Výsledky hledání

typ: novinka v produktu× v celém archivu zrušit filtry

146 karet z 150 položek · strana 3 z 3 CZ · EN/orig

1

1

2

Elastic Security MCP App: Interactive security operations inside your AI Tools

Every SOC analyst knows the drill: an alert fires, and the next ten minutes are spent switching between a triage dashboard, a threat hunt, a case file, and the AI tool that told you to look in the first place. Recently, we introduced MCP Apps for Elastic, built on the open MCP Apps extension to the Model Context Protocol, that lets an MCP tool return an interactive UI alongside its text response, rendered inline in Claude Desktop, Claude.ai, VS Code Copilot, Cursor, or any compatible host. This…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Elastic Security MCP App: Interactive security operations inside your AI Tools

1

3

Elastic Workflows GA: automation where your security data already lives

Elastic Workflows is generally available in 9.4. It is the automation layer built directly into Elastic, running where your data lives across Security, Observability, and Search. While this post focuses on a security deep dive, the same workflow capabilities apply across solutions, with no separate platform to deploy and no data to move. When an alert fires or a schedule triggers, a Workflow executes: querying Elasticsearch, enriching with threat intel, creating cases, calling external APIs,…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Elastic Workflows GA: automation where your security data already lives

Know who to watch before the incident finds you

Elastic Security v9.4 introduces Entity Analytics Watchlists, a new capability in the Entity Analytics suite that lets security teams create named, weighted lists of users, hosts, and services and feed that context directly into the platform's risk scoring pipeline. The gap this closes isn't awareness, as most security teams already know which entities deserve elevated scrutiny. The gap is that SIEMs have had no way to express that organizational knowledge as a risk signal. Watchlists do that…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · Know who to watch before the incident finds you

AI-generated hunting leads: The hunt starts before you ask the question

Threat hunting has always been a human art; a practitioner staring at logs, forming a hypothesis, and patiently chasing it down. What if the hardest part of the hunt (knowing where to look) could be done for you, automatically, in milliseconds, and tuned specifically to your environment? This is where AI-generated hunting leads come in, allowing you to shift from reactive alerting to proactive defense with entity-centric, risk-based threat hunting tailored specifically to your environment's…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · AI-generated hunting leads: The hunt starts before you ask the question

3

From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

Elastic Security now includes AI-powered detection rule creation, built into the rule creation workflow. Analysts describe a threat behavior in plain English and receive a complete, validated Elasticsearch Query Language (ES|QL) rule in return, with MITRE ATT\&CK mappings, severity recommendations, and a preview against live data, all without leaving the platform or writing a single line of query syntax. This post walks through exactly how that works using an Okta credential stuffing and…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

Elastic Conversational Entity Analytics: threat hunting in a single conversation

Entity Analytics is a core security analytics capability that extends Elastic Security from event-centric to entity-centric investigation. By focusing on critical entities, such as users, hosts, and services, it builds a complete profile of each entity’s attributes, lifecycle, behaviors, relationships, and risk score over time. This security context equips threat hunters to stop chasing isolated alerts and instead uncover the full narrative of a potential compromise. In this blog, we walk…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Elastic Conversational Entity Analytics: threat hunting in a single conversation

One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow

Three things land on you at once: Attack Discovery correlated 12 alerts into a credential-harvesting campaign overnight, your team just onboarded a new fleet of macOS endpoints and needs detection rules for LOLBin abuse, and a risk score spike on a service account just crossed the critical threshold. In most security operations centers (SOCs), that's three different people, three different workflows, and a morning spent context-switching. In Elastic Security 9.4, it's one conversation. You open…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow

1

2

CI/CD pipeline abuse: the problem no one is watching

Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…

GitHub GitLab Microsoft US

tg: rozbor tg: novinka v produktu tp: dodavatelský řetězec tp: AI tp: identita

· Elastic Security · CI/CD pipeline abuse: the problem no one is watching

1

1

1

1

1

Elastic Security Integrations Roundup: Q1 2026

A quarterly look at Elastic’s security integrations ecosystem Security teams can only protect what they can see. Gaps in coverage, like a macOS fleet generating logs that never reach your SIEM, an email gateway running in isolation, or a cloud environment producing findings that stay siloed in the vendor console, are easily exploited by attackers. Elastic’s answer to this is continuous and open investment in third-party integrations, built on the belief that a strong security ecosystem requires…

Elastic IBM Proofpoint US

tg: novinka v produktu tg: propagace

· Elastic Security · Elastic Security Integrations Roundup: Q1 2026

1

1

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

Introduction Linux systems remain a critical foundation for modern infrastructure, particularly in cloud-native environments where containers and orchestration platforms are the norm. As workloads move from long-lived hosts to ephemeral containers, attacker tradecraft shifts as well. Activity that once left persistent artifacts on disk is increasingly confined to short-lived, runtime behavior that can be difficult to capture using traditional log sources. Detection engineering in these…

Elastic US

tg: novinka v produktu tg: návod tg: propagace

· Elastic Security · Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

2

Get started with Elastic Security from your AI agent

Get started with Elastic Security from your AI agent Elastic Agent Skills are open source packages that give your AI coding agent native Elastic expertise. If you're already using Elastic Agent Builder, you get AI agents that work natively with your security data. Agent Skills are for the other side: bringing that same Elastic Security knowledge to the external AI tools your team already uses, like Cursor, Claude Code, or GitHub Copilot. If you use an AI coding agent and want to evaluate…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Get started with Elastic Security from your AI agent

1

Managing Elastic Security Detection Rules with Terraform

At the core of Elastic Security lie outstanding detection capabilities, allowing users to create, test, tune, manage, deploy detection rules, as code, in their environments. The ability to create robust detections is critical for Security Operations as detection logic elevates threat signal from the telemetry noise. This article highlights how Elastic's new Terraform resources for security detection rules and exceptions expand practitioners' capabilities for detection-as-code deployment. Below…

Elastic US

tg: novinka v produktu tg: návod tg: propagace tp: AI

· Elastic Security · Managing Elastic Security Detection Rules with Terraform

1

GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities

GreyNoise's integration with Google Security Operations delivers standardized indicator ingestion, pre-built dashboards, YARA-L detection rules, saved searches, response actions, webhook support, and ready-to-deploy playbooks.‍

Google US

tg: novinka v produktu tg: propagace

· GreyNoise Labs · GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities

1