CYBERSECURITYTRACKER
TRACKING6,626 stories in this site build1,366 vulnerability news stories in this site build
Permanent story citation

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3631

As cited

Copy frozen at (site build).

vulnerabilities

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

Elastic announced three endpoint security enhancements to Elastic Defend: automated detection rule generation for over 800 vulnerable drivers by continuously monitoring public disclosure sources, an Automatic Troubleshooting capability via Elastic Agent Builder to improve endpoint management efficiency, and support for Windows on ARM64 architecture. The vulnerable driver detection system closes gaps between public disclosure and vendor protection by decoupling coverage from release cycles and publishing protections immediately as new drivers are identified from VirusTotal, LOLDrivers, and Microsoft's Vulnerable Driver Block List.

Why it matters: Security teams defending Windows endpoints need awareness of Elastic's real-time vulnerable driver protection to reduce the window of exposure that attackers exploit when using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security tools before ransomware deployment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

Elastic announced three endpoint security enhancements to Elastic Defend: automated detection rule generation for over 800 vulnerable drivers by continuously monitoring public disclosure sources, an Automatic Troubleshooting capability via Elastic Agent Builder to improve endpoint management efficiency, and support for Windows on ARM64 architecture. The vulnerable driver detection system closes gaps between public disclosure and vendor protection by decoupling coverage from release cycles and publishing protections immediately as new drivers are identified from VirusTotal, LOLDrivers, and Microsoft's Vulnerable Driver Block List.

Why it matters: Security teams defending Windows endpoints need awareness of Elastic's real-time vulnerable driver protection to reduce the window of exposure that attackers exploit when using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security tools before ransomware deployment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

Elastic announced three endpoint security enhancements to Elastic Defend: automated detection rule generation for over 800 vulnerable drivers by continuously monitoring public disclosure sources, an Automatic Troubleshooting capability via Elastic Agent Builder to improve endpoint management efficiency, and support for Windows on ARM64 architecture. The vulnerable driver detection system closes gaps between public disclosure and vendor protection by decoupling coverage from release cycles and publishing protections immediately as new drivers are identified from VirusTotal, LOLDrivers, and Microsoft's Vulnerable Driver Block List.

Why it matters: Security teams defending Windows endpoints need awareness of Elastic's real-time vulnerable driver protection to reduce the window of exposure that attackers exploit when using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security tools before ransomware deployment.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary