<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title><![CDATA[Paul Ewing - Elastic Security Labs]]></title>
    <description><![CDATA[Trusted security news & research from the team at Elastic.]]></description>
    <copyright><![CDATA[© 2026. Elasticsearch B.V. All Rights Reserved]]></copyright>
    <image>
      <title><![CDATA[Paul Ewing - Elastic Security Labs]]></title>
      <url>https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blte2c6b841aff36df4/6a88d9784acc96e3f324863d/security-labs-thumbnail.png</url>
      <link>https://www.elastic.co/security-labs/author/paul-ewing</link>
    </image>
    <link>https://www.elastic.co/security-labs/author/paul-ewing</link>
    <atom:link href="https://www.elastic.co/security-labs/rss/author/paul-ewing.xml" rel="self" type="application/rss+xml"/>
    <language><![CDATA[en]]></language>
    <lastBuildDate>Fri, 02 Oct 2026 12:17:11 GMT</lastBuildDate>
  <item>
    <title><![CDATA[Supercharge Your SOC]]></title>
    <description><![CDATA[Detection Engineering in the Era of AI Agents - The New Frontier.]]></description>
    <content:encoded><![CDATA[<h2 id="preamble">Preamble</h2>
<p>The landscape of cybersecurity is evolving, and the role of the Detection Engineer (DE) is more critical and demanding than ever. Traditionally, this role involves a comprehensive, end-to-end workflow: from threat modeling and telemetry tuning to writing, testing, and maintaining performance-optimized detection rules to flag malicious behavior.</p>
<p><strong>Elastic Security is purpose-built to streamline this entire workflow, empowering DEs - and anyone involved in security operations - to build, manage, and optimize detection rules at scale. This allows security teams to concentrate their efforts on the most critical task: protecting the organization.</strong></p>
<p>The rise of generative AI and, more specifically, advanced AI <strong>coding agents</strong> like Claude and Cursor, is fundamentally changing and supercharging this workflow.  These tools are no longer just for general software development; they are becoming expert partners for the Security Operations Center (SOC). By integrating the power of conversational AI, these agents can take high-level security requirements and instantly translate them into validated, workable detection logic.</p>
<h2 id="fromgeneralisttoelasticexpertagentskills">From Generalist to Elastic Expert: Agent Skills</h2>
<p>Elastic Security is embracing this shift not only by having native AI capabilities built-into our agentic security operations platform , but also by <a href="https://www.elastic.co/search-labs/blog/agent-skills-elastic">open-sourcing <strong>agent skills for 3rd party agentic IDEs</strong></a>, a native platform experience for the entire Elastic ecosystem (Security, Observability, etc.). By loading these skills into any agent runtime, your AI assistant moves from being a generalist to an on-demand expert in Elastic’s tooling. You can then ask your agent to triage alerts or, in this context, expertly create and tune detection rules</p>
<h2 id="ausecasewalkthroughthenotepadattack">A Use Case Walkthrough: The Notepad++ Attack</h2>
<p>To illustrate the agent’s power, let’s look at a real-world supply chain-based attack involving a backdoor targeting the Notepad++ infrastructure described in Elastic Security Lab’s blog, <a href="https://www.elastic.co/security-labs/speeding-apt-attack-discovery-confirmation-with-attack-discovery-workflows-and-agent-builder">“Speeding APT Attack”</a><strong>.</strong></p>
<h3 id="instantconditionalrules">Instant Conditional Rules</h3>
<p>A detection engineer’s first step is often to create conditional rules based on known Indicators of Compromise (IOCs). To begin, we can instruct the agent to investigate data within Elastic Security, as evidence of the attack was present in our cluster.</p>
<pre><code>"Can you help me create a detection rule that will detect malicious activity similar
 to what I'm seeing in my Elastic Security deployment involving notepad++.exe 
 and BluetoothService.exe?"
</code></pre>
<p>The agent immediately went to work:</p>
<ul>
<li>It rapidly found process lineage and documented attack details.  </li>
<li>It extracted key IOCs and found the corresponding MITRE ATT&amp;CK™ mappings.  </li>
<li>It generated two foundational rules: one for a suspicious child process spawned by <strong>Notepad++</strong>, and one focusing on the masqueraded executable.  </li>
<li>Crucially, the rules were immediately tested against threat emulation data, confirming multiple successful hits.</li>
</ul>
<p>Each step is happening quickly, and the built-in validation significantly accelerates the 'test and tune' phase.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt87d1d998bfaf8d40/6a7d855fead8ecced5ba7bb4/image2.png" alt="Agent progress initiating creation of conditional detection rules (Claude Code shown)" title="Agent progress initiating creation of conditional detection rules (Claude Code shown)" /></p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt95740b6937b8be40/6a7d8562bd2198c741755346/image7.png" alt="Agent report after creating two conditional detection rules (Claude Code shown)" title="Agent report after creating two conditional detection rules (Claude Code shown)" /></p>
<p>Let’s take a look at the agent-created rule in Elastic Security:</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt2ea5f513432aaaba/6a7d85656c6eacd7eaf113df/image3.png" alt="Agent-created rule details appear seamlessly in Elastic Security" title="Agent-created rule details appear seamlessly in Elastic Security" /></p>
<h3 id="divingintoadvancedesqlaggregation">Diving into Advanced ESQL Aggregation</h3>
<p>Conditional logic is great, but modern threats require more behavioral and entity-focused detections. Using Elastic’s powerful piping language, <a href="https://www.elastic.co/docs/reference/query-languages/esql">ES|QL</a> (Elastic Search Query Language), the agent was challenged to create an <strong>aggregation-based rule</strong> that looks for generic, suspicious characteristics across tasks, aggregates them, and assigns a dynamic risk score to host and user entities.</p>
<p>The agent delivered, creating an advanced query that looks for suspicious executables, negates benign directories, and assesses scores based on the activity's risk level. This demonstrates the agent's ability to create sophisticated detections unique to Elastic's capabilities, moving beyond simple lookups to complex entity analytics.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltd650a7d9edb9450a/6a7d8568b4377077c14d3ff0/image4.png" alt="Agent creating aggregation-based detection rule (Claude Code shown)" title="Agent creating aggregation-based detection rule (Claude Code shown)" /></p>
<p>Here’s the rule in Elastic Security:</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt94f60f0e5b240f04/6a7d856b4c4bfb27f3cca8b4/image1.png" alt="More complex aggregation-based rule appears properly in Elastic Security" title="More complex aggregation-based rule appears properly in Elastic Security" /></p>
<h3 id="sequentialdetectionswitheqlandsuppression">Sequential Detections with EQL and Suppression</h3>
<p>To detect multi-stage attacks, a <strong>sequential rule</strong> is essential—if Event A, then Event B, then Event C, then alert. Using the <a href="https://www.elastic.co/docs/solutions/security/detect-and-alert/eql">Event Query Language (EQL)</a>, the agent crafted a perfect three-stage sequence for the attack:</p>
<ol>
<li>Unsigned dropper activity.  </li>
<li>Service masquerade (implant deployed).  </li>
<li>Final execution for persistence.</li>
</ol>
<p>To make the rule more reliable and reduce noise, suppression logic was then added, focusing on limiting alerts per unique Host ID. This quick iteration shows how an agent can help a detection engineer rapidly move from a basic detection to a highly robust, multi-stage rule.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt32c9df23e83b8f47/6a7d856ebdcff000bbc400eb/image6.png" alt="Agent creating advanced sequence-based detection rule (Claude Code shown)" title="Agent creating advanced sequence-based detection rule (Claude Code shown)" /></p>
<h3 id="thellmaugmentedquerysummariesinthealert">The LLM-Augmented Query: Summaries in the Alert</h3>
<p>The ultimate demonstration of the new agentic workflow is using <a href="https://www.elastic.co/security-labs/beyond-behaviors-ai-augmented-detection-engineering-with-esql-completion">Elastic’s <strong>ESQL COMPLETION syntax</strong></a>. This feature allows an inference model to be referenced <em>directly within the query</em>.</p>
<p>The prompt asked the agent to: </p>
<pre><code>Based off this recent elastic blog,
 https://www.elastic.co/security-labs/beyond-behaviors-ai-augmented-detection-engineering-with-esql-completion, 
 create a rule that incorporates a COMPLETION command with my  default inference 
 model that will summarize findings from attack into one "esql.summary"
</code></pre>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt3bad61ef696f4e17/6a7d8572c2cc0905892466db/image5.png" alt="Agent creating advanced detection rule with included AI Summary (Claude Code shown)" title="Agent creating advanced detection rule with included AI Summary (Claude Code shown)" /></p>
<p>The result? The generated rule didn't just fire an alert; it natively included an <strong>ES|QL summary row</strong> in the alert itself:</p>
<blockquote>
  <p>This telemetry shows a masquerading technique where a process named "BluetoothService.exe" is executing from a user's AppData directory with a PE original name of "BDSubWiz.exe" (a legitimate file mismatch), running as SYSTEM with service-like characteristics including spawning from services.exe, indicating persistence establishment (MITRE ATT&amp;CK T1036.004 Masquerading and T1543 Service Persistence). The executable's location in a user directory, combined with SYSTEM-level execution, service persistence indicators, and the name/PE mismatch across multiple events, suggests Defense Evasion and Persistence stages. This represents high severity due to successful SYSTEM-level persistence with active defense evasion through masquerading.</p>
</blockquote>
<p>This cuts triage time dramatically, as analysts no longer need to pivot to a separate runbook to understand the context and severity of the alert.</p>
<h2 id="theagenticsocishere">The Agentic SOC is Here</h2>
<p>The collaboration between AI agents and the Elastic Security solution provides a glimpse into Elastic’s <a href="https://www.elastic.co/security-labs/why-2026-is-the-year-to-upgrade-to-an-agentic-ai-soc"><strong>Agentic SOC</strong></a> of the future. It’s a world where detection engineers can have a conversation, define their intent, and instantly generate, test, and deploy highly sophisticated, context-rich detection rules. This is not about replacing the human expert, but about augmenting their knowledge and accelerating their workflow, allowing them to focus on high-value threat intelligence and modeling.</p>
<h2 id="gettingstarted">Getting started</h2>
<p><strong>Before you get started:</strong> AI coding agents operate with real credentials, real shell access, and often the full permissions of the user running them. When those agents are pointed at security workflows, the stakes are higher: you're handing an automated system access to detection logic, response actions, and sensitive telemetry. Every organization's risk profile is different. Before enabling AI-driven security workflows, evaluate what data the agent can access, what actions it can take, and what happens if it behaves unexpectedly</p>
<p>Don't have an Elasticsearch cluster yet? Start an <a href="https://cloud.elastic.co/registration">Elastic Cloud free trial</a>. It takes about a minute to get a fully configured environment.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/supercharge-your-soc</link>
    <guid isPermaLink="false">supercharge-your-soc</guid>
    <category><![CDATA[AI & Automation]]></category>
    <dc:creator><![CDATA[Paul Ewing]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltb8df046ae13e84fe/6a7d8574e3a21910a199c778/supercharge-your-soc.jpg" length="0" type="image/jpeg"/>
    <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title><![CDATA[Streamlining the Security Analyst Experience]]></title>
    <description><![CDATA[Alert Triage, Investigation, and Response with Elastic's Agentic Security Operations Platform.]]></description>
    <content:encoded><![CDATA[<p>The term <strong>Agentic SOC (Security Operations Center)</strong> is one of the most popular concepts in security today. But what does it truly mean in practice, and how does Elastic Security approach this next evolution of security operations?</p>
<p>In simple terms, an Agentic SOC is a security operations center that has deployed AI Agents and corresponding AI Agent Skills to perform SOC-related workflows such as detection engineering, alert triage, incident investigation, escalation, response, and threat hunting. When these workflows are performed by AI agents, they’re often called “Agentic workflows.” These AI Agents and Skills may run natively in a security operations platform like SIEM, XDR, or security analytics, or they may be layered on top of legacy SIEM as an “AI SOC Agent” or “AI SOC analyst”, or they may even be run from an AI Coding Tool. </p>
<p>Regardless of how they are implemented, the shift to the Agentic SOC is not about AI replacing human analysts; it's about transforming how the SOC functions. To keep pace with rapidly evolving attackers, defenders must leverage AI and autonomous agents to respond as quickly as possible. At its core, an Agentic SOC is defined by how a security operations center uses <strong>AI and agents to protect against adversaries</strong>.</p>
<p>Let’s simplify a successful security operations center to three fundamental pillars, all of which the Agentic SOC significantly enhances:</p>
<ol>
<li><strong>Observe:</strong> The foundation of all security is centralized data—aggregating logs and events into one location, which is the core strength of a SIEM solution.  </li>
<li><strong>Detect:</strong> This involves deploying core protections like endpoint-based security (XDR, such as Elastic Defend) and security solution-focused detections (cloud, identity data). This technology drives the generation of high-quality alerts. Elastic, for example, ships over <a href="https://elastic.github.io/detection-rules-explorer/"><strong>1,700 pre-built rules</strong></a> for its SIEM by default, not including its XDR solution's endpoint rule library.  </li>
<li><strong>Act:</strong> This is the critical final stage of triaging, investigating, and acting on the generated alerts.</li>
</ol>
<h2 id="agenticsocinaction">Agentic SOC in Action</h2>
<p>Imagine this real-life scenario unfolding in your Security Operations Center using the Elastic security platform. It begins not with a siren, but with a simple, direct Slack notification. Building on our recent <a href="https://www.elastic.co/security-labs/speeding-apt-attack-discovery-confirmation-with-attack-discovery-workflows-and-agent-builder">blog</a> on Attack Discovery, Workflows, and Agent Builder, let's further examine how Elastic Security can help you respond to an active attack.</p>
<ol>
<li><strong>The Initial Alert and Immediate Action</strong><br />
Your security analyst receives an urgent notification in their team channel. This message isn't just a heads-up; it points directly to an observed, active attack. Crucially, the Elastic Agentic SOC has already taken decisive, pre-emptive action: a vulnerable host has been isolated from the network to contain the threat and limit potential damage. This was all powered by Elastic Workflows and Elastic Agent Builder processing realtime alert and attack data from Elastic.<br />
<img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt8ef1f1122b1021db/6a7d854a5967e5a8e65da5b3/image5.png" alt="Example analyst notification in Slack after the AI agent has performed initial triage." title="Example analyst notification in Slack after the AI agent has performed initial triage." />  </li>
<li><strong>The Centralized Case</strong><br />
The analyst's next step is a click away, moving from Slack directly to the centralized Case within Elastic that was created by the workflow. Elastic Case Management enables the SOC to coordinate the response and provides a single pane of glass into all aggregated critical information:  </li>
</ol>
<ul>
<li><p><strong>Attack Summary:</strong> A high-level overview detailing what has occurred using Attack Discovery.  </p></li>
<li><p><strong>Attached Alerts:</strong> The specific security alerts that triggered the initial observation.  </p></li>
<li><p><strong>Observables:</strong> A list of suspicious artifacts (IP addresses, file hashes, domains, etc.) collected from the event.  </p></li>
<li><p><strong>Attached Events:</strong> Non-alert events that, while not an alert themselves, provide critical context and are of further interest to the investigation.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt67359a276970e887/6a7d854dfc63ab762e64a026/image2.png" alt="" /></p></li>
</ul>
<ol>
<li><strong>Supporting the Investigation</strong><br />
To support the immediate findings, detailed <strong>Investigations</strong> are attached directly to the Case. These searches allow the analyst to visually and contextually step through the sequence of events leading up to, during, and immediately following the attack.<br />
The Elastic Case also provides instant context by highlighting <strong>Similar cases</strong>. By cross-referencing observables, the system identifies previous incidents involving the same entities or artifacts, providing a deeper understanding of the threat actor's history and potential motives.  </li>
<li><strong>The Path to Resolution</strong><br />
The agents don’t just catalog the past; it dictates the future. A clear set of <strong>Next steps and actions</strong> are outlined, with specific team members assigned for review and execution.</li>
</ol>
<p>The analyst then steps through a methodical process reviewing the automated analysis:</p>
<ol>
<li><strong>Reviewing Findings:</strong> Scrutinizing all aggregated data, alerts, and investigations.  </li>
<li><strong>Evidence Collection:</strong> Collecting any additional forensic evidence needed for a complete analysis.  </li>
<li><strong>Remediation:</strong> Executing manual or automated actions, such as deleting malicious files or killing persistent processes on the isolated host with Elastic Defend.  </li>
<li><strong>Final Release:</strong> Eventually, the host is safely released back to the network, but not before additional, targeted rules or policies are automatically applied to prevent a recurrence based on the lessons learned from this incident.<br />
In the Agentic SOC, the analyst moves seamlessly from a high-level alert to a comprehensive investigation to full remediation—all within a unified, intelligent workflow powered by Elastic.</li>
</ol>
<h2 id="elasticsecurityandcoresiemworkflows">Elastic Security and Core SIEM Workflows</h2>
<p>Before exploring advanced agentic workflows, it's essential to recognize that Elastic Security already provides a comprehensive suite of core capabilities crucial for modern security operations. This foundation begins with the ingestion of security-relevant data, which is automatically normalized to a common schema, ensuring consistency and ease of analysis. The platform offers Extended Detection and Response (XDR) capabilities via Elastic Defend, a robust detection engine built directly into the Elastic Stack, and sophisticated alert workflows that include built-in correlations to reduce noise and surface true threats.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blte4187c1ba459f447/6a7d8550227b1c5bf6595890/image4.png" alt="" /></p>
<p>Elastic Security further differentiates itself by tightly integrating key operational functions. This includes entity-based threat hunting, machine learning for anomaly detection and behavior analysis, and comprehensive case management for tracking incidents. Finally, the platform provides end-to-end response and forensic capabilities, enabling security teams to move swiftly from initial alert to investigation and remediation, all within a unified, scalable platform.</p>
<h2 id="empoweringanalystswithagenticcapabilities">Empowering Analysts with Agentic Capabilities</h2>
<h3 id="aipoweredalerttriageandprioritization">AI-Powered Alert Triage and Prioritization</h3>
<p>The Elastic Security Solution integrates AI capabilities via <strong>Agent Builder</strong> to augment and make SOC operations truly agentic. This is where efficiency improvements are most keenly felt:</p>
<ul>
<li><strong>Conversational Triage:</strong> A built-in agent is readily available to Tier 1/2 analysts, allowing them to use conversational commands to query and prioritize open alerts (e.g., "What priority alerts should I review from the last 30 days?"). This is the first entry point for using AI to augment SOC operations.  </li>
<li><strong>LLM Agnostic Platform:</strong> A key differentiating feature of Elastic's <strong>Agent Builder</strong> is that it is <strong>LLM agnostic</strong>, allowing organizations to pick their preferred model, even locally running models for privacy or regulatory reasons.  </li>
<li><strong>Attack Discovery:</strong> This premier feature moves beyond basic triage. It uses LLM configurations to create <strong>higher-order attack detections</strong>, taking hundreds of open alerts and prioritizing them into a small, manageable subset of known attacks or incidents. This dramatically reduces the impact of alert fatigue.</li>
</ul>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltfdc4cd6ef3ac26da/6a7d855363e9596e0773af1b/image3.png" alt="" /></p>
<h3 id="enrichedinvestigations">Enriched Investigations</h3>
<p>Once an attack or incident is found, the agent helps start the investigation:</p>
<ul>
<li><strong>Summarization and Enrichment:</strong> The agent can be used to summarize the attack, identify important artifacts, and conduct automated third-party enrichments (like checking VirusTotal). This tailored experience provides a full assessment, including an attack chain, threat intelligence information, related cases, entity risk scoring, and a full investigation guide.  </li>
<li><strong>Case Management:</strong> The agent can be instructed to take immediate action, such as generating a security case and notifying the team in Slack, all through simple conversational commands that execute pre-configured workflows.</li>
</ul>
<h3 id="automatedresponseandthreathunting">Automated Response and Threat Hunting</h3>
<p>The true power of the Agentic SOC is realized through action and automation that goes beyond simple conversation:</p>
<ul>
<li><p><strong>Workflows and SOAR-like Automation:</strong> Agents can reference and execute <strong>Workflows</strong>, Elastic's SOAR-like automation tool. These workflows allow analysts to take immediate, complex actions. For example, a command like "Please create a case for this attack, and notify my team in Slack" triggers multiple, pre-defined steps. Further critical response actions, such as <strong>isolating a host</strong>, can be executed with a single workflow action while the investigation continues.  </p></li>
<li><p><strong>AI-Assisted Threat Hunting:</strong> AI assists threat hunters by leveraging <strong>Entity Analytics</strong> and pre-built skills. The agent can be asked to find high-risk hosts and users to begin hunting, and then automatically generate specific ESQL queries (e.g., "Please tell me the most uncommon processes executed for each host") to uncover unusual or malicious activity.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt857cd03cbefa2cf7/6a7d855748511b665de7d3e7/image1.png" alt="" /></p></li>
</ul>
<h3 id="themandateofautomation">The Mandate of Automation</h3>
<p>For maximum effectiveness, all these steps,from alert triage and enrichment to case creation and host isolation,can be configured to run <strong>automatically</strong> as an Agentic Alert Triage workflow. This allows the system to solve problems as soon as they are discovered, setting up the human analyst in the loop with a consolidated case and all the necessary findings in a single pane of glass.</p>
<p>This approach delivers substantial <strong>efficiency improvements</strong>, making speed the single most important factor in a modern, Agentic SOC.</p>
<p>Elastic’s Agentic Security Operations Platform</p>
<p>Whether you use our UI, our agents, or your own, Elastic Security provides a strong open foundation for modern security operations. best-in-class data architecture, search, workflows, analytics, detection engineering content, and automation.</p>
<h2 id="gettingstarted">Getting started</h2>
<p><strong>Before you get started:</strong> AI coding agents operate with real credentials, real shell access, and often the full permissions of the user running them. When those agents are pointed at security workflows, the stakes are higher: you're handing an automated system access to detection logic, response actions, and sensitive telemetry. Every organization's risk profile is different. Before enabling AI-driven security workflows, evaluate what data the agent can access, what actions it can take, and what happens if it behaves unexpectedly</p>
<p>Don't have an Elasticsearch cluster yet? Start an <a href="https://cloud.elastic.co/registration">Elastic Cloud free trial</a>. It takes about a minute to get a fully configured environment.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/streamlining-the-security-analyst-experience</link>
    <guid isPermaLink="false">streamlining-the-security-analyst-experience</guid>
    <category><![CDATA[SOC]]></category>
    <dc:creator><![CDATA[Paul Ewing]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltd70ec2f45cf3fd8d/6a7d855a1967eab59f32d91c/streamlining-the-security-analyst-experience.jpg" length="0" type="image/jpeg"/>
    <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title><![CDATA[From Hypothesis to Action: Proactive Threat Hunting with Elastic Security]]></title>
    <description><![CDATA[Elastic Security is designed to enable hypothesis-driven threat hunting at speed and scale. By unifying security telemetry and enabling analytics across clusters, threat hunters can ask complex questions across all their data, correlate signals, and validate hypotheses quickly without manual data stitching.]]></description>
    <content:encoded><![CDATA[<p>When a new threat actor technique emerges — whether from a research blog, an intelligence feed, or breaking news — every threat hunter instinctively shifts into hypothesis mode. Could this be happening in my environment? Are early signals hiding in the noise?</p>
<p>Take the recent TOLLBOOTH research as an example. The moment Elastic Security Labs <a href="https://www.elastic.co/security-labs/tollbooth">published the attack chain</a>, an analyst might begin forming hypotheses based on specific techniques described, such as:</p>
<ul>
<li><em>Have historically frozen or archived IIS server logs shown any anomalies when re-examined with full telemetry?</em>  </li>
<li><em>Are there signs of credential dumping or privilege escalation attempts on any IIS servers?</em></li>
</ul>
<p>This is the essence of hypothesis-driven hunting; start with a developing threat, and rapidly ask targeted questions. It’s one of the most effective ways to get ahead of emerging attacks, but it demands broad visibility and tools that can keep up with your curiosity.</p>
<p>The reality for many SOC teams, however, falls short. They face data silos, limited search capabilities, and the fatigue of manual correlation.</p>
<p>Elastic Security is designed to remove these barriers by enabling <strong>hypothesis-driven threat hunting at speed and scale</strong>. By unifying security telemetry and enabling analytics across clusters, threat hunters can ask complex questions across all their data, correlate signals, and validate hypotheses quickly without manual data stitching.</p>
<p>This capability is delivered through a set of foundational building blocks that work together:</p>
<ul>
<li><p><strong>Agentic workflows</strong> triage alerts, while a <strong>knowledge-grounded AI Assistant</strong> generates validated ES|QL queries, drives remediation, and recommends next steps.</p></li>
<li><p><strong>Elastic Security Labs</strong> to bring continuously updated threat research and adversary insights directly into detections and investigations.</p></li>
<li><p><strong>Detection rules</strong> that provide out-of-the-box coverage aligned to real-world attack techniques and hunting scenarios.</p></li>
<li><p><strong>Entity analytics</strong> to correlate users, hosts, and services, assign risk scores, and surface anomalies to enrich every investigation.</p></li>
<li><p><strong>Machine learning and anomaly detection</strong> to surface deviations from normal behavior and expose unknown or emerging threats.</p></li>
<li><p><strong>ES|QL, visualizations, and cross-cluster search</strong> to enable fast, expressive querying, intuitive analysis, and seamless hunting across distributed environments without blind spots.</p></li>
</ul>
<p>Together, these building blocks give security teams the <strong>speed, scale, and analytical depth</strong> needed to move from reactive investigation to confident, proactive threat hunting—testing hypotheses across all of their data within a single, unified Elastic Security platform.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt9c6aa657f87a9737/6a7d83afbd21981f7b755304/image5.png" alt="" /></p>
<h2 id="intothewoodsnavigatingarealworldlolbinshunt">Into the woods: Navigating a real-world LOLBins hunt</h2>
<p>This section shows how a threat hunt plays out in practice, moving from an empty search bar to a confirmed and contained threat through a real-world scenario focused on Living Off the Land Binaries (LOLBins).</p>
<h3 id="buildyourhypothesiswitharagpoweredaiassistant">Build your hypothesis with a RAG-powered AI Assistant</h3>
<p>Your investigation can begin even before writing a single query. You can use Elastic’s retrieval-augmented generation (RAG)–powered AI Assistant to pull in trusted <a href="https://www.elastic.co/docs/solutions/security/ai/ai-assistant-knowledge-base">knowledge sources</a>, such as Elastic Security Labs research, and build the foundation of your hypothesis. You can add any trusted sources as knowledge to ensure the Assistant reflects the data you rely on.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blta0b2db5a24cbe689/6a7d83b2bd21986a17755308/image1.png" alt="Elastic AI Assistant knowledge base entries" title="Elastic AI Assistant knowledge base entries" /></p>
<p>If you don’t have a specific target yet, you can ask the Assistant, </p>
<p><em>“Based on current trends, what hypothesis should I start my hunt with today?”</em> The Assistant scans the configured knowledge base, which provides relevant context and directly generates a primary hypothesis along with supporting reasons and evidence. In this scenario, Elastic Security Labs content has been added to the knowledge base to supply the context.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt000e583a8252575c/6a7d83b5448e4ee4a55bdb84/image9.png" alt="" /></p>
<h3 id="sitbackwhileaiassistantcreatesyourtailoredthreathuntingquery">Sit back while AI Assistant creates your tailored threat hunting query</h3>
<p>Once you accept the LOLBin hypothesis, the AI Assistant generates a precise ES|QL threat hunting query tailored to your environment. Instead of writing complex syntax from scratch, you receive a targeted search designed to surface the specific suspicious behaviors.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt4a78447319501a1f/6a7d83b85588ad79eeee433e/image8.png" alt="Elastic AI Assistant-generated ES|QL query to detect Office/Server spawned LOLBins with suspicious patterns" title="Elastic AI Assistant-generated ES|QL query to detect Office/Server spawned LOLBins with suspicious patterns" /></p>
<p>To ensure queries are ready to run, the Elastic AI Assistant uses an agentic workflow to generate bespoke ES|QL queries from human-supplied use cases. It draws on your Elastic cluster data to craft accurate, ready-to-run responses and performs automatic validation before returning the final query. This background validation removes the need for manual troubleshooting, delivering a verified, ready-to-use query that can be pulled directly into your investigation timeline from the AI Assistant.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt1201c435fe377d2c/6a7d83bb498caf999c01eebc/image7.png" alt="Elastic Security Timeline with ES|QL pulled over from the AI-assistant" title="Elastic Security Timeline with ES|QL pulled over from the AI-assistant" /></p>
<p>Alternatively, you can link a GitHub repository of Elastic’s <a href="https://github.com/elastic/detection-rules/tree/main/hunting">threat hunting queries</a> to the Assistant’s knowledge base to use existing queries as a baseline for your next steps.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltb60d250e22729032/6a7d83be42a1173ffc95915e/image13.png" alt="Threat hunt queries section within Elastic’s pre-built detection rules GitHub repository" title="Threat hunt queries section within Elastic’s pre-built detection rules GitHub repository" /></p>
<h3 id="huntthreatsacrossyourentireenvironmentwithesql">Hunt Threats Across Your Entire Environment with ES|QL</h3>
<p>If you manage a global environment and need to determine whether this activity is occurring in other clusters, you can expand your hypothesis by asking the AI Assistant to adapt the query for a Cross-Cluster Search (CCS). This enables you to search across multiple clusters in your environment—including frozen and long-term data—without disrupting your investigative workflow.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt04afde6003c5f29a/6a7d83c1a529e11b7b59c95c/image11.png" alt="Updated ES|QL query using cross-cluster search to show Office/Server spawned LOLBins with suspicious patterns in both local and remote clusters" title="Updated ES|QL query using cross-cluster search to show Office/Server spawned LOLBins with suspicious patterns in both local and remote clusters" /></p>
<p>Seamlessly transition from the AI Assistant to the timeline view and run the query. This targeted search uncovers a critical finding: an instance of <em>rundll32.exe</em> executing on a Windows server with hostname <em>elastic-defend-endpoint</em> under the <em>gbadmin</em> user account<em>.</em></p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltfbc6becc8a15c093/6a7d83c4d0f11499539fa06a/image6.png" alt="LOLBin Investigation Timeline results" title="LOLBin Investigation Timeline results" /></p>
<h3 id="addcontextwithanalyticsandvisualizations">Add context with analytics and visualizations</h3>
<p>Finding a hit is only step one; now, you must determine if this is an admin performing maintenance or an actual attack. Validating your ideas requires deep analytics across hosts and users. By drilling down into the affected host, you land in the Entity Details.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltb95d58239c360036/6a7d83c74c4bfb8293cca885/image10.png" alt="Host Entity flyout" title="Host Entity flyout" /></p>
<p>Here, you’re not just seeing a hostname. You’re seeing a consolidated view of the host’s risk score, the specific alerts contributing to that score, and the asset’s criticality—all in one place. By bringing together detection signals, behavioral anomalies, and asset importance, Elastic’s entity risk scoring helps analysts quickly understand why an asset is risky, how urgent the threat is, and where to focus first. This unified context reduces investigation time, minimizes guesswork, and enables confident prioritization in high-volume environments.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt5353f72af8b119d6/6a7d83caea068d7271f0725c/image14.png" alt="Entity details, risk score, and associated alerts for the affected host" title="Entity details, risk score, and associated alerts for the affected host" /></p>
<h3 id="confirmtheanomalywithmachinelearning">Confirm the anomaly with machine learning</h3>
<p>When you examine the risk score, the supporting evidence is displayed alongside it. You can see the specific alerts contributing to the elevated risk score, including a mix of medium-severity alerts and a Machine Learning (ML) alert such as <strong><em>“Unusual Windows Path Activity”</em></strong>. </p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt00686de1005ae7f0/6a7d83ccd0f11440b29fa06e/image16.png" alt="Machine learning anomaly alert" title="Machine learning anomaly alert" /></p>
<p>Because ML is uniquely suited to detecting subtle deviations that static rules often miss, seeing an ML alert contributing to the risk score helps validate that this activity isn’t just noise—it points to a meaningful behavioral anomaly.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltae76d25fe871f09f/6a7d83cfc2e9148675013ce1/image2.png" alt="‘Unusual Windows Path Activity’ alert flyout" title="‘Unusual Windows Path Activity’ alert flyout" /></p>
<p>The event details immediately visualize the process lineage, revealing the critical evidence right in the panel. These insights transform your hypothesis from plausible to provable.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt9eadb58b1dd73a84/6a7d83d2e88c65a34e0089ac/image12.png" alt="Visual event analyzer with rundll32.exe flyout" title="Visual event analyzer with rundll32.exe flyout" /></p>
<h3 id="takeactionfrominsighttoresponse">Take Action: From Insight to Response</h3>
<p>After validating your hypothesis by uncovering suspicious activity, the immediate next step is response. Elastic Security lets responders act directly from their investigations without switching platforms.</p>
<p>Once a compromised host is confirmed, you can take action from the console by isolating the host to prevent lateral movement or terminating the malicious process tree uncovered in your <strong>LOLBIN hunt</strong>. This seamless transition from investigation to response enables rapid containment using the same tools and context.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltfa68d994fe3f0c91/6a7d83d586c8d94e469863d7/image4.png" alt="Response console for isolated host, elastic-defend-endpoint" title="Response console for isolated host, elastic-defend-endpoint" /></p>
<h3 id="operationalizequeriesandautomatehunting">Operationalize Queries and Automate Hunting</h3>
<p>To automate future hunts and eliminate manual verification of recurring patterns, you can directly import a query into an operational detection rule, or create a rule for specific behaviors, anomalies, or new term values appearing for the first time, and convert it into a fully operational detection rule with a single click.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt8b2b08b99ba726c9/6a7d83d86693f845dd6610cd/image15.png" alt="Detection rule creation with ES|QL in Elastic Security" title="Detection rule creation with ES|QL in Elastic Security" /></p>
<p>In enterprise environments, a LOLBin hunt can quickly generate a high volume of alerts. This is where agentic <a href="https://www.elastic.co/docs/solutions/security/ai/attack-discovery"><strong>Attack Discovery</strong></a> makes a big difference. Its primary purpose is to help you triage efficiently by automatically correlating signals and highlighting the activity that requires immediate attention.</p>
<p>You can also group and tag hunting-related alerts and run Attack Discovery specifically on those sets to uncover meaningful patterns. This flexibility makes Attack Discovery valuable not only for automated alert triage, but also for advanced, hypothesis-driven threat hunting workflows.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt902b67fe5c00e8c4/6a7d83db2f00b23614efbf2c/image3.png" alt="Running Attack Discovery on a curated group of LOLBin hunting alerts" title="Running Attack Discovery on a curated group of LOLBin hunting alerts" /></p>
<h3 id="bonusautomatewithelasticagentbuilder">Bonus: Automate with Elastic Agent Builder</h3>
<p>Imagine building a <strong>LOLBin Hunter custom agent</strong>—purpose-built to hunt for LOLBin activity across your security data. Using <a href="https://www.elastic.co/docs/solutions/search/agent-builder/get-started"><strong>Elastic Agent Builder</strong></a>, you can create this agent powered by an LLM and equipped with tools such as the ES|QL queries used in your manual workflow. </p>
<p>Once configured, you can interact with your security data using natural language, and the agent will reason through your request, select the most relevant tools, and take action. For example, you could ask: <em>“Show me LOLBin activity that triggered machine learning anomalies and summarize the affected hosts and their risk scores.”</em></p>
<h3 id="stayaheadofemergingattackswithelasticsecurity">Stay ahead of emerging attacks with Elastic Security</h3>
<p>Hypothesis-driven threat hunting is critical for staying ahead of modern attacks, but it can be complex and time-consuming without the right tools. Elastic Security combines AI-assisted investigation, ES|QL search, contextual analytics, machine learning, and integrated response to make every stage simpler and faster.</p>
<p>From the moment a new threat emerges to the point of actionable response, Elastic empowers analysts to uncover hidden signals, validate their hypotheses, and act decisively—turning raw data into intelligence and intelligence into action.</p>
<p>Interested in learning more about Elastic Security? <a href="https://www.elastic.co/events">Browse our webinars, events, and more</a> or <a href="https://www.elastic.co/start">get started with your free trial</a> today.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/proactive-threat-hunting-with-elastic-security</link>
    <guid isPermaLink="false">proactive-threat-hunting-with-elastic-security</guid>
    <category><![CDATA[Threat Hunting]]></category>
    <dc:creator><![CDATA[Paul Ewing,Sandiya Ramamoorthy]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt2f738c71ebadacc8/6a7d83de8fc2d0dbb23eb8e9/image0.png" length="0" type="image/png"/>
    <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
  </item>
  </channel>
</rss>