proomt

Search

Search posts, papers, and topics

All posts

ElasticMia LaVada5 min readintermediate

The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic

Summary

Elastic Security achieved a perfect 100% score in AV‑Comparatives’ 2026 Endpoint Prevention and Response (EPR) test, stopping all 50 attack scenarios at the prevention stage with zero false positives or workflow delays. The test measured active prevention, passive detection, operational accuracy, and workflow impact across 14 vendors. Elastic’s claim is backed by open‑source protection rules and…

  • AV‑Comparatives EPR 2026 runs 50 multi‑phase attack scenarios based on MITRE ATT&CK tactics, covering executables, scripts, Office add‑ins, USB payloads, obfuscation, AMSI bypasses, and fileless techniques.
  • Elastic scored 100% on both Active Response (prevention) and Passive Response (detection) and reported zero operational accuracy costs or workflow delays, the lowest total cost of ownership among 14 vendors.
  • The product’s prevention rules are published in an open GitHub repo, and Elastic can ingest third‑party endpoint telemetry to provide unified detection and response.
  • Elastic’s Attack Discovery feature leverages a user‑chosen LLM to summarize alerts into an attack narrative, and the platform integrates with Osquery for live host queries.

Endpoint prevention that blocks attacks before execution can dramatically reduce alert fatigue, investigation time, and overall incident cost. A zero‑false‑positive score suggests that Elastic’s rules may be tuned to avoid the common trade‑off between detection coverage and operational noise, which…

4/10

Related reading

  1. GPT-6 Astra Is the First Model OpenAI Classifies as Critical for Cybersecurity

    OpenAI labeled GPT‑6 Astra as “Critical” for cybersecurity under its Preparedness Framework – the first model to meet that bar. In controlled tests the model autonomously discovered zero‑day bugs in a browser and an OS kernel, building working exploit chains in 29 h (browser) and 12 h (kernel). A benchmark of post‑cutoff vulnerabilities confirmed its ability to find unknown flaws. OpenAI reports…

    InfoQinfoq.com3 min
  2. Elastic announces GA of cross-project search on Serverless, enabling teams to query across all linked projects without moving a byte

    Elastic Cloud Serverless now offers General Availability of Cross‑Project Search (CPS), letting you run a single query across up to 100 linked projects (any region, cloud, or solution type) without moving data. Setup is UI‑driven, permissions are evaluated per‑project, and costs are $0.009 / GB retained plus $0.05 / GB egress. CPS works for Observability, Security, Search, vector DB, and ML jobs,…

    Elasticelastic.co6 minrelease
  3. Poisoned Documents, Real Risks: Sebastián Passaro Puts AI’s Weakest Link to the Test at Testear.la 2026

    Sebastián Passaro (Qubika) demonstrated a live RAG pipeline attack at Testear.la 2026, showing how a single poisoned document can hijack LLM outputs and trigger unsafe actions. He tied the demo to the OWASP LLM Top 10, highlighted open‑source tooling for finding such weaknesses, and advocated a defense‑in‑depth threat model for QA teams. The talk reframed AI from a testing aid to a security surfa…

    Moove-itqubika.com4 min