Blogs

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Filters

DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector

Learn how Elastic Defend's ransomware protection successfully detects and prevents DYNOWIPER execution using canary file monitoring.

Elastic Security Labs

Automating GOAD and Live Malware Labs

Stop building labs by hand. Automate the deployment of a fully instrumented Purple Team range using Ludus and Elastic Security. Spin up infrastructure, execute attacks, and validate detection rules in a single, repeatable workflow.

Nic Palmer

The Engineer's Guide to Elastic Detections as Code

This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.

Eric Forte

From Alert Fatigue to Agentic Response: How Workflows and Agent Builder Close the Loop

Attempting to chase individual alerts is a losing strategy. To succeed, we have to move beyond simple automation scripts and into the era of Agentic AI.

Dhrumil Patel

From Qradar to Elastic: Automate your Detection Rule Migration

Today, we are excited to announce a major expansion to our Automatic Migration feature that changes that narrative. In Elastic Security 9.3, we are introducing Automatic Migration support for QRadar detection rules (now in Tech Preview), joining our existing Splunk translation capabilities to further expedite your journey to Elastic Security. Let's take a closer look at what's supported.

Charles Davidson

How Elastic Infosec Optimizes Defend for Cost and Performance

This article details the internal Elastic Infosec team's process to optimize our endpoint data collection using Event Filtering and Advanced Policy Settings in Elastic Defend.

Aaron Jewitt

From Hypothesis to Action: Proactive Threat Hunting with Elastic Security

Elastic Security is designed to enable hypothesis-driven threat hunting at speed and scale. By unifying security telemetry and enabling analytics across clusters, threat hunters can ask complex questions across all their data, correlate signals, and validate hypotheses quickly without manual data stitching.

Paul Ewing

Automating detection tuning requests with Kibana cases

Learn how to automate detection rule tuning requests in Elastic Security. This guide shows how to add custom fields to Cases, create a rule to detect tuning needs, and use a webhook to create a frictionless feedback loop between analysts and detection engineers.

Aaron Jewitt

TOR Exit Node Monitoring Overview

Learn how to monitor your enterprise for TOR exit node activity.

Peter Titov

Time-to-Patch Metrics: A Survival Analysis Approach Using Qualys and Elastic

In this article, we describe how we applied survival analysis to vulnerability management (VM) data from Qualys VMDR, using the Elastic Stack.

Laura Voicu

Agentic Frameworks Summary

Agentic systems require security teams to balance autonomy with alignment, ensuring that AI agents can act independently while remaining goal-consistent and controllable .

Mika Ayenson

How AI and contextual search enhance defence cybersecurity

Contextual search brings clarity, speed, and insight to defence security teams

Crossley McEwen