[Photo: Shutterstock]

[DigitalToday reporter Chi-gyu Hwang] Elastic unveiled an AI agent team called AlertZero to reduce security operations center alert overload. SiliconANGLE reported on Oct. 8 that AlertZero is built into Elastic Security and supports alert triage, threat hunting and forensic analysis.

The company said AlertZero is focused on solving alert overload. Security operations center (SOC) teams have been burdened with more alerts than analysts can handle. With false positives mixed in, the number of alerts that need to be checked has grown further.

Customers can directly adjust AlertZero’s automation scope down to the task level. Even at the highest autonomy setting, human approval is required when decisions are unclear. Customers also choose the model to use, and analysts can switch models if evidence changes during an investigation.

AlertZero consists of four agent groups. "Triage Watch" enriches incoming alerts to determine whether they are real threats, and closes alerts judged to be noise after recording the reason. "Hunt Watch" continuously tracks threats based on threat research. "Detection Watch" learns from the results of the other three watches and suggests adjusting noisy detection rules or adding new rules to fill gaps. Rules are not changed without approval. "Forensic Watch" is responsible for malware analysis and tracing exploit paths.

Mike Nichols (마이크 니콜스), head of Elastic Security, said, "The people who built AlertZero are those who have sat in the SOC analyst seat." He said the goal is to have teams accept only as much automation as they can oversee.

AlertZero is offered as a technical preview in Elastic Cloud, self-managed and air-gapped environments.

Keyword

#Elastic #AlertZero #Elastic Security #Security Operations Center #Elastic Cloud
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.