Prevention at Machine Speed: Hunting Beyond Known Detections (Aug. 13th)
Thursday, August 13th, 2026: 2:00 PM to 3:00 PM
AI broke the SOC at both ends. Attackers now move faster than an analyst can open the case, and the techniques that matter most surface in a threat research blog long before anyone writes them into a rule. Detect-and-respond still matters, but it now sits between two jobs that matter more: stopping decisive actions at the point of execution, and hunting for what your defenses were never built to see.
Virtual
James Spiteri and Paul Ewing show how Elastic Security works both ends. At the endpoint, machine-speed attacks need controls that deny malicious behavior before it executes, not one more alert for later: the prevention architecture, behavioral protections, and containment across Windows, macOS, and Linux, on-prem, cloud, or air-gapped.
At the other end, Attack Discovery showed tier 1 triage how an agentic system reasons across alerts and surfaces what warrants attention. This session extends that to tier 2 hunting with a human on the loop at every step. The system reads unstructured threat research, the blogs and reports Elastic was built to search, pulls out the tradecraft, writes and runs the queries, correlates the evidence, and proposes new detection rules for review.
One side compresses the loop to the endpoint. The other expands what you know how to find. Help, not hype.
Hosted by Dark Reading