CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Know who to watch before the incident finds you

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 623

As cited

Copy frozen at (site build).

identity access

Know who to watch before the incident finds you

Elastic Security v9.4 introduces Entity Analytics Watchlists, a feature that allows security teams to create weighted lists of users, hosts, and services to inject organizational context directly into the platform's risk scoring pipeline. The capability bridges the gap between what security teams know about their environment and what their SIEM can operationalize, without requiring engineering configuration or custom queries. Watchlist membership compounds with alert activity, asset criticality, and behavioral signals to produce prioritized risk scores.

Why it matters: Security teams and insider threat programs need to operationalize existing organizational knowledge about high-risk entities: this feature enables faster detection and prioritization of anomalies involving departing employees, privileged admins, and other elevated-risk targets without manual engineering overhead.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Know who to watch before the incident finds you

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Know who to watch before the incident finds you

Elastic Security version 9.4 adds Entity Analytics Watchlists, allowing teams to create named lists of users, hosts, and services and assign risk weightings that feed into the platform's risk scoring. The feature integrates with the security information and event management (SIEM) risk engine so that alerts from listed entities receive higher scores without requiring custom query language or detection engineering changes.

Why it matters: Security teams can now improve insider threat detection by feeding organizational knowledge into the SIEM risk engine, reducing the time to prioritize risky entities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary