<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title><![CDATA[Jamie Hynds - Elastic Security Labs]]></title>
    <description><![CDATA[Trusted security news & research from the team at Elastic.]]></description>
    <copyright><![CDATA[© 2026. Elasticsearch B.V. All Rights Reserved]]></copyright>
    <image>
      <title><![CDATA[Jamie Hynds - Elastic Security Labs]]></title>
      <url>https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blte2c6b841aff36df4/6a88d9784acc96e3f324863d/security-labs-thumbnail.png</url>
      <link>https://www.elastic.co/security-labs/author/jamie-hynds</link>
    </image>
    <link>https://www.elastic.co/security-labs/author/jamie-hynds</link>
    <atom:link href="https://www.elastic.co/security-labs/rss/author/jamie-hynds.xml" rel="self" type="application/rss+xml"/>
    <language><![CDATA[en]]></language>
    <lastBuildDate>Tue, 22 Sep 2026 09:38:06 GMT</lastBuildDate>
  <item>
    <title><![CDATA[Data access: the hidden cost of security vendor lock-in]]></title>
    <description><![CDATA[Getting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the evaluation most teams overlook.]]></description>
    <content:encoded><![CDATA[<p>Your security data is the most important asset in your SOC. Not the dashboards, not the detections, not the AI features on the roadmap slide. The data. And most vendors make you pay, wait, or license your way to getting it back out. Every investigation your analysts run, every model you train, every agent you deploy is only as good as the telemetry underneath it. So here is the question I want you to ask every vendor in your stack: if I want my data, right now, what does that take?</p><p>Most vendors cannot answer it cleanly. And the answer matters more than almost anything else on the RFP.</p><h2><strong>What open actually means</strong></h2><p>The industry has gotten comfortable treating “open” as a checkbox. Support an open schema, publish an API, sponsor a standard, done. But a standard tells you how data is shaped. It tells you nothing about whether you can actually get it. Open data means three things, and you need all three:</p><p><strong>It is yours, at no additional cost.</strong> You generated this telemetry. You paid to collect it, and you paid to store it. If your vendor charges you a second time to access it, that is not a data feature. That is a toll booth on your own driveway.</p><p><strong>It is all of your data.</strong> Not the alerts. Not a normalized summary. Not the tables the vendor decided are ready. The full-fidelity record because you cannot predict today which field matters in next year’s investigation.</p><p><strong>It is real time.</strong> This one used to be a nice-to-have. Not anymore. <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike’s own 2026 Global Threat Report </a>clocked the average eCrime breakout time at 29 minutes, the fastest at 27 seconds, and one intrusion where exfiltration started four minutes after initial access. Attackers are moving faster too, using AI to shorten the gap between breaking in and doing real damage. If your telemetry arrives in batches, minutes apart, the attack can be over before your data shows up. You would not accept a smoke detector that checks for fire twice an hour.</p><p>When a vendor fails any of these three, they are not protecting your data. They are building an artificial moat with it. Ingestion is always frictionless. Egress is licensed, delayed, or degraded. That asymmetry is not an accident of engineering. It is the business model, and the industry has a name for it: lock-in.</p><h2><strong>What the documentation actually says</strong></h2><p>Don’t take our word for it. Every claim in this table links to the vendor’s own documentation. Read it yourself, and hold us to the same bar.</p><p><strong>Vendor</strong></p><p><strong>How you get your data out</strong></p><p><strong>Cost to access your data</strong></p><p><strong>Freshness</strong></p><p><strong>Fidelity</strong></p><p><strong>Openness</strong></p><p><strong>CrowdStrike</strong></p><p><a href="https://developer.crowdstrike.com/accomplish/stream-and-analyze-data/">Falcon Data Replicator</a>: batched file export to object storage</p><p><a href="https://www.crowdstrike.com/en-us/resources/data-sheets/falcon-data-replicator/">Licensed add-on</a></p><p>Bulk batches, not a live stream; <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-falcon-and-humio-leverage-all-your-fdr-data-in-one-place/">deleted after 7 days</a> for CrowdStrike managed-buckets</p><p>Raw telemetry is only available via FDR; the <a href="https://developer.crowdstrike.com/accomplish/stream-and-analyze-data/">event stream API</a> sends detections, not telemetry</p><p><strong>Restricted</strong></p><p><strong>Palo Alto Networks</strong></p><p>XSIAM <a href="https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/manage-event-forwarding">Event Forwarding</a>: batch files to a Palo Alto-managed bucket</p><p><a href="https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses">Two paid Event Forwarding add-ons</a>: GB and Endpoint</p><p><a href="https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/manage-event-forwarding">Batch; up to 2 hours to appear; kept 14 days</a></p><p>Endpoint and log data <a href="https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses">split across the two add-ons</a></p><p><strong>Restricted</strong></p><p><strong>Microsoft</strong></p><p>Defender <a href="https://learn.microsoft.com/en-us/defender-xdr/streaming-api">streaming API</a>; Sentinel <a href="https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-data-export">data export</a></p><p>Streaming: pay Azure infra; <a href="https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-data-export">Sentinel export billed per GB</a></p><p><a href="https://learn.microsoft.com/en-us/defender-xdr/api-overview">Real-time stream</a> (via Azure Event Hubs)</p><p><a href="https://learn.microsoft.com/en-us/defender-xdr/supported-event-types">Generally-available fields only</a>; Azure destinations only</p><p><strong>Partially open</strong></p><p><strong>Google</strong></p><p><a href="https://docs.cloud.google.com/chronicle/docs/reference/data-export-api-enhanced">Bulk export</a> to your storage, or a <a href="https://docs.cloud.google.com/chronicle/docs/reports/bigquery-export">continuous BigQuery feed</a></p><p>Export capped; <a href="https://docs.cloud.google.com/chronicle/docs/reports/bigquery-export">BigQuery billed by query</a></p><p><a href="https://docs.cloud.google.com/chronicle/docs/reports/bigquery-export">Live feed 5-10 min behind</a> (top tier only); raw export is point-in-time</p><p>Live feed is normalized only; no continuous raw path</p><p><strong>Limited</strong></p><p><strong>Splunk </strong></p><p><a href="https://help.splunk.com/en/splunk-cloud-platform/search/search-manual/9.3.2411/export-search-results/export-data-using-the-splunk-rest-api">Search/export REST API</a></p><p>Included</p><p>On-demand query via <a href="https://help.splunk.com/en/splunk-cloud-platform/search/search-manual/9.3.2411/export-search-results/export-data-using-the-splunk-rest-api">export data API</a>; data available near-real-time</p><p>Full events returned as structured JSON</p><p><strong>Open</strong></p><p><strong>Elastic</strong></p><p>REST APIs including <a href="https://www.elastic.co/docs/solutions/search/the-search-api">Search</a>, <a href="https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-open-point-in-time">Point in time</a> and <a href="https://www.elastic.co/docs/reference/query-languages/esql/esql-rest">ES|QL</a></p><p>No export license or per-query export fee; <a href="https://www.elastic.co/docs/deploy-manage/cloud-organization/billing/cloud-hosted-deployment-billing-dimensions">Elastic Cloud applies ordinary cloud data-transfer metering</a>, not an egress toll</p><p>On-demand query via API; data available to query <a href="https://www.elastic.co/docs/manage-data/data-store/near-real-time-search">as soon as it is indexed</a></p><p>Full raw and parsed events, returned as structured JSON</p><p><strong>Open</strong></p><p><em>This table reflects each vendor's public documentation as of September 2026.</em></p><p></p><p>A note on the ratings, because we want them to be defensible, not convenient. Open means all three tests pass: no added cost, full fidelity, and no batch window between the moment data arrives and the moment you can use it. Data you can query the moment it lands clears that bar; a scheduled batch measured in minutes or hours does not. Partially open means the vendor genuinely tries but with real constraints; credit to Microsoft for a true streaming path, even if it covers only generally-available fields and only lands in Azure. Limited means the data comes back, but late or in a form only the vendor can read. Restricted means access to your own telemetry is a paid product, a delayed batch, or both.</p><p>And since Elastic is on this list too, as an endpoint agent and a SIEM, hold us to the same bar. Our rating is about live access: APIs that return JSON, with no license between you and your own telemetry. On Elastic Cloud you pay ordinary data-transfer rates like any cloud service. What you never pay is a license to reach data that was already yours.</p><p>If any vendor believes we have mischaracterized their documentation, I genuinely want to hear it, and we will correct it.</p><h2><strong>So what does this actually cost you?</strong></h2><p>Here is what that comparison means when it really counts, in the middle of an incident. Detection you cannot act on in time is not detection. When your telemetry arrives in scheduled batches, a window opens between the alert and the evidence. Sometimes minutes, sometimes longer, and in that window the attack is live while your data is not yet in front of you. You paid to collect that telemetry. You paid to store it. And at the one moment it matters, it is still in transit. Or worse, it is not there at all because exporting it requires a separate license. That’s the difference between stopping an intrusion and reading about it afterward.</p><p>You do not create that gap during an incident. You inherit it at purchase. You already run a strong endpoint agent. It works, and you trust it. Now that same vendor offers to be your SIEM as well. One console, one relationship, one invoice. There is nothing wrong with one vendor doing both. We do both at Elastic. The question is what it costs you to change your mind. So look closely at what it takes to move that endpoint telemetry somewhere other than their own platform. Every vendor makes it easy to get data in. Getting it back out is something you buy, then wait for.</p><p>It is rarely just one handoff. Most security environments are heterogeneous by design, with each layer chosen because it is good at its own job. Modern attacks move across all of them, from a stolen identity to a cloud workload to an endpoint, and you only see the full chain if the data from each can meet in one place, quickly and without a toll. When a vendor makes its telemetry expensive or slow to share, it is not just charging you. It’s fragmenting the picture, and a fragmented picture is exactly where intrusions hide. The all-in-one pitch offers to solve that. But the fragmentation was manufactured: vendors made their data hard to move, then sold you the one console where it comes back together. So before convenience makes the decision for you, ask three questions, and make the vendor answer them in writing:</p><ul><li><p>Can I get all of my telemetry out, continuously, without buying a separate license to do it?</p></li><li><p>How long, exactly, from the moment an event happens to the moment it is usable in a system I chose?</p></li><li><p>On the day I add a different analytics engine, a data lake, or a new AI model, what breaks?</p></li></ul><p>If the honest answers are “extra cost,” “in batches,” and “quite a lot,” then you are not buying a SIEM. You are renting access to your own data. The point is not that these layers must stay separate. Plenty of teams consolidate for good reasons, and we sell both layers ourselves. The point is that the choice should stay yours: you can add the analytics platform you want, or leave the one you have, without paying a toll or waiting on a batch to get your own data. The only reason to accept less is that a vendor made leaving hard enough that staying felt like a decision. It was not a decision. It was the absence of one.</p><h2><strong>The strategic question</strong></h2><p>Your SIEM is not a tool you bought. It is where isolated alerts become an attack story, and where you go to find out what actually happened. The vendor holding it is a strategic dependency, whether you planned it that way or not.</p><p>So evaluate them like one. Put data portability on the RFP, not in the demo, and score it on two things: what it costs to move your telemetry somewhere else, and how much delay it adds.</p><p>Because you cannot build a real-time defense on a delayed copy of your own telemetry, and you should not have to buy your data back to try.</p><p>It is your data. Any vendor who makes that complicated has told you what kind of partner they intend to be.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/siem-data-export-comparison</link>
    <guid isPermaLink="false">siem-data-export-comparison</guid>
    <category><![CDATA[Security Operations]]></category>
    <category><![CDATA[SOC]]></category>
    <dc:creator><![CDATA[Mike Nichols,Jamie Hynds]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt194a2b93239a98c3/6a9a90363481c2bd668af9b3/2189.png" length="0" type="image/png"/>
    <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title><![CDATA[From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence]]></title>
    <description><![CDATA[Find out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.]]></description>
    <content:encoded><![CDATA[<p>Elastic Security natively ingests Google Threat Intelligence: known-malicious IPs, domains, URLs, and file hashes matched against your telemetry the moment they appear, each carrying a verdict and a 0–100 threat score. The setup consists of an API key and two data streams, with no extra infrastructure. When an indicator is ambiguous, workflows built on Agent Builder query VirusTotal in real time, enrich the alert, correlate with your telemetry, and summarize findings in real time. </p>
<h2 id="howthreatintelligenceworksinelasticsecurity">How threat intelligence works in Elastic Security</h2>
<p>In modern security operations, threat intelligence must work across detection, investigation, and response, not sit in a reference table.</p>
<p>Elastic Security supports this in two ways. Ingested intelligence via <a href="https://www.elastic.co/docs/reference/integrations/threat-intelligence-intro">integrations</a> drives continuous detection and historical hunting. Agentic workflows, built on Elastic Workflows and Agent Builder, provide on-demand enrichment and investigative reasoning during an active investigation. This post focuses on how Elastic's Google Threat Intelligence (GTI) integration powers ingestion-based detection and hunting, and how it fits into a broader, more dynamic SOC model where AI-driven workflows use that intelligence at alert time.</p>
<h2 id="whatgooglethreatintelligenceprovides">What Google Threat Intelligence provides</h2>
<p>The Google Threat Intelligence integration brings curated threat intelligence directly into Elastic Security, making it actionable across detection and investigation. GTI combines intelligence from Google's global security visibility with VirusTotal data to deliver enriched context on indicators of compromise, with coverage across malware, ransomware, phishing, infostealers, malicious infrastructure, threat actors, and other adversary activity.</p>
<p>Each indicator is returned with: a verdict (Malicious, Suspicious, or Undetected), a severity, and a composite threat score from 0–100. Because that score is derived from multiple signals, security teams can prioritize indicators based on confidence rather than their presence alone.</p>
<h2 id="howthegooglethreatintelligenceintegrationworksinelasticsecurity">How the Google Threat Intelligence integration works in Elastic Security</h2>
<p>Setup takes only a few minutes. You provide your GTI API key in the Elastic integration, and ingestion begins on a scheduled polling interval, with no additional infrastructure or collectors required. The integration ingests two primary data streams.</p>
<p>| Purpose | Threat List | IOC Stream |
|--------|-------------|------------|
| Purpose | High-confidence detection | Threat hunting + early visibility |
| Volume | Curated, lower volume | Broader, higher volume |
| Best for | Precision-critical alerting | Emerging and exploratory activity |</p>
<p>As data is ingested, indicators are standardized using the Elastic Common Schema (ECS), along with GTI context, such as verdict, severity, score, malware families, threat actor associations, and campaign metadata (where available). This enables GTI to be searched and correlated consistently alongside other ECS-compliant intelligence sources (including TAXII feeds), custom intelligence, and the broader security telemetry already present in Elastic Security. Elastic also manages indicator lifecycle automatically, including expiration and revocation, which reduces matches against stale intelligence. Once ingested, GTI indicators become part of the same searchable dataset as logs, endpoint, and cloud telemetry, enabling unified correlation across the environment.</p>
<h2 id="usinggooglethreatintelligenceforindicatormatchdetections">Using Google Threat Intelligence for indicator match detections</h2>
<p>Elastic's <a href="https://www.elastic.co/docs/solutions/security/detect-and-alert/indicator-match">indicator match rules</a> use GTI data to detect when known malicious IPs, domains, URLs, or file hashes appear in security telemetry, continuously correlating intelligence against observed activity and surfacing matches for investigation. Because GTI provides structured fields such as score, verdict, and severity, teams can tune detections by confidence: high-confidence indicators can trigger immediate escalation, while lower-confidence indicators can be routed for review or further validation.</p>
<h2 id="threathuntingwithgtiindicatorsinelasticsecurity">Threat hunting with GTI indicators in Elastic Security</h2>
<p>With GTI metadata, analysts can pivot from a single IOC to all associated infrastructure and search historical telemetry; not just check if an indicator appeared, but understand what campaign it belongs to.</p>
<p>GTI enriches indicators with metadata such as threat actor associations and malware family context, allowing analysts to move beyond single-IOC searches. Hunters can pivot from an adversary or campaign to all associated indicators (IPs, domains, and file hashes) and search across historical telemetry using ES|QL. This makes it straightforward to determine whether known malicious infrastructure has ever interacted with the environment.</p>
<h2 id="monitoringthreatintelligenceactivitywithgtidashboards">Monitoring threat intelligence activity with GTI dashboards</h2>
<p>The integration includes prebuilt dashboards that provide visibility into threat intelligence activity and the detections GTI drives. Using saved searches and aggregated metrics, these dashboards summarize observed threats across malware families, campaigns, threat actors, toolkits, and vulnerabilities, helping SOC teams understand which threat types are most active in their environment and how intelligence is being operationalized.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt5e9ea4f4c8281953/6a7d7f838fc2d071393eb86d/image1.png" alt="Elastic Security’s Google Threat Intelligence Adversary Intelligence dashboard" title="Elastic Security’s Google Threat Intelligence Adversary Intelligence dashboard" /></p>
<h3 id="googlethreatintelligencefeedcategoriesandcoverage">Google Threat Intelligence feed categories and coverage</h3>
<p>GTI includes 14 categorized feed categories, so organizations can tailor coverage to their needs and subscription level. Supported categories include:</p>
<ul>
<li>Cryptominers</li>
<li>Trending threats</li>
<li>Initial access and delivery vectors</li>
<li>Infostealers</li>
<li>IoT threats</li>
<li>Linux malware</li>
<li>Malicious infrastructure</li>
<li>General malware</li>
<li>Mobile threats</li>
<li>macOS threats</li>
<li>Phishing</li>
<li>Ransomware</li>
<li>Threat actors</li>
<li>Vulnerability exploitation and weaponization</li>
</ul>
<p>Availability depends on your Google Threat Intelligence subscription tier, and additional feeds can be enabled without changes to the Elastic configuration.</p>
<h2 id="agenticenrichmentandrealtimetriagewithelasticworkflows">Agentic enrichment and real-time triage with Elastic Workflows</h2>
<p>For ambiguous or emerging indicators not yet in an indexed feed, Elastic Security supports AI-driven investigation through Agent Builder and Elastic Workflows, which complement intelligence ingestion by enabling real-time enrichment and reasoning during an investigation.</p>
<p>With workflows, an analyst is no longer limited to the intelligence already in the index. During alert triage, a workflow can query external intelligence and reputation services such as VirusTotal in real time, enrich an alert with fresh context about the IPs, domains, or file hashes involved, correlate that live intelligence against Elastic telemetry, and summarize the findings into a structured investigation context that the analyst can act on. Agent Builder extends this further: teams can compose reusable, task-specific capabilities, such as agent skills for alert triage, enrichment, or case handling, so the assistant executes multi-step investigative tasks with the consistency of traditional automation, through a natural-language interface.</p>
<p>![Elastic Workflows editor showing the "Send Hash to VirusTotal" workflow](https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt6a78dda4577bd409/6a7d7f864c4bfb416dcca811/image3.png "Elastic Workflows editor showing the \"Send Hash to VirusTotal\" workflow")</p>
<p>This introduces a complementary model. Ingested intelligence (GTI, TAXII, and custom feeds) provides continuous detection and historical hunting against indicators you already hold. Agentic workflows provide on-demand enrichment and investigative reasoning at alert time, reaching out to live sources and assembling context on the fly. Together, they enable teams to detect known threats at scale and provide context to investigations.</p>
<h2 id="gettingstartedwithgooglethreatintelligenceinelasticsecurity">Getting started with Google Threat Intelligence in Elastic Security</h2>
<p>To use the <a href="https://www.elastic.co/docs/reference/integrations/ti_google_threat_intelligence">Google Threat Intelligence integration</a> in Elastic Security, you need an active GTI license and API key.</p>
<ol>
<li><strong>Install:</strong> open Integrations catalog in Kibana → search "Google Threat Intelligence" → add integration → enter your API key</li>
<li><strong>Configure the data streams:</strong> enable Threat List (high-confidence detections) and IOC Stream (hunting coverage) → set polling frequency to match API limits and operational needs</li>
<li><strong>Tune:</strong> prebuilt indicator match rules activate automatically; if alert volume is high, start by filtering on confidence threshold</li>
</ol>
<p>All indicators are stored in Elasticsearch and accessible through the GTI threat intelligence data view, enabling search, correlation, and custom detection logic. Full configuration details and troubleshooting guidance are available in the official documentation.</p>
<h2 id="tyingitalltogether">Tying it all together</h2>
<p>Threat intelligence only matters if a team can act on it. By bringing Google Threat Intelligence into Elastic Security, SOC teams get ingestion-based detection running continuously across their telemetry and agent-driven investigation reasoning over that intelligence in real time. The combination lets threat intelligence operate continuously and contextually, helping analysts move from indicators to confident decisions faster.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/elastic-security-google-threat-intelligence</link>
    <guid isPermaLink="false">elastic-security-google-threat-intelligence</guid>
    <category><![CDATA[Integrations & Tools]]></category>
    <dc:creator><![CDATA[Jamie Hynds,Mia LaVada]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt6b515b033b0962c4/6a7d7f89bd21985f46755287/image2.jpg" length="0" type="image/jpeg"/>
    <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title><![CDATA[Investigating from the Endpoint Across Your Environment with Elastic Security XDR]]></title>
    <description><![CDATA[This article highlights how Elastic Security XDR unifies endpoint protection with multi-domain security analytics to help analysts trace and contain multi-stage attacks across hybrid and cloud environments.]]></description>
    <content:encoded><![CDATA[<h2 id="preamble">Preamble</h2>
<p>Security investigations rarely stay confined to a single host. Today’s attackers increasingly use automation and AI to compress multi-stage attacks into minutes, turning what once unfolded over days into coordinated activity across endpoints, identities, workloads, and cloud services within minutes.</p>
<p>While many attacks begin on an endpoint, investigators must quickly determine how that activity spreads across the environment. In many environments, per-endpoint licensing limits how broadly protection and telemetry can be deployed, creating protection gaps during these investigations.</p>
<p>Elastic Security XDR is built around that reality. It includes best-in-class endpoint protection, without per-endpoint licensing constraints, in an agentic security operations platform where endpoint telemetry, infrastructure signals, and supporting artifacts can be analyzed together.</p>
<p>This post explores how Elastic Security XDR supports investigations across endpoints, workloads, and the broader environment, highlighting tools and workflows that help analysts collect evidence, pivot across telemetry, and respond efficiently.</p>
<h2 id="endpointattheheartofxdr">Endpoint at the heart of XDR</h2>
<p>The <a href="https://www.elastic.co/resources/security/report/global-threat-report">2025 Elastic Global Threat Report</a> reveals that with 90% of malware targeting Windows, and browsers acting as the 'primary battleground', host-level visibility is essential to stopping a breach before it scales to the cloud. Elastic Defend, Elastic Security’s native endpoint protection, powers XDR from the endpoint outward. It not only prevents threats across Windows, macOS, and Linux, but also generates rich, investigation-grade telemetry that gives analysts the context they need to understand what happened on a host.</p>
<p>As activity occurs, Elastic Defend captures system events including process execution, file changes, network connections, and related artifacts. This telemetry forms the foundation for broader investigations, allowing analysts to correlate endpoint behavior with activity across workloads, identities, and other systems.</p>
<p>Multiple detection layers protect against malware, ransomware, fileless techniques, and other malicious behaviors, using both static and behavioral analysis. Independent validation from the <a href="https://www.elastic.co/blog/av-comparatives-business-security-test-2025">AV-Comparatives Business Security Test</a> confirms Elastic’s effectiveness; in the 2025 test cycle, Elastic Security was the only vendor that blocked every tested threat, earning perfect scores in both Real-World Protection and Malware Protection.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt80217ed76e64a868/6a7d8267ead8ec549dba7b58/image2.png" alt="" /></p>
<p>Elastic also takes a principled approach to openness. Unlike many endpoint security tools that operate as a black box, Elastic publishes detection and prevention logic in an <a href="https://github.com/elastic/protections-artifacts">open repository</a>. This transparency lets analysts understand how protections work, validate them in their own environments, and prioritize high-risk gaps. By empowering users with visibility and insight, Elastic ensures security teams can act with confidence and maximize the value of their investigations.</p>
<h2 id="beyondtheendpointexpandingtheinvestigation">Beyond the endpoint: expanding the investigation</h2>
<p>Attacks rarely stay confined to a single host. Credentials may be compromised, workloads modified, or activity spread across cloud services and infrastructure. To fully understand an incident, analysts need to correlate endpoint activity with signals from the broader environment.</p>
<p>Elastic Security XDR enables this by bringing multiple data sources into the same analysis environment through <a href="https://www.elastic.co/integrations/data-integrations?solution=all-solutions&amp;category=security">hundreds of integrations</a> with popular security tools and data sources. Endpoint telemetry,whether collected by Elastic Defend or another EDR platform, can be analyzed alongside cloud activity, identity events, network telemetry, and third-party logs, without forcing organizations into a closed security stack. Elastic provides the <a href="https://www.elastic.co/docs/reference/ecs">common schema</a> and unified detection engine required to normalize disparate signals, allowing analysts to bypass manual data mapping and immediately pivot between sources to follow how activity moves across users, systems, and infrastructure. </p>
<p>Centralized <a href="https://elastic.github.io/detection-rules-explorer/">detection rules</a> operate across the unified dataset in the security platform, complementing <a href="https://github.com/elastic/protections-artifacts">real-time protections</a> that run directly on the endpoint. They enable alerts to reflect correlated activity across multiple domains. Suspicious process activity on a host can be matched with identity events, cloud API calls, or network behavior, helping analysts determine whether an event is isolated or part of a larger attack chain.</p>
<p>Container workloads highlight another way XDR extends investigations. <a href="https://www.elastic.co/security-labs/getting-started-with-defend-for-containers">Elastic Defend for Containers</a> monitors runtime behavior inside containerized environments, detecting suspicious activity such as unexpected process execution, privilege escalation, or access to sensitive resources. By connecting endpoint behavior to the broader environment, Elastic Security XDR gives analysts the visibility needed to scope incidents accurately, prioritize critical threats, and respond with confidence.</p>
<h2 id="reconstructingtheattackpath">Reconstructing the attack path</h2>
<p>After relevant telemetry is collected, analysts need to piece together what happened and how the attack progressed. Investigations involve pivoting between events, validating hypotheses, and assembling a complete timeline of activity across the environment.</p>
<p>Elastic Security XDR provides <a href="https://www.elastic.co/docs/solutions/security/investigate">investigation tools</a> designed to support this process. Visual Event Analyzer, Session View, and Timeline allow analysts to explore relationships between events, trace execution chains, and correlate activity across datasets while maintaining investigative context.</p>
<p>Visual Event Analyzer offers a graphical view of process relationships, helping analysts spot suspicious parent-child behavior and understand execution flows. Session View reconstructs activity within a process session, showing commands, network connections, and other actions as they unfolded. Timeline acts as an investigative workspace where analysts collect and correlate events from multiple sources, refine queries, and build a coherent attack narrative.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltc0ac720020ed07cc/6a7d826aea068dbb84f07241/image5.png" alt="Investigate alerts &amp; processes with Event Analyzer" title="Investigate alerts &amp; processes with Event Analyzer" /></p>
<p>Together, these tools help analysts validate hypotheses faster, deepen analysis, and enable more confident response decisions.</p>
<h2 id="agenticinvestigationdiscoverysummarizationandnaturallanguagequerying">Agentic investigation: discovery, summarization, and natural language querying</h2>
<p>Elastic Security’s AI-driven investigative workflows help analysts keep pace with modern attacks by accelerating investigation and surfacing connected activity across the environment. Attack Discovery identifies connected alerts across endpoints, workloads, cloud services, and integrated third-party data, helping analysts uncover hidden attack chains without manually correlating events.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt1d2ce67fc2da3255/6a7d826d437e0fb75bdd85e6/image6.png" alt="Attack Discovery detects and summarizes attack activity against the MITRE Attack Chain." title="Attack Discovery detects and summarizes attack activity against the MITRE Attack Chain." /></p>
<p>Once an investigation is underway, Elastic AI Assistant and Agent Builder enable natural-language workflows that let analysts interact with data and automation more efficiently. Analysts can summarize observations, ask questions about entities and activity, and move seamlessly from supporting signals to containment or remediation actions. With the introduction of <a href="https://www.elastic.co/security-labs/agent-skills-elastic-security">agent skills</a>, teams can now extend these workflows with reusable, task-specific capabilities, such as alert triage, rule management, and case handling, allowing the assistant to execute complex, multi-step security tasks with the same consistency and repeatability as traditional automation, but through a conversational interface.</p>
<p>In practice, these capabilities reduce the time from an initial alert to full incident understanding, allowing SOC teams to respond faster, focus on high-priority threats, and act with confidence.</p>
<h2 id="builtinforensicsandhostartifactcollection">Built-in forensics and host artifact collection</h2>
<p>During incident response, investigators often need to retrieve additional host artifacts to confirm attacker behavior, identify persistence, or validate user activity.</p>
<p>Elastic Security XDR includes built-in forensic capabilities that allow responders to collect investigative artifacts directly from affected hosts, reducing the need for separate forensic tooling during common investigative tasks. Elastic Defend supports capturing <a href="https://www.elastic.co/docs/solutions/security/endpoint-response-actions#memory-dump">memory snapshots</a> for deeper forensic analysis, while <a href="https://www.elastic.co/docs/solutions/security/investigate/osquery">Osquery Manager</a> enables analysts to run targeted queries to gather and examine host artifacts as part of an investigation.</p>
<p>Forensic visibility is further extended through ongoing collaboration with Osquery. By extending Osquery-based forensics with supplemental tables for common investigative artifacts, Elastic helps uncover evidence such as browser history, AMCache records, and jumplist artifacts. These sources make it easier for analysts to examine user activity and execution history on Windows systems during an investigation. Also available is library of prebuilt forensic queries and packs to extract common investigative artifacts across Windows, macOS, and Linux, including:</p>
<ul>
<li>process listings and execution context  </li>
<li>scheduled tasks, startup items, and persistence mechanisms  </li>
<li>shell history and command execution artifacts  </li>
<li>network configuration and connectivity context  </li>
<li>file hashes and other execution-related artifacts</li>
</ul>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt60f1200f41990efe/6a7d8270e02facfb465d353c/image3.png" alt="Osquery forensic packs within Elastic Security" title="Osquery forensic packs within Elastic Security" /></p>
<p>These capabilities turn artifact collection into an embedded  step of the investigation, rather than a separate workflow, so teams can confirm what happened all in one platform and act sooner.</p>
<h2 id="responseactionsthatkeepinvestigationsmoving">Response actions that keep investigations moving</h2>
<p>Once investigators confirm malicious behavior, the priority shifts to containment and remediation. Elastic Security XDR enables analysts to take immediate action directly from the investigation context, isolating a host, terminating suspicious processes, collecting a file from the endpoint, or running a response script to collect additional evidence needed to complete the analysis.</p>
<p>For organizations using third-party EDRs, Elastic Security XDR can orchestrate containment and response across mixed environments, allowing teams to keep investigation, enforcement, and incident record-keeping anchored in a single platform.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt510fc14e7270ac4a/6a7d8273b437702b494d3f9b/image4.png" alt="Isolating a CrowdStrike-managed host directly from Elastic Security" title="Isolating a CrowdStrike-managed host directly from Elastic Security" />  </p>
<div>
  
</div>
<h2 id="controllingremovablemediawithdevicecontrol">Controlling removable media with Device Control</h2>
<p>Investigations often uncover risk paths beyond traditional malware, such as removable media usage or potential USB-based exfiltration. Elastic Security XDR’s Device Control capabilities let teams manage and enforce removable media policies across endpoints, reducing attack surface and preventing unauthorized data transfer.</p>
<p>Device Control also allows teams to automatically block USB devices and maintain a trusted set of approved devices, ensuring policies are enforced consistently across all endpoints.</p>
<h2 id="scalingresponsewithelasticworkflows">Scaling response with Elastic Workflows</h2>
<p>Incident response often follows repeatable steps. When an alert fires, teams enrich it, gather evidence, contain affected hosts, open cases, notify responders, and document decisions, ensuring investigations persist across handoffs and shift changes.</p>
<p><a href="https://www.elastic.co/search-labs/blog/elastic-workflows-automation">Elastic Workflows</a> gives teams a way to encode those steps as a reusable playbook that runs inside the Elastic platform. Workflows are defined declaratively in YAML in Kibana, and can be triggered in multiple ways: when a Kibana alerting rule fires, on a schedule, or manually on demand.</p>
<p>From there, a workflow can execute a sequence of steps that look a lot like what an analyst would do manually:</p>
<ul>
<li>Query Elastic data (including ES|QL), transform results, and branch based on conditions   </li>
<li>Create or update a Case, attach supporting context, and keep an auditable record of what was collected and why.  </li>
<li>Notify downstream systems (Slack, Jira, PagerDuty, and other services) using connectors you’ve already configured, or call internal/external APIs via HTTP steps.</li>
</ul>
<p>This becomes especially impactful when paired with endpoint response capabilities. When an alert fires, teams can automatically isolate the host and kick off a standardized evidence bundle - capture a memory dump, collect a suspicious file (get-file), and list running processes - so responders have what they need immediately.</p>
<p>The net effect is faster execution of the first steps in incident response, while investigations follow consistent playbooks across analysts and shifts. Instead of relying on memory and manual checklists, Workflows helps enforce a repeatable investigation standard and makes it easier to scale response when alert volume spikes.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt5a7412ea677e7817/6a7d8276c2cc095b1e2466a4/image1.png" alt="Alert Triage workflow built with Elastic Workflows native automation." title="Alert Triage workflow built with Elastic Workflows native automation." /></p>
<h2 id="elasticsecuritylabsresearchthatpowersrealworlddefenses">Elastic Security Labs - Research that powers real-world defenses</h2>
<p>Elastic Security is informed by the work of <a href="https://www.elastic.co/security-labs/about">Elastic Security Labs</a>, a team dedicated to studying real adversary behavior and translating those findings into practical detection and investigation guidance. Threat Command tracks emerging techniques, malware activity, and endpoint tradecraft, then turns that research into updates that matter in day-to-day security operations: new and refined detection rules, improvements to prevention logic, and clearer guidance on how to investigate what you’re seeing.</p>
<p>Elastic Security Labs also publishes technical write-ups and analyses to help the broader community understand how threats operate in the wild. For defenders, that research provides useful context behind detections - why a technique matters, what evidence to look for, and how to scope impact once an alert fires.</p>
<h2 id="tyingitalltogether">Tying it all together</h2>
<p>As a core capability of our agentic security operations platform, Elastic Security XDR unifies traditionally siloed defenses to tackle the speed and complexity of modern threats. An initial host-based signal can quickly spread across endpoints, identities, and cloud services. Agentic workflows and agent skills help analysts investigate and respond at machine speed. Analysts no longer need to stitch together disconnected tools - they can follow attacker activity throughout the environment, combining endpoint prevention with autonomous investigative and response capabilities in a single platform.</p>
<h2 id="learnmore">Learn More</h2>
<p>Visit <a href="https://elastic.co/security/xdr">elastic.co/security/xdr</a> to learn more. Try a free <a href="https://cloud.elastic.co/serverless-registration">Elastic Security trial</a>, explore Elastic Defend with our <a href="https://videos.elastic.co/watch/wVJRXJQR5orNBEkjgUbVRq">Getting Started video</a>, or practice with real malware at <a href="https://ohmymalware.com">ohmymalware.com</a>.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/investigating-from-the-endpoint-across-your-environment</link>
    <guid isPermaLink="false">investigating-from-the-endpoint-across-your-environment</guid>
    <category><![CDATA[Endpoint Protection & Security]]></category>
    <dc:creator><![CDATA[Jamie Hynds,Caitlin Betz]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt78792ca34ac3640d/6a7d8279bdcff0c0c9c4008c/investigating-from-the-endpoint-across-your-environment.jpg" length="0" type="image/jpeg"/>
    <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
  </item>
  </channel>
</rss>