THREAT OPS › Threat News › One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless
One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless
<p>Run security operations for more than one team, region, or customer, and you inherit a familiar tradeoff. One giant deployment gives you a single view but costs you tenant isolation, while separate environments preserve isolation and scatter your analysts across contexts, with detection rules drifting into 12 slightly different copies along the way. <a href="https://www.elastic.co/blog/cross-pr
MITRE ATT&CK techniques
- ServerlessT1583.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- https://cloud.elastic.co/registrationurl
- static-www.elastic.codomain