⤷ Title: An Introduction to SOC with Elastic: Building a Smarter, Scalable Security Operations Center
════════════════════════
𐀪 Author: Hamdan Ansari
════════════════════════
ⴵ Time: Sat, 01 Mar 2025 07:36:05 GMT
════════════════════════
⌗ Tags: #cyberattack #elastic_security #security #cybersecurity #blue_team
════════════════════════
𐀪 Author: Hamdan Ansari
════════════════════════
ⴵ Time: Sat, 01 Mar 2025 07:36:05 GMT
════════════════════════
⌗ Tags: #cyberattack #elastic_security #security #cybersecurity #blue_team
Medium
An Introduction to SOC with Elastic: Building a Smarter, Scalable Security Operations Center
Introduction: Building a Smarter SOC with Elastic
⤷ Title: Elastic Uncovers Stealthy Campaign Using GHOSTPULSE and ARECHCLIENT2 Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:22:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arechclient2 #ClickFix #cybersecurity #Elastic Security Labs #GHOSTPULSE #Infostealer #malware #phishing #rat #Remote Access Trojan #SecTopRAT #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 19 Jun 2025 00:22:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arechclient2 #ClickFix #cybersecurity #Elastic Security Labs #GHOSTPULSE #Infostealer #malware #phishing #rat #Remote Access Trojan #SecTopRAT #social engineering
Daily CyberSecurity
Elastic Uncovers Stealthy Campaign Using GHOSTPULSE and ARECHCLIENT2 Malware
Elastic uncovers a sophisticated ClickFix campaign deploying the GHOSTPULSE loader to deliver ARECHCLIENT2 malware, leveraging social engineering for credential theft and remote access.
⤷ Title: SHELLTER Evasion Framework Abused: Elite v11.0 Packages LUMMA, RHADAMANTHYS, ARECHCLIENT2 Infostealers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 00:07:26 +0000
════════════════════════
⌗ Tags: #Malware #Arechclient2 #cybersecurity #Elastic Security Labs #Evasion Framework #Infostealer #Lumma #malware #polymorphic #Red Team tool #Rhadamanthys #shellter
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 00:07:26 +0000
════════════════════════
⌗ Tags: #Malware #Arechclient2 #cybersecurity #Elastic Security Labs #Evasion Framework #Infostealer #Lumma #malware #polymorphic #Red Team tool #Rhadamanthys #shellter
Daily CyberSecurity
SHELLTER Evasion Framework Abused: Elite v11.0 Packages LUMMA, RHADAMANTHYS, ARECHCLIENT2 Infostealers
Elastic Security Labs reveals SHELLTER Elite v11.0 is being abused to deploy LUMMA, RHADAMANTHYS, and ARECHCLIENT2 infostealers, leveraging advanced evasion techniques to bypass AV/EDR
⤷ Title: Shellter Tool Abused by Hackers: Developers Slam Elastic for “Negligent” Disclosure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:55:57 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #Elastic Security Labs #Evasion Framework #Infostealer #malware #Red Team Tool #Responsible Disclosure #Shellter
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:55:57 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #Elastic Security Labs #Evasion Framework #Infostealer #malware #Red Team Tool #Responsible Disclosure #Shellter
Penetration Testing Tools
Shellter Tool Abused by Hackers: Developers Slam Elastic for "Negligent" Disclosure
Shellter developers confirm their AV/EDR evasion tool is being used by malicious actors, criticizing Elastic for "negligent" disclosure that risked further misuse.
⤷ Title: Elastic Cloud S.I.E.M Lab | Deployment and Configuration Guide
════════════════════════
𐀪 Author: Antonio Tanco
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 19:28:55 GMT
════════════════════════
⌗ Tags: #elasticsearch #system_administration #cybersecurity #elk_stack #elastic_security
════════════════════════
𐀪 Author: Antonio Tanco
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 19:28:55 GMT
════════════════════════
⌗ Tags: #elasticsearch #system_administration #cybersecurity #elk_stack #elastic_security
Medium
Elastic Cloud S.I.E.M Lab | Deployment and Configuration Guide
Platform: Elastic Cloud Skills Demonstrated: Configuration Management, System Administration Tools: Powershell
⤷ Title: WARMCOOKIE Resurfaces After Takedown: New Variant Adds Stealth Handlers, Uses Expired C2 Certificates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:05:16 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #cybersecurity #Elastic Security Labs #MaaS #malware #Operation Endgame #persistence #WarmCookie
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:05:16 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #cybersecurity #Elastic Security Labs #MaaS #malware #Operation Endgame #persistence #WarmCookie
Daily CyberSecurity
WARMCOOKIE Resurfaces After Takedown: New Variant Adds Stealth Handlers, Uses Expired C2 Certificates
WARMCOOKIE has resurfaced post-Operation Endgame with new execution handlers, a MaaS model, and evasive techniques like disguised scheduled tasks using company names.
⤷ Title: Lunar Spider Campaign: FakeCAPTCHA Used to Exploit CORS Flaws and Deliver Latrodectus Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 02:08:40 +0000
════════════════════════
⌗ Tags: #Malware #CORS #DLL Sideloading #Elastic Security #FakeCaptcha #Latrodectus #Lunar Spider #Ransomware Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 02:08:40 +0000
════════════════════════
⌗ Tags: #Malware #CORS #DLL Sideloading #Elastic Security #FakeCaptcha #Latrodectus #Lunar Spider #Ransomware Loader
Penetration Testing Tools
Lunar Spider Campaign: FakeCAPTCHA Used to Exploit CORS Flaws and Deliver Latrodectus Loader
The Lunar Spider group is exploiting CORS flaws on European websites, injecting a FakeCAPTCHA to deliver the Latrodectus loader for pre-ransomware reconnaissance and data theft.
⤷ Title: Basics & Advanced Elasticsearch Security Solution Tips. Part 1
════════════════════════
𐀪 Author: Yousef Helmy
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 23:36:02 GMT
════════════════════════
⌗ Tags: #elasticsearch #siem #cybersecurity #elastic_security #kibana
════════════════════════
𐀪 Author: Yousef Helmy
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 23:36:02 GMT
════════════════════════
⌗ Tags: #elasticsearch #siem #cybersecurity #elastic_security #kibana
Medium
Basics & Advanced Elasticsearch Security Solution Tips. Part 1
Elasticsearch features a security solution that allows you to create detection rules, view alerts, manage cases, and more. In this…
⤷ Title: The Silent Hijack: BADIIS Malware Turns 1,800+ Servers into Illicit Websites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:46:39 +0000
════════════════════════
⌗ Tags: #Malware #BadIIS #Cybercrime #Elastic Security Labs #Gambling Scam #IIS Server #malware #SEO Poisoning #Traffic Redirection #UAT_8099 #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:46:39 +0000
════════════════════════
⌗ Tags: #Malware #BadIIS #Cybercrime #Elastic Security Labs #Gambling Scam #IIS Server #malware #SEO Poisoning #Traffic Redirection #UAT_8099 #Windows Security
Daily CyberSecurity
The Silent Hijack: BADIIS Malware Turns 1,800+ Servers into Illicit Websites
Elastic Security Labs uncovers BADIIS malware compromising 1,800+ IIS servers. Attackers use SEO poisoning to redirect users to illicit gambling sites.
⤷ Title: The ‘Human Verification’ Trap: ClickFix Campaign Hijacks Trusted Sites to Deploy MIMICRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #ClickFix Campaign #Cyber Security #Elastic Security Labs #Fileless Malware #infosec #MIMICRAT #powershell #Remote Access Trojan #social engineering #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #ClickFix Campaign #Cyber Security #Elastic Security Labs #Fileless Malware #infosec #MIMICRAT #powershell #Remote Access Trojan #social engineering #threat intelligence
Daily CyberSecurity
The 'Human Verification' Trap: ClickFix Campaign Hijacks Trusted Sites to Deploy MIMICRAT
Elastic Security Labs uncovers a ClickFix campaign turning human helpfulness into a weapon. Fake verifications deploy the fileless MIMICRAT via PowerShell.
⤷ Title: The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 03:00:20 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #CNB Bot #Cost Per Action Fraud #CPA Fraud #cryptomining #Elastic Security Labs #infosec #Malware Analysis #Monero #REF1695 #Themida #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 03:00:20 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #CNB Bot #Cost Per Action Fraud #CPA Fraud #cryptomining #Elastic Security Labs #infosec #Malware Analysis #Monero #REF1695 #Themida #XMRig
Daily CyberSecurity
The Crypto-Con: Unmasking the Multi-Layered "REF1695" Mining Operation
Elastic Security Labs unmasks REF1695, a threat actor using the CNB Bot and custom XMRig loaders for Monero mining and CPA fraud. Is your server a silent miner?
⤷ Title: Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 17:56:01 +0000
════════════════════════
⌗ Tags: #Security #Crypto #Malware #Cybersecurity #Elastic #Elastic Security Labs #Fraud #Monero #REF1695 #Scam #XMR
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 17:56:01 +0000
════════════════════════
⌗ Tags: #Security #Crypto #Malware #Cybersecurity #Elastic #Elastic Security Labs #Fraud #Monero #REF1695 #Scam #XMR
Hackread
Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware
REF1695 hackers spread Monero mining malware via fake non-profit installers, using stealth tactics to evade detection and hijack systems for profit.
⤷ Title: The Autonomous Blue Team: Build a Self-Healing SIEM with the AI Detection Engineering Lab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:13:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI security #Blue Team Automation #Claude Code #Detection Engineering #DevSecOps #Elastic Security #Fawkes C2 #MITRE ATT&CK #SIEM #Sigma Rules #Splunk #Threat Intel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:13:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI security #Blue Team Automation #Claude Code #Detection Engineering #DevSecOps #Elastic Security #Fawkes C2 #MITRE ATT&CK #SIEM #Sigma Rules #Splunk #Threat Intel
Penetration Testing Tools
The Autonomous Blue Team: Build a Self-Healing SIEM with the AI Detection Engineering Lab
Deploy an AI-powered detection pipeline using Claude Code. Automate the full SIEM lifecycle, from Sigma rule authoring to MITRE ATT&CK validation and tuning.
⤷ Title: Self-Spreading TCLBANKER Trojan Hijacks WhatsApp to Drain Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 12:02:20 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #cybersecurity #Elastic Security Labs #infosec #Malware Analysis #REF3076 #TCLBANKER #threat intelligence #Vishing #WhatsApp Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 12:02:20 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #cybersecurity #Elastic Security Labs #infosec #Malware Analysis #REF3076 #TCLBANKER #threat intelligence #Vishing #WhatsApp Hijacking
Daily CyberSecurity
Self-Spreading TCLBANKER Trojan Hijacks WhatsApp to Drain Accounts
Elastic Security Labs exposes TCLBANKER, an advanced banking trojan that hijacks WhatsApp to spread while blinding defenders with invisible WPF overlays.