AI
AI
AI
Security operations centers have spent years stacking tools to solve alert volume issues that tools simply can’t fix, and Elastic is now making the case that AI-powered SOC is the only viable path forward.
The problem is structural, according to Mike Nichols (pictured), general manager of security at Elastic. Analysts are burning out because their tools generate more noise and chaos than any human team can absorb. It’s not a matter of lacking the necessary tools, so Elastic’s answer is Alert Zero, a destination where agents and analysts work together to reduce the queue so only validated, legitimate attacks remain. Machine speed handles the volume, and human judgement handles making the calls.
“We hire and pay for these detectives to come work in our environments, but then most security operations centers, they’re beat cops writing traffic tickets all day long,” Nichols said. “Imagine if you could eliminate that work, and they really are just showing up at the scene of the crime and doing their analysis and investigation.”
Nichols spoke with Krista Case at Black Hat USA during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how Elastic’s expanded Attack Discovery platform now investigates threats before they reach an analyst, why vendor lock-in is the next major risk in the AI-powered SOC market and where human judgement remains indispensable.
Elastic’s Attack Discovery actively investigates alerts the way a human analyst would, by hunting raw events, checking entity risk scores and corroborating across data sources before flagging anything as a confirmed attack. The result is a short list of validated security threats instead of walls of raw alerts. When it finds a detection gap, it drafts a new detection rule and routes it for human approval. On the endpoint side, Elastic’s threat research team monitors sources like VirusTotal continuously, automatically generating and deploying YARA rules the moment a vulnerable driver is disclosed.
“The model vendors have done amazing work getting really efficient in cost and performance,” Nichols said. “Now we can go through every single alert, give it a confidence score, and couple that with Attack Discovery.”
Nichols also warned practitioners to be wary of the next generation of vendor lock-in, where proprietary AI models become the new mechanism that traps organizations. If an AI SOC vendor’s model is a black box, all the agentic operating procedures built on top of it are stuck there as well. Elastic’s answer is a “bring-your-own-model” avenue that’s built on open architecture, full reasoning transparency through OpenTelemetry tracing and plain-language workflow authoring that any team member can audit, modify and trust.
“LLMs are now becoming the vendors’ new lock-in mechanism,” Nichols said. “If you pick an amazing AI SOC vendor who has a black box or proprietary model… if you decide to move off of that vendor in the future, how do you take all that work you’ve done somewhere else? It’s proprietary, it’s built into that ecosystem.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA:
(* Disclosure: Elastic sponsored this segment of theCUBE. Neither Elastic nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.