Respond and contain
When your detection rules find a threat, triage the alert, then act on the affected host to stop the threat from spreading. You can isolate a host, stop a process, collect a file for analysis, and take other actions without leaving Elastic Security.
To investigate an alert before you act, such as to find its root cause or its scope, refer to Investigate. To review alerts that AI has grouped into attacks, refer to Attack Discovery.
You usually move from an alert to a response action in a few steps:
- Triage the alert: On the Alerts page, filter alerts to focus on what matters, and change each alert's status as you work through it.
- Act on the host: From the alert details flyout, select Take action → Respond to open the response console for the host that generated the alert. Enter commands in the console to isolate the host, stop processes, get files, and more.
- Check the results: The response actions history records every action and its output, so you can confirm that an action completed.
| Your goal | Start here |
|---|---|
| View, filter, and change the status of detection alerts | Manage detection alerts |
| Run response actions on an endpoint from the response console | Endpoint response actions |
| Block a host from communicating with your network | Isolate a host |
| Run response actions automatically when a rule generates an alert | Automated response actions |
| Respond on hosts that CrowdStrike, Microsoft Defender for Endpoint, or SentinelOne manage | Configure third-party response actions → Third-party response actions |
| Review past response actions and their results | Response actions history |
After you contain a threat, you can:
- Track the incident and coordinate with your team in cases.
- Add host isolation exceptions for IP addresses that isolated hosts still need to reach.
- Reduce noise and false positives by tuning the rules that generated the alerts.