Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC

Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC
Elastic Security 9.5 introduces Alert Zero tools that help SOC teams reduce alert fatigue by automating triage, correlating related alerts, and embedding investigations into existing workflows while keeping analysts in control. The update centers on Security alert analysis, Attack Discovery, and Elastic Workflows, with support for custom models, inspectable agent reasoning, and approved detection-gap remediation. #ElasticSecurity #AttackDiscovery #ElasticWorkflows #ESQL #VirusTotal

Keypoints

  • Alert Zero is a target operating state where the SOC queue no longer dictates the analyst’s day.
  • Elastic Security 9.5 provides three main capabilities to support this goal: Security alert analysis, Attack Discovery, and Elastic Workflows.
  • Security alert analysis classifies alerts as true positive, false positive, or inconclusive, and can optionally auto-close high-confidence false positives.
  • Attack Discovery correlates related alerts, builds attack chains, and now investigates the underlying activity behind them.
  • Attack Discovery is integrated into the new Attacks page under Detections, alongside Alerts, so analysts can work from correlated narratives instead of raw alert walls.
  • Elastic Workflows lets teams embed discovery, validation, enrichment, and approval steps into existing SOC playbooks without replacing their current operating model.
  • Teams can use their own AI models, including local LLMs, and keep automation inspectable with human approval for higher-risk actions.

MITRE Techniques

  • [T1087 ] Account Discovery – Used during investigation to inspect entity context and identify relevant users or accounts in alert-related activity (‘inspect entity context’).
  • [T1005 ] Data from Local System – Used when the workflow searches raw logs in Elasticsearch to gather supporting evidence for the attack narrative (‘search raw logs in the Elasticsearch platform’).
  • [T1059 ] Command and Scripting Interpreter – Referenced indirectly through workflow and detection drafting in ES|QL, where analysts review query logic before rule creation (‘draft an Elasticsearch Query Language (ES|QL) rule’).
  • [T1046 ] Network Service Scanning – Not explicitly named, but related activity hunting across alerts and logs can uncover broader attacker movement patterns (‘hunt for related activity’).
  • [T1114 ] Email Collection – Not mentioned.

Indicators of Compromise

  • [Product/Platform names ] SOC automation and investigation workflow context – Elastic Security 9.5, Elastic Workflows
  • [Query/Rule language ] detection-gap remediation context – Elasticsearch Query Language (ES|QL)
  • [External service ] validation/enrichment context – VirusTotal
  • [Deployment type ] model choice and governance context – local large language models (LLMs), air-gapped and sovereign deployments


Read more: https://www.elastic.co/security-labs/agentic-soc-alert-triage-alertzero