THREATOPS
THREAT OPSThreat News › SOC case management and detection rule history in Elastic Security

SOC case management and detection rule history in Elastic Security

medelastic_securityPublished 2026-08-03

<p>Elastic Security now tracks every change to a detection rule and lets you roll back to any previous version with one click. The same history log gives compliance teams a timestamped audit trail that's immutable and append-only. Case data is queryable across 3 global indices (down from 12 per space), so SOC managers can build dashboards on closure rates, assignment load, and case volume without

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/soc-case-management-detection-rule-history