New York, USA: Elastic, the Search AI Company, has unveiled its new Elastic AI SOC Engine (EASE) – a serverless security solution designed to integrate AI-driven detection and triage capabilities with existing security tools. The package aims to help security operations centres (SOCs) reduce alert fatigue and speed up threat investigations without requiring organisations to replace or migrate from their current SIEM or EDR platforms.
New Elastic AI SOC Engine (EASE)
EASE delivers agentless integrations and uses Elastic’s Attack Discovery technology to correlate alerts intelligently. The system also features an AI Assistant designed to support SOC analysts in uncovering hidden and coordinated threats more quickly while reducing the manual workload involved in investigations.
Delivered via the Elastic Cloud, EASE provides a straightforward way for security teams to prioritise threats, enhance the effectiveness of their existing investments, and lower operational friction.
“SOC analysts are overwhelmed by high alert volumes and lack the AI support they need from their existing SIEM and EDR solutions to investigate threats effectively,” said Santosh Krishnan, GM – Observability and Security, Elastic.
“EASE brings Elastic’s proven AI capabilities into the security tools teams already use, to automatically prioritise threats, correlate alerts, and accelerate investigations, reducing the load on teams. When ready, teams can seamlessly migrate to Elastic Security for a unified, AI-driven platform that brings together SIEM, XDR, and cloud security, without missing a beat,” added Krishnan.
The new engine is designed for rapid deployment in environments relying on popular platforms such as Splunk, Microsoft Sentinel, and CrowdStrike. Key features include:
Agentless integrations that enable immediate AI analysis of alerts from third-party SIEM and EDR platforms
AI-powered alert correlation and prioritisation through Elastic Attack Discovery with an AI-enhanced alert view
A context-aware AI Assistant that enriches investigations by connecting internal knowledge bases like Jira, GitHub, and SharePoint, and supports natural language queries
Transparent AI with flexible model choices, allowing organisations to select their own large language model or use Elastic’s managed version, with full logging and traceability
Operational dashboards providing metrics on time saved, detection improvements, and return on investment to demonstrate business value
“Elastic is tackling a common challenge: how to bring open and transparent AI into the SOC without starting from scratch. EASE helps teams with faster detection and investigation using the tools they already have,” commented Michelle Abraham, Senior Research Director – IDC.
