This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

La sécurité de nouvelle génération propulsées par l’IA

Download resources

About this session

Patrick Boulanger, a Montreal-based solutions architect at Elastic, walks through how Elastic Security uses AI to speed up detection, investigation and response. He opens with three challenges facing security operations: a growing attack surface from cloud, hybrid work and shadow IT; low-fidelity detections adversaries deliberately produce to hide in noise; and overloaded teams facing a global skills shortage. He positions Elastic's advantage as open source, so LLMs already understand the product, and as a long-standing generative-AI and vector-database vendor, then explains the data layer: cheap long-term storage, a large integration catalog, schema-on-write, and the Elastic Common Schema now adopted by OpenTelemetry. He demos two AI features built on roughly 1,500 detection rules: the AI Assistant, a RAG chat over a customer's own security data, and Attack Discovery, which correlates alerts into active attacks and drafts remediation. A live demo fails to connect. A long Q&A covers log-source agnosticism, rule maintenance, training-data provenance, hallucination risk, on-prem versus cloud, ticketing integrations, and how auditable the assistant's reasoning really is.

Plongez dans l’avenir de la cybersécurité Participez à notre session immersive sur les opérations de sécurité de nouvelle génération propulsées par l’intelligence artificielle. Découvrez comment Elastic Attack Discovery révolutionne les opérations de sécurité en exploitant des modèles de langage avancés (LLMs) pour analyser des centaines d’alertes et identifier celles qui comptent vraiment. D’un simple clic, cette fonctionnalité innovante : Automatise le tri des alertes : Elastic Attack Discovery passe au crible un volume massif d’alertes bruyantes, élimine les faux positifs et regroupe les signaux liés en chaînes d’attaque distinctes. Fournit des informations exploitables : Elle associe les alertes corrélées au cadre MITRE ATT&CK, met en évidence les utilisateurs et hôtes impliqués, et détaille les activités suspectes pour créer une narration complète des menaces potentielles. S’intègre parfaitement : Associée à l’assistant IA d’Elastic, cette fonctionnalité permet des requêtes de suivi en direct, offrant aux équipes de sécurité la possibilité d’approfondir leurs investigations, d’enrichir leur contexte de menace et d’accélérer leur réponse aux incidents. Au cours de cette session, vous assisterez à des démonstrations en direct d’Elastic Security, illustrant comment Attack Discovery permet de faire le tri dans le bruit, de réduire la fatigue liée aux alertes et de renforcer la capacité de votre SOC à répondre à des attaques complexes avec une rapidité et une précision inégalées. Rejoignez-nous pour découvrir comment ces outils pilotés par l’IA peuvent redéfinir vos opérations de sécurité et renforcer votre défense face aux menaces cyber émergentes.

Key takeaways

  • Keep at least six months of searchable security data online; that is the window Elastic says is typically needed to reconstruct an attack's full history.
  • Use a correlation tool like Attack Discovery to group low-fidelity, easy-to-dismiss alerts into attack chains instead of triaging hundreds of individual alerts by severity alone.
  • Adopt the Elastic Common Schema or OpenTelemetry conventions early so ingested data normalizes automatically instead of requiring custom parsing per source.
  • Before trusting an AI assistant's remediation output in production, ask the vendor directly about training-data provenance, hallucination safeguards and audit trails for its reasoning steps; this presenter could not fully answer that question live.
  • Treat retrieval-augmented generation and model fine-tuning as separate risk questions: RAG grounds answers in your own tenant data without training the model on it, but your chosen LLM provider still needs its own data-handling guarantees.

Speakers

Patrick Boulanger
Patrick Boulanger
Senior Solution Architect · Elastic
Patrick Boulanger - Senior Solutions Architect at Elastic With over four years of experience at Elastic, Patrick Boulanger supports businesses in adopting and optimizing Elastic solutions. As a Senior Solutions Architect, he plays a key role in… Read moreRead less

Patrick Boulanger - Senior Solutions Architect at Elastic With over four years of experience at Elastic, Patrick Boulanger supports businesses in adopting and optimizing Elastic solutions. As a Senior Solutions Architect, he plays a key role in customer success by providing demonstrations, technical validations, and strategic guidance. A regular speaker at meetups and events, he is a recognized voice of Elastic in Quebec.

Resources

Tags

More from GoSec 2025

Also from Patrick Boulanger

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.