LevelBlue disclosed RAVEN, an offensive security framework built to test how exposed or compromised Kibana and Elasticsearch environments can be abused for full-spectrum intrusion activity. The tool demonstrates Kibana reconnaissance through the /api/status endpoint, extraction of dashboards and saved objects, and exploitation of known flaws including CVE-2018-17246 and CVE-2019-7609, the latter using a Timelion prototype-pollution chain that can lead to remote code execution. The reporting also highlights that Kibana access alone can reveal embedded credentials and operational intelligence even without a successful exploit.
The same framework shows how attackers could move from access to impact inside Elasticsearch by exporting individual or all non-system indices, using Point-in-Time or Scroll APIs for bulk collection, and performing stealthier snapshot-based exfiltration from the server side. It also demonstrates persistence through API keys, rogue superuser accounts, and Watcher jobs that can recreate deleted backdoors, allowing access to survive password rotation unless every artifact is removed. In its final phase, RAVEN simulates destructive actions including index deletion, document wiping, mapping corruption, Meow-style tampering, and multiple denial-of-service modes, underscoring the risk posed by exposed management interfaces and incomplete remediation.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News summarized LevelBlue's RAVEN research, highlighting Elasticsearch data exfiltration, snapshot abuse, API key persistence after password rotation, and Watcher-based restoration of attacker access. The article emphasized that the work described controlled penetration-testing research rather than an active criminal campaign.
LevelBlue published Part 5 of its RAVEN series covering destructive operations such as index deletion, delete-by-query wiping, mapping corruption, Meow-style simulation, and five denial-of-service modes. The post also described RAVEN's triple-gated safety controls and cleanup logging for reversible actions.
LevelBlue released a follow-on post describing post-compromise use of RAVEN against Elasticsearch and Kibana, including bulk index exfiltration, snapshot-based theft, API key abuse, and persistence via rogue users, long-lived API keys, and Watcher jobs. The demonstrations were conducted in Docker-based lab environments.
LevelBlue published research showing RAVEN modules for Kibana reconnaissance, CVE detection, exploitation, and saved-object intelligence extraction in lab environments. The post demonstrated exploitation paths for CVE-2018-17246 and CVE-2019-7609 against vulnerable Kibana targets.
The LevelBlue article states that the real Meow Attack in 2020 wiped documents from exposed Elasticsearch databases and replaced them with random alphanumeric strings ending in "-meow." It says more than 12,000 Elasticsearch databases were corrupted.
CVE-2019-7609 was disclosed as a prototype pollution flaw in Kibana's Timelion visualizer affecting versions before 5.6.15 and 6.0.0 through 6.6.0. The bug could lead to remote code execution when Kibana later forked a new Node.js child process.
CVE-2018-17246 affected Kibana versions before 6.4.3 and allowed arbitrary file reads via the Console plugin's file inclusion mechanism. The flaw could disclose file contents indirectly through Kibana application logs.
The LevelBlue research references CVE-2015-5531 as a vulnerability that enables file-read capability through the Elasticsearch snapshot API, providing historical context for snapshot-related abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcelevelblue.com
Open sourcelevelblue.com
Open sourcelevelblue.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.