attack® techniques, and indicators of compromise.

## Elastic Security opens public detection rules repo

DevFeed: [Elastic Security opens public detection rules repo](<https://devfeed.tech/articles/elastic-security-opens-public-detection-rules-repo-48880.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/elastic-security-opens-public-detection-rules-repo>)

Author: Ross Wolf,Elastic Security Intelligence & Analytics Team

Published: 2022-05-20T00:00:00Z

Content type: release

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Repository](<https://devfeed.tech/topics/repository.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [software-development](<https://devfeed.tech/topics/software-development.md>), [Software Testing](<https://devfeed.tech/topics/software-testing.md>), [kibana](<https://devfeed.tech/topics/kibana.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [coverage](<https://devfeed.tech/tags/coverage.md>), [detection](<https://devfeed.tech/tags/detection.md>), [github](<https://devfeed.tech/tags/github.md>), [kibana](<https://devfeed.tech/tags/kibana.md>), [linux](<https://devfeed.tech/tags/linux.md>), [logs](<https://devfeed.tech/tags/logs.md>), [macos](<https://devfeed.tech/tags/macos.md>), [mitre](<https://devfeed.tech/tags/mitre.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [operating-systems](<https://devfeed.tech/tags/operating-systems.md>), [repo](<https://devfeed.tech/tags/repo.md>), [rules](<https://devfeed.tech/tags/rules.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>)

### AI overview

Elastic Security announces that its detection rules repository is now public on GitHub, inviting community contributions and collaborative rule development. The repository supports automated threat detection and includes rules covering MITRE ATT&CK techniques across multiple operating systems and cloud services.

### Source excerpt

Elastic Security has opened its detection rules repository to the world. We will develop rules in the open alongside the community, and we're welcoming your community-driven detections. This is an opportunity to share collective security knowledge.