Elastic Security Labs Threat Commandによる主要な脅威調査

検出工学

すべて表示

マルウェア分析

すべて表示
エージェント型SOCのベンチマーク:セキュリティワークフローにおけるLLMの評価方法

エージェント型SOCのベンチマーク:セキュリティワークフローにおけるLLMの評価方法

公開されているランキングでは、SOCでどのLLMを信頼すべきかを判断することはできません。そこでElasticは、Agent Builder、Attack Discovery、自動移行における作業(ツール呼び出し、実行トレース、ブラインド評価)に基づいてモデルを評価するフレームワークを構築しました。

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports

Elastic InfoSecのエージェント型SOCの内部:AIエージェントのLLMコールを60%削減する方法

Elastic InfoSecのエージェント型SOCの内部:AIエージェントのLLMコールを60%削減する方法

We run fourteen AI agents that triage Elastic InfoSec alerts. They were taking 19 LLM calls to do work that needed 8. Here's the five-step optimization loop we run across the fleet, plus the prompt template you can use with any AI assistant.

Linuxに夢中:ルートキット検出エンジニアリング

Linuxに夢中:ルートキット検出エンジニアリング

全2回シリーズの第2回となる本稿では、Linuxのルートキット検出技術について、静的検出への依存の限界と、ルートキットの挙動検出の重要性に焦点を当てて解説します。

脅威インテリジェンス

すべて表示

機械学習

すべて表示
エージェント型SOCのベンチマーク:セキュリティワークフローにおけるLLMの評価方法

エージェント型SOCのベンチマーク:セキュリティワークフローにおけるLLMの評価方法

公開されているランキングでは、SOCでどのLLMを信頼すべきかを判断することはできません。そこでElasticは、Agent Builder、Attack Discovery、自動移行における作業(ツール呼び出し、実行トレース、ブラインド評価)に基づいてモデルを評価するフレームワークを構築しました。

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports

Alert Zero:エージェント型SOC向けのAI駆動型アラートトリアージおよび攻撃調査

Alert Zero:エージェント型SOC向けのAI駆動型アラートトリアージおよび攻撃調査

Elastic Security 9.5では、SOCチーム向けに、最初の段階のアラートのトリアージと調査を処理するAIが提供されるため、アナリストはキューのノイズを処理する代わりに、脅威ハンティングと検出エンジニアリングに専念できるようになります。

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Every stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection.