elastic security labs logo
About
Vulnerability updatesReportsTools
SubscribeStart free trialContact sales

Category

Perspectives

Subscribe

24 January 2025

WinVisor – A hypervisor-based emulator for Windows x64 user-mode executables

WinVisor is a hypervisor-based emulator for Windows x64 user-mode executables that leverages the Windows Hypervisor Platform API to provide a virtualized environment for logging syscalls and enabling memory introspection.

placeholder image
Storm on the Horizon: Inside the AJCloud IoT Ecosystem
20 September 2024

Storm on the Horizon: Inside the AJCloud IoT Ecosystem

Wi-Fi cameras are popular due to their affordability and convenience but often have security vulnerabilities that can be exploited.

Kernel ETW is the best ETW
13 September 2024

Kernel ETW is the best ETW

This research focuses on the importance of native audit logs in secure-by-design software, emphasizing the need for kernel-level ETW logging over user-mode hooks to enhance anti-tamper protections.

Forget vulnerable drivers - Admin is all you need
25 August 2023

Forget vulnerable drivers - Admin is all you need

Bring Your Own Vulnerable Driver (BYOVD) is an increasingly popular attacker technique whereby a threat actor brings a known-vulnerable signed driver alongside their malware, loads it into the kernel, then exploits it to perform some action within the kernel that they would not otherwise be able to do. Employed by advanced threat actors for over a decade, BYOVD is becoming increasingly common in ransomware and commodity malware.

  • Sitemap
  • Elastic.co
  • @elasticseclabs

© 2025. Elasticsearch B.V. All Rights Reserved.