Výsledky hledání

výrobce: Elastic× v celém archivu zrušit filtry

68 karet z 68 položek · strana 2 z 2 CZ · EN/orig

4

Investigating from the Endpoint Across Your Environment with Elastic Security XDR

Preamble Security investigations rarely stay confined to a single host. Today’s attackers increasingly use automation and AI to compress multi-stage attacks into minutes, turning what once unfolded over days into coordinated activity across endpoints, identities, workloads, and cloud services within minutes. While many attacks begin on an endpoint, investigators must quickly determine how that activity spreads across the environment. In many environments, per-endpoint licensing limits how…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Investigating from the Endpoint Across Your Environment with Elastic Security XDR

Security Automation with Elastic Workflows: From Alert to Response

The daily loop An alert fires. You open it. You read through the details. You gather context from the surrounding activity. You check for related signals across your environment. You decide what it means and what to do next. Sometimes you escalate. Sometimes you close it and move on. You do this dozens of times a day. The steps are almost always the same. The data you need is already in your SIEM. The actions you take are predictable. But the work is still manual. This is the kind of work that…

Elastic US

tg: návod tg: propagace

· Elastic Security · Security Automation with Elastic Workflows: From Alert to Response

Streamlining the Security Analyst Experience

The term Agentic SOC (Security Operations Center) is one of the most popular concepts in security today. But what does it truly mean in practice, and how does Elastic Security approach this next evolution of security operations? In simple terms, an Agentic SOC is a security operations center that has deployed AI Agents and corresponding AI Agent Skills to perform SOC-related workflows such as detection engineering, alert triage, incident investigation, escalation, response, and threat hunting.…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Streamlining the Security Analyst Experience

Supercharge Your SOC

Preamble The landscape of cybersecurity is evolving, and the role of the Detection Engineer (DE) is more critical and demanding than ever. Traditionally, this role involves a comprehensive, end-to-end workflow: from threat modeling and telemetry tuning to writing, testing, and maintaining performance-optimized detection rules to flag malicious behavior. Elastic Security is purpose-built to streamline this entire workflow, empowering DEs - and anyone involved in security operations - to build,…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Supercharge Your SOC

1

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

Introduction Linux systems remain a critical foundation for modern infrastructure, particularly in cloud-native environments where containers and orchestration platforms are the norm. As workloads move from long-lived hosts to ephemeral containers, attacker tradecraft shifts as well. Activity that once left persistent artifacts on disk is increasingly confined to short-lived, runtime behavior that can be difficult to capture using traditional log sources. Detection engineering in these…

Elastic US

tg: novinka v produktu tg: návod tg: propagace

· Elastic Security · Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

1

Get started with Elastic Security from your AI agent

Get started with Elastic Security from your AI agent Elastic Agent Skills are open source packages that give your AI coding agent native Elastic expertise. If you're already using Elastic Agent Builder, you get AI agents that work natively with your security data. Agent Skills are for the other side: bringing that same Elastic Security knowledge to the external AI tools your team already uses, like Cursor, Claude Code, or GitHub Copilot. If you use an AI coding agent and want to evaluate…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Get started with Elastic Security from your AI agent

1

Managing Elastic Security Detection Rules with Terraform

At the core of Elastic Security lie outstanding detection capabilities, allowing users to create, test, tune, manage, deploy detection rules, as code, in their environments. The ability to create robust detections is critical for Security Operations as detection logic elevates threat signal from the telemetry noise. This article highlights how Elastic's new Terraform resources for security detection rules and exceptions expand practitioners' capabilities for detection-as-code deployment. Below…

Elastic US

tg: novinka v produktu tg: návod tg: propagace tp: AI

· Elastic Security · Managing Elastic Security Detection Rules with Terraform

1