#ElasticWorkflows
Elastic built an AI-assisted bug bounty triage system for HackerOne reports, using multi-stage analysis, adversarial review, and sandboxed reproduction. It matches human security engineers 85% of the time. #HackerOne #Elastic #GoogleCloud
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
Elastic built an AI-assisted bug bounty triage system to handle a surge of AI-generated HackerOne reports, using multi-stage analysis, adversarial review, and sandboxed reproduction on ephemeral Google Cloud VMs. The system agrees with human security engineers 85% of the time and uses Elastic-specific triage rules to distinguish real issues from features or out-of-scope reports while keeping a human in the final decision loop. #HackerOne #Elastic #Claude #ElasticWorkflows #GoogleCloudPlatform #Elasticsearch #Kibana
www.hendryadrian.com
August 5, 2026 at 1:15 AM
Elastic Workflows 9.4 advances native automation with production-ready stability, enhanced case management, AI integration, event-driven triggers, and new tools like Agent Builder and VirusTotal for improved triage. #ElasticWorkflows #WorkflowAutomation
Elastic Workflows GA: automation where your security data already lives
Elastic 9.4 delivers Elastic Workflows as a production-ready, built-in automation layer for Security, Observability, and Search with expanded case management, human-in-the-loop primitives, AI integration, and composable workflow features. The release also introduces event-driven triggers, execution-based pricing for Enterprise/Complete tiers, and integrations like Agent Builder and VirusTotal to streamline triage and investigations. #ElasticWorkflows #ChrysalisAPT
www.hendryadrian.com
May 5, 2026 at 8:15 AM
Elastic Workflows in Kibana automate alert triage using YAML playbooks to enrich alerts, run ES|QL queries, consult VirusTotal, create cases, and notify responders—scaling investigations with AI-driven classification and summaries. #ElasticWorkflows #AlertAutomation
Security Automation with Elastic Workflows: From Alert to Response
Elastic Workflows brings automation into Kibana to handle repetitive alert triage by running YAML-defined workflows that enrich alerts, query Elasticsearch, consult threat intel (e.g., VirusTotal), create cases, and notify responders. The article demonstrates a step-by-step alert triage playbook that includes ES|QL queries, connector-backed actions, conditional branching, and AI steps (classify, summarize, agent) to scale investigations and persist reasoning trails. #ElasticWorkflows #VirusTotal
www.hendryadrian.com
March 24, 2026 at 9:20 AM