Hunt and assess posture

Find risks in your environment before they become incidents. Review dashboards, cloud posture findings, and entity risk scores to decide where to look first, and come back regularly to see what changed since your last review.

These tools summarize the data that your other Elastic Security features collect. When a score or finding needs a closer look, use the tools in Investigate, such as Timeline, Discover, and ES|QL, to hunt through the events behind it.

Each tool shows a different view of your risk:

  • Dashboards: Give you a summary of alerts, cloud posture, entity risk, rule health, and data quality. Use them to see trends and to find the area that needs attention.
  • Cloud Security: Findings show which cloud and Kubernetes resources fail Center for Internet Security (CIS) benchmark checks, and which AWS EC2 Linux workloads have known vulnerabilities. Cloud Security Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM) find the misconfigurations, and Cloud Native Vulnerability Management (CNVM) finds the vulnerabilities. Each misconfiguration finding includes steps to fix it.
  • Entity analytics: Scores the risk of each host, user, and service, based on its detection alerts and its asset criticality. It also uses machine learning to find unusual behavior. Use it to find the entities to investigate first.
Your goal Start here
See a summary of alerts, posture, and risk in your environment Dashboards → Overview dashboard
Find and fix misconfigured cloud and Kubernetes resources Cloud Security → CSPM findings or KSPM findings
Find known vulnerabilities on AWS EC2 Linux workloads Cloud Native Vulnerability Management → CNVM findings
Find the hosts, users, and services with the highest risk Entity risk scoring → View and analyze risk score data
Find unusual behavior with machine learning Advanced behavioral detections
Check that your detection rules and data are healthy Detection rule monitoring dashboard → Data Quality dashboard

After you find a risk, you can: