Výsledky hledání

typ: propagace× v celém archivu zrušit filtry

282 karet z 283 položek · strana 5 z 5 CZ · EN/orig

1

4

Elastic Workflows GA: automation where your security data already lives

Elastic Workflows is generally available in 9.4. It is the automation layer built directly into Elastic, running where your data lives across Security, Observability, and Search. While this post focuses on a security deep dive, the same workflow capabilities apply across solutions, with no separate platform to deploy and no data to move. When an alert fires or a schedule triggers, a Workflow executes: querying Elasticsearch, enriching with threat intel, creating cases, calling external APIs,…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Elastic Workflows GA: automation where your security data already lives

Know who to watch before the incident finds you

Elastic Security v9.4 introduces Entity Analytics Watchlists, a new capability in the Entity Analytics suite that lets security teams create named, weighted lists of users, hosts, and services and feed that context directly into the platform's risk scoring pipeline. The gap this closes isn't awareness, as most security teams already know which entities deserve elevated scrutiny. The gap is that SIEMs have had no way to express that organizational knowledge as a risk signal. Watchlists do that…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · Know who to watch before the incident finds you

AI-generated hunting leads: The hunt starts before you ask the question

Threat hunting has always been a human art; a practitioner staring at logs, forming a hypothesis, and patiently chasing it down. What if the hardest part of the hunt (knowing where to look) could be done for you, automatically, in milliseconds, and tuned specifically to your environment? This is where AI-generated hunting leads come in, allowing you to shift from reactive alerting to proactive defense with entity-centric, risk-based threat hunting tailored specifically to your environment's…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · AI-generated hunting leads: The hunt starts before you ask the question

Your UEBA is lying to you: Why entity record quality decides everything

There's an uncomfortable truth in security analytics that nobody talks about at conferences: The quality of your detections, alerts, and investigations is only as good as the entity records that represent the users, hosts, and services in your environment. Not the machine learning models. Not the anomaly detection algorithms. Not the risk scoring engine. The entities: the foundations to teach your system about the data and protect it. Get the entities wrong, and everything downstream is…

Elastic US

tg: názor tg: propagace tp: identita

· Elastic Security · Your UEBA is lying to you: Why entity record quality decides everything

3

From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

Elastic Security now includes AI-powered detection rule creation, built into the rule creation workflow. Analysts describe a threat behavior in plain English and receive a complete, validated Elasticsearch Query Language (ES|QL) rule in return, with MITRE ATT\&CK mappings, severity recommendations, and a preview against live data, all without leaving the platform or writing a single line of query syntax. This post walks through exactly how that works using an Okta credential stuffing and…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security

Elastic Conversational Entity Analytics: threat hunting in a single conversation

Entity Analytics is a core security analytics capability that extends Elastic Security from event-centric to entity-centric investigation. By focusing on critical entities, such as users, hosts, and services, it builds a complete profile of each entity’s attributes, lifecycle, behaviors, relationships, and risk score over time. This security context equips threat hunters to stop chasing isolated alerts and instead uncover the full narrative of a potential compromise. In this blog, we walk…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Elastic Conversational Entity Analytics: threat hunting in a single conversation

One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow

Three things land on you at once: Attack Discovery correlated 12 alerts into a credential-harvesting campaign overnight, your team just onboarded a new fleet of macOS endpoints and needs detection rules for LOLBin abuse, and a risk score spike on a service account just crossed the critical threshold. In most security operations centers (SOCs), that's three different people, three different workflows, and a morning spent context-switching. In Elastic Security 9.4, it's one conversation. You open…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow

1

DFIR: From alert to root cause using Osquery without leaving Elastic Security

Modern DFIR doesn't start with a disk image. That model worked when environments were smaller, endpoints were static, and time wasn't the primary constraint. Endpoints are now ephemeral, fleets scale to thousands of hosts, and attackers operate on timelines measured in minutes. By the time a full forensic image is collected, the system may no longer exist. Forensics today is no longer about collecting everything. It's about asking the right questions, in real time, across your entire…

Elastic US

tg: návod tg: propagace

· Elastic Security · DFIR: From alert to root cause using Osquery without leaving Elastic Security

1

1

1

1

Monitoring Claude Code/Cowork at scale with OTel in Elastic

As AI coding assistants become standard tools in engineering workflows, security teams face a new challenge: how do you maintain visibility into what an AI agent is doing (and why) across your organization? When those agents can execute shell commands, read files, call APIs, and interact with internal systems via MCP connectors, you need real-time observability to support threat detection, incident response, and compliance. This post walks through how Elastic's InfoSec team built a monitoring…

Anthropic Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Monitoring Claude Code/Cowork at scale with OTel in Elastic

1

1

2

1

1

Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floor

Where to begin. For the fourth consecutive year, Elastic has had the privilege of serving as a trusted industry partner on Exercise Defence Cyber Marvel - the UK Ministry of Defence's flagship cyber exercise series. DCM26 was, without question, the most ambitious iteration yet, and we're chuffed to bits to finally be able to talk about what we built, how we built it, and what we learnt along the way. What is Defence Cyber Marvel? For those unfamiliar, Defence Cyber Marvel (DCM) is the largest…

obrana US

tg: rozbor tg: propagace

· Elastic Security · Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floor

1

1

Elastic Security Integrations Roundup: Q1 2026

A quarterly look at Elastic’s security integrations ecosystem Security teams can only protect what they can see. Gaps in coverage, like a macOS fleet generating logs that never reach your SIEM, an email gateway running in isolation, or a cloud environment producing findings that stay siloed in the vendor console, are easily exploited by attackers. Elastic’s answer to this is continuous and open investment in third-party integrations, built on the belief that a strong security ecosystem requires…

Elastic IBM Proofpoint US

tg: novinka v produktu tg: propagace

· Elastic Security · Elastic Security Integrations Roundup: Q1 2026

1

Prioritizing Alerts Triage with Higher-Order Detection Rules

At Elastic, we operate a large and diverse set of behavior detection rules across multiple datasets, environments, and severity levels. Most of these rules are atomic, each designed to detect a specific behavior, signal, or attack pattern. In addition, we ingest and promote external alerts from security integrations such as firewalls, EDR, WAF, and other security controls. The result is powerful visibility but also significant alert volume. From our telemetry, even when considering only non…

Elastic US

tg: návod tg: propagace

· Elastic Security · Prioritizing Alerts Triage with Higher-Order Detection Rules

2

5

Investigating from the Endpoint Across Your Environment with Elastic Security XDR

Preamble Security investigations rarely stay confined to a single host. Today’s attackers increasingly use automation and AI to compress multi-stage attacks into minutes, turning what once unfolded over days into coordinated activity across endpoints, identities, workloads, and cloud services within minutes. While many attacks begin on an endpoint, investigators must quickly determine how that activity spreads across the environment. In many environments, per-endpoint licensing limits how…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Investigating from the Endpoint Across Your Environment with Elastic Security XDR

Security Automation with Elastic Workflows: From Alert to Response

The daily loop An alert fires. You open it. You read through the details. You gather context from the surrounding activity. You check for related signals across your environment. You decide what it means and what to do next. Sometimes you escalate. Sometimes you close it and move on. You do this dozens of times a day. The steps are almost always the same. The data you need is already in your SIEM. The actions you take are predictable. But the work is still manual. This is the kind of work that…

Elastic US

tg: návod tg: propagace

· Elastic Security · Security Automation with Elastic Workflows: From Alert to Response

Streamlining the Security Analyst Experience

The term Agentic SOC (Security Operations Center) is one of the most popular concepts in security today. But what does it truly mean in practice, and how does Elastic Security approach this next evolution of security operations? In simple terms, an Agentic SOC is a security operations center that has deployed AI Agents and corresponding AI Agent Skills to perform SOC-related workflows such as detection engineering, alert triage, incident investigation, escalation, response, and threat hunting.…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Streamlining the Security Analyst Experience

Supercharge Your SOC

Preamble The landscape of cybersecurity is evolving, and the role of the Detection Engineer (DE) is more critical and demanding than ever. Traditionally, this role involves a comprehensive, end-to-end workflow: from threat modeling and telemetry tuning to writing, testing, and maintaining performance-optimized detection rules to flag malicious behavior. Elastic Security is purpose-built to streamline this entire workflow, empowering DEs - and anyone involved in security operations - to build,…

Elastic US

tg: návod tg: propagace tp: AI

· Elastic Security · Supercharge Your SOC

2

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

Introduction Linux systems remain a critical foundation for modern infrastructure, particularly in cloud-native environments where containers and orchestration platforms are the norm. As workloads move from long-lived hosts to ephemeral containers, attacker tradecraft shifts as well. Activity that once left persistent artifacts on disk is increasingly confined to short-lived, runtime behavior that can be difficult to capture using traditional log sources. Detection engineering in these…

Elastic US

tg: novinka v produktu tg: návod tg: propagace

· Elastic Security · Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

1

2

Get started with Elastic Security from your AI agent

Get started with Elastic Security from your AI agent Elastic Agent Skills are open source packages that give your AI coding agent native Elastic expertise. If you're already using Elastic Agent Builder, you get AI agents that work natively with your security data. Agent Skills are for the other side: bringing that same Elastic Security knowledge to the external AI tools your team already uses, like Cursor, Claude Code, or GitHub Copilot. If you use an AI coding agent and want to evaluate…

Elastic US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Get started with Elastic Security from your AI agent

2

3

Managing Elastic Security Detection Rules with Terraform

At the core of Elastic Security lie outstanding detection capabilities, allowing users to create, test, tune, manage, deploy detection rules, as code, in their environments. The ability to create robust detections is critical for Security Operations as detection logic elevates threat signal from the telemetry noise. This article highlights how Elastic's new Terraform resources for security detection rules and exceptions expand practitioners' capabilities for detection-as-code deployment. Below…

Elastic US

tg: novinka v produktu tg: návod tg: propagace tp: AI

· Elastic Security · Managing Elastic Security Detection Rules with Terraform

1

GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities

GreyNoise's integration with Google Security Operations delivers standardized indicator ingestion, pre-built dashboards, YARA-L detection rules, saved searches, response actions, webhook support, and ready-to-deploy playbooks.‍

Google US

tg: novinka v produktu tg: propagace

· GreyNoise Labs · GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities

1

1