Loading

Attack Discovery

Attack Discovery uses large language models (LLMs) to analyze alerts and identify potential attacks. Each discovery groups related alerts into an attack narrative. It shows which users and hosts are involved, how alerts map to the MITRE ATT&CK matrix, and which threat actor might be responsible. Use discoveries to prioritize investigation and shorten mean time to respond.

You can start a run from the UI (manual or scheduled), from an automated workflow, or from an Elastic Agent Builder conversation. All methods use the same analysis steps.

For a demo, refer to the following video (click to view).

Attack Discovery video

Each discovery includes the following information describing the potential threat, generated by the connected LLM:

  1. A descriptive title and a summary of the potential threat.
  2. The number of associated alerts and which parts of the MITRE ATT&CK matrix they correspond to.
  3. The implicated entities (users and hosts), and what suspicious activity was observed for each.
Attack Discovery detail view

Choose how to start a run from the Attacks view, a workflow, Elastic Agent Builder, or the Attack Discovery page in Run Attack Discovery.