Elastic: Prevention at machine speed: hunting beyond known detections
Adversaries now move at machine speed, executing actions before an analyst can open the first alert. Manual detection and response isn't enough; it’s time to stop chasing alerts and start closing gaps.
Elastic Security's James Spiteri and Paul Ewing show a two-pronged approach to using AI within security detection and response.
- At the endpoint: behavioral protections and containment denies malicious behavior before it can execute, across Windows, macOS, and Linux, whether on-premises, in the cloud, or air-gapped.
- Beyond your detections: an AI system reads unstructured threat research, extracts the tradecraft, writes and runs the queries, and proposes new detection rules for analyst review, with a human on the loop at every step.
You'll walk away with:
- A prevention-first architecture: How to stop machine-speed attacks at the endpoint before they become incidents
- Agentic hunting in practice: How an AI system reasons across unstructured threat research to surface tradecraft your rules don't cover
- A sharper detection pipeline: How to turn external threat intelligence into reviewed, deployable detection rules without manual overhead