Elastic has announced major advances to its agentic security operations platform ahead of Black Hat USA 2026, led by a significantly expanded Attack Discovery, broader endpoint protection, and enhanced native workflow automation . These updates help security teams move toward Alert Zero—a state where agents and analysts work together to reduce the queue to only the attacks that actually matter .
Attack Discovery now acts as an autonomous triage agent, investigating and validating threats before flagging them, turning raw alerts into a short list of real attacks .
When Attack Discovery finds a detection gap, it drafts a new rule and routes it to an analyst for approval .
A companion alert analysis workflow filters likely false positives before they reach the investigation stage .
Elastic Defend now automatically generates and deploys YARA rules to protect against vulnerable driver exploits as they are disclosed .
Windows on ARM devices are now fully supported at no per-device cost .
Elastic Workflows adds plain-language workflow generation, version history with one-click rollback, and human-in-the-loop approval routing to tools like Slack .
Elastic, the Search AI Company, today announced major advances to its agentic security operations platform ahead of Black Hat USA 2026, led by a significantly expanded Attack Discovery, broader endpoint protection, and enhanced native workflow automation .
AI-driven attacks are making an already persistent SOC challenge even more urgent. Even well-equipped teams spend their shifts working through a queue of alerts that grows faster than they can clear it. Elastic's latest updates help organizations move toward Alert Zero, a state where agents and analysts work together to reduce the queue to only the attacks that actually matter, so analysts spend their time on the threats that deserve their judgment .
At the center of this announcement is a major advancement of Attack Discovery. Previously, it correlated alerts into a consolidated view of an attack. Now it goes further and acts as an autonomous triage agent, conducting its own investigation before flagging anything as an attack. It hunts raw events, checks entity risk scores, and corroborates evidence beyond the initial alerts . Analysts open a short list of validated threats instead of a wall of raw alerts .
When Attack Discovery finds a gap in detection coverage, it drafts a new rule to close the gap and routes it to an analyst for approval. Alongside Attack Discovery, a companion alert analysis workflow runs in parallel, filtering likely false positives before they reach the investigation stage, with rationale analysts can review and tune .
"Security teams are not losing because they lack tools; they're losing because the tools generate more work than the team can absorb," said Mike Nichols, general manager, Security, Elastic. "Elastic Security is built by people who've sat in the SOC and worked the queue. These updates go after one of the biggest sources of analyst burnout, which are alerts that shouldn't be alerts in the first place. Removing this overwhelming data barrier means teams can focus their attention where it's needed most – real threats" .
To enhance endpoint defenses, Elastic now automatically generates and instantly deploys YARA rules to protect against vulnerable driver exploits, a technique attackers use to reach the kernel via signed, trusted drivers with known flaws . This real-time functionality is critical, as AI-driven attacks can propagate across a network in under a minute . Windows on ARM devices, including Surface laptops, are now fully supported by Elastic Defend, bringing ARM-based endpoints into the same protection as the rest of a fleet at no per-device cost .
Elastic Workflows, the platform's native automation layer, also gains significant updates, including plain-language workflow generation, full version history with one-click rollback, a visual graph view, and human-in-the-loop approval routing to tools like Slack . Workflows runs natively within the Elasticsearch platform, extending across search, observability, and security. Automation runs where your security data already lives, rather than as a bolt-on integration .
The updates reinforce each other. Stronger prevention at the endpoint keeps alerts from being raised in the first place. The ones that remain arrive validated instead of raw. Automation keeps prevention and investigation moving at machine speed, while analysts stay on the decisions that need a human. The result is a SOC moving steadily closer to Alert Zero. That is what an agentic SOC looks like when it is built to help the people in it, rather than replace them .
About Elastic
Elastic, the Search AI Company, integrates its deep expertise in search technology with artificial intelligence to help everyone transform all of their data into answers, actions, and outcomes. The Elasticsearch Platform — the foundation for its search, observability, and security solutions — is used by thousands of companies, including more than 50% of the Fortune 500.