Elastic has announced significant updates to its security offerings, focusing on reducing analyst workload and improving detection and prevention capabilities. These enhancements, which include advancements to Attack Discovery, Elastic Defend, and Elastic Workflows, aim to streamline security operations and move towards what the company calls "Alert Zero."
The Alert Zero initiative is designed to minimize the volume of raw alerts security teams face, allowing them to concentrate on validated threats. Attack Discovery, a key component of this strategy, now functions more like a human analyst. It aggregates related alerts, threat-hunts for raw events beyond initial triggers, evaluates entity risk for involved users and hosts, corroborates findings across various data sources, and ultimately classifies an event as a validated attack. This process provides security teams with a concise list of confirmed threats rather than an overwhelming stream of raw data.
A new feature within Attack Discovery automatically drafts detection rules when it identifies something missed by existing rules. These proposed rules are then presented to an analyst for approval, aiming to close detection gaps and reduce false positives. The system also offers full visibility into its reasoning, detailing how an alert was escalated to an attack. Additionally, an alert analysis workflow helps differentiate between likely false and true positives, further refining the input for Attack Discovery.
Elastic Defend, the endpoint protection solution, has been enhanced to address vulnerable drivers more proactively. Attackers often exploit known flaws in signed, trusted drivers to gain kernel access. Elastic's threat research team now continuously monitors public disclosure sources like VirusTotal, loldrivers.io, and Microsoft's blocklist. Through an automated process, the system instantly generates and deploys YARA rules as new vulnerable drivers are disclosed, ensuring protection keeps pace with new threats rather than waiting for scheduled releases. Elastic Defend also now provides full endpoint protection for Windows on ARM devices, including Surface and other ARM-based laptops, integrating them into existing security fleets without additional per-device costs. A new troubleshooting feature automatically flags policy and performance issues on endpoints.
Elastic Workflows introduces plain-language authoring for automation, allowing users to describe desired automations for the system to generate. It also includes version control, enabling users to track changes, compare versions, and roll back to previous configurations. A visual mode displays workflows as graphs, showing triggers, steps, branches, and logic alongside the YAML code. Future updates will include drag-and-drop editing.
For decisions requiring human input, Workflows can pause and route requests for approval or other actions to tools like Slack. This "human-in-the-loop" approach ensures that automation handles routine tasks while analysts focus on critical judgments. Workflows operates natively within the Elasticsearch platform, integrating across search, observability, and security data.
Elastic indicates that these updates are designed to combat analyst burnout, a significant challenge in security operations, by reducing the number of non-actionable alerts. The company emphasizes its commitment to building an open and transparent platform that empowers security teams to customize and manage their security stacks effectively. The new capabilities will be showcased at upcoming industry events, demonstrating agents that reduce false positives, SIEM built for an "agentic SOC," XDR across cloud, Kubernetes, and endpoint environments, and native automation with Elastic Workflows.






