Elastic Security 9.5: AI Agent Proactively Investigates and Auto-Closes Security Alerts
shashib · x · 2026-08-04
Elastic has upgraded its Attack Discovery feature in Security 9.5, transitioning it from a passive alert aggregator into a proactive AI agent.
- Proactive Investigation: Instead of waiting for an analyst, it now hunts through raw events, checks entity risk scores, and pulls evidence from various data sources before flagging a validated attack.
- Automated Closure: For the first time, an agent can make the decision to close an alert. It can also draft new detection rules in Elasticsearch Query Language when it identifies coverage gaps.
- Access Control: High-risk actions like auto-closing and rule creation are gated by SOC manager settings, not left to the model's discretion.
More from coding & agent
- FP8 nearly triples Llama 3 70B throughput on two H100s, guide says — AccBalanced · 2026-08-04
- DeepSeek built a browser FM synth in one session for $1.10 and 742 tool calls — keunwoochoi · 2026-08-04
- Vercel open-sources a cloud browser for agent workflows — fernandorojo · 2026-08-04
- DispatchMail ships as an open-source local AI assistant for managing email inboxes — tom_doerr · 2026-08-04
- Local two-agent setup shares one persistent memory and blocks bad decisions offline — PrajwalTomar_ · 2026-08-04
- Developer Warns Against Replacing Code Reading with LLM Summaries — brandon_xyzw · 2026-08-04