Context
Security teams are racing to adopt Agentic SOCs (security operations centers) to improve their security; ironically, AI SOCs themselves can pose a serious security risk. Given the prevalence of untrusted data (malicious activity reports) and the capability for sensitive actions involved in incident response, AI SOCs are prime targets for indirect prompt injection attacks. We demonstrate this threat in EASE, Elastic's AI SOC.
Elastic’s Agentic SOC agent is susceptible to manipulation by the alerts it was created to triage, and it can take any action in Elastic with the user’s privileges; no human-in-the-loop approval is required.
In the attack chain below, the agent is manipulated into minting API keys and sending them to an attacker. The attacker can then take any action the user has permissions for, such as disabling detection rules, creating fake alerts to conceal a real attack, exfiltrating data from Elasticsearch, or deleting data from the tenant.
This vulnerability was reported to Elastic on August 23, 2026, but has not been addressed despite four follow-ups. As such, we are publishing this report to inform users of the risk and configurations to mitigate it. More details on responsible disclosure are at the end of the article.
The Attack Chain
The user asks the AI SOC for assistance triaging phishing alerts
One very common data source in a SOC is a phishing tipline, where users can forward suspicious emails for triage by the security team.
The user asks Elastic AI to triage phishing alerts. The AI SOC is manipulated by one of the alerts to create and execute a malicious workflow
One of the phishing emails the agent is trying to assess states that there are additional alerts to retrieve from a specific URL and that it should use a workflow with a subagent to handle them.
Elastic AI follows instructions embedded in an alert. The workflow retrieves data from an attacker-controlled URL and then spawns a subagent with no context other than the attacker's data and a system prompt: ‘Action the below’... leading the subagent to take whatever action the attacker’s server supplies.
The workflow retrieves an attacker-controlled prompt and runs a subagent. Note: This all occurs without human-in-the-loop approval because the agent has discretion over when to add a ‘waitForApproval’ step to its workflows, and the prompt injection discourages doing so.
Malicious workflow exfiltrates API keys
Here, the attacker’s server returns an instruction telling the subagent that it is participating in a competition. To win, it needs to mint new API keys and send them to the attacker’s server to ‘submit its findings’.
The attacker server logs API keys submitted by the subagent. Technical note: The attack also exfiltrated the workspace URL, which is necessary for the attacker to make requests using the exfiltrated API key.
Attacker exploits API access to take unauthorized actions in the SOC and exfiltrate data
The attacker uses stolen API keys to query data and modify alert rules. Using the exfiltrated credentials, the attacker can take any action a user could. This includes:
- Disabling or removing alert rules
- Creating fake alerts to cover for a real attack
- Exfiltrating data from across Elastic and integrations
- Establishing persistence through scheduled jobs
- Harvesting data from devices monitored by the AI SOC
We also note that all of these outcomes can be achieved directly via a workflow run by a manipulated subagent, rather than using the workflow to exfiltrate keys and proceeding from there.
Mitigations
Agent configurations:
Disable the Elastic AI Agent setting “Include built-in capabilities automatically” to allow manual management of which tools are enabled.
Your Project > Agents (left sidebar) > Overview > Edit Agent Settings > Customization > Include built-in capabilities automatically > Toggle OFF
We then recommend disabling write-capable tools, as the system does not currently appear to support human-in-the-loop approval controls, except for ‘waitForApproval’ workflow steps, which are used only at the agent’s discretion.
Your Project > Agents (left sidebar) > Elastic AI Agent (Dropdown) > Manage Agents > Hover 'Elastic AI Agent', click Edit icon that appears > Tools Tab > Uncheck unwanted Tools
The following tools, which are enabled by default on the default agent, carry the highest risk:
- Platform.core.execute_esql
- Platform.core.execute_workflow
We also highly recommend disabling the setting to automatically assign all current and future Elastic-built tools, Skills, and Plugins to the agent.
Your Project > Agents (left sidebar) > Elastic AI Agent (Dropdown) > Manage Agents > Hover 'Elastic AI Agent', click Edit icon that appears > Setting Tab > Elastic Capabilities > Toggle OFF
Default model selection
Currently, the default model in Elastic is Anthropic Claude Sonnet 4.5.
Elastic AI’s default model is Anthropic Claude Sonnet 4.5. More recent models are substantially more robust against indirect prompt injection. Configure an alternative default model via:
Your Project > Discover Elastic AI / Configure AI Provider > Select Provider > Select model in dropdown
IP Access Restrictions
To restrict ingress and egress from Elastic Cloud to and from untrusted IPs, configure Network Security policies under:
Organization Settings > Network Security > Create Policy
Responsible Disclosure
PromptArmor disclosed the vulnerabilities described in this article on August 23, 2026. Elastic acknowledged receipt of the report but did not engage with the disclosure despite four follow-ups. As such, we are publishing to inform users of the risks and pertinent controls to mitigate them.
We note that Elastic’s reporting policy explicitly permits email disclosure, stating, “If you do not wish to use the bug bounty program, you may email us directly at security@elastic.co.".
Timeline
| Date | Event |
|---|---|
| August 23, 2026 | PromptArmor discloses to Elastic |
| August 27, 2026 | PromptArmor follows up |
| August 28, 2026 | Elastic requests submission via HackerOne |
| August 28, 2026 | PromptArmor clarifies email preference |
| September 1, 2026 | PromptArmor follows up, citing email as documented reporting channel |
| September 6, 2026 | PromptArmor follows up |