TMCnet News
Elastic Announces AlertZero, a Team of Specialized AI Agents for the Security Operations LifecycleElastic (NYSE: ESTC) today introduced AlertZero, the agentic layer built into Elastic Security, with a team of specialized agents that learn from and adapt to how a security team already works. The agents handle alert triage, investigation, threat hunting, detection tuning and forensic analysis, so each alert gets an evidence-backed answer. This puts analysts on the path to an equivalent of inbox zero: a short queue of recommended actions instead of thousands of raw alerts. Analysts retain full control over which actions are automated and which require human judgement: they choose how much work to delegate to AlertZero and when they need to make the decisions. Releasing into Technical Preview, AlertZero works with any model in any deployment, so teams can adopt AI on their terms. Security teams face the same persistent bottleneck: alert volume has outpaced the analysts available to work through it, and false positives add to a queue that was already too large to clear. As attackers' use of AI evolves, new problems keep compounding this issue. In a recent high-profile attack, an autonomous AI agent generated more than 17,000 events across a production environment in only four days, moving from a dataset-pipeline exploit to credential theft and lateral movement. The individual signals were detectable, but understanding the attack required connecting them. That is exactly what AlertZero was built for. It continuously correlates and investigates activity while helping teams reduce false positives that clog the alert queue, with the flexibility to adapt as threats evolve. AlertZero organizes that work around Watches: specialized named groups of agents with defined responsibilities that run on triggers and schedules. Each Watch focuses on a specific area of security operations and carries its findings into a shared investigation record:
"What makes AlertZero different is that our team who built it have sat in the SOC analyst's seat," said Mike Nichols, general manager, Security, Elastic. "We focused on building a platform that gives teams enough visibility and control to deploy agentic automation at the scale and scope they can handle effectively. Every Watch in AlertZero aligns directly with key SOC responsibilities, and the level of autonomy is customizable for each Watch. Security teams get help where they need it most, with the model and deployment that are most effective for their needs." Customers can extend AlertZero using the same Agent Builder skills and Elastic Workflows that Elastic used to build it, adding workflows specific to their environment without leaving the platform. Availability AlertZero will be available to Elastic Security customers as a Technical Preview in Elastic Cloud, self-managed, and air-gapped environments. It builds on existing Elastic Security capabilities, including Attack Discovery, ES|QL, Agent Builder, and Elastic Workflows. Receive updates on AlertZero by signing up here. Additional Materials Blog: Inside what's coming with AlertZero: connecting investigation, hunting, and response About Elastic Elastic (NYSE: ESTC) integrates its deep expertise in search technology with artificial intelligence to help everyone transform all of their data into answers, actions, and outcomes. Elasticsearch, which is the foundation for its search, observability, and security solutions, is used by thousands of companies, including more than 75% of the Fortune 100. Learn more at elastic.co. Elastic and associated marks are trademarks or registered trademarks of elasticsearch B.V. and its subsidiaries. All other company and product names may be trademarks of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20261008390511/en/ |

