As cited
Copy frozen at (site build).
cloud saas
SOC case management and detection rule history in Elastic Security
Elastic Security 9.5 introduces detection rule change history with point-in-time comparisons and one-click rollback, creating an immutable audit trail for compliance. Case management gains customizable templates with new field types and enforcement options, while case analytics now ship enabled by default across three global indices instead of requiring manual configuration per space. These features enable SOC teams to track investigation data consistently and debug rule changes without external tooling.
Why it matters: Security operations and compliance teams need reliable audit trails for detection rule changes and investigation case data to meet standards like SOC 2, ISO 27001, and DORA; these GA features eliminate manual configuration work and provide out-of-box dashboarding on case metrics and rule history.
- Source published
- First seen by Cybersecurity Tracker