Elastic has unveiled AlertZero, an AI agent team built into Elastic Security to reduce security operations center (SOC) alert overload. The offering is designed to support alert triage, threat hunting and forensic analysis.
Customers can directly adjust AlertZero’s automation scope down to the task level. Even at the highest autonomy setting, human approval is required when decisions are unclear. Customers also choose the model to use, and analysts can switch models if evidence changes during an investigation.
AlertZero’s four agent groups
Triage Watch enriches incoming alerts to determine whether they are real threats and closes alerts judged to be noise after recording the reason. Hunt Watch continuously tracks threats based on threat research. Detection Watch learns from the results of the other watches and suggests adjusting noisy detection rules or adding new rules to fill gaps; rules are not changed without approval. Forensic Watch is responsible for malware analysis and tracing exploit paths.
Mike Nichols, head of Elastic Security, said, “The people who built AlertZero are those who have sat in the SOC analyst seat.” He said, “The goal is to have teams accept only as much automation as they can oversee.”
AlertZero is offered as a technical preview in Elastic Cloud, self-managed and air-gapped environments.

