Elastic Security Labs
@elasticseclabs
Elastic Security Labs is democratizing security by sharing knowledge and capabilities necessary to prepare for threats. Spiritually serving humanity since 2019.
ID: 1592609157793710080
https://www.elastic.co/security-labs/ 15-11-2022 20:07:28
426 Tweet
3,3K Followers
356 Following
Elastic Security Labs is currently researching a new family of IIS malware impacting a large number of organizations globally. With a US university-based MDR provider, we’ve observed a novel attack chain, RMMs, a Godzilla-forked framework, and a malicious driver. Details coming soon.
Elastic Security Labs Love some IIS modules on a Tuesday. Thank you all for sharing
#ElasticSecurityLabs joins forces with Texas A&M System and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57
Amazing experience to work the great folks Elastic Security Labs on this write up to showcase some interesting activity we discovered together! Excited to keep our collaboration going to give back what we can to the security community!
Braxton Williams Elastic Security Labs Your team and the customer squashing it from the get go was great! Love talking about good folks doin' the good work!
Fantastic work by the HarfangLab team describing and documenting indicators and detection logic for "RudePanda," described with complementary analysis by the Elastic Security Labs team as "TOLLBOOTH." harfanglab.io/insidethelab/r…