Blogs

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Filters
No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current
Security Labs

No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current

Elastic InfoSec runs Linux endpoint management through Elastic Defend with a scheduled workflow that gets Cursor and Codex config onto new laptops without piling up duplicate actions on offline hosts, and it works for other config too.

Wieger van der Meulen
Quarantined isn't contained: Agentic phishing response with Elastic and Sublime
Security Labs

Quarantined isn't contained: Agentic phishing response with Elastic and Sublime

The native Sublime Security integration sends email detections into Elastic Security, where phishing incident response can tie a quarantined email to what happens next on the endpoint and pull the threat from every mailbox it reached.

Sandiya Ramamoorthy
One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless
Security Labs

One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless

We linked one Elastic Security project to 100 others and ran the full prebuilt detection catalog from the origin, with all the ingest landing in the linked projects. It held up, and where it deliberately does not reach is the interesting part.

Chuddy Park
Why 2026 is the Year to Upgrade to an Agentic AI SOC
Security Labs

Why 2026 is the Year to Upgrade to an Agentic AI SOC

Agentic AI SOCs differ from copilot-only models by autonomously prioritizing attacks over alerts, executing closed-loop containment, and providing traceable reasoning for every decision, allowing analysts to focus on high-value investigations.

Sandiya Ramamoorthy
Data access: the hidden cost of security vendor lock-in
Security Labs

Data access: the hidden cost of security vendor lock-in

Getting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the evaluation most teams overlook.

Mike Nichols
Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass
Security Labs

Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass

We reproduced this java deserialization vulnerability against official Log4j 2.26.1 JARs. Getting to command execution took two more things that Log4j itself does not ship. Here is how the bypass works, which versions carry it, and what to hunt for.

Ruben Groenewoud
Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy
Security Labs

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now clear most alerts with a single click in Slack.

Maggie Musquez
How a team of entity maintainers monitors, connects and scores entities in Elastic Security
Security Labs

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Inside Elastic Security, background jobs called maintainers each own one piece of every user, host and service record, from building entities out of raw logs to resolving identities and scoring risk.

Uri Weisman
13 million tool calls: auditing every AI coding agent action with Elastic Agent
Security Labs

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

Wieger van der Meulen
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
Security Labs

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

A 40-line CEL integration snapshots .npmrc files every 6 hours to catch cooldown removals. This post walks through the three ways we broke filestream before landing on snapshot semantics.

Wieger van der Meulen
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
Security Labs

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports

Ioannis Kakavas
SOC case management and detection rule history in Elastic Security
Security Labs

SOC case management and detection rule history in Elastic Security

Elastic Security now tracks every detection rule change with one-click rollback and makes case data queryable out of the box, so SOC teams get audit trails and reporting without configuring anything.

Kseniia Ignatovych