Know who to watch before the incident finds you
ID: a94c8aa9-2ee7-57b4-ad11-1d6300db8f42
STIX ID: report--a94c8aa9-2ee7-57b4-ad11-1d6300db8f42
Feed Name: Elastic Security Labs
Elastic Security v9.4 introduces Entity Analytics Watchlists, a feature that allows security, HR, and ops teams to create named, weighted lists of users, hosts, and services so that that organizational context (e.g., departing employees, privileged users, critical hosts) is injected directly into the platform's entity risk scoring pipeline without ES|QL or pipeline engineering; watchlists can be manually curated or automatically populated and are intended to prioritize investigations by compounding list membership with alerts, asset criticality, and behavioral signals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
