# Elastic

<https://www.elastic.co/security/tip>

Make threat intelligence actionable and empower security teams — all through the same Elastic Security interface.

[Explore Threat Intelligence](https://www.elastic.co/blog/oct-2022-launch-announcement)

![](/files/OvkoFyjkZLErxbzd98Eb)

![](/files/LnaYF1gkWVuhbqXpRE85)

## Fully leverage your threat intel

Ease investigation and response to emerging threats in one place.

* Combine TI feeds

  Access all your active Indicators of Compromise (IoCs) in one centralized view.
* Investigate in real time

  Search, sort, and filter IoCs in real time to find and address threats faster.
* Contain attacks quickly

  Take action or add an IoC to a timeline to further the investigation process.

Many organizations lack the technology to view all relevant threat intelligence side-by-side in their SIEM and some lack the staff to automate the use of threat intelligence to improve protection. Elastic consolidates the artifacts of all active threat intelligence feeds into one view.

See full article

## Insights into threats just got easier

Elastic integrates with these leading threat intelligence providers.

* AbuseCH
* AlienVault OTX
* Anomali
* Cybersixgill
* MISP
* Recorded Future
* ThreatQuotient
* Rapid7 Threat Command
* Maltiverse

## TIP the scales in your favor

Intelligence to help you get ahead of threats.

* Gain contextual insights

  Learn from security researchers about recent malware, campaigns or attack patterns from [Elastic Security Labs](https://www.elastic.co/security-labs).
* See threats & take action

  Automatic visibility to Log4j, BLISTER, or CUBA allow you to make informed and immediate decisions.
* Context in one pane of glass

  Provides enough context so that investigators can take immediate action.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://book.konstantinsecurity.com/readme/architect/siem-soc/threat-intelligence/elastic.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
