Ruben Groenewoud
@rfgroenewoud
A security research engineer at @Elastic focusing mainly on Linux behavior-, signature- and ML-based detection engineering. Github: github.com/Aegrah
ID: 1487011738604249089
https://www.rgrosec.com/ 28-01-2022 10:37:09
67 Tweet
399 Takipçi
233 Takip Edilen
Hoping to streamline rule management in Elastic Security? Today, we’re exploring DaC updates made in our detection rules repo. Eric Forte and Mika Ayenson highlight the new capabilities and how you can create a DaC strategy: go.es.io/3yqW85v #ElasticSecurityLabs
New stealer on the block 'Banshee' being sold and deployed against macOS. Thank you to Victor Kubashok who was kind enough to share the sample with me for analysis. I've detonated the sample against Elastic Defend. Lets break down the behavior #Banshee exhibits using the 'Elastic
In a follow up from his article on Auditd, Ruben Groenewoud dives deeply into Linux Persistence mechanisms. Become an expert with this new primer:go.es.io/3WKrpbu #ElasticSecurityLabs #Linux
The #linux detection engineering saga continues! Breakdown persistence techniques both simple and complex in this new article from Ruben Groenewoud: go.es.io/3X6w7k9 #ElasticSecurityLabs #detectionengineering
Detection engineering is complicated, but this new 5 tier maturity model from Mika Ayenson, Terrance DeJesus, and Samir provides guidance for security teams: go.es.io/3MySV7l #ElasticSecurityLabs #detectionengineering #maturitymodel