صورة غلاف ‏Elastic‏‏
Elastic

Elastic

تطوير البرامج

‏San Francisco‏، ‏California‏ ‏٥٥٠٬٤٥١‏ ‏متابع‏

نبذة عنا

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale. Elastic’s solutions for search, observability, and security are built on the Elastic Search AI Platform — the development platform used by thousands of companies, including more than 50% of the Fortune 500.

الموقع الإلكتروني
http://www.elastic.co
المجال المهني
تطوير البرامج
حجم الشركة
‏١٠٠١ - ٥٠٠٠ موظف
المقر الرئيسي
‏San Francisco‏, ‏California‏
النوع
شركة عامة
التخصصات
‏Big Data، AWS، Kibana، Observability، APM، Search، Distributed، Lucene، Database، Open Source، Cloud، SIEM، Security، Logging، Analytics، Elasticsearch، App Search، Site Search، Enterprise Search، و ELK‏

المواقع الجغرافية

موظفين في ‏Elastic‏

التحديثات

  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    A malware-as-a-service kit is being sold with one purpose: kill your EDR, including ours. In August 2026, eSentire documented a ClickFix campaign selling a DLL sideloader as a service. It drops a malicious mscoree.dll next to a signed Microsoft binary, vb7to8.exe. Windows loads the planted copy first, so the attacker's code runs inside a trusted process. The kit doesn't stop there. It also ships a vulnerable driver, a Bring Your Own Vulnerable Driver (BYOVD) technique, to disable endpoint detection. That's a separate problem. This post is about the attacker gaining code execution. So we rebuilt the sideloading technique, the DLL search-order hijack itself, to test our detection against it. We reverse engineered the sample, recreated it as a NativeAOT .NET 7 library with faked exports and a module initializer that fires on load, then dropped it beside vb7to8.exe and ran it. Elastic Defend 9.5.0 flagged the load as DLL Hijack: Masquerading. Here's why that matters for detection teams: writing this rule before 9.5.0 took around 88 lines of logic and a maintained list of ~2,600 library names. Every newly abused library was another line to maintain. Now the core detection is one line, and the sensor handles the library inventory, path exclusions, and signature checks. Less rule to maintain. Fewer coverage gaps when the next abusable library shows up. MITRE ATT&CK: T1574.001 (Hijack Execution Flow: DLL) and T1036 (Masquerading). Reverse engineering walkthrough, the .NET rebuild, and the detection breakdown by Ian G. and Tamás Péter: https://go.es.io/4gxbLKs

    • لا يوجد نص بديل لوصف هذه الصورة
  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    Julia Liuson has been nominated to join Elastic’s Board of Directors. Julia brings more than three decades of technology leadership, most recently as President of Microsoft’s Developer Division, with deep experience across AI, developer platforms and enterprise technology. As AI reshapes how applications are built, how technology is operated and how organizations defend themselves, Julia’s experience will be invaluable as we continue to innovate across Search, Observability and Security. We look forward to your joining Elastic, Julia! https://go.es.io/45Vel8j

    • لا يوجد نص بديل لوصف هذه الصورة
  • عرض ملف ‏Jon Fortt‏ الشخصي
    Jon Fortt ‏Jon Fortt‏ عضو مؤثر

    Elastic's fiscal Q1 2027 landed as a beat and raise: CEO Ashutosh Kulkarni told me revenue rose 15% year over year, sales-led subscription revenue 18%, and non-GAAP operating margin hit 16.2%. The company lifted its full-year revenue and margin guide. Kulkarni tied momentum to AI adoption. Fully 37% of $100K-plus customers now use Elastic's AI features, up from 21% a year ago, driving 27% RPO growth. He casts Elastic as the context bridge linking LLMs to proprietary data. Full Fortt Knox conversation linked in the comments:

    • لا يوجد نص بديل لوصف هذه الصورة
  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    We reproduced the new Log4j 2 deserialization bug on official 2.26.1 JARs. Getting to command execution took two things Log4j does not ship: - A process still deserializing serialized LogEvent objects - A gadget library already on that JVM log4j-api and log4j-core alone were not enough. So here is what to hunt for: Java accepting a network connection, followed by spawning a suspicious child process. That is post-exploitation behaviour, not a signature of the bug itself. Treat it as possible gadget execution and check the JVM. ES|QL hunt queries and affected versions are in the post. How the bypass works, which versions carry it, and what to hunt for by Ruben Groenewoud Bryan Porras Terrance DeJesus: https://go.es.io/4cgTPTd

    • لا يوجد نص بديل لوصف هذه الصورة
  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    Elastic is supporting OpenAI's call for collective action on cyber defense. The same advances in AI that are changing the threat landscape can also change what’s possible for defenders. This is why, across the security community, we have the opportunity to put AI to work where it can make a real difference by helping teams uncover vulnerabilities sooner, detect and investigate issues faster, and respond to threats with greater speed and precision. Elastic is committed to doing our part with an open approach to security - as always. Read the open letter: https://go.es.io/4gGrwz1

  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    Today we announced our Q1 FY27 earnings. We delivered a strong start to the year, beating across all guided metrics with record customer additions to our >$100K ACV customer cohort. Swipe through to learn more and see our first quarter fiscal 2027 financial results. For our full results and information about forward looking statements and non-GAAP financial measures see our press release here: https://go.es.io/4xtjZe2

  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    Same agent, same question, one test run: 12 tool calls and 167K tokens before, 8 calls and 92K tokens after. The difference is where the context lives. Most agents burn tokens on discovery, inspecting mappings, sampling docs, and probing indices before they can even start answering. Knowledge Indicators move that work upfront. A Kibana Workflow profiles each index once (purpose, key fields, routing heuristics), stores the profiles in an AI Index, and agents query them with ES|QL. Available in Serverless today, coming to future Stack releases. 45% fewer tokens, and the answer was still grounded and correct. At agent scale, that discovery overhead is a real line item on your inference bill. Full walkthrough with ES|QL queries and a companion notebook: https://go.es.io/4hJ3vcN

    • لا يوجد نص بديل لوصف هذه الصورة
  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    When you develop a recipe, you test a few variations before settling on the final version. Building an embedding model works the same way, and the process has a name: ablation. For the audio and vision pipelines in jina-embeddings-v5-omni, eight configurations were swept before landing on the final architecture: freeze all the encoders, train only the small projectors and a handful of delimiter tokens, about 0.35% of the model's weights. The clearest result came from vision: unfreezing the encoder before the projector was trained dropped nDCG@10 from 0.158 to 0.079. Architecture details in the blog: https://go.es.io/4xfTmcv

    • لا يوجد نص بديل لوصف هذه الصورة
  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    Today, we completed our acquisition of Deductive AI. By joining forces, we are advancing our goal to set the standard for production incident investigation, bringing more AI-powered investigation and automation to Elastic Observability. We have been building AI into Elastic Observability to help move teams from detection to resolution faster, and this acquisition takes that further. Deductive’s AI SRE agent approaches incident investigation as a rigorous reasoning problem, not a search query or a summarization task. It gathers evidence, forms hypotheses, conducts tests, and learns from each investigation to improve the next. Combined with Elastic's telemetry depth and ability to infer entities, relationships, and significant operational events, the goal is straightforward: fewer hours spent manually tracing incidents, and faster resolution when it matters. Elastic CEO Ashutosh Kulkarni summed up the opportunity: “Engineering teams today are drowning in telemetry but starved for answers.” This is how we change that. Existing Deductive AI customers will continue to receive support. Additional product details coming in the months ahead. The full details: https://go.es.io/4xTIlNO

    • لا يوجد نص بديل لوصف هذه الصورة
  • مشاهدة صفحة منظمة ‏Elastic‏

    ‏٥٥٠٬٤٥١‏ ‏متابع‏

    Treasury doesn’t just have a data problem. It has a decision latency problem. Balances, transactions, forecasts, payment activity, market signals: the information may already exist. But when it’s fragmented across ERP systems, treasury platforms, banking systems, dashboards, and spreadsheets, teams still have to find it, reconcile it, and determine what to do next. Agentic AI changes what happens next. As AI moves from surfacing information to recommending or executing predefined actions, access to data isn’t enough. Institutions need the right context behind a recommendation and visibility into the systems that produced it. That’s where search and observability become part of the decision architecture: connecting relevant information across systems while helping teams understand whether the underlying technology is operating as intended. Autonomy doesn’t have to happen overnight. The path can move from connected information to AI-assisted investigation, evidence-backed recommendations, human-approved workflows, and selective automation within established controls. Move from decision latency to decision confidence: https://go.es.io/45ChWrK

صفحات مشابهة