Elastic: Prevention at machine speed: hunting beyond known detections

 PT
Online

Adversaries now move at machine speed, executing actions before an analyst can open the first alert. Manual detection and response isn't enough; it’s time to stop chasing alerts and start closing gaps.

Elastic Security's James Spiteri and Paul Ewing show a two-pronged approach to using AI within security detection and response.

  • At the endpoint: behavioral protections and containment denies malicious behavior before it can execute, across Windows, macOS, and Linux, whether on-premises, in the cloud, or air-gapped.
  • Beyond your detections: an AI system reads unstructured threat research, extracts the tradecraft, writes and runs the queries, and proposes new detection rules for analyst review, with a human on the loop at every step.

You'll walk away with:

  • A prevention-first architecture: How to stop machine-speed attacks at the endpoint before they become incidents
  • Agentic hunting in practice: How an AI system reasons across unstructured threat research to surface tradecraft your rules don't cover
  • A sharper detection pipeline: How to turn external threat intelligence into reviewed, deployable detection rules without manual overhead