THREAT OPS › Threat News › SOC case management and detection rule history in Elastic Security
SOC case management and detection rule history in Elastic Security
<p>Elastic Security now tracks every change to a detection rule and lets you roll back to any previous version with one click. The same history log gives compliance teams a timestamped audit trail that's immutable and append-only. Case data is queryable across 3 global indices (down from 12 per space), so SOC managers can build dashboards on closure rates, assignment load, and case volume without
MITRE ATT&CK techniques
- ServerlessT1583.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- https://join.slack.com/t/elasticstack/shared_invite/zt-2sgssfr0n-NhTOlSwHbaGH85tYfx6kGgurl