Category: AI & Automation

Articles tagged AI & Automation

Subscribe
Filters
No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current
Security Labs

No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current

Elastic InfoSec runs Linux endpoint management through Elastic Defend with a scheduled workflow that gets Cursor and Codex config onto new laptops without piling up duplicate actions on offline hosts, and it works for other config too.

Wieger van der Meulen
Quarantined isn't contained: Agentic phishing response with Elastic and Sublime
Security Labs

Quarantined isn't contained: Agentic phishing response with Elastic and Sublime

The native Sublime Security integration sends email detections into Elastic Security, where phishing incident response can tie a quarantined email to what happens next on the endpoint and pull the threat from every mailbox it reached.

Sandiya Ramamoorthy
Why 2026 is the Year to Upgrade to an Agentic AI SOC
Security Labs

Why 2026 is the Year to Upgrade to an Agentic AI SOC

Agentic AI SOCs differ from copilot-only models by autonomously prioritizing attacks over alerts, executing closed-loop containment, and providing traceable reasoning for every decision, allowing analysts to focus on high-value investigations.

Sandiya Ramamoorthy
Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy
Security Labs

Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy

Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now clear most alerts with a single click in Slack.

Maggie Musquez
13 million tool calls: auditing every AI coding agent action with Elastic Agent
Security Labs

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

Wieger van der Meulen
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
Security Labs

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports

Ioannis Kakavas
Journey to AlertZero: AI-driven alert triage and attack investigation for the agentic SOC
Security Labs

Journey to AlertZero: AI-driven alert triage and attack investigation for the agentic SOC

Elastic Security 9.5 gives SOC teams AI that handles first-pass alert triage and investigation, so analysts can get back to threat hunting and detection engineering instead of working through queue noise.

David Elgut
Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%
Security Labs

Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%

We run fourteen AI agents that triage Elastic InfoSec alerts. They were taking 19 LLM calls to do work that needed 8. Here's the five-step optimization loop we run across the fleet, plus the prompt template you can use with any AI assistant.

Aaron Jewitt
Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction
Security Labs

Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

We tested two agentic SOC architectures in parallel across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.

Aaron Jewitt
How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
Security Labs

How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

Elastic InfoSec tested this detection rule pattern on their own cloud fleet, filtering noisy curl and wget events with deterministic logic and LLM triage so only genuine threats reach an analyst.

Aaron Jewitt
Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3
Security Labs

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic's InfoSec team built AI agents on Elastic Workflows that investigate every alert and assemble the case before an analyst ever opens it.

Aaron Jewitt
From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI
Security Labs

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

How Elastic's security team built an AI agent with RAG against MITRE's CWE and CAPEC catalogues to draft CVE advisories from raw vulnerability reports, including the full prompt and crawler configs.

Paul McCann

Elastic Security Labs Newsletter