Author

Articles by Kseniia Ignatovych

Product Manager, Security Core - Security Content

Videos

Building effective threat hunting and detection rules in Elastic Security

Learn to create custom detection rules in Elastic Security. We cover best practices for using ES|QL and Elastic AI Assistant for threat detection to add vital context. Discover how to preview, test, and enhance rules to improve security operations.

Videos

Elastic Security simplifies customization of prebuilt SIEM detection rules

Learn about the prebuilt rule editing capabilities that allow you to get even more value from out-of-the-box SIEM detection rules.

Videos

What’s new in Elastic Security 8.18 and 9.0

Elastic Security 8.18 and 9.0 bring Automatic Migration for detection rules, a Lookup Join function for ES|QL, several AI feature enhancements, and more!

Videos

NEW Elastic Security 8.16: Elastic AI Assistant knowledge, cloud detection and response, and agentless integrations

Elastic Security 8.16 delivers simplified and seamless data onboarding with agentless integrations, vendor-agnostic cloud security workflows for contextualized threat investigation, and custom knowledge base support for Elastic AI Assistant.

Videos

Know your tools: The full range of Elastic Security’s detection engineering capabilities

This blog provides a comprehensive overview of the detection capabilities available in Elastic Security. Learn about the latest features and get useful tips and tricks for your detection practice!

Videos

Rolling your own Detections as Code with Elastic Security

Detections as Code (DaC) is transforming security rule management. Learn about Elastic's latest enhancements in the detection-rules repo, how to leverage it for custom rule management, and our comprehensive guide for adopting DaC.

Videos

NEW! Elastic Security 8.13: Manage benchmark rules and automated endpoint responses

Elastic Security 8.13 unveils an enhanced benchmark rules page, simplifying navigation and decision-making with enable/disable controls. Automate endpoint actions, such as process termination, to accelerate incident response and threat mitigations.

Videos

What’s new in Elastic Security 8.10: Scale your defenses and outpace attackers

Elastic Security 8.10 brings richer alert contextualization, generative AI in GA, a MITRE ATT&CK® coverage page, and cloud security posture management (CSPM) for GCP.

Videos

Elastic Security 8.9: Streamline the analyst experience with GAI and advanced analytics

See the new features available now in Elastic Security 8.9, including advanced analytics, streamlined workflows, new dashboards, AI assistants, and so much more!