RAVEN Tool Exfiltrates Entire Elasticsearch Databases and Maintains Access After Password Rotation

A newly detailed offensive security tool called RAVEN shows how a compromised Elasticsearch environment can become a data-loss incident with persistent access. The tool demonstrates what an intruder could do after reaching an exposed cluster or controlling Kibana. The attack path begins after reconnaissance and exploitation have opened the door. An operator can query Elasticsearch, […]

This article has been indexed from Cyber Security News

Read the original article: