Introducing AlertZero: Inbox zero for your alert queue
Elastic previews AlertZero, an agentic Elastic Security layer that triages alerts and proposes analyst-approved SOC actions.
Elastic previewed AlertZero, an agentic layer for Elastic Security meant to drive SOC alert queues toward inbox zero. Specialized Watches for Triage, Hunt, Detection, and Forensics correlate and enrich alerts, propose evidence-backed actions, and help tune detections, with every consequential action requiring analyst approval. It supports proprietary and open-source models on Elastic Cloud, self-managed, or air-gapped deployments, building on Elastic AI Assistant, Attack Discovery, Agent Builder, and Workflows. A demo walks through an impossible-travel login for cfo@corp and a proposed endpoint isolation.
- Four Watches cover Triage, Hunt, Detection, and Forensics.
- Autonomy is manual, assisted, or supervised; consequential actions need approval.
- Teams can use proprietary or open-source models, including air-gapped deployments.
- It extends Elastic AI Assistant, Attack Discovery, Agent Builder, and Workflows.
Full article2,075 words · extracted from elastic.co · click to collapse
For the last several months, we’ve been busy talking to security teams and building answers to the AI-accelerated challenges that you’ve told us you’re facing. Among these are the overwhelming volume and velocity of alerts, exacerbated by attackers equipped with AI. The Hugging Face incident demonstrated another core challenge in the security operations center (SOC). Even if all of the signals are detected, that’s not enough, unless something connects them as part of a single attack. Combined, these problems force most teams to ration coverage by headcount, so the contents of the alert queue decide what gets attention, and the rest ages out unexamined. Spending time on proactive defenses then feels even more challenging.
Today, we’re giving you a peek at AlertZero, the new agentic layer of Elastic Security. AlertZero has a straightforward premise: put SOC teams on the path to the equivalent of inbox zero for alerts, with every alert answered. It does this by reducing the existing queue and the false positives that contribute to it, through high-volume correlation and enrichment, proposing actions, and then helping to create and tune detections.
AlertZero has agents, called Watches, each with one named job: Triage, Hunt, Detection, or Forensics. The Watches run on triggers and schedules to propose evidence-backed conclusions, called Proposed Actions, for approval, modification, escalation, or dismissal. Each Watch surfaces decisions to the analyst based on its autonomy level: manual, assisted, or supervised. Regardless of level, every consequential action is proposed to the analyst for approval.
AlertZero retains the same ″open by design″ philosophy as Elastic Security. You can use the model that works best for your team, including proprietary and open source models, with the same product and features, across Elastic Cloud, self-managed, or fully air-gapped.
We didn’t think of this overnight. AlertZero builds on three years of generative AI (GenAI) innovation in Elastic Security. Elastic AI Assistant started with conversational help in 2023. Attack Discovery extended that into a dedicated investigation task in 2024, connecting related alerts into an attack narrative. Elastic Agent Builder and security skills added agents that use tools and apply domain expertise, while Elastic Workflows supplies repeatable execution. AlertZero brings these capabilities together, tailored to the responsibilities of a SOC.
AlertZero Watches stay in their lane (and they handle it well)
Every Watch in AlertZero is directly aligned with the key responsibilities in the SOC, and their levels of autonomy are customizable. Within each Watch, Workers carry out specific tasks. For example, a Triage Worker runs Attack Discovery, which connects related alerts into attack narratives, while a Forensics Worker examines endpoint activity. Your team controls how much each Worker can do without human review, so you can tailor Watches to help your team in the places you most need it.
The upcoming technical preview introduces four Watches:
Watch name | What it helps your team do |
|---|---|
Triage | Assesses alerts, connects related activity, and identifies findings that need attention. |
Hunt | Uses threat research to look for evidence of attacks in the available telemetry. |
Detection | Investigates noisy rules and coverage gaps and then prepares detection changes for review. |
Forensics | Examines endpoint activity to establish what happened and to identify supported response actions. |
Figure 1. The four Watches align automated security tasks with familiar SOC responsibilities. Analysts choose which tasks to run and how much to delegate.
A hunt can start from new threat research, and detection analysis can start from recurring false positives. Endpoint analysis can start from a finding that needs a closer look, and all of the Watches can run on triggers or a schedule. Watches don’t form a mandatory pipeline.
How AlertZero handles suspicious login sessions
The following example shows how the Triage and Forensics Hunts work together. We’re starting on the Proposed Actions page, where Watches awaiting human approval show their work before carrying out an action.
Figure 2. AlertZero’s list of Proposed Actions, organized by the type of action awaiting human input.
Proposed Actions are grouped by the type of action they’re waiting for. In this specific scenario, under Respond, an impossible-travel finding for an executive account, cfo@corp, has an endpoint-isolation action waiting for review. Before we even open this screen, the Triage Watch and Forensics Watch have already gathered the findings behind that recommendation.
Opening the item reveals the associated Investigation and its supporting evidence.
Figure 3. The analyst opens the evidence behind the Proposed Action in its associated Investigation.
In this example, the account was active in Boston and then, 39 minutes later, it was active from a distant hosting network, using the same session identifier without a fresh multifactor authentication (MFA) event.
The endpoint findings add more context: an unsigned process accessing browser session material. If needed, we can examine how that process started and what it contacted, along with the time period covered. To see the full scope of the incident, there are the related alerts and affected entities, in addition to endpoint findings, in the same flyout. In this case, the pattern warrants investigating session replay. Virtual private network (VPN) use and proxies also need consideration, as does inaccurate geolocation.
From the Investigation’s conversation, we can ask these follow-up questions before deciding how to proceed: What did the account access after the suspicious sign-in? What would isolating the endpoint interrupt? These questions also prompt further analysis, and the existing findings are available as context.
Figure 4. Review begins with a Proposed Action. The analyst can inspect evidence and ask questions before deciding; approved actions record their execution outcome.
In this scenario, the endpoint response is set to manual review. So, after checking the target, rationale, and likely impact, we can approve or decline the Proposed Action. An approval would trigger host isolation through Elastic Defend. The Investigation records the decision and the execution outcome separately for auditability.
When an Investigation (or set of Investigations) needs a coordinated and constrained response, an analyst can open an Escalation and link the relevant Investigations.
Figure 5. Teammates and an attached Investigation share one Escalation conversation.
Teammates can discuss the evidence and, in the same conversation, ask an agent follow-up questions. They can also opt to never invoke an agent in particularly sensitive situations.
Beyond alert triage: What else does AlertZero do?
Reducing the alert queue by handling the correlation and enrichment at scale is one part of the solution. On the other side of things, we’re helping with the work that happens when nothing is on fire.
A head start on your hunt
For threat hunting, the Hunt Watch:
Continuously observes your environment.
Maps observed technologies and exposures to relevant threats.
Proposes hunts, findings, coverage improvements, or escalations.
Its core purpose is to answer the question Is there evidence of this threat in my environment?, without requiring you to provoke the hunt or feed the intel.
The Hunt Watch gets you started with threat research, even when no detection alert has been fired. It relates that research to the environment and available telemetry and searches for relevant indicators. It also examines supporting behavior. The findings identify what was searched and what was found.
Turning false positives and coverage gaps into rule changes
To improve your environment-specific defenses, hunt findings can inform the Detection Watch by looking at whether existing rules would detect the behavior.
Suppose a legitimate administrative tool repeatedly triggers a rule. The closure itself is useful feedback, but someone still has to connect several decisions to a common cause in the rule. This is how false-positive closures provide another input for the Detection Watch to contextualize. The Watch reviews the alert examples and existing logic and then prepares a proposed change, like an exception, with the supporting diagnosis. From there, a detection engineer can assess whether a narrow exception fits the benign activity while preserving detection of malicious use of the same tool.
As an example, the Watch would run an Elasticsearch Query Language (ES|QL) query like this:
Once the Watch reviews the rules’ rankings based on their recently closed false positives, it identifies those with high counts to investigate further. A high count doesn’t necessarily prove that the rule is defective, but the analysis needs to inspect the examples and their closure rationale, because an incorrect false-positive label can otherwise become an incorrect exclusion.
In this example, the Detection Watch’s Rule Tuning Worker is set to manual. After the analyst authorizes the analysis, the resulting Proposed Action brings together the diagnosis, the motivating alerts, the existing logic, the proposed logic, and backtest results. That gives a detection engineer an actual change to assess and the evidence used to construct it.
Figure 6. A rule-tuning Proposed Action includes examples, current and proposed logic, and a backtest. Five sample alerts become zero in this example; that result alone doesn’t establish preserved attack coverage.
With the proposal, we can see that the five sample false positives no longer match the revised query.
We can open the Proposed Action to review the change and ask follow-up questions in the linked Investigation, such as What other activity would this exclusion suppress? Because this backtest only covers benign samples, the analyst still needs to validate detection of known malicious activity through the team’s existing testing process before approving. If it’s approved, the change is applied; if it’s declined, the rule is unchanged.
You can decide how much to delegate
You choose which Watches run and how far each goes, with autonomy configurable per Worker. We’ve built this into AlertZero because no two security teams are organized the same way. Some run tiers, some run pods, many have no detection engineer, and most cannot staff nights. Regardless of team structure, autonomy also is configurable because different jobs carry different risks, like assessing an alert versus responding on an endpoint. You can delegate routine analysis while choosing more cautiously when a host may be affected. As an example, the Triage Watch Worker runs Attack Discovery, while a Forensics Watch Worker performs endpoint analysis. Each runs as an Elastic Workflow, calling Agent Builder agents and skills for analysis.
For true-positive or inconclusive Attack Discovery assessments, manual review lets the analyst decide whether to close an Investigation or request endpoint analysis. In supervised operation, a true-positive assessment can continue into endpoint analysis automatically. An inconclusive assessment still needs a person's decision.
Endpoint analysis has its own control. Manual operation presents supported response actions for review. Supervised operation is designed to permit host isolation, process termination, and process suspension without an additional approval for each action. Detection changes continue to require approval. Teams can therefore automate one part of the sequence while retaining review of another.
Figure 7. Endpoint analysis has its own autonomy control; manual review is selected here.
Every alert is answered, and every decision is yours
As AI that helps move an investigation forward, AlertZero connects work that too often stops at a handoff. The evidence gathered during triage can guide endpoint analysis and support a response decision. It can also give teammates a place to continue the investigation. Teams choose what to delegate and where their judgment is needed.
To know when future AlertZero news is published, sign up for updates. AlertZero will be available soon to all users of Elastic Security.
Glossary
AlertZero: The agentic layer of Elastic Security, connecting alert triage, threat hunting, detection engineering, and endpoint forensics.
Watch: A grouping of automated tasks around a security responsibility. The initial four are Triage, Hunt, Detection, and Forensics.
Worker: A defined task implemented as a workflow in Elastic Workflows, using agents and skills to produce findings, evidence, and supported actions.
Proposed Actions: Recommended changes with supporting evidence and rationale, presented for approval where review is required.
Investigation: The shared record for a line of inquiry, bringing together findings, affected entities, evidence, and Proposed Actions.
Escalation: A conversation that a person creates to coordinate work around linked Investigations. Teammates can discuss evidence and ask agents questions; visibility can be public or private.
Autonomy setting: A per-Worker control over how much work can proceed without review. Its behavior depends on the task.
Consequential action: An operation that changes the environment, such as isolating a host or editing a rule.
Elastic Defend: Elastic's endpoint security capability, providing supported endpoint response actions.
Attack Discovery: A capability that connects related alerts into suspected attacks. The Triage Watch uses it to open an Investigation for each identified attack.
Elastic Agent Builder, Elastic Workflows: Extensible building blocks for Watches: Agent Builder provides agents, tools, and skills; Elastic Workflows coordinates execution.