Respond and contain

When your detection rules find a threat, triage the alert, then act on the affected host to stop the threat from spreading. You can isolate a host, stop a process, collect a file for analysis, and take other actions without leaving Elastic Security.

To investigate an alert before you act, such as to find its root cause or its scope, refer to Investigate. To review alerts that AI has grouped into attacks, refer to Attack Discovery.

You usually move from an alert to a response action in a few steps:

  1. Triage the alert: On the Alerts page, filter alerts to focus on what matters, and change each alert's status as you work through it.
  2. Act on the host: From the alert details flyout, select Take action → Respond to open the response console for the host that generated the alert. Enter commands in the console to isolate the host, stop processes, get files, and more.
  3. Check the results: The response actions history records every action and its output, so you can confirm that an action completed.
Your goal Start here
View, filter, and change the status of detection alerts Manage detection alerts
Run response actions on an endpoint from the response console Endpoint response actions
Block a host from communicating with your network Isolate a host
Run response actions automatically when a rule generates an alert Automated response actions
Respond on hosts that CrowdStrike, Microsoft Defender for Endpoint, or SentinelOne manage Configure third-party response actions → Third-party response actions
Review past response actions and their results Response actions history

After you contain a threat, you can: