Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

What’s new in Elastic Security 7.11: Cloud and host ML jobs and detection rules, streamlined SecOps workflows, and enhanced usability and accessibility

Blog post from Elastic

Post Details
Company
Date Published
Author
Mark Settle
Word Count
1,699
Company Posts That Month
29
Language
-
Hacker News Points
-
Post removed?
No
Summary

Elastic Security 7.11 introduces a range of enhancements aimed at improving threat detection, alert management, and data integration capabilities for security teams. Key features include prebuilt detection rules for cloud applications and Windows environments, updated machine learning jobs for anomaly detection across Windows and Linux hosts, and specialized detection rules for SUNBURST-related threats. The update also supports MITRE ATT&CK sub-techniques, offers expanded alert management actions for integration with third-party tools like Jira and ServiceNow, and introduces customizable alert notifications for better context. The usability of the Timeline workspace has been improved with features like tabbed information access and multicolumn sorting, while accessibility enhancements include better keyboard navigation and screen reader support. Elastic Agent now supports additional data sources and can ingest database audit logs, Snyk vulnerability data, and Windows security events by default. Additionally, Elastic 7.11 offers malware prevention options recognized by Windows and streamlined lifecycle management through its Fleet interface. The release also includes the general availability of searchable snapshots, allowing for extended retention and cost-effective access to high-volume security data from various sources.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 1 559 111 33 +17%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.