elastic security labs logo
About
Vulnerability updatesReportsTools
SubscribeStart Free TrialContact Sales

Author

Elastic Security Labs

Subscribe

Articles

NETWIRE Configuration Extractor
27 January 2023

NETWIRE Configuration Extractor

Python script to extract the configuration from NETWIRE samples.

BLISTER Configuration Extractor
6 December 2022

BLISTER Configuration Extractor

Python script to extract the configuration and payload from BLISTER samples.

BPFDoor Configuration Extractor
6 December 2022

BPFDoor Configuration Extractor

Configuration extractor to dump out hardcoded passwords with BPFDoor.

BPFDoor Scanner
6 December 2022

BPFDoor Scanner

Python script to identify hosts infected with the BPFDoor malware.

Cobalt Strike Beacon Extractor
6 December 2022

Cobalt Strike Beacon Extractor

Python script that collects Cobalt Strike memory data generated by security events from an Elasticsearch cluster, extracts the configuration from the CS beacon, and writes the data back to Elasticsearch.

EMOTET Configuration Extractor
6 December 2022

EMOTET Configuration Extractor

Python script to extract the configuration from EMOTET samples.

ICEDID Configuration Extractor
6 December 2022

ICEDID Configuration Extractor

Python script to extract the configuration from ICEDID samples.

PARALLAX Payload Extractor
6 December 2022

PARALLAX Payload Extractor

Python script to extract the payload from PARALLAX samples.

QBOT Configuration Extractor
6 December 2022

QBOT Configuration Extractor

Python script to extract the configuration from QBOT samples.

Sneak Peek: Elastic’s 2022 Global Threat Report
30 November 2022

Sneak Peek: Elastic’s 2022 Global Threat Report

Elastic Security Labs has compiled the 2022 Global Threat Report to share trends and tactics adversaries and attack groups use, as observed by our threat research team and broader user community over the past year.

  • Sitemap
  • Elastic.co
  • @elasticseclabs

© 2024. Elasticsearch B.V. All Rights Reserved.