elastic / elastic/roadmap

Entity Analytics - Watchlist

Open
#158 0 comments 0 reactions 1 assignee Claimed by @erikh-elastic View on GitHub
product-area:security v9.4.0
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**Background:**

The Watchlist feature provides a way for analysts to manually tag and monitor high-risk entities. Besides alerts, security teams often have known risks they must monitor. These can include privilege administrators, C-level executives (high value targets), Departing Employers (potential insider threats), or concerning behaviors from machines or AI Agents.

**Value proposition**

Our watchlists serve as the ideal starting point for hypothesis-driven threat hunting. Instead of boiling the ocean, hunters can begin with a pre-curated, risk-scored list of entities that already warrant suspicion (e.g., "Privilege users", "Departing Employees", or "Unauthorized 3rdparty LLM Usage by Employees."). By reviewing the detailed behavioral baselines and anomalies for just this high-risk group, hunters can efficiently uncover sophisticated, low-and-slow attacks that would otherwise remain invisible.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.