As cited
Copy frozen at (site build).
vulnerabilities
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
Elastic announced three endpoint security enhancements to Elastic Defend: automated detection rule generation for over 800 vulnerable drivers by continuously monitoring public disclosure sources, an Automatic Troubleshooting capability via Elastic Agent Builder to improve endpoint management efficiency, and support for Windows on ARM64 architecture. The vulnerable driver detection system closes gaps between public disclosure and vendor protection by decoupling coverage from release cycles and publishing protections immediately as new drivers are identified from VirusTotal, LOLDrivers, and Microsoft's Vulnerable Driver Block List.
Why it matters: Security teams defending Windows endpoints need awareness of Elastic's real-time vulnerable driver protection to reduce the window of exposure that attackers exploit when using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security tools before ransomware deployment.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
Elastic announced three endpoint security enhancements to Elastic Defend: automated detection rule generation for over 800 vulnerable drivers by continuously monitoring public disclosure sources, an Automatic Troubleshooting capability via Elastic Agent Builder to improve endpoint management efficiency, and support for Windows on ARM64 architecture. The vulnerable driver detection system closes gaps between public disclosure and vendor protection by decoupling coverage from release cycles and publishing protections immediately as new drivers are identified from VirusTotal, LOLDrivers, and Microsoft's Vulnerable Driver Block List.
Why it matters: Security teams defending Windows endpoints need awareness of Elastic's real-time vulnerable driver protection to reduce the window of exposure that attackers exploit when using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security tools before ransomware deployment.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
Elastic announced three endpoint security enhancements to Elastic Defend: automated detection rule generation for over 800 vulnerable drivers by continuously monitoring public disclosure sources, an Automatic Troubleshooting capability via Elastic Agent Builder to improve endpoint management efficiency, and support for Windows on ARM64 architecture. The vulnerable driver detection system closes gaps between public disclosure and vendor protection by decoupling coverage from release cycles and publishing protections immediately as new drivers are identified from VirusTotal, LOLDrivers, and Microsoft's Vulnerable Driver Block List.
Why it matters: Security teams defending Windows endpoints need awareness of Elastic's real-time vulnerable driver protection to reduce the window of exposure that attackers exploit when using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security tools before ransomware deployment.
- Source published
- First seen by Cybersecurity Tracker