Blogs

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Filters

Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

We tested two agentic SOC architectures in parallel across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.

Aaron Jewitt

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.

Ruben Groenewoud

How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

Elastic InfoSec tested this detection rule pattern on their own cloud fleet, filtering noisy curl and wget events with deterministic logic and LLM triage so only genuine threats reach an analyst.

Aaron Jewitt

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic's InfoSec team built AI agents on Elastic Workflows that investigate every alert and assemble the case before an analyst ever opens it.

Aaron Jewitt

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

How Elastic's security team built an AI agent with RAG against MITRE's CWE and CAPEC catalogues to draft CVE advisories from raw vulnerability reports, including the full prompt and crawler configs.

Paul McCann

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.

Terrance DeJesus

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Find out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.

Jamie Hynds

Elastic Security MCP App: Interactive security operations inside your AI Tools

Elastic Security is the first security vendor to ship an interactive UI in AI tools. Triage alerts, hunt threats, correlate attack chains, and open cases, all from inside your AI conversation.

David Elgut

Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

This article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.

Erik-Jan de Kruijf

Your UEBA is lying to you: Why entity record quality decides everything

Most entity analytics systems are confidently wrong. They track users who do not exist, generate risk scores built on noise, and call it behavioral analytics. Learn why the entities records you don't create matter as much as the ones you do and how a confidence-tiered model changes the game.

Erik Huang

AI-generated hunting leads: The hunt starts before you ask the question

Introducing AI-generated hunting leads, proactive, environment-aware threat hypotheses powered by Elastic Entity analytics and integrated AI reasoning.

Erik Huang

Know who to watch before the incident finds you

Elastic Security v9.4 introduces Entity Analytics Watchlists, a way to codify what your team already knows about high-risk entities and feed that context directly into risk scoring, without custom pipelines or detection engineering overhead

Erik Huang