Blogs

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Filters

Elastic Workflows GA: automation where your security data already lives

Elastic Workflows is generally available in 9.4, bringing production-ready security automation with deeper case management integration, human-in-the-loop support, natural language authoring, and more.

Tinsae Erkailo

One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow

Elastic Security 9.4 introduces skills, modular AI capabilities that teach the Elastic AI Agent how to detect, investigate, and hunt like a specialist. This is how they work, and why they matter for the SOC.

Dhrumil Patel

Elastic Conversational Entity Analytics: threat hunting in a single conversation

Conversational Entity Analytics delivers Entity Analytics features as rich inline attachments and Canvas previews into Agent Builder, so you don’t have to leave the conversation.

Erik Huang

From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

Elastic Security now lets analysts describe a threat behavior in plain language and receive a complete, validated Elasticsearch ES|QL detection rule in return, no query expertise required.

Kseniia Ignatovych

DFIR: From alert to root cause using Osquery without leaving Elastic Security

Learn how to perform distributed, real-time Digital Forensics and Incident Response (DFIR) using Osquery and Elastic to investigate threats at scale without relying on disk imaging.

Raquel Tabuyo

Monitoring Claude Code/Cowork at scale with OTel in Elastic

How Elastic's InfoSec team built a monitoring pipeline for Claude Code and Claude Cowork using their native OTel export capabilities and Elastic's OTel ingestion infrastructure.

Spencer Niemi

Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floor

An overview of the Elastic Security and AI infrastructure deployed to support the UK Ministry of Defence's flagship cyber exercise, Defence Cyber Marvel 2026.

James Garside

Elastic Security Integrations Roundup: Q1 2026

Elastic Security Labs announces nine new integrations for Elastic Security spanning cloud security, endpoint visibility, email threat detection, identity and SIEM.

Carrie Pascale

Prioritizing Alerts Triage with Higher-Order Detection Rules

Scaling SOC efficiency through multi-signal correlation and higher-order detection patterns.

Samir Bousseaden

Elastic releases detections for the Axios supply chain compromise

Hunting and detection rules for the Elastic-discovered Axios supply chain compromise.

Ruben Groenewoud

Streamlining the Security Analyst Experience

Alert Triage, Investigation, and Response with Elastic's Agentic Security Operations Platform.

Paul Ewing

Security Automation with Elastic Workflows: From Alert to Response

A practical guide to building intelligent, automated security playbooks with Elastic Workflows.

Tinsae Erkailo