icon

ELASTIC ENDPOINT SECURITY

Stop threats in their tracks

Elastic Endpoint Security is the only endpoint protection product to combine prevention, detection, and response into a single, autonomous agent. It's easy to use, built for speed, and stops threats at the earliest stages of attack.

MarketoFEForm

Cultivate the skills and procedures that enable successful threat hunting with this guidebook.

View free guidebook

Learn how your security team can benefit from our resource-based pricing model.

Read more

Make sense of how each security vendor performed in MITRE ATT&CK® evals.

View the results in Kibana

New

In 7.8, we updated our Elastic Endpoint Security model for detecting malware, reducing the incidence of both false negatives and false positives.

As simple as antivirus, but way more powerful

Integrating endpoint security with Elastic SIEM delivers a comprehensive security operations solution that supports numerous use cases.

Ransomware prevention

Ransomware prevention

With a combination of behavior-based detection, MalwareScore, and exploit prevention technology, we stop ransomware and other destructive attacks before disk encryption occurs.

Phishing prevention

Phishing prevention

The industry's only on-endpoint phishing prevention. Machine learning blocks the execution of malicious Microsoft Office documents and PDFs.

Reflex™ Custom Prevention

Reflex™ Custom Prevention

The first autonomous prevention and detection engine that invokes custom incident response actions on the endpoint without the need for cloud connectivity.

Malware prevention

Malware prevention

MalwareScore® blocks unknown attacks against Windows and macOS endpoints with machine-learning powered, signatureless methods. It is published to VirusTotal and validated by third-parties like NSS Labs.

Exploit prevention

Exploit prevention

Block attempts to exploit vulnerabilities — even zero-day vulnerabilities and kernel exploits designed to elevate privileges — before malicious code can execute.

Fileless attack prevention

Fileless attack prevention

Our injection protection stops in-memory attacks like reflective DLL and shellcode injection. We detect and can block suspicious and malicious PowerShell scripts, and CLR Guard is an industry first for .NET reflection attacks.

Validated by the best

More than just endpoint protection

We're bringing endpoint protection and SIEM together to streamline how you secure your organization.

ENDPOINT + SIEM

Unified protection with Elastic Security

Streamline your security stack by shipping rich host data to your SIEM from the same agent already deployed to protect your endpoints. Enabling defense in depth doesn’t get any simpler.

SCALABLE & FAST

Get total attack (way, way) lookback

Laptops wander, cloud instances shut down — but investigators still need retrospective visibility. Threats often incubate for over 100 days, exceeding the data retention period for most SOCs. Elastic enables the central analysis of months or even years of endpoint data, appreciably improving your security posture.

PROTECTION ANYWHERE

Works with speed and without compromise

From submarines to Starbucks, attacks can happen anywhere — and endpoints aren’t always connected to the cloud. We’ve designed for hybrid environments by locating prevention and detection logic on the endpoint, making our protection as effective in a Faraday cage as it is when cloud-connected. Go even further against advanced attacks with global detection on Elastic SIEM.

FLEXIBLE LICENSING

Keep it simple. No more pricing by endpoint.

Traditional cybersecurity licensing forces you to make compromises. Why should you need to count the number of devices you need to protect? Or choose how many days of threat intelligence data you can afford to retain? With Elastic, you won’t have to do any of that to get the best protection from our products. Just pay for the resources you use and continue doing great things with Elastic.

Here's how we stack up

The rest of the industry focuses on monetizing protection capabilities. With Elastic, you get optimal protection the first time.

ELASTIC ENDPOINT SECURITY

CROWDSTRIKEFalcon

CARBON BLACKCB Defense

Signatureless malware and ransomware prevention

Automated threat hunting and response

Additional products required
Additional products required

Comprehensive MITRE ATT&CK® protection

Additional products required

Full protection when online and offline

Cloud lookup required
Cloud only

Unlimited forensic review

7 days
Additional products required

On-prem and cloud management options

Signatureless malware and ransomware prevention

Automated threat hunting and response

Comprehensive MITRE ATT&CK® protection

Full protection when online and offline

Unlimited forensic review

On-prem and cloud management options

ELASTIC ENDPOINT SECURITY

CROWDSTRIKEFalcon

CARBON BLACKCB Defense

Additional products required
Additional products required
Additional products required
Cloud lookup required
Cloud only
7 days
Additional products required

Accomplish More

Plus all the goodness of Elastic

Elastic Endpoint Security is built on the Elastic Stack, presenting an entire universe of products and features to enrich and extend your use case.

Trusted, used, and loved by