Elastic Advances the Agentic SOC, Bringing Security Teams Closer to Alert Zero
Attack Discovery now investigates and validates threats, turning a wall of raw alerts into a short list of real attacks and moving teams closer to Alert Zero, a state where the queue is worked down to the attacks that really matter.
Elastic (NYSE: ESTC), the Search AI Company, today announced major advances to its agentic security operations platform ahead of Black Hat USA 2026, led by a significantly expanded Attack Discovery, broader endpoint protection, and enhanced native workflow automation.
AI-driven attacks are making an already persistent SOC challenge even more urgent. Even well-equipped teams spend their shifts working through a queue of alerts that grows faster than they can clear it. Elastic's latest updates help organizations move toward Alert Zero, a state where agents and analysts work together to reduce the queue to only the attacks that actually matter, so analysts spend their time on the threats that deserve their judgment.
At the center of this announcement is a major advancement of Attack Discovery. Previously, it correlated alerts into a consolidated view of an attack. Now it goes further and acts as an autonomous triage agent, conducting its own investigation before flagging anything as an attack. It hunts raw events, checks entity risk scores, and corroborates evidence beyond the initial alerts. Analysts open a short list of validated threats instead of a wall of raw alerts. When Attack Discovery finds a gap in detection coverage, it drafts a new rule to close the gap and routes it to an analyst for approval. Alongside Attack Discovery, a companion alert analysis workflow runs in parallel, filtering likely false positives before they reach the investigation stage, with rationale analysts can review and tune.









