Security Labs

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Featured Articles

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now clear most alerts with a single click in Slack.

Maggie Musquez

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Uri Weisman

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Wieger van der Meulen

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

Wieger van der Meulen

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Ioannis Kakavas
All articles

Blog

Hand-picked stories from our editors — threat detection, audit logging, and security operations insights.

SOC case management and detection rule history in Elastic Security

Elastic Security now tracks every detection rule change with one-click rollback and makes case data queryable out of the box, so SOC teams get audit trails and reporting without configuring anything.

Kseniia Ignatovych

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.

Jackie McGuire

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

Elastic Defend automatically generates and instantly deploys vulnerable driver YARA rules from VirusTotal, LOLDrivers and Microsoft's blocklist, closing the gap BYOVD attacks depend on. Plus a new troubleshooting skill and ARM endpoint protection.

Pedro Jaramillo

Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC

Elastic Security 9.5 gives SOC teams AI that handles first-pass alert triage and investigation, so analysts can get back to threat hunting and detection engineering instead of working through queue noise.

David Elgut

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Elastic's first automatic migration from a modern SIEM. Translate your Sentinel detection rules into Elastic Security without rebuilding them.

Charles Davison

Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%

We run fourteen AI agents that triage Elastic InfoSec alerts. They were taking 19 LLM calls to do work that needed 8. Here's the five-step optimization loop we run across the fleet, plus the prompt template you can use with any AI assistant.

Aaron Jewitt

Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

We tested two agentic SOC architectures in parallel across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.

Aaron Jewitt

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.

Ruben Groenewoud

How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

Elastic InfoSec tested this detection rule pattern on their own cloud fleet, filtering noisy curl and wget events with deterministic logic and LLM triage so only genuine threats reach an analyst.

Aaron Jewitt

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic's InfoSec team built AI agents on Elastic Workflows that investigate every alert and assemble the case before an analyst ever opens it.

Aaron Jewitt

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

How Elastic's security team built an AI agent with RAG against MITRE's CWE and CAPEC catalogues to draft CVE advisories from raw vulnerability reports, including the full prompt and crawler configs.

Paul McCann

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.

Terrance DeJesus

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Find out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.

Jamie Hynds

Elastic Security MCP App: Interactive security operations inside your AI Tools

Elastic Security is the first security vendor to ship an interactive UI in AI tools. Triage alerts, hunt threats, correlate attack chains, and open cases, all from inside your AI conversation.

David Elgut

Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

This article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.

Erik-Jan de Kruijf