Category: AI & Automation

Articles tagged AI & Automation

Filters

One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow

Elastic Security 9.4 introduces skills, modular AI capabilities that teach the Elastic AI Agent how to detect, investigate, and hunt like a specialist. This is how they work, and why they matter for the SOC.

Dhrumil Patel

Elastic Conversational Entity Analytics: threat hunting in a single conversation

Conversational Entity Analytics delivers Entity Analytics features as rich inline attachments and Canvas previews into Agent Builder, so you don’t have to leave the conversation.

Erik Huang

From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

Elastic Security now lets analysts describe a threat behavior in plain language and receive a complete, validated Elasticsearch ES|QL detection rule in return, no query expertise required.

Kseniia Ignatovych

Security Automation with Elastic Workflows: From Alert to Response

A practical guide to building intelligent, automated security playbooks with Elastic Workflows.

Tinsae Erkailo

Supercharge Your SOC

Detection Engineering in the Era of AI Agents - The New Frontier.

Paul Ewing

Get started with Elastic Security from your AI agent

Go from zero to a fully populated Elastic Security environment without leaving your IDE, using open source Agent Skills.

Sneha Sachidananda

Why 2026 is the Year to Upgrade to an Agentic AI SOC

Agentic AI SOCs differ from copilot-only models by autonomously prioritizing attacks over alerts, executing closed-loop containment, and providing traceable reasoning for every decision, allowing analysts to focus on high-value investigations.

Sandiya Ramamoorthy

Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder

This article walks through how Elastic Security's Attack Discovery, combined with Workflows and Agent Builder, can automatically detect, correlate, and confirm APT-level attacks like Chrysalis while reducing analyst response time from hours to minutes.

James Spiteri

From Alert Fatigue to Agentic Response: How Workflows and Agent Builder Close the Loop

Attempting to chase individual alerts is a losing strategy. To succeed, we have to move beyond simple automation scripts and into the era of Agentic AI.

Dhrumil Patel

Agentic Frameworks Summary

Agentic systems require security teams to balance autonomy with alignment, ensuring that AI agents can act independently while remaining goal-consistent and controllable .

Mika Ayenson

How AI and contextual search enhance defence cybersecurity

Contextual search brings clarity, speed, and insight to defence security teams

Crossley McEwen

Elastic changes the SIEM game with AI-driven security analytics

Learn more about Elastic's AI-driven security analytics

Santosh Krishnan