
Author
Articles by Aaron Jewitt
Principal Security Analyst, Elastic
.jpg)
How to detect malicious browser extensions using Elastic
Learn how the Elastic Infosec team created a full inventory of all browser extensions using osquery and Elastic Security with examples on building detections to alert the security team when a known bad browser extension is installed on a workstation.

Detection engineering — Maximizing analyst efficiency using Cardinality Threshold rules on your alerts
Using Threshold rules to create alerts on your alerts is a great way to maximize your analyst effectiveness without sacrificing visibility. By using these rules, security analysts spend less time investigating false positives.
Sign up for Elastic Cloud free trial
Spin up a fully loaded deployment on the cloud provider you choose. As the company behind Elasticsearch, we bring our features and support to your Elastic clusters in the cloud.