Category: Integrations & Tools

Articles tagged Integrations & Tools

Subscribe
Filters
Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here
Security Labs

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Elastic's first automatic migration from a modern SIEM. Translate your Sentinel detection rules into Elastic Security without rebuilding them.

Charles Davison
From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence
Security Labs

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Find out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.

Jamie Hynds
Monitoring Claude Code/Cowork at scale with OTel in Elastic
Security Labs

Monitoring Claude Code/Cowork at scale with OTel in Elastic

How Elastic's InfoSec team built a monitoring pipeline for Claude Code and Claude Cowork using their native OTel export capabilities and Elastic's OTel ingestion infrastructure.

Spencer Niemi
Elastic Security Integrations Roundup: Q1 2026
Security Labs

Elastic Security Integrations Roundup: Q1 2026

Elastic Security Labs announces nine new integrations for Elastic Security spanning cloud security, endpoint visibility, email threat detection, identity and SIEM.

Carrie Pascale
Managing Elastic Security Detection Rules with Terraform
Security Labs

Managing Elastic Security Detection Rules with Terraform

Learn to define and deploy Elastic Security detection rules and exceptions using the Elastic Stack Terraform Provider vs detection-rules repository DaC capabilities.

Kseniia Ignatovych
Manage your Elastic security stack as code with the Elastic Stack Terraform provider
Security Labs

Manage your Elastic security stack as code with the Elastic Stack Terraform provider

From detection rules to AI connectors - the latest Terraform provider releases bring security, observability, and ML capabilities to your infrastructure-as-code workflows.

Omer Kushmaro
Automating GOAD and Live Malware Labs
Security Labs

Automating GOAD and Live Malware Labs

Stop building labs by hand. Automate the deployment of a fully instrumented Purple Team range using Ludus and Elastic Security. Spin up infrastructure, execute attacks, and validate detection rules in a single, repeatable workflow.

Nic Palmer
From Qradar to Elastic: Automate your Detection Rule Migration
Security Labs

From Qradar to Elastic: Automate your Detection Rule Migration

Today, we are excited to announce a major expansion to our Automatic Migration feature that changes that narrative. In Elastic Security 9.3, we are introducing Automatic Migration support for QRadar detection rules (now in Tech Preview), joining our existing Splunk translation capabilities to further expedite your journey to Elastic Security. Let's take a closer look at what's supported.

Charles Davidson
Elastic and Keep join forces to help users manage alerts and automate workflows
Security Labs

Elastic and Keep join forces to help users manage alerts and automate workflows

Elastic announces the acquisition of Keep Alerting

Ken Exner
WinVisor – A hypervisor-based emulator for Windows x64 user-mode executables
Security Labs

WinVisor – A hypervisor-based emulator for Windows x64 user-mode executables

WinVisor is a hypervisor-based emulator for Windows x64 user-mode executables that leverages the Windows Hypervisor Platform API to provide a virtualized environment for logging syscalls and enabling memory introspection.

Elastic Security Labs
Streamlining Security: Integrating Amazon Bedrock with Elastic
Security Labs

Streamlining Security: Integrating Amazon Bedrock with Elastic

This article will guide you through the process of setting up the Amazon Bedrock integration and enabling Elastic's prebuilt detection rules to streamline your security operations.

Shashank K S
STIXy Situations: ECSaping your threat data
Security Labs

STIXy Situations: ECSaping your threat data

Structured threat data is commonly formatted using STIX. To help get this data into Elasticsearch, we’re releasing a Python script that converts STIX to an ECS format to be ingested into your stack.

Cyril François