Blogs

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Filters

Investigating from the Endpoint Across Your Environment with Elastic Security XDR

This article highlights how Elastic Security XDR unifies endpoint protection with multi-domain security analytics to help analysts trace and contain multi-stage attacks across hybrid and cloud environments.

Jamie Hynds

Supercharge Your SOC

Detection Engineering in the Era of AI Agents - The New Frontier.

Paul Ewing

Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

This publication provides a real-world walkthrough of TeamPCP's multi-stage container compromise, demonstrating how Elastic's D4C surfaces runtime signals across each stage of the attack chain.

Ruben Groenewoud

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

This technical resource provides a comprehensive walkthrough of Elastic’s Defend for Containers (D4C) integration, covering Kubernetes-based deployment, the analysis of BPF-enriched runtime telemetry, and the practical application of policy-driven security controls to monitor and alert on activities within containerized Linux environments.

Ruben Groenewoud

Get started with Elastic Security from your AI agent

Go from zero to a fully populated Elastic Security environment without leaving your IDE, using open source Agent Skills.

Sneha Sachidananda

Managing Elastic Security Detection Rules with Terraform

Learn to define and deploy Elastic Security detection rules and exceptions using the Elastic Stack Terraform Provider vs detection-rules repository DaC capabilities.

Kseniia Ignatovych

Patch diff to SYSTEM

Leveraging LLMs and patch diffing, this research details a Use-After-Free vulnerability in Windows DWM, demonstrating a reliable exploit that achieves escalation from low-privileged user permissions to SYSTEM.

Joe Desimone

Manage your Elastic security stack as code with the Elastic Stack Terraform provider

From detection rules to AI connectors - the latest Terraform provider releases bring security, observability, and ML capabilities to your infrastructure-as-code workflows.

Omer Kushmaro

Why 2026 is the Year to Upgrade to an Agentic AI SOC

Agentic AI SOCs differ from copilot-only models by autonomously prioritizing attacks over alerts, executing closed-loop containment, and providing traceable reasoning for every decision, allowing analysts to focus on high-value investigations.

Sandiya Ramamoorthy

Make The Most of Network Firewall Logs with Elastic Security

Make the most of your firewall logs. In Part 1 of our series, learn how to ingest and parse logs from any firewall with Elastic Agent and use the Network Page to visually explore your network traffic for instant insights.

Marvin Ngoma

Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder

This article walks through how Elastic Security's Attack Discovery, combined with Workflows and Agent Builder, can automatically detect, correlate, and confirm APT-level attacks like Chrysalis while reducing analyst response time from hours to minutes.

James Spiteri

SolarWinds Web Help Desk Exploitation - February 2026

Elastic Security detection and prevention capabilities for the recently-disclosed SolarWinds Web Help Desk vulnerabilities.

Elastic Security Labs