Elastic Advances the Agentic SOC, Bringing Security Teams Closer to Alert Zero
Elastic Advances the Agentic SOC, Bringing Security Teams Closer to Alert Zero
Attack Discovery now investigates and validates threats, turning a wall of raw alerts into a short list of real attacks and moving teams closer to Alert Zero, a state where the queue is worked down to the attacks that really matter.
SAN FRANCISCO--(BUSINESS WIRE)--Elastic (NYSE: ESTC), the Search AI Company, today announced major advances to its agentic security operations platform ahead of Black Hat USA 2026, led by a significantly expanded Attack Discovery, broader endpoint protection, and enhanced native workflow automation.
AI-driven attacks are making an already persistent SOC challenge even more urgent. Even well-equipped teams spend their shifts working through a queue of alerts that grows faster than they can clear it. Elastic's latest updates help organizations move toward Alert Zero, a state where agents and analysts work together to reduce the queue to only the attacks that actually matter, so analysts spend their time on the threats that deserve their judgment.
At the center of this announcement is a major advancement of Attack Discovery. Previously, it correlated alerts into a consolidated view of an attack. Now it goes further and acts as an autonomous triage agent, conducting its own investigation before flagging anything as an attack. It hunts raw events, checks entity risk scores, and corroborates evidence beyond the initial alerts. Analysts open a short list of validated threats instead of a wall of raw alerts. When Attack Discovery finds a gap in detection coverage, it drafts a new rule to close the gap and routes it to an analyst for approval. Alongside Attack Discovery, a companion alert analysis workflow runs in parallel, filtering likely false positives before they reach the investigation stage, with rationale analysts can review and tune.
"Security teams are not losing because they lack tools; they're losing because the tools generate more work than the team can absorb," said Mike Nichols, general manager, Security, Elastic. "Elastic Security is built by people who've sat in the SOC and worked the queue. These updates go after one of the biggest sources of analyst burnout, which are alerts that shouldn't be alerts in the first place. Removing this overwhelming data barrier means teams can focus their attention where it’s needed most – real threats."
To enhance endpoint defenses, Elastic now automatically generates and instantly deploys YARA rules to protect against vulnerable driver exploits, a technique attackers use to reach the kernel via signed, trusted drivers with known flaws. This real-time functionality is critical, as AI-driven attacks can propagate across a network in under a minute. Windows on ARM devices, including Surface laptops, are now fully supported by Elastic Defend, bringing ARM-based endpoints into the same protection as the rest of a fleet at no per-device cost.
Elastic Workflows, the platform's native automation layer, also gains significant updates, including plain-language workflow generation, full version history with one-click rollback, a visual graph view, and human-in-the-loop approval routing to tools like Slack. Workflows runs natively within the Elasticsearch platform, extending across search, observability, and security. Automation runs where your security data already lives, rather than as a bolt-on integration.
The updates reinforce each other. Stronger prevention at the endpoint keeps alerts from being raised in the first place. The ones that remain arrive validated instead of raw. Automation keeps prevention and investigation moving at machine speed, while analysts stay on the decisions that need a human. The result is a SOC moving steadily closer to Alert Zero. That is what an agentic SOC looks like when it is built to help the people in it, rather than replace them.
Availability
Attack Discovery updates, alert analysis workflow enhancements, Elastic Defend vulnerable driver coverage, Windows on ARM support, and Elastic Workflows updates are available to Elastic Security customers. Elastic will be demonstrating all capabilities live at Black Hat USA 2026, booth # 3444, August 3-6, 2026, at the Mandalay Bay Convention Center, Las Vegas. Elastic is also a Blue Tier sponsor of Blue Team Village at DEFCON 33. For more information, visit elastic.co/security.
Where to find Elastic at Black Hat and DEF CON:
- Elastic will be at Black Hat USA 2026, booth # 3444, August 3-6, 2026 at the Mandalay Bay Convention Center, Las Vegas.
-
Sober Speakeasy with Sober in Cyber
Tuesday, August 4 | 7:00–9:30 PM PT | The Mob Museum Underground Speakeasy
An alcohol-free networking evening for infosec professionals, sober or sober-curious. Open to all Black Hat attendees. -
Blitz & Defend: An Executive Evening with Elastic and AWS
Wednesday, August 5 | 6:30–8:30 PM PT | Allegiant Stadium
A behind-the-scenes reception and tour of the Raiders locker room, hosted by Elastic and AWS for security and technology executives. -
GDIT Sip & Cipher
Wednesday, August 5 | 6:00–9:00 PM PT | Toca Madera
A cybersecurity networking reception with Elastic among the sponsors. -
InnovatHERs: Women Shaping Tomorrow
Thursday, August 6 | 7:00–9:00 AM PT | Hosted with WiCyS
A breakfast to celebrate and connect women in cybersecurity, in partnership with Women in CyberSecurity. -
DEFCON: Blue Team Village
Thursday–Sunday, August 6–9
Security people go to Black Hat because they have to. They go to DEF CON because they want to. That's why Elastic is proud to be a Blue Tier sponsor of Blue Team Village and home to the SOC, DFIR, and incident response communities.
Additional Materials
-
Learn more in the blogs:
- Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas
- Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC
- What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support
- One prompt, a complete workflow: Elastic's AI agent writes your automation for you
About Elastic
Elastic (NYSE: ESTC), the Search AI Company, integrates its deep expertise in search technology with artificial intelligence to help everyone transform all of their data into answers, actions, and outcomes. The Elasticsearch Platform — the foundation for its search, observability, and security solutions — is used by thousands of companies, including more than 50% of the Fortune 500. Learn more at elastic.co.
Elastic and associated marks are trademarks or registered trademarks of elasticsearch B.V. and its subsidiaries. All other company and product names may be trademarks of their respective owners.
Contacts
Media Contact
Elastic PR
PR-team@elastic.co
