Elastic Security · Black Hat USA

From Assistant
to Assistant

Three years from a chat sidekick to agents that investigate, reason, and act.

James Spiteri · Elastic Security

The arc · one interaction model at a time

Ask → Apply → Act

2023
01

Ask

Natural language becomes the interface. The Assistant explains alerts, writes queries, and answers questions.

GPT-4 · 32K context
2024
02

Apply

Models move inside specific workflows: bulk triage, imports, migrations, and troubleshooting.

Claude 3 · 200K context · LangGraph
2025–26
03

Act

Agents reason across tools, run workflows, expose their evidence, and pause for human approval.

Reasoning · tool use · MCP
June 2023
The ask era

The chat era begins

We shipped the Elastic AI Assistant to learn where natural language could remove friction inside a SOC.

01Alert summarization
02Query conversion
03Workflow guidance
04Anonymization built in
“Useful, novel — and nowhere near enough.”
Elastic AI Assistant · October 2023
Elastic AI Assistant in 2023
GPT-4 era32K contextany modelOSS / self-hosted
Attack Discovery · correlated attack chain
Attack Discovery detail view
bulk triageattack chainspatent pendingdesign patent granted
May 2024
The apply era

Attack Discovery moves beyond chat

Instead of waiting for a prompt, the model triages alerts in bulk and delivers structured discoveries in a purpose-built interface.

The shiftChat is an interface.
The workflow is the product.
Claude 3's 200K context made whole-alert-set reasoning practical.
May 2024 · under the hood

How Attack Discovery works

Click a node · arrow keys follow the flow

2024
Lesson one · learned the hard way

No evals, no trust

95%25%

Adjacent prompt variants. Same task. Wildly different outcomes.

The practiceGate prompt changes and model swaps on curated attack scenarios.
prompt × accuracy
Evaluation heatmap of prompt accuracy
LangSmithregression gatesmodel swaps in hours
2024 → 2025
Purpose-built AI

Sell finished chores, not “AI”

01

Automatic Import

Turn an unfamiliar log source into a working integration and ingest pipeline.

Weeks → minutes
02

Automatic Migration

Translate legacy SIEM rules and dashboards into Elastic equivalents.

Migration blocker → workflow
03

Automatic Troubleshooting

Diagnose Elastic Defend deployment failures without hours of doc-spelunking.

Toil → guided resolution
ArchitectureLangGraph + query sub-agents
AWS · 2024Global GenAI Infrastructure & Data Partner
LangChain · 2024#2 Top LangGraph Agent in Production
2025
MCP lands · customer expectations flip

From “why?” to “how fast?”

Then“We don't really know how we would use generative AI in our SOC.”
Now“We want this end-to-end agentic flow. How do we build it with Elastic?”
0customer conversations
ControlChoose tools, boundaries, approvals
CustomizationBring your workflows and models
InsightShow evidence and reasoning
Elastic Agent Builder · platform architecture
Elastic Agent Builder platform architecture
Elastic and KeepNovember 2025 · Keep joins Elastic
Early 2025 → November 2025
The rebuild

Agents become a platform primitive

01 · ControlScoped tools, prompts, and security boundaries per agent.
02 · CustomizationAny model — commercial, open source, cloud, or self-hosted — plus your tools and workflows.
03 · InsightVisible reasoning, executions, evidence, and approvals.
2025 · anatomy of an investigation

What “agent” means in production

Click a node · arrow keys follow the loop

January 2026
Elastic 9.3

Agentic capabilities land in the analyst flow

9.3
01

Agentic investigations

Pull context, run queries, and build the picture across security data.

02

AI entity summaries

Explain why a host is risky and what the analyst should do next.

03

Agent Builder in Security

Custom agents, tools, workflows, MCP, and APIs come together.

AI entity summary & risk
Elastic 9.3 AI entity summary
Security MCP App · Alert Triage inside Claude
Elastic Security MCP App rendered inside Claude
interactive UIlive cluster datasame SOC objects
May 2, 2026
The SOC comes to your AI tools

The Security MCP App

Not a wall of text: interactive SOC surfaces rendered inside Claude, Cursor, and VS Code.

Alert TriageThreat HuntAttack Discovery Case ManagementDetection RulesSample Data
SkillsTeach the agent when to hunt, pivot, investigate, and open a case.
May 5, 2026
Elastic 9.4

The agentic SOC starts operating end to end

9.4
Elastic Workflows · visual graph of the triage flow
Elastic Workflows visual graph viewer
01

Workflows GA

Native triage, enrichment, response, notification, and case automation.

02

Five Security skills

Triage, rule authoring, entity investigation, hunting, and anomaly analysis.

03

Agent-ready entity context

Resolved identities, dynamic watchlists, and hunting leads.

July 31, 2026
Elastic 9.5

Alert Zero: the queue stops running the day

Click a node · arrow keys follow the flow

What production taught us

Five requirements for a trusted agent

01

Evals before features

Measure quality continuously or you're shipping vibes.

02

Workflow over chat

Aim models at specific jobs and give outputs a real home.

03

Secure actions

Scope tools, guard workflows, and make agents earn write access.

04

Readable evidence

Analysts trust what they can inspect and audit.

05

Human control

Customization and approval beat autonomy theater.

The assistant answered questions. The agent does the work.

James Spiteri · Elastic Security

← → navigate · N notes · O overview · B blackout · F fullscreen