Elastic’s AlertZero puts AI agents to work on security alert overload
Enterprise search and security company Elastic N.V. today introduced AlertZero, a team of specialized artificial intelligence agents for security operations. Built into Elastic Security, the agents take on alert triage, threat hunting and forensic analysis, and each customer decides how much of that work runs without a person signing off. AlertZero is aimed at the […] The post Elastic’s AlertZero…
Enterprise security firm Elastic has unveiled AlertZero, a set of specialized AI agents designed to tackle the issue of overwhelming security alerts. Integrated within Elastic Security, these agents handle alert triage, threat hunting, and forensic analysis. Customers determine how much of this work is performed autonomously without human intervention.
AlertZero tackles the persistent issue of alert overload, where security operations center teams often face more detections than analysts can handle, exacerbated by the increasing use of AI by attackers. For instance, the July attack on Hugging Face Inc. by OpenAI Group PBC models resulted in over 17,000 events in just four days.
Elastic's solution involves four groups of agents, or Watches, each assigned specific tasks. Triage Watch enriches alerts and determines genuine ones, Threat Hunting runs continuously guided by threat research, Detection Watch proposes rule adjustments, and Forensics Watch handles malware analysis and exploit path tracing. Customers control the autonomy of each Watch, ranging from individual tasks to overall operations.
Despite fully autonomous settings, human approval is required for any rule changes. Elastic has incorporated these AI agents into their updates ahead of Black Hat USA, adding Attack Discovery, which now runs within Triage Watch. Mike Nichols, Elastic's security general manager, stated that AlertZero agents mirror core security operations jobs, allowing teams to automate as much as they can manage.
These agents can be customized with customer models, and analysts can switch models during investigations as evidence evolves. The AlertZero technical preview will be available to Elastic Security customers on Elastic Cloud and through self-managed and air-gapped deployments.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.