Elastic is showcasing its latest security innovations at Black Hat and DEF CON 2026. Key updates include Attack Discovery, which now investigates alerts like a human analyst by threat-hunting raw events, checking entity risk, and auto-drafting detection rules to close gaps. Elastic Defend gains vulnerable driver coverage via automatically deployed YARA rules and full Windows on ARM support. Elastic Workflows adds plain-language automation authoring, version control, and human-in-the-loop Slack approvals. Together these features aim toward 'Alert Zero' — reducing alert noise so analysts focus on validated threats rather than raw queues.
Table of contents
Alert Zero: From alert queue to validated threatsElastic Defend endpoint protection: vulnerable driver coverage and Windows on ARMElastic Workflows: SOC automation you can describe in plain languageFind Elastic Security at Black Hat and DEF CON 202657 Impressions