# Looking for a list of "Out of the Box" Use Cases for Elastic SIEM

**URL:** <https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101>\
**Category:** SIEM\
**Created:** [September 13, 2021, 3:58pm UTC](https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101 "2021-09-13T15:58:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [September 13, 2021, 3:58pm UTC](https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101/1 "2021-09-13T15:58:22Z")

</div>

I am working on a secure project that is utilizing ELK SIEM and we are looking for Use Cases that we can direct the client towards for answering what the Elastic SIEM can do for them. Is there a link or area that I can use to answer common Use Case scenarios?

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [September 13, 2021, 4:34pm UTC](https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101/2 "2021-09-13T16:34:18Z")

</div>

Hey there @MKirby 👋

This post from @Frank_Hassanabad is a good summary of information available around what Elastic SIEM and now Elastic Security can do, so highly recommend checking that out!

> [@What can Elastic SIEM be used for?](https://discuss.elastic.co/t/what-can-elastic-siem-be-used-for/244637):
>
> (This was originally posted in [WHAT SIEM CAN DO?](https://discuss.elastic.co/t/what-siem-can-do/244483/2), and has been slightly adapted) SIEM and security is very broad and has many different context's depending on your individual and company goals as well as size and scope. This is a good starter you can sign up for - [https://www.elastic.co/training/elastic-siem-fundamentals](https://www.elastic.co/training/elastic-siem-fundamentals) We have lots of good blogs and series that go over a lot of different things as well - [https://www.elastic.co/blog/elastic-siem-for-small-business-and-home-1-getting-started](https://www.elastic.co/blog/elastic-siem-for-small-business-and-home-1-getting-started). …

* * *

Since then though, we've had _six additional releases_, and have added all sorts of new functionality, from Malware and Ransomware detection/prevention on Elastic Endpoint, introduction of OSQuery for host instrumentation, and the GA of Fleet/Elastic Agent for managing all your hosts and integrations. I highly recommend checking out the below release blog posts for all the details around the functionality and use-cases we've added since that original post.

Hope this helps, and please let us know if you have any additional questions around a specific topic in any of these posts -- cheers! 🙂

-Garrett

> **[Elastic Security 7.9 delivers anti-malware and collection, new cloud...](https://www.elastic.co/blog/whats-new-elastic-security-7-9-0-free-endpoint-security)**

> **[Elastic Security 7.10 equips the SOC to automate the detection and...](https://www.elastic.co/blog/whats-new-elastic-security-7-10-0-correlation-cloud-visibility-detection)**
>
> Elastic Security 7.10 delivers key new capabilities that drive greater SIEM value into the detection engine, enabling security teams to more easily detect complex threat behavior and move faster in addressing the most critical issues.

> **[What’s new in Elastic Security 7.11: Cloud and host ML jobs and detection...](https://www.elastic.co/blog/whats-new-elastic-security-7-11-0-cloud-host-detections-accessible-ui)**
>
> Elastic Security 7.11 delivers prebuilt ML jobs and detection rules for cloud apps and hosts, streamlined SecOps workflows, and enhanced usability and accessibility, supporting SIEM, endpoint security, and other use cases.

> **[What’s new in Elastic Security 7.12: Leave threats nowhere to hide](https://www.elastic.co/blog/whats-new-elastic-security-7-12-0-analyst-driven-correlation-ransomware-prevention)**
>
> Elastic Security 7.12 arms practitioners with analyst-driven correlation, behavioral ransomware prevention, and more.

> **[Elastic Security 7.13](https://www.elastic.co/blog/whats-new-elastic-security-7-13-0)**
>
> With embedded support for osquery, security teams can leverage centralized management and unified analysis of host data. And threat intelligence is now contextually presented in the Alert details panel on the Timeline workspace.

> **[Elastic Security 7.14: Limitless XDR protection](https://www.elastic.co/blog/whats-new-elastic-security-7-14-0)**
>
> Elastic Security 7.14 introduces the industry’s first free and open Limitless XDR solution, unifying the capabilities of SIEM and endpoint security. Elastic Agent helps prevent, detect, and respond to threats.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2021, 4:35pm UTC](https://discuss.elastic.co/t/looking-for-a-list-of-out-of-the-box-use-cases-for-elastic-siem/284101/3 "2021-10-11T16:35:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
