Výsledky hledání

typ: návod× v celém archivu zrušit filtry

148 karet z 148 položek · strana 3 z 3 CZ · EN/orig

1

1

1

1

1

1

1

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

AAD Graph Activity Logs are now ingestible into Elastic and usable for threat detection within the SIEM/XDR solution. That sentence shouldn't be exciting, but it is. For most of the past decade, this slice of telemetry simply didn't exist as a customer-accessible log stream. Microsoft Graph Activity Logs (the modern graph.microsoft.com surface) went GA in April 2024. The legacy graph.windows.net surface, the one adversary tooling actually hits, stayed dark until early 2026. This post walks the…

Microsoft Elastic US

tg: rozbor tg: novinka v produktu tg: návod tp: identita

· Elastic Security · Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

2

1

1

1

1

1

Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

Introduction Self-hosted services exposed through a reverse proxy inevitably attract automated scanners probing for misconfigurations, admin panels, and vulnerable endpoints. In this article, I show how to turn routine Traefik access logs into an active defensive control using Elastic Security and Cloudflare. I use an out-of-the-box ES|QL detection rule to identify web server discovery and fuzzing behavior. When suspicious probing patterns are detected, an automated workflow immediately blocks…

Elastic Cloudflare Traefik Labs US

tg: návod tg: propagace

· Elastic Security · Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

1

DFIR: From alert to root cause using Osquery without leaving Elastic Security

Modern DFIR doesn't start with a disk image. That model worked when environments were smaller, endpoints were static, and time wasn't the primary constraint. Endpoints are now ephemeral, fleets scale to thousands of hosts, and attackers operate on timelines measured in minutes. By the time a full forensic image is collected, the system may no longer exist. Forensics today is no longer about collecting everything. It's about asking the right questions, in real time, across your entire…

Elastic US

tg: návod tg: propagace

· Elastic Security · DFIR: From alert to root cause using Osquery without leaving Elastic Security

1

Monitoring Claude Code/Cowork at scale with OTel in Elastic

As AI coding assistants become standard tools in engineering workflows, security teams face a new challenge: how do you maintain visibility into what an AI agent is doing (and why) across your organization? When those agents can execute shell commands, read files, call APIs, and interact with internal systems via MCP connectors, you need real-time observability to support threat detection, incident response, and compliance. This post walks through how Elastic's InfoSec team built a monitoring…

Anthropic Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Monitoring Claude Code/Cowork at scale with OTel in Elastic

1

1

1

2

Hooked on Linux: Rootkit Detection Engineering

Introduction In part one, we examined how Linux rootkits work: their evolution, taxonomy, and techniques for manipulating user space and kernel space. In this second part, we turn to detection engineering. We begin by showing why static detection is often unreliable against Linux rootkits, even when binaries are only trivially modified, and then move on to behavioral and runtime signals that defenders can use instead. From shared object abuse and LKM loading to eBPF, io_uring, persistence, and…

Linux US

tg: rozbor tg: návod tp: malware

· Elastic Security · Hooked on Linux: Rootkit Detection Engineering

Prioritizing Alerts Triage with Higher-Order Detection Rules

At Elastic, we operate a large and diverse set of behavior detection rules across multiple datasets, environments, and severity levels. Most of these rules are atomic, each designed to detect a specific behavior, signal, or attack pattern. In addition, we ingest and promote external alerts from security integrations such as firewalls, EDR, WAF, and other security controls. The result is powerful visibility but also significant alert volume. From our telemetry, even when considering only non…

Elastic US

tg: návod tg: propagace

· Elastic Security · Prioritizing Alerts Triage with Higher-Order Detection Rules

4

Investigating from the Endpoint Across Your Environment with Elastic Security XDR

Preamble Security investigations rarely stay confined to a single host. Today’s attackers increasingly use automation and AI to compress multi-stage attacks into minutes, turning what once unfolded over days into coordinated activity across endpoints, identities, workloads, and cloud services within minutes. While many attacks begin on an endpoint, investigators must quickly determine how that activity spreads across the environment. In many environments, per-endpoint licensing limits how…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Investigating from the Endpoint Across Your Environment with Elastic Security XDR

Security Automation with Elastic Workflows: From Alert to Response

The daily loop An alert fires. You open it. You read through the details. You gather context from the surrounding activity. You check for related signals across your environment. You decide what it means and what to do next. Sometimes you escalate. Sometimes you close it and move on. You do this dozens of times a day. The steps are almost always the same. The data you need is already in your SIEM. The actions you take are predictable. But the work is still manual. This is the kind of work that…

Elastic US

tg: návod tg: propagace

· Elastic Security · Security Automation with Elastic Workflows: From Alert to Response

Streamlining the Security Analyst Experience

The term Agentic SOC (Security Operations Center) is one of the most popular concepts in security today. But what does it truly mean in practice, and how does Elastic Security approach this next evolution of security operations? In simple terms, an Agentic SOC is a security operations center that has deployed AI Agents and corresponding AI Agent Skills to perform SOC-related workflows such as detection engineering, alert triage, incident investigation, escalation, response, and threat hunting.…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Streamlining the Security Analyst Experience

Supercharge Your SOC

Preamble The landscape of cybersecurity is evolving, and the role of the Detection Engineer (DE) is more critical and demanding than ever. Traditionally, this role involves a comprehensive, end-to-end workflow: from threat modeling and telemetry tuning to writing, testing, and maintaining performance-optimized detection rules to flag malicious behavior. Elastic Security is purpose-built to streamline this entire workflow, empowering DEs - and anyone involved in security operations - to build,…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Supercharge Your SOC

1

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

Introduction Linux systems remain a critical foundation for modern infrastructure, particularly in cloud-native environments where containers and orchestration platforms are the norm. As workloads move from long-lived hosts to ephemeral containers, attacker tradecraft shifts as well. Activity that once left persistent artifacts on disk is increasingly confined to short-lived, runtime behavior that can be difficult to capture using traditional log sources. Detection engineering in these…

Elastic US

tg: novinka v produktu tg: návod tg: propagace

· Elastic Security · Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

1

1

Managing Elastic Security Detection Rules with Terraform

At the core of Elastic Security lie outstanding detection capabilities, allowing users to create, test, tune, manage, deploy detection rules, as code, in their environments. The ability to create robust detections is critical for Security Operations as detection logic elevates threat signal from the telemetry noise. This article highlights how Elastic's new Terraform resources for security detection rules and exceptions expand practitioners' capabilities for detection-as-code deployment. Below…

Elastic US

tg: novinka v produktu tg: návod tg: propagace tp: AI

· Elastic Security · Managing Elastic Security Detection Rules with Terraform