<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title><![CDATA[Roxana Gheorghe - Elastic Security Labs]]></title>
    <description><![CDATA[Trusted security news & research from the team at Elastic.]]></description>
    <copyright><![CDATA[© 2026. Elasticsearch B.V. All Rights Reserved]]></copyright>
    <image>
      <title><![CDATA[Roxana Gheorghe - Elastic Security Labs]]></title>
      <url>https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blte2c6b841aff36df4/6a88d9784acc96e3f324863d/security-labs-thumbnail.png</url>
      <link>https://www.elastic.co/security-labs/author/roxana-gheorghe</link>
    </image>
    <link>https://www.elastic.co/security-labs/author/roxana-gheorghe</link>
    <atom:link href="https://www.elastic.co/security-labs/rss/author/roxana-gheorghe.xml" rel="self" type="application/rss+xml"/>
    <language><![CDATA[en]]></language>
    <lastBuildDate>Wed, 30 Sep 2026 08:57:57 GMT</lastBuildDate>
  <item>
    <title><![CDATA[What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support]]></title>
    <description><![CDATA[Elastic Defend automatically generates and instantly deploys vulnerable driver YARA rules from VirusTotal, LOLDrivers and Microsoft's blocklist, closing the gap BYOVD attacks depend on. Plus a new troubleshooting skill and ARM endpoint protection.]]></description>
    <content:encoded><![CDATA[<p>We know you’re tired of hearing how every vendor is going to finally help you solve alert fatigue. Well, one way we’re improving alert fatigue is from a slightly different angle, better prevention at the endpoint. Because stopping more at the endpoint means fewer alerts ever raised. </p>
<p>We have three endpoint enhancements, all contributing to better endpoint prevention:</p>
<ol>
<li>To be even more proactive about Bring Your Own Vulnerable Driver (BYOVD) attacks, we’re continuously monitoring public vulnerable driver disclosures and automatically generating endpoint protections   </li>
<li>To improve your endpoint management efficiency, Automatic Troubleshooting is now available as a skill via Elastic Agent Builder  </li>
<li>To expand our coverage surface, Elastic Defend is now available for Windows on ARM </li>
</ol>
<p>Let’s dig into each one.</p>
<h2 id="whatisabyovdattackandhowdoesitbypassendpointprotection">What is a BYOVD attack and how does it bypass endpoint protection?</h2>
<p>BYOVD is a technique attackers use to gain kernel-level access on Windows machines by abusing legitimately signed drivers, letting them bypass defenses meant to block unauthorized code. Windows requires low-level software drivers that run in the kernel to be digitally signed, so rather than trying to sneak in something unsigned, attackers bring a driver that's already signed and trusted, but that has a known security flaw. That flaw is enough to disable security software or tamper with memory, and once an attacker has that level of access, security tools can no longer reliably protect the host.</p>
<p>This combination is why BYOVD has become so appealing to ransomware operators. The technique started as tradecraft mostly reserved for advanced state actors and red teams. Elastic Security Labs has tracked its shift into a routine step ransomware crews now use to tamper with or shut down endpoint security software before deploying their payload, as detailed in <a href="https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks">Stopping Vulnerable Driver Attacks</a>.</p>
<p>Now, why does timing matter here? BYOVD attacks have depended on one thing for years: the delay between a vulnerable driver's public disclosure and a vendor shipping coverage for it. The moment a vulnerable driver becomes public knowledge, attackers already know about it. When it takes a vendor an entire product release to ship a protection, that gap is exactly what the technique depends on.</p>
<p>To close this gap, Elastic Security Labs Threat Command, Elastic's security research team now continuously monitors public vulnerable driver disclosure sources, including VirusTotal, the LOLDrivers catalog, and Microsoft's Vulnerable Driver Block List, and automatically generates and instantly deploys detection rules. Because we know any delay could be the difference between an exposed endpoint and a secured one, we’ve decoupled this coverage from any release cycle and publish the protections in the open.</p>
<h2 id="howelasticautomaticallygeneratesvulnerabledriveryararules">How Elastic automatically generates vulnerable driver YARA rules</h2>
<p>Elastic Security Labs has published <a href="https://www.elastic.co/security-labs/invisible-miners-unveiling-ghostengine">detection coverage for vulnerable drivers</a> for years. That coverage now runs through an always-on process that adds new drivers to the protections library as they're disclosed. An always- on process means coverage ships continuously, not whenever the next major release happens to land, and it doesn’t require an update or setting change. A driver flagged today becomes a driver Elastic Defend recognizes.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt4d73019429157966/6a7d86f2c2cc098a85246703/image2.png" alt="" /></p>
<p>Elastic Security Labs Threat Command monitors three public sources for newly disclosed vulnerable and malicious drivers:</p>
<ul>
<li>VirusTotal  </li>
<li>The community-run <a href="https://www.loldrivers.io/">LOLDrivers</a> catalog  </li>
<li>Microsoft's Vulnerable Driver Block List</li>
</ul>
<p>No single source catches everything, so the system checks all three, filters out drivers Elastic already covers, and builds new detection rules from the driver's digital signature and file characteristics.</p>
<p>One example: Avast's signed anti-rootkit driver (<code>aswArPot.sys</code>), which was abused to terminate protected processes from the kernel and has been leveraged in Cuba ransomware intrusions as well as <a href="https://www.elastic.co/security-labs/invisible-miners-unveiling-ghostengine">GHOSTENGINE</a> campaigns. Elastic generates detection coverage for weaponized drivers like these automatically as soon as they surface in the wild.</p>
<p>Every rule this process generates is public. Coverage lands in Elastic's open <a href="https://github.com/elastic/protections-artifacts"><code>protections-artifacts</code></a> repository alongside the rest of Elastic's detection content, so a security team can verify it directly before applying it to their systems. The sources are named and the rules themselves are published in the open, unlike a vendor's private threat feed. You can see which driver triggered a rule, which source flagged it, and inspect the detection logic itself.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt9d0d6356db47380d/6a7d86f5ea068d3f87f072b6/image1.png" alt="" /></p>
<p>This process has taken coverage from an initial 65 rules in 2023 to more than 800 known vulnerable drivers today, and the number keeps growing. These protections ship through Elastic Security's <a href="https://www.elastic.co/docs/solutions/security/configure-elastic-defend/configure-an-integration-policy-for-elastic-defend#malware-protection">malware protection</a>, so make sure it's enabled and set to <strong>Prevent</strong> to get the full benefit. </p>
<p>Signature coverage is also just one layer though. This automated coverage sits alongside protections Elastic Defend has carried for years: validating drivers against a blocklist before they're allowed to load and flagging drivers the moment they're seen for the first time in an environment. A newly disclosed driver doesn't have to wait on a signature alone to be caught doing something suspicious, and a driver built to slip past one layer still has to get past the others built to detect it.</p>
<h2 id="automaticendpointtroubleshootinginelasticagentbuildernowavailableasaskill">Automatic endpoint troubleshooting in Elastic Agent Builder, now available as a skill</h2>
<p>The <a href="https://www.elastic.co/docs/solutions/security/ai/agent-builder/skills-use-cases">automatic troubleshooting skill in Elastic Agent Builder</a> flags policy and performance issues, bringing automation and natural language chat to endpoint diagnosis. Just like the existing <a href="https://www.elastic.co/docs/solutions/security/manage-elastic-defend/automatic-troubleshooting">Automatic Troubleshooting feature</a> scans for and surfaces known endpoint issues, this skill also lets you ask questions, get a diagnosis, and receive specific remediation guidance. It handles the failures that consume the most investigation time: third-party antivirus conflicts, policy application failures, and the errors that typically send analysts into logs for hours.</p>
<p>The skill runs continuously to identify issues’ root causes, tell you what to fix, what commands to run, and what data to collect, all available the second you’re aware of an issue. The existing automatic troubleshooting feature remains available; this skill sits alongside it as a faster path to resolution, specifically tailored for teams that want to work through issues conversationally.</p>
<h2 id="windowsonarmelasticdefendcoverageforsnapdragonandcopilotpcs">Windows on ARM: Elastic Defend coverage for Snapdragon and Copilot+ PCs</h2>
<p>With the increased popularity of ARM processors, Snapdragon laptops, Copilot+ PCs, ARM workstations are more commonly showing up in enterprises’ fleets. If your endpoint protection doesn't cover them, they're unmonitored, and an unmonitored endpoint is a gap an attacker can use. That’s why Elastic Defend has now expanded to cover Windows on ARM. ARM workstations, Snapdragon laptops, and Copilot+ PCs can enroll under your existing policy with the same detection rules and telemetry as x64 endpoints. As you add ARM devices to your fleet, they can enroll automatically to your existing policies.</p>
<h2 id="getstartedwithelasticsecuritytoday">Get started with Elastic Security today</h2>
<p>Elastic Security has significant enhancements to endpoint protections, efficiencies for diagnosing and resolving performance issues, and expanding coverage to new systems, all aimed at shifting defenses earlier, to prevention at the endpoint. </p>
<p>Elastic Security Labs Threat Command now continuously monitors public vulnerable driver disclosure sources and automatically generates and instantly deploys protection rules, decoupled from any release cycle and published in the open. That speed matters when AI-driven attacks can move from one machine to the next in under a minute, faster than any response workflow can react.</p>
<p>Browse the rules directly in the <a href="https://github.com/elastic/protections-artifacts"><code>elastic/protections-artifacts</code></a> repo, alongside the rest of Elastic's open detection content and test out the <a href="https://www.elastic.co/docs/solutions/security/ai/agent-builder/skills-use-cases">automatic troubleshooting skill</a> through Elastic Agent Builder.</p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/blog/vulnerable-driver-detection-elastic-defend-byovd</link>
    <guid isPermaLink="false">vulnerable-driver-detection-elastic-defend-byovd</guid>
    <category><![CDATA[Endpoint Protection & Security]]></category>
    <dc:creator><![CDATA[Pedro Jaramillo,Roxana Gheorghe,Mia LaVada]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt4d73019429157966/6a7d86f2c2cc098a85246703/image2.png" length="0" type="image/png"/>
    <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title><![CDATA[Elastic excels in AV-Comparatives EPR Test 2025: A closer look]]></title>
    <description><![CDATA[Elastic shares results of the 2025 AV Comparatives EPR test]]></description>
    <content:encoded><![CDATA[<p>In a threat landscape defined by sophisticated, multistage attacks, enterprises demand endpoint security solutions that not only detect threats but also actively prevent them and enable rapid responses when the unexpected occurs. Elastic Security demonstrated exceptional performance in a recent AV-Comparatives evaluation, achieving a remarkable 99.3% detection rate. This impressive and consistent figure across both Active Response and Passive Response methods from the <a href="https://www.av-comparatives.org/tests/endpoint-prevention-response-epr-test-2025/?utm_source=blog&amp;utm_medium=referral&amp;utm_campaign=av-comparatives-epr-test-2025-gc">Endpoint Prevention and Response (EPR) Test</a> highlights the versatility and robustness of Elastic Security capabilities, showing strong protection across different attack vectors.</p>
<h2 id="whatistheeprtest"><strong>What is the EPR Test?</strong></h2>
<p>AV-Comparatives’ EPR Test is one of the most rigorous evaluations in the industry. It simulates complex, realistic attack scenarios that traverse the full kill chain, including:</p>
<ul>
<li>Endpoint compromise and foothold (e.g.,initial access, execution, and persistence)  </li>
<li>Internal propagation (e.g., privilege escalation, lateral movement, and credential theft)  </li>
<li>Asset breach (e.g., exfiltration, command and control, and impact)</li>
</ul>
<p>The EPR Test replicates APT-like multistage attacks rather than relying on synthetic malware samples. It evaluates <a href="https://www.elastic.co/blog/elastic-extended-security">endpoint prevention and response solutions</a> against the MITRE ATT\&amp;CK® framework, covering: </p>
<p><strong>Phase 1: Endpoint Compromise and Foothold</strong></p>
<ul>
<li><strong>Initial Access, Execution, and Persistence</strong>  </li>
<li>Replication through removable media  </li>
<li>Malicious documents/scripts   </li>
<li>Registry modifications </li>
</ul>
<p><strong>Phase 2: Internal Propagation</strong></p>
<ul>
<li><strong>Privilege Escalation, Lateral Movement, and Credential Access</strong>  </li>
<li>Scheduled tasks/launch daemons   </li>
<li>Unsecure credentials  </li>
<li>Exploitation of remote services</li>
</ul>
<p><strong>Phase 3: Asset Breach</strong></p>
<ul>
<li><strong>Collection, Command and Control, and Exfiltration</strong>  </li>
<li>Data encoding  </li>
<li>Input and screen capture  </li>
<li>Application layer protocol</li>
</ul>
<p>All participants are scored on two vectors: </p>
<ul>
<li><strong>Active Response:</strong> The product blocks the attack automatically.   </li>
<li><strong>Passive Response:</strong> The product detects and alerts on the activity, providing actionable data for analysts. </li>
</ul>
<p>Additionally, the test quantifies: </p>
<ul>
<li><strong>Operational Accuracy Costs</strong> (false positives, admin overhead)  </li>
<li><strong>Workflow Delay Costs</strong> (productivity impact)  </li>
<li><strong>Total Cost of Ownership (TCO)</strong> for a <strong>5,000-endpoint/5-year deployment</strong></li>
</ul>
<p>**<img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltfd78e1a1a4775159/6a85be27e2447a51aa8b1113/image4.png" alt="AV-Comparatives Enterprise CyberRisk Quadrant™" title="AV-Comparatives Enterprise CyberRisk Quadrant™" /></p>
<h2 id="avcomparativescertifiedeprproductaward"><strong>AV-Comparatives’ Certified EPR Product Award</strong></h2>
<p>In order to get a meaningful comparison between all participants, AV-Comparatives developed the Enterprise CyberRisk Quadrant, which takes into consideration all aspects described above. Elastic Security achieved <em>Certified</em> status, meaning a high level of performance in all key areas, confirming the product meets stringent evaluation standards as stated by Andreas Clementi, CEO and founder of AV-Comparatives:<br />
Elastic achieved strong results in AV-Comparatives’ 2025 Endpoint Prevention and Response Test. The product demonstrated consistent performance across both Active and Passive Response methods, highlighting its ability to provide reliable protection against a broad range of attack vectors.</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt55f53f79d4c18418/6a85be2a80984ce914668ca3/image1.png" alt="av comparative certified EPR 2025 illustration" title="av comparative certified EPR 2025 illustration" /></p>
<h2 id="howelasticsecurityperformedonthetest"><strong>How Elastic Security performed on the test</strong></h2>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt3fcc8854099d617f/6a85be2d68266640a71ea928/image3.png" alt="" /> </p>
<p>| Metric | Elastic Security results | Interpretation |
| :---- | :---- | :---- |
| Active Response (Prevention) | 99.3% | Automated blocking effective across most stages of attack chains |
| Passive Response (Detection) | 99.3% | Alerts enriched with MITRE ATT\&amp;CK mappings, aiding triage and forensic workflows |
| Operational Accuracy Cost | Low | Minimal impact due to detection tuning |
| Workflow Delay Cost | None | No user workflow disruption |</p>
<h2 id="whytheseresultsmatter"><strong>Why these results matter</strong></h2>
<p><strong>1. Prevention is front and center:</strong><br />
A 99.3% active response rate means Elastic Security was able to stop threats <em>before</em> they could run wild in almost all test cases. This includes interrupting attacks in early phases like execution, persistence, or initial foothold — highly valuable since earlier detection often means lower damage.</p>
<p><strong>2. Low noise, minimal disruption:</strong><br />
False positives (mistakenly flagged benign behavior) and workflow delays are often silent risks; they may not make headlines, but they erode confidence, reduce productivity, and increase costs. Elastic Security’s low operational accuracy cost and zero workflow delay in this test show that strong security doesn’t need to come at the expense of usability. </p>
<p><strong>3. Balanced total cost of ownership (TCO):</strong><br />
The test factors in not just purchase and licensing costs, but also the cost of responding to incidents, staffing, false positives, and potential breach fallout over time. Elastic Security’s strong showing suggests that its solution offers good value in the long term. </p>
<p><strong>4. Holistic protection:</strong><br />
Because the test spans multiple stages of an attack, it rewards vendors who do more than just detect malware signatures. Elastic Security’s performance across initial compromise, propagation, and asset breach phases indicates depth — protection at different layers, good detection capabilities, and the ability to give admins useful data for remediation. </p>
<h2 id="conclusions"><strong>Conclusions</strong></h2>
<p>Elastic Security’s results in the AV-Comparatives EPR Test 2025 reaffirm its role as a leading endpoint prevention, detection, and response solution. With near-perfect prevention rates, minimal false positives, no workflow delays, and favorable total cost projections, it demonstrates that enterprise security need not force a trade-off between robust protection and operational efficiency. </p>
<h2 id="onemoreresourcebeforeyougo"><strong>One more resource before you go</strong></h2>
<p>Elastic Security isn’t just getting noticed in the analyst community. Cybersecurity practitioners like John Hammond, who recently took <a href="https://youtu.be/tw-NNqzgohk">a hands-on look at Elastic Security</a> are taking notice, too. If you’re interested in just the key highlights from the interview, we summarize them all in <a href="https://www.elastic.co/blog/raw-data-real-time-defense-john-hammond"><em>From raw data to real-time defense: A conversation with John Hammond</em></a>.</p>
<h2 id="getstartedwithelasticsecurity"><strong>Get started with Elastic Security</strong></h2>
<p>Join the growing number of businesses that trust Elastic Security to protect their organization against attacks. Experience the peace of mind that comes with knowing that your endpoints <em>and organization as a whole</em> are secure against the latest threats. Start your Elastic Security <a href="https://cloud.elastic.co/registration">free trial</a>, and discover the difference that our protection can make. Visit <a href="https://www.elastic.co/security">elastic.co/security</a> to learn more.<br />
<em>The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.</em></p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/reports/elastic-av-comparatives-epr-test-2025</link>
    <guid isPermaLink="false">elastic-av-comparatives-epr-test-2025</guid>
    <dc:creator><![CDATA[Roxana Gheorghe]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt3602ca0a63b74eaf/6a85be3011893c71eda7a886/image2.jpg" length="0" type="image/jpeg"/>
    <pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title><![CDATA[Elastic Security scores 100% in AV-Comparatives Business Security Test]]></title>
    <description><![CDATA[Elastic Security nailed it with a perfect score of 100% in the most recent AV-Comparatives Business Security Test.]]></description>
    <content:encoded><![CDATA[<p>We’re thrilled to share that Elastic Security achieved a score of 100% in the recent <a href="https://www.av-comparatives.org/tests/business-security-test-march-april-2025-factsheet/">AV-Comparatives Business Security Test</a>.</p>
<h2 id="whytheavcomparativesbusinesssecuritytestmatters">Why the AV-Comparatives Business Security Test matters</h2>
<p>AV-Comparatives is a highly respected organization that conducts rigorous, independent testing specifically for business endpoint security solutions. Unlike consumer antivirus tests, AV-Comparatives evaluations go beyond basic malware detection. The Real-World Protection Test simulates real-world attack scenarios, including malicious websites, in a multipronged approach that evaluates a product’s ability to safeguard businesses from contemporary threats. Earning top honors in AV-Comparatives' Business Security Test signifies a solution's effectiveness in protecting organizations.</p>
<p>The test simulates 220 distinct and complex attack scenarios that replicate the tactics and techniques of contemporary threat actors. The Malware Protection Test assesses a security product’s ability to protect a system against infection by malicious files before, during, or after execution. The evaluation utilized a substantial dataset of 1,018 unique and recently identified malware samples, representing the current threat landscape.</p>
<p>Elastic Security earned perfect scores in both critical categories, demonstrating its robust capabilities to accurately identify and prevent a wide spectrum of sophisticated threats, including both targeted attacks and prevalent malware.</p>
<h2 id="highlightsfromelasticsecuritysperformance">Highlights from Elastic Security’s performance</h2>
<p><strong>Ranked first of the tested products:</strong> The following business products were tested under Microsoft Windows 11 64-bit:</p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltb72e96e549d031fb/6a7d751573d9bdf2df29a8ac/image1.png" alt="ranked first tested products" title="ranked first tested products" /></p>
<p><strong>Real-World Protection Test:</strong> Elastic Security excelled in the Real-World Protection Test, achieving 100% coverage and demonstrating exceptional defense against current cyber attacks. This demonstrates how Elastic gives your business the necessary protection to effectively combat the newest threats, reducing the likelihood of data breaches and operational interruptions.  </p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt46f44d8a9fac0d26/6a7d75173cab1ce6e90e16c8/image4.png" alt="real world protection test" title="real world protection test" /></p>
<p><strong>100% protection in Malware Protection Test:</strong> Elastic Security was the sole participant among 17 vendors to achieve a perfect 100% score in both the Real-World Protection Test and the Malware Protection Test. Our advanced threat detection engine is exceptionally effective at identifying and mitigating malware, proactively combating the increasingly sophisticated malware environment. This perfect score across both critical evaluation criteria highlights not only the efficacy of Elastic Security’s solutions in practical, real-world scenarios but also its comprehensive capabilities in identifying and neutralizing a broad spectrum of malicious software.  </p>
<p><img src="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/blt05b600c94e215b7d/6a7d751a42a117576b958df1/image2.png" alt="malware protection test" title="malware protection test" /></p>
<p>Our <a href="https://www.elastic.co/blog/elastic-av-comparatives-business-security-test">consistently excellent results</a> demonstrate our ongoing commitment to delivering dependable protection for businesses of all scales. Elastic Security is a proven solution for safeguarding your organization's data against threats.</p>
<h2 id="performanceiskeytosecurity">Performance is key to security</h2>
<p>Elastic Security recognizes that effective cybersecurity requires more than just identifying and stopping malicious activity. Advanced cybersecurity demands seamless integration with daily operations for sophisticated security and business efficiency. Comprehensive security capabilities, such as advanced threat detection, proactive ransomware defense, and sophisticated malware analysis, form the bedrock of a strong security posture. However, their true value is diminished if they lead to system performance degradation. Slow, resource-intensive security solutions can frustrate users, impede productivity, and ultimately undermine the very security they aim to provide.</p>
<p>At Elastic Security, performance is not a secondary consideration but a fundamental pillar of our security philosophy and product design. We are committed to delivering world-class security without the performance overhead that can disrupt workflows. Our engineering efforts focus on optimizing every aspect of our platform to minimize CPU and memory consumption.</p>
<h2 id="edrstopsattheendpointxdrdoesnt"><strong>EDR stops at the endpoint, XDR doesn’t</strong></h2>
<p>Todayʼs threat landscape is complex and dynamic, with attacks originating from various sources and targeting diverse environments. By correlating information from endpoints, networks, cloud workloads, and more, extended detection and response (XDR) offers a holistic view of the security posture, protecting against increasingly complex threats. The shift from endpoint detection and response (EDR) to XDR is a critical evolution in security operations, offering more robust, efficient, and effective defense mechanisms.</p>
<p><a href="https://www.elastic.co/security/xdr">XDR security from Elastic</a> is designed to protect data across the entire organization — regardless of where it resides. Elastic Security helps organizations improve detection rates, reduce response times, and mitigate overall risk by unifying data types and providing limitless ingestion, analysis, and protection.</p>
<ul>
<li><strong>Extended visibility:</strong> Elastic provides a unified view of your security landscape, encompassing endpoints, networks, and cloud environments. This comprehensive perspective empowers analysts to see the big picture and connect the dots between potential threats. With hundreds of integrations and the AI-driven Automatic Import feature at the ready, your team can seamlessly onboard all types of data from various sources, expanding your visibility across the organization.  </li>
<li><strong>XDR detection capabilities:</strong> Elastic Securityʼs AI-driven security analytics correlates data across all sources to uncover sophisticated threats that often evade detection by individual security solutions. Our vast library, with hundreds of prebuilt rules mapped to the MITRE ATT\&amp;CK® matrix, combined with proprietary research and detection content from Elastic Security Labs, helps you separate the signal from the noise so you can focus on actual threats. Elastic Security also provides more than 75 machine learning detection rules to automatically detect anomalies across numerous security domains like suspicious user or host activity.  </li>
<li><strong>Native and third-party responses:</strong> Analysts often face an overwhelming volume of alerts, making it challenging to focus on legitimate threats. To address this, Elastic security offers both native and third-party response actions to stop attackers in their tracks.</li>
</ul>
<p>We believe XDR should be accessible to every organization, regardless of budget constraints. Thatʼs why our XDR solution is included without any hidden costs or “optional extras.” Our comprehensive visibility goes beyond endpoint telemetry, eliminating the need for additional licenses to unlock full XDR capabilities — all included in the Elastic Security solution. With no per-host or per-agent charges, you have the flexibility to provide coverage where and when you need it.</p>
<p><strong>Read more:</strong> <a href="https://www.elastic.co/blog/elastic-extended-security">You thought Elastic only did SIEM? Think again!</a></p>
<h2 id="getstartedwithelasticsecurity">Get started with Elastic Security</h2>
<p>Join the growing number of businesses that trust Elastic Security to protect their organization against attacks. Experience the peace of mind that comes with knowing your endpoints — and organization as a whole — are secure against the latest threats. Start your Elastic Security <a href="https://cloud.elastic.co/registration">free trial</a> and discover the difference that our protection can make. Visit <a href="https://www.elastic.co/security">elastic.co/security</a> to learn more and get started. </p>
<p>For more detailed results and to see the full report, visit the <a href="https://www.av-comparatives.org/tests/business-security-test-march-april-2025-factsheet/">AV-Comparatives Business Security Test 2025 website</a>.</p>
<p><em>The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.</em></p>]]></content:encoded>
    <link>https://www.elastic.co/security-labs/reports/elastic-security-av-comparatives-business-security-test-2025</link>
    <guid isPermaLink="false">elastic-security-av-comparatives-business-security-test-2025</guid>
    <dc:creator><![CDATA[Roxana Gheorghe]]></dc:creator>
    <enclosure url="https://static-www.elastic.co/v3/assets/bltefdd0b53724fa2ce/bltb6e62fd280d4aa47/6a7d751dea068db0d4f06f26/image3.jpg" length="0" type="image/jpeg"/>
    <pubDate>Mon, 09 Jun 2025 00:00:00 GMT</pubDate>
  </item>
  </channel>
</rss>