NG Solution Team
Cybersecurity

AlertZero: Elastic launches AI agents for security triage

Elastic on Oct. 8 launched AlertZero, an agentic layer for Elastic Security that assigns alert triage, threat hunting, detection engineering and endpoint forensics to four specialized AI agents.

The system organizes work into four AI groups called Watches — Triage, Hunt, Detection and Forensics — which can run from triggers or schedules and record their findings in a shared investigation record.

Triage evaluates alerts and links related activity. Hunt searches security telemetry using threat research. Detection reviews noisy rules and coverage gaps before preparing proposed changes. Forensics examines endpoint activity and identifies supported response actions.

AlertZero Watches and operating modes

AlertZero is entering technical preview across Elastic Cloud, self-managed environments and fully air-gapped deployments. Customers can use proprietary or open-source models and may switch models during an investigation.

Autonomy can be configured per task through three operating modes: manual, assisted and supervised. Detection-rule changes still require approval. In supervised endpoint operations, host isolation, process termination and process suspension may proceed without separate approval for every action. An inconclusive Attack Discovery assessment still requires a person’s decision, including when the system is operating in supervised mode.

The preview builds on Attack Discovery, Elastic Agent Builder, Elastic Workflows and Elasticsearch Query Language (ES|QL). Attack Discovery connects related alerts into attack narratives and can investigate activity that existing detections may have missed.

Elastic said an autonomous AI agent generated more than 17,000 events across a production environment during four days of a recent attack involving a dataset-pipeline exploit, credential theft and lateral movement.

“What makes AlertZero different is that our team who built it have sat in the SOC analyst’s seat,” said Mike Nichols, general manager, Security, Elastic.

Related posts

Manchester Airports Group cybersecurity breach hits almost 9 million

Jessica Williams

Are Fortinet VPN credentials at risk due to FortiBleed exposure?

James Smith

Is Taiko’s Bridge Infrastructure Compromised?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy