- They said that Cmd will add runtime security capabilities to Elastic Limitless XDR, unifying security information and event management (SIEM), endpoint, and cloud security
- Elastic will integrate Cmd’s cloud-native data collection and protection using eBPF directly into the Elastic Agent, and integrate Cmd’s innovative and practitioner-oriented user experience and workflows directly into Kibana
Elastic has entered into a definitive agreement to acquire Cmd, a leader in infrastructure detection and response (IDR) to give customers deep visibility into cloud workloads and perform expert detection and prevention on cloud-native data.
They said that Cmd will add runtime security capabilities to Elastic Limitless XDR, unifying security information and event management (SIEM), endpoint, and cloud security from build-time, to deployment-time, to runtime, all in a single search platform.
Elastic Security provides kernel-level visibility into Linux systems and Linux protection capabilities such as malware prevention and advanced MITRE ATT&CK-mapped Linux rules. With Cmd, Elastic will expand its security capabilities for cloud-native runtime application workloads using extended Berkeley Packet Filter (eBPF) technology.
They added, “As a leader in eBPF, Cmd provides deep and performant visibility into cloud workloads, enabling developers to rapidly innovate and deliver entirely new observability and security outcomes for users. eBPF has revolutionized how organizations observe and protect cloud workloads and is a cornerstone of efficient, safe, and all-encompassing observability for Linux.
Elastic will integrate Cmd’s cloud-native data collection and protection using eBPF directly into the Elastic Agent, and integrate Cmd’s innovative and practitioner-oriented user experience and workflows directly into Kibana. Elastic customers will benefit from the cloud-native security capabilities of Cmd, while Cmd customers will be able to take advantage of Elastic Limitless XDR, including hundreds of stateful detections and machine learning models mapped to MITRE ATT&CK, built-in case workflows, client security on Windows and macOS, and anti-malware prevention on Linux.