# Elastic Launches AlertZero AI Agents for Security Alert Triage

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/28577
Published: 2026-10-08T23:12:47.000Z
Updated: 2026-10-08T23:12:47.000Z
Section: Technology

> The technical preview divides security work among four specialized Watches and lets customers set approval requirements for different tasks.

Elastic launched AlertZero on Oct. 8 as an agentic layer for Elastic Security, dividing alert triage, threat hunting, detection engineering and endpoint forensics among specialized AI agents.

The system uses four AI groups called Watches: Triage, Hunt, Detection and Forensics. They can run from triggers or schedules and save their findings in a shared investigation record.

Triage evaluates alerts and links related activity. Hunt searches security telemetry using threat research. Detection reviews noisy rules and coverage gaps before preparing proposed changes. Forensics examines endpoint activity and identifies supported response actions.

AlertZero is entering technical preview across Elastic Cloud, self-managed environments and fully air-gapped deployments. Customers can use proprietary or open-source models and switch models during an investigation.

Autonomy can be configured for each task through three operating modes: manual, assisted and supervised. Detection-rule changes still require approval. In supervised endpoint operations, host isolation, process termination and process suspension may proceed without separate approval for every action.

An inconclusive Attack Discovery assessment still requires a person’s decision, including when the system is operating in supervised mode.

The preview builds on Attack Discovery, Elastic Agent Builder, Elastic Workflows and Elasticsearch Query Language (ES|QL). Attack Discovery connects related alerts into attack narratives and can investigate activity that existing detections may have missed.

An autonomous AI agent generated more than 17,000 events across a production environment during four days of a recent attack involving a dataset-pipeline exploit, credential theft and lateral movement.

“What makes AlertZero different is that our team who built it have sat in the SOC analyst’s seat,” said Mike Nichols, general manager, Security, Elastic.
