Attack Discovery
Attack Discovery uses large language models (LLMs) to analyze alerts and identify potential attacks. Each discovery groups related alerts into an attack narrative. It shows which users and hosts are involved, how alerts map to the MITRE ATT&CK matrix, and which threat actor might be responsible. Use discoveries to prioritize investigation and shorten mean time to respond.
You can start a run from the UI (manual or scheduled), from an automated workflow, or from an Elastic Agent Builder conversation. All methods use the same analysis steps.
For a demo, refer to the following video (click to view).
Attack Discovery requires at least one configured LLM connector. If your subscription or project includes Elastic Managed LLMs, one may already be available with no setup required. Otherwise, refer to Configure access to LLMs to add one.
We recommend using one of the models in the Large language model performance matrix for Attack Discovery.
Each discovery includes the following information describing the potential threat, generated by the connected LLM:
- A descriptive title and a summary of the potential threat.
- The number of associated alerts and which parts of the MITRE ATT&CK matrix they correspond to.
- The implicated entities (users and hosts), and what suspicious activity was observed for each.
Choose how to start a run from the Attacks view, a workflow, Elastic Agent Builder, or the Attack Discovery page in Run Attack Discovery.
