<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Elastic Security Labs - Articles by Santosh Krishnan</title>
        <link>https://www.elastic.co/fr/security-labs</link>
        <description>Trusted security news &amp; research from the team at Elastic.</description>
        <lastBuildDate>Wed, 05 Aug 2026 21:07:31 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <image>
            <title>Elastic Security Labs - Articles by Santosh Krishnan</title>
            <url>https://www.elastic.co/fr/security-labs/assets/security-labs-thumbnail.png</url>
            <link>https://www.elastic.co/fr/security-labs</link>
        </image>
        <copyright>© 2026. elasticsearch B.V. All Rights Reserved</copyright>
        <item>
            <title><![CDATA[Elastic changes the SIEM game with AI-driven security analytics]]></title>
            <link>https://www.elastic.co/fr/security-labs/ai-driven-security-analytics</link>
            <guid>ai-driven-security-analytics</guid>
            <pubDate>Tue, 06 May 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn more about Elastic's AI-driven security analytics]]></description>
            <content:encoded><![CDATA[<p>Traditional SIEMs have heavily relied on the human behind the screen for success. Alerting, dashboarding, threat hunting, and finding context among a deluge of signals are all very human-intensive. Search AI will upend this old model and replace the traditional SIEM with an <a href="https://www.elastic.co/fr/security/ai">AI-driven security analytics</a> solution for the modern SOC. Imagine a system that sifts through all of your data, ignoring the noise and identifying what’s critical, discovering specific attacks, and crafting specific remediations. Powered by Elastic's Search AI Platform, Elastic Security is delivering on this evolution, replacing largely manual processes for configuration, investigation, and response. The Search AI Platform uniquely combines search and retrieval augmented generation (RAG) to provide hyper-relevant results that matter.</p>
<p>Since the release of Elastic Security for SIEM in 2019, the solution has grown to include some of the industry’s most advanced analytics capabilities, including <a href="https://www.elastic.co/fr/guide/en/security/current/prebuilt-ml-jobs.html">100+ prebuilt ML-based anomaly detection jobs</a> to detect previously unknown threats fast. Elastic introduced <a href="https://www.elastic.co/fr/blog/elastic-ai-assistant-amazon-bedrock-security-analysts">Elastic AI Assistant for Security</a> last year to help SOC analysts with rule authoring, alert summarization, and workflow and integration recommendations. IDC recently highlighted how Elastic overcomes these limitations in an <a href="https://www.elastic.co/fr/blog/idc-market-perspective-elastic-ai-assistant">IDC Market Perspective on</a> their impressions of AI Assistant.</p>
<p>Co-pilots like AI Assistant are fast becoming table-stakes for many types of security products. As such, these early efforts still depend on the ability of the analyst to use them effectively. It is now time to integrate AI guidance and automation into the core investigative workflows of the SOC. Today, we are ushering in a new AI feature, <a href="http://elastic.co/security/ai">Elastic Attack Discovery</a> (patent pending), powered by the <a href="https://www.elastic.co/fr/platform">Search AI Platform</a>. Attack Discovery triages hundreds of alerts down to the few attacks that matter with a single button click and returns results in an intuitive interface, allowing security operations teams to quickly understand the presented attacks, take immediate follow-up actions, and more.</p>
<p><img src="https://www.elastic.co/fr/security-labs/assets/images/ai-driven-security-analytics/image2.png" alt="Attack Discovery" /></p>
<h2><strong>Prioritize attacks, not alerts</strong></h2>
<p>Elastic’s AI-driven security analytics is built on the Search AI Platform, which includes RAG powered by the industry's foremost search technology. Large language models (LLMs) are only as accurate and current as the information they leverage: their underlying training data and the context provided with the prompt. As such, they require rich, up-to-date data to deliver accurate, tailored results — and efficiently gathering this confidential knowledge requires search. Search-based RAG delivers this context automatically and eliminates the need to build a bespoke LLM and constantly retrain it on ever-changing internal data.</p>
<h4><strong>Fight smarter: Accelerate your SOC with AI</strong></h4>
<p>See how empowering security analysts with generative AI and machine learning helps ensure the success of your SOC.</p>
<p><a href="https://www.elastic.co/fr/virtual-events/accelerate-your-soc-with-ai">Explore what's possible</a><br />
Attack Discovery uniquely leverages the Search AI Platform to sort and identify which alert details should be evaluated by the LLM. By querying the rich context contained within Elastic Security alerts with the <a href="https://www.elastic.co/fr/search-labs/tutorials/search-tutorial/semantic-search/hybrid-search">hybrid search</a> capabilities of Elasticsearch, the solution retrieves the most relevant data to provide to the LLM and instructs it to identify and prioritize the few attacks accordingly. This includes data such as host and user risk scores, asset criticality scores, alert severities, descriptions, alert reasons, and more.<br />
“As a lean organization, we do not operate a traditional SOC team, so the ability to secure our assets faster using our existing team and generative AI is very exciting,&quot; said Kadir Burak Mavzer, Cloud Security team lead at Bolt. &quot;We've already seen great results with Elastic AI Assistant and are looking forward to using Attack Discovery soon.”</p>
<p>“The attacks companies face are as constant as they are sophisticated, and with no lever to slow the deluge of signals, most security teams struggle to keep their heads above water,” said Santosh Krishan, general manager of Security at Elastic. “Nearly 20% of our security customers already use our AI Assistant to boost team efficiency. Similarly, Attack Discovery will power productivity and supplement practitioner knowledge to speed up threat detection, investigation, and response. It helps your people — and SOC — succeed.”</p>
<h2><strong>Lighten SOC workloads</strong></h2>
<p>Many SOCs have thousands of alerts to sift through daily. Much of this work is dull, time-intensive, and error-prone. Elastic removes the need for such manual effort. Attack Discovery triages out the false positives and maps the remaining strong signals to discrete attack chains, showing how related alerts are part of an attack chain. Attack Discovery uses LLMs to evaluate alerts, taking into consideration severity, risk scores, asset criticality, and more. By delivering this accurate and fast triage, analysts can spend less time sifting through alerts and more time investigating and addressing threats.</p>
<p>“You solved the workforce shortage problem with AI Attack Discovery. This investigation would have taken entire teams working on this,” said Ken Buckler, security analyst at EMA. “Attack Discovery blows Splunk out of the water!”</p>
<h2><strong>Elastic’s advantage</strong></h2>
<p>The Search AI Platform harnesses data representing your entire attack surface, improving the accuracy of the insights and guidance delivered by the LLM. Elastic takes an LLM-agnostic approach and enables organizations to anonymize and redact confidential data by default.</p>
<p>Check out our <a href="https://www.elastic.co/fr/security/ai">AI-driven security analytics solution</a> today.<br />
<em>The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.</em></p>
<p><em>In this blog post, we may have used or referred to third party generative AI tools, which are owned and operated by their respective owners. Elastic does not have any control over the third party tools and we have no responsibility or liability for their content, operation or use, nor for any loss or damage that may arise from your use of such tools. Please exercise caution when using AI tools with personal, sensitive or confidential information. Any data you submit may be used for AI training or other purposes. There is no guarantee that information you provide will be kept secure or confidential. You should familiarize yourself with the privacy practices and terms of use of any generative AI tools prior to use.</em></p>
<p><em>Elastic, Elasticsearch, ESRE, Elasticsearch Relevance Engine and associated marks are trademarks, logos or registered trademarks of Elasticsearch N.V. in the United States and other countries. All other company and product names are trademarks, logos or registered trademarks of their respective owners.</em></p>
]]></content:encoded>
            <category>security-labs</category>
            <enclosure url="https://www.elastic.co/fr/security-labs/assets/images/ai-driven-security-analytics/image1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Forecast and Recommendations: 2022 Elastic Global Threat Report]]></title>
            <link>https://www.elastic.co/fr/security-labs/forecast-and-recommendations-2022-elastic-global-threat-report</link>
            <guid>forecast-and-recommendations-2022-elastic-global-threat-report</guid>
            <pubDate>Wed, 30 Nov 2022 00:00:00 GMT</pubDate>
            <description><![CDATA[With the release of our first Global Threat Report at Elastic, customers, partners, and the security community at large are able to identify many of the focus areas our team has had over the past 12 months.]]></description>
            <content:encoded><![CDATA[<p>Today, we released our first-ever <a href="https://www.elastic.co/fr/explore/security-without-limits/global-threat-report">Global Threat Report</a> at Elastic. Now, customers, partners, and the security community at large will be able to identify many of the focus areas our team has had over the past 12 months. In addition to a technical perspective, this report also brings along a series of strategic recommendations for executives and security leaders alike: a summarized, accurate perspective of where we can expect to see adversaries move over the coming months.</p>
<p>Our hope is that threat researchers and the security industry as a whole will use this report to prepare for the next set of threats and campaigns. At Elastic, we are ensuring that our customers using the Elastic Security solution are best protected from these types of threats, including endpoint and cloud capabilities for automated protection.</p>
<p>This year, our report included six key forecasts and recommendations for strategists and practitioners to stay better informed of potential directions that threat actors may focus on in 2023 and beyond. Below, we summarize the first three of our forecasts. Further details on these and our other recommendations are available in our full, <a href="https://www.elastic.co/fr/explore/security-without-limits/global-threat-report">downloadable report</a> for 2022:</p>
<blockquote>
<p>Adversaries will continue to abuse built-in binary proxies to evade security instrumentation. </p>
<p>The use of proven adversarial tactics remains a key area of focus for observed threat groups, and this year remains no different. Hostile groups leverage legitimate, native system binaries to load malicious software — evading many detection strategies used by modern enterprises.</p>
<p>With this continued focus, Elastic Security has enhanced our deep visibility and pre-built protections, including numerous rules and signatures, alongside ML models to detect these threats faster and more effectively.</p>
</blockquote>
<p><img src="https://www.elastic.co/fr/security-labs/assets/images/forecast-and-recommendations-2022-elastic-global-threat-report/blog-elastic-threat2022-1.jpg" alt="" /></p>
<blockquote>
<p>LNK and ISO payloads will replace more conventional script and document payloads.</p>
<p>Adversarial behavior focuses on finding easier, more efficient pathways for attack — and this year, it is no different. System defaults have forced threat groups to pivot their strategies to leverage LNK and ISO payloads over familiar scripts and documents we have observed in the past.</p>
<p>LNK and ISO files are often used to smuggle malicious software into enterprises because most security technologies don't inspect them. Elastic Security has focused on building instrumentation into our products and platform, allowing us to determine the exact mechanisms used to better build a defense against these malicious acts.</p>
</blockquote>
<p><img src="https://www.elastic.co/fr/security-labs/assets/images/forecast-and-recommendations-2022-elastic-global-threat-report/blog-elastic-threat2022-2.jpg" alt="" /></p>
<blockquote>
<p>Valid IAM accounts will continue to be a target for adversaries.</p>
<p>The early stages of many attacks focus on credential theft in all forms; however, IAM and administrative credentials often remain the area of focus for many adversarial groups looking to evade detection and avoid exploitation of services. </p>
<p>Understanding standard account actions and user behaviors exhibited in environments is critical to defending them, and ensuring we have a comprehensive library of detections alongside integration capabilities within the stack has provided a strong foundation in detecting threats earlier.</p>
</blockquote>
<p><img src="https://www.elastic.co/fr/security-labs/assets/images/forecast-and-recommendations-2022-elastic-global-threat-report/blog-elastic-threat2022-3.jpg" alt="" /></p>
<p>This is just a small introduction to the findings found in the report. Far greater detail, recommendations, and source data are available in the <a href="https://www.elastic.co/fr/explore/security-without-limits/global-threat-report">2022 Elastic Global Threat Report</a>.</p>
<p>Those looking to learn more about the threats we observed and the mechanisms adversarial groups leveraged over the last year can read far more detailed information in our full report — alongside many recommendations and findings we have leveraged to help shape the strategy used within the Elastic Security solution, and future feature roadmap.</p>
<p>Feel free to check out the full <a href="https://www.elastic.co/fr/explore/security-without-limits/global-threat-report">2022 Elastic Global Threat Report</a> here.</p>
]]></content:encoded>
            <category>security-labs</category>
            <enclosure url="https://www.elastic.co/fr/security-labs/assets/images/forecast-and-recommendations-2022-elastic-global-threat-report/gtr-blog-image-720x420.jpg" length="0" type="image/jpg"/>
        </item>
    </channel>
</rss>