Výsledky hledání

typ: propagace× v celém archivu zrušit filtry

282 karet z 283 položek · strana 4 z 5 CZ · EN/orig

1

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a modern SIEM, available now in Tech Preview in 9.5, and it works across multiple cloud providers and regions so you can deploy closer…

Elastic Microsoft US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

6

Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambda

Key Takeaways Qualys now delivers automated AWS Lambda vulnerability scanning, extending serverless security beyond posture checks (CSPM) into workload-level risk visibility. CSPM alone only catches misconfigurations (excessive permissions, exposure, logging, encryption) — it can’t detect vulnerable open-source packages or outdated libraries inside function code. Lambda’s granular permissions model, dynamic execution environments, and lack of persistent infrastructure make traditional security…

AWS US

tg: novinka v produktu tg: propagace tp: AI

· Qualys · Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambda

The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is compressing the gap between discovery, decision-making, and execution for cloud attackers. The interval…

Amazon Web Services US

tg: incident tg: rozbor tg: propagace tp: podvod tp: AI tp: identita

· Qualys · The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%

This is Part 3 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it · Part 2: Choosing the right agent architecture for a 5× cost reduction We run 14 AI agents in the Elastic InfoSec security operations pipeline. They were producing correct verdicts and taking up to 19 large language model (LLM) calls to do work that needed 8, at thousands of input tokens per call. At hundreds of runs per day, that compounds fast. We built a five-step…

Elastic US

tg: rozbor tg: návod tg: propagace tp: AI

· Elastic Security · Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%

Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%

This is Part 3 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it · Part 2: Choosing the right agent architecture for a 5× cost reduction We run 14 AI agents in the Elastic InfoSec security operations pipeline. They were producing correct verdicts and taking up to 19 large language model (LLM) calls to do work that needed 8, at thousands of input tokens per call. At hundreds of runs per day, that compounds fast. We built a five-step…

Elastic US

tg: rozbor tg: návod tg: propagace tp: AI

· Elastic Security · Inside Elastic InfoSec's agentic SOC: How we cut AI agent LLM calls by 60%

4

Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

This is Part 2 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it. Part 3: how we cut AI agent LLM calls by 60%. Investigating a Windows endpoint alert in Elastic InfoSec's production agentic security operations center (SOC) costs $0.69. That's what we pay running an orchestration workflow of specialized Elastic AI agents on the Elastic Inference Service (EIS). Route the same alert to a single agent working through 14 skills, and the…

Elastic US

tg: rozbor tg: návod tg: propagace tp: AI

· Elastic Security · Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

This is Part 2 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it. Part 3: how we cut AI agent LLM calls by 60%. Investigating a Windows endpoint alert in Elastic InfoSec's production agentic security operations center (SOC) costs $0.69. That's what we pay running an orchestration workflow of specialized Elastic AI agents on the Elastic Inference Service (EIS). Route the same alert to a single agent working through 14 skills, and the…

Elastic US

tg: rozbor tg: návod tg: propagace tp: AI

· Elastic Security · Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction

3

Preview: Cisco Talos at Black Hat USA 2026

We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence.Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too.Here’s some of the ways we’ll…

US

tg: propagace tp: AI

· Cisco Talos · Preview: Cisco Talos at Black Hat USA 2026

How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

We ran a noisy wget detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) COMPLETION triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from curl and wget executions, filters known-good hosts, redacts secrets, and then hands whatever’s left to a large language model (LLM) for a triage verdict. File transfer detections stay on in cloud…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

We ran a noisy wget detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) COMPLETION triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from curl and wget executions, filters known-good hosts, redacts secrets, and then hands whatever’s left to a large language model (LLM) for a triage verdict. File transfer detections stay on in cloud…

Elastic US

tg: rozbor tg: návod tg: propagace tp: AI

· Elastic Security · How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

1

1

1

1

1

1

2

2

2

1

3

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

This is Part 1 of the Inside Elastic InfoSec's Agentic SOC series. Part 2: choosing the right agent architecture for a 5× cost reduction. Part 3: how we cut AI agent LLM calls by 60% Elastic's InfoSec team built an agentic SOC that triages every alert before an analyst opens it. A 30-minute manual investigation now finishes in under 3 minutes: deterministic ES|QL queries close obvious false positives at zero token cost, specialized AI agents investigate the rest across endpoint, cloud, and SaaS…

Elastic US

tg: rozbor tg: propagace tp: AI

· Elastic Security · Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

This is Part 1 of the Inside Elastic InfoSec's Agentic SOC series. Part 2: choosing the right agent architecture for a 5× cost reduction. Part 3: how we cut AI agent LLM calls by 60% Elastic's InfoSec team built an agentic SOC that triages every alert before an analyst opens it. A 30-minute manual investigation now finishes in under 3 minutes: deterministic ES|QL queries close obvious false positives at zero token cost, specialized AI agents investigate the rest across endpoint, cloud, and SaaS…

Elastic US

tg: rozbor tg: propagace tp: AI

· Elastic Security · Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

1

1

2

3

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

Elastic's InfoSec Product Security Team built a generative AI agent using Elastic Agent Builder that drafts complete CVE security advisories (CWE classification, CAPEC methodology, CVSS scoring, and mitigation guidance) directly from raw vulnerability reports. The agent uses RAG against the MITRE CWE and CAPEC catalogues indexed in Elasticsearch, which grounds its output in authoritative data and prevents hallucinated classification IDs. ESA-2026-01 is already in production as an example of…

Elastic US

tg: rozbor tg: propagace tp: AI

· Elastic Security · From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

1

1

2

2

Governing Claude Enterprise in Environments Where Inline Controls Can't Go

TrendAI™ integrates the Claude Compliance API into TrendAI Vision One™ through two collectors that bring AI-aware visibility and detection to Claude Enterprise usage: one keeps all data inside the environment, while the other feeds TrendAI Vision One™ for deeper correlation and compliance.

Trend Micro JP

tg: novinka v produktu tg: propagace tp: AI

· Trend Micro · Governing Claude Enterprise in Environments Where Inline Controls Can't Go

1

1

1

1

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Elastic Security natively ingests Google Threat Intelligence: known-malicious IPs, domains, URLs, and file hashes matched against your telemetry the moment they appear, each carrying a verdict and a 0–100 threat score. The setup consists of an API key and two data streams, with no extra infrastructure. When an indicator is ambiguous, workflows built on Agent Builder query VirusTotal in real time, enrich the alert, correlate with your telemetry, and summarize findings in real time. How threat…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

1

2

1

2

1

1

2

Elastic Security MCP App: Interactive security operations inside your AI Tools

Every SOC analyst knows the drill: an alert fires, and the next ten minutes are spent switching between a triage dashboard, a threat hunt, a case file, and the AI tool that told you to look in the first place. Recently, we introduced MCP Apps for Elastic, built on the open MCP Apps extension to the Model Context Protocol, that lets an MCP tool return an interactive UI alongside its text response, rendered inline in Claude Desktop, Claude.ai, VS Code Copilot, Cursor, or any compatible host. This…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Elastic Security MCP App: Interactive security operations inside your AI Tools

2

Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

Introduction Self-hosted services exposed through a reverse proxy inevitably attract automated scanners probing for misconfigurations, admin panels, and vulnerable endpoints. In this article, I show how to turn routine Traefik access logs into an active defensive control using Elastic Security and Cloudflare. I use an out-of-the-box ES|QL detection rule to identify web server discovery and fuzzing behavior. When suspicious probing patterns are detected, an automated workflow immediately blocks…

Elastic Cloudflare Traefik Labs US

tg: návod tg: propagace

· Elastic Security · Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

1