
- TOP
- ã¿ã°äžèЧ
- èªç¶èšèªåŠç
èªç¶èšèªåŠç
ã€ãã³ã

ãã¬ãžã³
æè¡ããã°
ã¯ããã« ããã«ã¡ã¯ãã«ã±ãã·ã§ããŒã¿ãµã€ãšã³ãã£ã¹ããããŠããå·éã§ãã 2026幎3æ9æ¥ã13æ¥ã«æ æšçå®éœå®®åžã®ã©ã€ããã¥ãŒãå®éœå®®ã§éå¬ããããèšèªåŠçåŠäŒç¬¬32å幎次倧äŒïŒNLP2026ïŒã«åå ããŠããŸããã ã«ã±ãã·ã¯ãã©ããã¹ãã³ãµãŒãšããŠåè³ããã¹ãã³ãµãŒããŒã¹ã®åºå±ã«å ãããã¹ã¿ãŒçºè¡šãè¡ããŸãããæ¬èšäºã§ã¯ãçºè¡šå
容ã®ç޹ä»ãåŠäŒã®æ§åãæ°ã«ãªã£ãçºè¡šã«ã€ããŠã¬ããŒãããŸãã NLP2026ã«ã€ã㊠èšèªåŠçåŠäŒå¹Žæ¬¡å€§äŒã¯ãèªç¶èšèªåŠçïŒNLPïŒã«é¢ããåœå
æå€§çŽã®åŠè¡äŒè°ã§ããä»å¹Žã¯åå è
çŽ2,300åè¶
ãçºè¡š797ä»¶ãšãããããæŽä»£æå€ã®èŠæš¡ã§ã®éå¬ãšãªããŸããã ä»å¹ŽâŠ
æ
å ±æºïŒ Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floor Elastic Security Labs ã«æ²èŒããã DCM26 ã®èšäºãããšã«ãæ¬ããã°ã§ã¯æ§æãèšèšäžã®ãã€ã³ããæŽçããŸãã ãµã€ãªã¹ãã¯ãããžãŒæ ªåŒäŒç€Ÿ Saman ã€ã®ãªã¹åœé²çäž»å¬ã® Defence Cyber Marvel 2026ïŒDCM26ïŒ ã¯ãäŒçµ±çãªITãããã¯ãŒã¯ãäŒæ¥ç°å¢ãè€éãªç£æ¥å¶åŸ¡ã·ã¹ãã ã察象ã«ãããè±åœæå€§çŽã®è»äºãµã€ããŒæŒç¿ã§ãã圢åŒãšããŠã¯ force-on-force å ãæ¡çšãããŠãããé²åŸ¡ãæ
ã Blue Team ãæ
åœã·ã¹ãã ãå®ããæ»æãæ
ã Red Team ãããŸããŸãªææ³ã§äŸµå
¥ã劚害ã詊ã¿ãŸããããã«ããã®æ»é²ã White Team ãç£èŠããã·ã¹ãã å¯çšæ§ãæ»ææ€ç¥ãã€ã³ã·ãã³ãå ±åã埩æ§ç¶æ³ãªã©ãããšã«è©äŸ¡ããŸããã€ãŸã DCM26 ã¯ãåãªãè£œåæ€èšŒããã¢ã§ã¯ãªããæ»æã»é²åŸ¡ã»è©äŸ¡ãåæã«é²ã宿Šåã®æŒç¿ãšããŠèšèšãããŠããŸããã DCM26ã«ã¯ 29ã«åœã»70çµç¹ãã 2,500人以äžãåå ãã5,000ãè¶
ããä»®æ³ã·ã¹ãã ã皌åããŸãããæŒç¿ã¯ 2026幎2æã«5æ¥éã«ããã£ãŠè¡ãããã·ã³ã¬ããŒã«ã® Exercise Control ãäžå¿ã«éå¶ãããŸãããBlue Team ã¯å°ççã«åæ£ããç¶æ
ã§åå ããè±åœå
ãæµ·å€ã®æ ç¹ãã VPN çµç±ã§æŒç¿ç°å¢ã«æ¥ç¶ããŠããŸããããã®åæã ãã§ããåå è
å
šå¡ã«åãç°å¢ãå®å
šã«é
åžããããŒã ããšã«å³å¯ã«åé¢ããªãããæ»æãšé²åŸ¡ãåæã«æç«ãããå¿
èŠããã£ãããšãããããŸãã ããããåæã®äžã§ãElastic 㯠DCM26 å
šäœã圹å²ããšã«ç°ãªãåœ¢ã§æ¯ããŠããŸãããç¹ã«äžå¿ãšãªã£ãã®ã¯ Blue Team åãã®åäžãã«ãããã³ãåºç€ã§ãããããã«å ã㊠Red Team åãã«ã¯ C2 å¯èŠåçšã®å°çšãããã€ã¡ã³ããNSOC åãã«ã¯æŒç¿å
šäœãš AI å©çšç£æ»ãæ
ãå°çšãããã€ã¡ã³ããçšæãããŠããŸãããã€ãŸã Elastic ã¯ãæ»æã»é²åŸ¡ã»éå¶ã®åã¬ã€ã€ãŒãããããã«åã£ãæ§æã§æ¯ããŠããã®ã§ãã ç®æ¬¡ Blue Teamåºç€ã®èšèš ããŒã¿åé¢ã®ä»çµã¿ äºåæ€èšŒãšè² è·ãã¹ã æŒç¿åãã®é²åŸ¡èšå® Red TeamãšNSOCã®åºç€ AI掻çšã®ã¬ããã³ã¹ Attack Discoveryã®åœ¹å² 3ã€ã®AI掻çšã¬ã€ã€ãŒ ææ
åæãšãã詊㿠ãŸãšã çšèªé Blue Teamåºç€ã®èšèš Blue Team åãã®äžå¿æ§æã¯ãåäžã® Elastic Cloud ãããã€ã¡ã³ã ãããŒã¹ã«ãããã«ãããã³ãèšèšã§ãããèšäºã§ã¯ã40ã® defending Blue Teams ãæ¯ããåäžãããã€ã¡ã³ããäžæ žãšããŠç޹ä»ãããããŒã ããšã®åé¢ã«ã¯ Kibana Spaces ãš datastream namespaces ã䜿ãããŠãããšèª¬æãããŠããŸãã ãã®èšèšã®äŸ¡å€ã¯ãèŠæš¡ã倧ããã»ã©ã¯ã£ããããŸããåããŒã ã«åå¥ã¯ã©ã¹ã¿ãå²ãåœãŠãã°åé¢ã¯ããããäžæ¹ã§ãæ§ç¯ã»æŽæ°ã»ç£èŠã®è² è·ãæ¥å¢ããŸããéã«ãåäžãããã€ã¡ã³ãã«éçŽãã€ã€ Spaces ãšæš©éå¶åŸ¡ã§ããŒã åäœã«åããã°ãæšæºåãããããå
šäœéçšãçŸå®çã«ãªããŸããDCM26ã¯ããã®ãã«ãããã³ãæ¹åŒãå€§èŠæš¡æŒç¿ã«é©çšããå®äŸã§ããã ããŒã¿åé¢ã®ä»çµã¿ ãã®æ§æã§ã¯ãèŠãç®ã®ã¯ãŒã¯ã¹ããŒã¹ãåããã ãã§ãªããããŒã¿ã®æµãèªäœãããŒã åäœã§æŽçãããŠããŸãããåããŒã ã«ã¯ bt_01_deployed ã bt_01_hostnation ã®ãã㪠datastream namespace ãå²ãåœãŠãããèªã¿åãæš©éããã® namespace ã«å¿ããŠå¶åŸ¡ãããŠããŸãããèªèšŒã¯ Keycloak SSO ãš Elasticsearch ã® role mapping ã§ã€ãªãããŠãããã©ã®ãŠãŒã¶ãŒãã©ã®ããŒã 空éã«å
¥ããããæç¢ºã«ç®¡çãããŠããŸããã ãã®ç¹ãéèŠãªã®ã¯ããã«ãããã³ãç°å¢ã§æ¬åœã«é¿ãããã®ã¯ UI äžã®èŠãæ¹ã§ã¯ãªããããŒã¿å¢çã®ç Žã ã ããã§ããDCM26ã§ã¯ãSpacesã»ããŒã¿ã¹ããªãŒã ã»èªèšŒã»æš©éã®åã¬ã€ã€ãŒãããããããšã§ãæŒç¿ã«å¿
èŠãªå³æ Œãªåé¢ãæç«ãããŠããŸããã äºåæ€èšŒãšè² è·ãã¹ã ãã®ã¢ãŒããã¯ãã£ã¯ãã¶ã£ã€ãæ¬çªã§æ¡çšãããããã§ã¯ãããŸãããäºåã«ã¯ 50 ã® Kibana Spaces ãçšæããspace-scoped Fleet policies ãäœæããããã§ã6,000å°ã® EC2 ã€ã³ã¹ã¿ã³ã¹ã䜿ã£ãè² è·æ€èšŒãè¡ãããŸãããããã§ç¢ºèªãããã®ã¯ãããŒã¿æŒãããèµ·ããªãããšãFleet ããªã·ãŒæŽæ°ã 60 ç§ä»¥å
ã«äŒæããããšãspace ããšã«çµã£ãæ€çŽ¢ãé«è² è·ã§ãé«éã«åäœããããšãªã©ã§ãã ãŸãã6,000å°ãäžåºŠã«èµ·åããããšãããš AWS EC2 API ã®ã¬ãŒãå¶éã«åœããããã500å°ãã€æ®µéçã«èµ·åããéã« 5 åã®ã¯ãŒã«ãªããæã圢ã§å±éããŠããŸãããããããå°éãªèª¿æŽãå«ããŠå€§èп𡿧æãå®éçšã¬ãã«ã«åŒãäžããŠããç¹ã¯ããã®äºäŸã®å€§ããªäŸ¡å€ã§ãã æŒç¿åãã®é²åŸ¡èšå® Blue Team ã«ã¯ãSystemãElastic DefendãWindows event forwardingãAuditdãNetwork Packet Capture ãªã©ã®çµ±åãé
åžãããŠããŸããããã ãã Elastic Defend ã¯ãã®ãŸãŸã ãšé²åŸ¡åãé«ããããããæŒç¿äžã¯ Prevent mode ãç¡å¹ã«ããDetect-only mode ã§äœ¿ãããŠããŸãã ãããã« Memory Threat Prevention and Detection ããæŒç¿ã®å€§éšåã§ã¯ç¡å¹åãããŠããŸããã ãããããããã®ã¯ãDCM26ãåã«ãè£œåæ©èœãæå€§éèŠããå Žãã§ã¯ãªãã£ããšããããšã§ããéèŠã ã£ãã®ã¯ãé²åŸ¡åŽããã¡ããšæ€ç¥ãã倿ãã察å¿ããèšç·Žãæç«ãããããšã§ããããã®ããã«ã補åã®åŒ·ãããããŠå¶éãã倿ãåãããŠããã®ã§ãã Red TeamãšNSOCã®åºç€ Blue Team åãã®äžå¿åºç€ãšã¯å¥ã«ãRed Team åãã®å°çš Elastic ãããã€ã¡ã³ããšãNSOC åãã®å°çšãããã€ã¡ã³ããçšæãããŠããŸãããRed Team åŽã§ã¯ãTuoni ãšãã C2 ãã¬ãŒã ã¯ãŒã¯ã®ç¶æ
ãããŒã³ã³ã®ã³ãŒã«ããã¯ãæ»æãªãã¬ãŒã·ã§ã³ã®é²è¡ç¶æ³ã芳枬ããããã®åºç€ãšã㊠Elastic ã䜿ãããŠããŸããã äžæ¹ã® NSOC ã§ã¯ãæŒç¿å
šäœã®ãã«ã¹ç¶æ³ãã»ãã¥ãªãã£ç£èŠã«å ããAIå©çšã®ç£æ»ã察象ã«å«ãŸããŠããŸãããç¹ã« Bedrock API ã®åŒã³åºã㯠CloudWatch ã«èšé²ãããããã NSOC åŽã® Elastic ãããã€ã¡ã³ããã芳枬ã§ããããã«ãªã£ãŠããŸãããAIããŸããç£èŠãããã¹ãéçšå¯Ÿè±¡ãšããŠæ±ãããŠããããã§ãã AI掻çšã®ã¬ããã³ã¹ DCM26ã§ã¯ AWS Bedrock ãåºç€ãšã㊠AI ãæŽ»çšããŠããŸããããéçšã¯ããªãæ
éã«èšèšãããŠããŸãããBedrock Guardrails ã«ããããã€ããäŸ®èŸ±ãæ§çå
å®¹ãæŽåãšãã£ãäžé©åã³ã³ãã³ããPIIãããã«å®éã®æ©å¯äœæŠãçŸå®äžçã®è»äºæŽ»åã«é¢ãã話é¡ãå¶éããŠããŸããã ãã®ç¹ã¯ãäŒæ¥ã§çæAIãå°å
¥ãããšãã«ãéèŠã§ããå
ã«åãããã®ã¯ãã©ãã»ã©è³¢ãããã§ã¯ãªãããäœãæ±ãããŠããããã誰ã䜿ã£ããã远跡ã§ãããããæ±ã£ãŠã¯ãããªãæ
å ±ã«è§Šããªãããã§ããDCM26ã¯ãAIã®æ§èœä»¥åã«ãAIãå®å
šã«éçšããããã®æ¡ä»¶ãåºããŠããäºäŸãšããŠèªããŸãã Attack Discoveryã®åœ¹å² æŒç¿äžãBlue Team ã¯å€§éã®ã¢ã©ãŒãã«åãåãå¿
èŠããããŸãããããã§æå¹ã ã£ãã®ã Attack Discovery ã§ããè€æ°ã®ã¢ã©ãŒããçžé¢ããæ»æã®æµããã¹ããŒãªãŒãšããŠæŽçããããšã§ãå¹³åå¯Ÿå¿æéã®ççž®ã alert fatigue ã®è»œæžã«åœ¹ç«ã£ããšèª¬æãããŠããŸãã ããã§ã®åœ¹å²ã¯ããã¹ãŠãèªåã§è§£æ±ºããããšã§ã¯ãããŸãããã°ãã°ãã®ã·ã°ãã«ãæŽçããäœããèŠãã¹ããã倿ããããããããšã§ããã€ãŸããé²åŸ¡åŽã®å€æã眮ãæããã®ã§ã¯ãªãã 倿ããããç¶æ
ãäœã ããã®æ¯æŽãšããŠäœçœ®ã¥ããããŠããŸããã 3ã€ã®AI掻çšã¬ã€ã€ãŒ DCM26ã®AI掻çšãçè§£ããããã§ã¯ããã®3ã€ãæ··ããªãããšã倧åã§ãããŸã Elastic AI Assistant ã Attack Discovery ã¯ãElastic Security ã®æšæºæ©èœãšããŠãé²åŸ¡åŽã®èª¿æ»ãã¢ã©ãŒãçè§£ãå©ãã圹å²ãæ
ã£ãŠããŸããã äžæ¹ã§ Agent Builder ã¯ã圹å²å¥ã®ã«ã¹ã¿ã AIãšãŒãžã§ã³ããäœãããã«äœ¿ãããŠããŸãããå
šåå è
åãã® IT ãµããŒããæ
ã GrantPT ãWhite Team åãã®æ¡ç¹æ¯æŽãæ
ã RefPT ãRed Team åãã®æ»ææ¯æŽãæ
ã Red Rock ããã®äŸã§ããGrantPT ã¯æé æžãéå»ã®ãµããŒããã±ãããåç
§ããRefPT ã¯æåºã¬ããŒããæŒç¿ã€ãã³ããããšã«æ¡ç¹ãæ¯æŽããRed Rock ã¯è匱æ§ãæ»æãã¯ãã«ã®ç¥èã䜿ã£ãŠ Red Team ãå©ããŠããŸããã ããã« Tines 㯠AI ãã®ãã®ã§ã¯ãªããèªååãããŒã®åºç€ãšããŠäœ¿ãããŠããŸããããµããŒãèŠæ±ãçºçãããš Tines ãåããBedrock AI ãšé£æºããªããéå»ã®è§£æ±ºçãåç
§ããŠå¿çãè£å©ãããµããŒããã¥ãŒã®è² è·ãäžããŠããŸãããã€ãŸããElastic AI Assistant ã¯èª¿æ»æ¯æŽãAgent Builder ã¯åœ¹å²ç¹åã®ãšãŒãžã§ã³ãæ§ç¯ãTines ã¯éçšèªååãšãããããã®åœ¹å²ã¯æç¢ºã«åãããŠããŸãã ææ
åæãšãã詊㿠æŒç¿äžã«ã¯ RocketChat ã®äŒè©±å
šäœã Elastic ã«åã蟌ã¿ãNamed Entity Recognition ãšææ
åæãéããŠãäŒè©±å
容ãããŒã ç¶æ
ã®å€åãæããåãçµã¿ãè¡ãããŸãããæ»æãé害ã ãã§ãªããåå è
åŽã®ã¹ãã¬ã¹ãæ··ä¹±ã®å
åããéå¶ãææ¡ãã察象ã«å«ãŸããŠããããã§ãã å€§èŠæš¡æŒç¿ã§ã¯ãã·ã¹ãã ç°åžžã ãã§ãªãã人ã®ç²åŽãæ
å ±éå€ãææã«çŽçµããŸããElastic ããã°ä»¥å€ã®ããã¹ãããŒã¿ãåãåºç€ã§æ±ããããšããããããéå¶ã®ç«äœåã«ã€ãªãã£ãŠããŸããã ãŸãšã DCM26ã瀺ããã®ã¯ãAIã®äŸ¡å€ã¯åã«ã¢ãã«ãå°å
¥ããããšã§ã¯çãŸããªãããšããããšã§ããå€§èŠæš¡ããŒã¿ãåŠçã§ããåºç€ãããŒã ããšã«å³å¯ã«åé¢ãããèšèšãã¢ã©ãŒããæèåããæ©èœã圹å²å¥ã«äœããããšãŒãžã§ã³ãããã㊠AI å©çšãã®ãã®ãç£æ»ã§ããéçšã¢ãã«ãããããããã£ãŠã¯ãããŠãAIã¯å®æŠçãªäŸ¡å€ãæã¡ãŸãã Elastic ã¯ãã®æŒç¿ã§ãåãªããã°åºç€ã SIEM ãšããŠã§ã¯ãªããå¯èŠåã»æ€ç¥ã»AIæ¯æŽã»èªåå飿ºãã€ãªãäžæ žãšããŠæ©èœããŠããŸããããã ããã㯠Elastic åç¬ã§å®çµãã話ã§ã¯ãªããAWS BedrockãTinesãTuoni ãªã©ãšã®é£æºãå«ããŠæç«ããæ§æã§ããDCM26ã¯ãAIæä»£ã®ã»ãã¥ãªãã£åºç€ã«å¿
èŠãªã®ãåŒ·ãæ©èœã®å¯ãéãã§ã¯ãªããå®å
šã«éçšã§ããäžè²«ããèšèš ã§ããããšã瀺ããäºäŸã ãšèšããã§ãããã çšèªé Elastic æ€çŽ¢ããã°åæãã»ãã¥ãªãã£ç£èŠãå¯èŠ³æž¬æ§ãªã©ããŸãšããŠæ±ãããã©ãããã©ãŒã ã§ãã倧éã®ããŒã¿ãéããŠãèŠããåããåæããç°åžžãæ»æã®å
åãèŠã€ããããã«äœ¿ãããŸãã ä»®æ³ã·ã¹ãã ç©ççãªå°çšæ©åšã§ã¯ãªãããœãããŠã§ã¢äžã§åããµãŒããŒã端æ«ç°å¢ã®ããšã§ããã¯ã©ãŠããä»®æ³åæè¡ã䜿ã£ãŠã倿°ã®ã·ã¹ãã ãæè»ã«çšæã§ããŸãã ã€ãã³ã ã·ã¹ãã äžã§èµ·ããåºæ¥äºãèšé²ãããã®ã§ããããšãã°ãã°ã€ã³ããã¡ã€ã«äœæãéä¿¡ããšã©ãŒçºçãªã©ãã€ãã³ãã§ãã EPSïŒEvents Per SecondïŒ 1ç§ãããã«åŠçãããã€ãã³ãæ°ã§ãããã°ãã»ãã¥ãªãã£ã€ãã³ããã©ãããã倧éã«æµããŠããããèŠãç®å®ã§ãã ãã«ãããã³ã 1ã€ã®å€§ããªã·ã¹ãã ããè€æ°ã®ããŒã ãçµç¹ã§å
±çšããèãæ¹ã§ããããšãã°1ã€ã®å»ºç©ã®äžã«ãå¥ã
ã®äŒç€Ÿãããããå°çšã®éšå±ãæã£ãŠå
¥ã£ãŠããã€ã¡ãŒãžã§ãã ããã³ã ãã«ãããã³ãç°å¢ã®äžã§ãåããŒã ãåçµç¹ã«å²ãåœãŠãããç¬ç«ããå©çšé åã®ããšã§ãã ã¢ã¯ã»ã¹å¶åŸ¡ 誰ãã©ã®ããŒã¿ãæ©èœã䜿ããããæ±ºããä»çµã¿å
šäœãæããŸãã ã€ã³ãã©èªåå ãµãŒããŒæ§ç¯ãèšå®åæ ããœãããŠã§ã¢é
åžãªã©ãæäœæ¥ã§ã¯ãªãèªåã§è¡ãèãæ¹ã§ããå€§èŠæš¡ç°å¢ã»ã©éèŠã«ãªããŸãã Kibana Elasticã«å
¥ã£ãããŒã¿ãç»é¢ã§èŠãããæ€çŽ¢ããããã°ã©ããããã·ã¥ããŒããäœã£ããããããã®ç»é¢ããŒã«ã§ãã Kibana Spaces Kibanaã®äžã§ãããŒã ããšã«ç»é¢ãããã·ã¥ããŒããèšå®ãåããããã®ä»çµã¿ã§ããåãKibanaã䜿ã£ãŠããŠããããŒã Aã«ã¯Açšã®ç»é¢ãããŒã Bã«ã¯Bçšã®ç»é¢ãèŠããããŸãã Keycloak SSOããŠãŒã¶ãŒèªèšŒãæš©é管çãè¡ãããã®ãœãããŠã§ã¢ã§ãã誰ãã©ã®ãµãŒãã¹ã«å
¥ããããäžå
çã«ç®¡çã§ããŸãã SSOïŒSingle Sign-OnïŒ äžåºŠã®ãã°ã€ã³ã§ãè€æ°ã®ã·ã¹ãã ã䜿ããããã«ããä»çµã¿ã§ããäœåºŠãå¥ã
ã«IDãšãã¹ã¯ãŒããå
¥ããªããŠæžã¿ãŸãã èªåã¹ã±ãŒãªã³ã°ïŒAutoscalingïŒ è² è·ãå¢ãããšãã«ãå¿
èŠãªãªãœãŒã¹ãèªåã§å¢ããä»çµã¿ã§ããéã«è² è·ãæžãã°çž®å°ã§ããŸãã RBACïŒRole-Based Access ControlïŒ åœ¹å²ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ã§ããããã®äººã¯ãã®åœ¹å²ã ããããã®ããŒã¿ã ãèŠãããããšããããã«ãããŒã«ã«å¿ããŠæš©éãæ±ºããèãæ¹ã§ãã DLSïŒDocument Level SecurityïŒ ããã¥ã¡ã³ãåäœã®ã¢ã¯ã»ã¹å¶åŸ¡ã§ããåãããŒã¿ããŒã¹ã®äžã§ããããã®ãŠãŒã¶ãŒã«ã¯ãã®ææžã ãèŠããããå¥ã®ææžã¯èŠããªãããšçްããå¶åŸ¡ã§ããŸãã ããã¥ã¡ã³ã Elasticã®äžã«ä¿åããã1ä»¶1ä»¶ã®ããŒã¿ã®ããšã§ããããšãã°1ã€ã®ãã°èšé²ã1ã€ã®ã€ãã³ãèšé²ã1ããã¥ã¡ã³ãã«ãªããŸãã AIã¬ããã³ã¹ AIãå®å
šãã€é©åã«äœ¿ãããã®ç®¡çã®èãæ¹ã§ããäœãAIã«ãããããäœãçŠæ¢ããããèšé²ãã©ãæ®ãããªã©ã決ããŸãã PIIïŒPersonally Identifiable InformationïŒ å人ãç¹å®ã§ããæ
å ±ã®ããšã§ããæ°åãé»è©±çªå·ãã¡ãŒã«ã¢ãã¬ã¹ãªã©ã代衚äŸã§ãã ç£æ»ã㰠誰ãããã€ãäœãããããèšé²ãããã°ã§ããããšã§è¿œè·¡ã確èªãã§ããããã«æ®ããŸãã CloudWatch AWSäžã®ãã°ãã¡ããªã¯ã¹ãç£èŠã»ä¿åãããµãŒãã¹ã§ãã AWS Amazon Web Servicesã®ç¥ã§ããAmazonãæäŸããã¯ã©ãŠããµãŒãã¹çŸ€ã®ããšã§ãã IaCïŒInfrastructure as CodeïŒ ã€ã³ãã©ãã³ãŒãã§ç®¡çããæ¹æ³ã§ãããµãŒããŒãèšå®ãæäœæ¥ã§äœãã®ã§ã¯ãªããèšå®ãã¡ã€ã«ãã³ãŒãã§èªåçã«äœããããã«ããŸãã Terraform IaCãå®çŸãã代衚çãªããŒã«ã®1ã€ã§ããã¯ã©ãŠãç°å¢ãã€ã³ãã©æ§æãã³ãŒãã§å®çŸ©ããåãç°å¢ãäœåºŠã§ãåçŸã§ããŸãã HashiCorp Vault ãã¹ã¯ãŒããããŒã¯ã³ãèªèšŒæ
å ±ãªã©ã®ç§å¯æ
å ±ãå®å
šã«ä¿ç®¡ã»é
åžããããã®ããŒã«ã§ãã Catapult èšäºå
ã§ã¯ãç£èŠãšãŒãžã§ã³ãã®å±éãèªååããããã«äœ¿ãããããŒã«ãšããŠç»å ŽããŸãã倧éã®ç°å¢ã«åãèšå®ãäžæ¬ã§é
ã圹å²ãæã¡ãŸãã Fleet ãšãŒãžã§ã³ããšéä¿¡ããèšå®ãé
ä¿¡ããããã®ä»²ä»ãµãŒããŒã§ãã ããªã·ãŒ ã·ã¹ãã ã«é©çšããèšå®ã«ãŒã«ã®ããšã§ããããšãã°ããã®ãã°ãéãããããã®æåãç£èŠããããªã©ãå®çŸ©ããŸãã ãšãŒãžã§ã³ã åãµãŒããŒã端æ«ã«å
¥ããŠããã°åéãç£èŠãè¡ãå°ããªããã°ã©ã ã§ãã ããŒã¿ã¹ããªãŒã ïŒData StreamïŒ æç³»åã§å¢ãç¶ããããŒã¿ãå¹çããä¿åã»ç®¡çããããã®ä»çµã¿ã§ãããã°ãç£èŠããŒã¿ã®ããã«ãæéãšãšãã«ã©ãã©ã远å ãããããŒã¿ã«åããŠããŸãã ILMïŒIndex Lifecycle ManagementïŒ ã€ã³ããã¯ã¹ããäœæããåé€ãŸã§èªåã§ç®¡çããä»çµã¿ã§ããããšãã°ãå€ãããŒã¿ã¯å§çž®ãããã30æ¥åŸã«åé€ããããšãã£ãã«ãŒã«ãèªååã§ããŸãã ã€ã³ããã¯ã¹ Elasticã§ããŒã¿ãä¿åããåäœã§ããæ¬ã§ãããšã1åã®æ¬ããããŒã¿ããŒã¹ã§ãããšã衚ãã«è¿ãã€ã¡ãŒãžã§ãã ã¹ãã¬ã¹ãã¹ã é«ãè² è·ããããŠãã·ã¹ãã ãèãããããã確èªãããã¹ãã§ããæ¬çªåã«éçã匱ç¹ãèŠã€ããããã«è¡ããŸãã EC2 AWSäžã§ä»®æ³ãµãŒããŒãèµ·åã§ãããµãŒãã¹ã§ããå¿
èŠãªå°æ°ã®ãµãŒããŒãã¯ã©ãŠãäžã§æè»ã«çšæã§ããŸãã Attack Discovery 倿°ã®ã¢ã©ãŒããã€ãã³ããé¢é£ã¥ããŠãã1ã€ã®æ»æã®æµãããšããŠæŽçããElasticã®æ©èœã§ããã°ãã°ãã®èŠåãããã®ãŸãŸã§ã¯ãªãæå³ã®ããæ»æã¹ããŒãªãŒã«ãŸãšããŸãã ã¢ã©ãŒã ãç°åžžã®å¯èœæ§ããããã確èªãå¿
èŠããšã·ã¹ãã ãç¥ãããéç¥ã§ãã Initial Access æ»æè
ãæåã«ã·ã¹ãã ãžå
¥ãèŸŒãæ®µéã§ããããšãã°äžæ£ãã°ã€ã³ãèåŒ±æ§æªçšãå«ãŸããŸãã Lateral Movement æ»æè
ããæåã«äŸµå
¥ãã1å°ããå¥ã®ç«¯æ«ããµãŒããŒãžæšªã«åºãã£ãŠããåãã§ãã Exfiltration ããŒã¿ã®æã¡åºãã§ããæ»æè
ãæ©å¯æ
å ±ãå€éšãžéãæ®µéãæããŸãã MITRE ATT&CK ãµã€ããŒæ»æè
ã®æå£ãäœç³»çã«æŽçããæåãªãã¬ãŒã ã¯ãŒã¯ã§ããæ»æã®æ®µéãæ¹æ³ãå
±éèšèªãšããŠæ±ãããã«ãã䜿ãããŸãã çžé¢åæ ã°ãã°ãã«èŠããè€æ°ã®ããŒã¿ã®é¢ä¿ãèŠã€ããåææ¹æ³ã§ããåå¥ã§ã¯å°ããªç°åžžã§ããã€ãªãããšå€§ããªæ»æã®æµããèŠããããšããããŸãã Agent Builder çšéããšã«å°çšã®AIãšãŒãžã§ã³ããäœãããã®æ©èœã§ããå©çšè
ãç®çãåç
§ããŒã¿ã«å¿ããŠã圹å²å¥ã®AIãèšèšã§ããŸãã AIãšãŒãžã§ã³ã ç¹å®ã®ç®çã圹å²ãæã£ãŠåãAIã§ããåãªãéè«AIã§ã¯ãªããããµããŒãæ
åœAIããåææ
åœAIãã®ããã«ä»äºã決ãŸã£ãŠããŸãã Jira ãã±ãã管çãåãåãã管çã«ãã䜿ãããããŒã«ã§ããé害察å¿ãã¿ã¹ã¯ç®¡çã§åºã䜿ãããŠããŸãã SOPïŒStandard Operating ProcedureïŒ æšæºäœæ¥æé æžã§ããæ¥åžžéçšããã©ãã«å¯Ÿå¿ã§ããã®é çªã§å¯Ÿå¿ããããšããæšæºæé ããŸãšããææžã§ãã èåŒ±æ§ ã·ã¹ãã ããœãããŠã§ã¢ã«ãã匱ç¹ã®ããšã§ããæ»æè
ã«æªçšãããå¯èœæ§ããããŸãã å¯èŠ³æž¬æ§ïŒObservabilityïŒ ã·ã¹ãã ã®ç¶æ
ããå€ããååã«ææ¡ã§ããããã«ããèãæ¹ã§ããåé¡ãèµ·ãããšãã«ãä»ã©ãã§äœãèµ·ããŠãããããèŠããããã«ããŸãã Blue Team é²åŸ¡åŽããŒã ã§ããæ»æãæ€ç¥ãã調æ»ããå®ã圹å²ãæ
åœããŸãã Red Team æ»æåŽããŒã ã§ããå®éã®æ»æè
ãæš¡ããŠäŸµå
¥ãæ»æãè¡ããé²åŸ¡åŽã®åŒ±ç¹ãæããã«ããŸãã NSOC ãããã¯ãŒã¯ãã»ãã¥ãªãã£ã®éçšå
šäœãç£èŠã»çµ±å¶ãã圹å²ãæã€éçšã»ã³ã¿ãŒãæããŸããããã§ã¯æŒç¿å
šäœãèŠå®ãçµ±å¶åŽãšããŠäœ¿ãããŠããŸãã White Team æŒç¿ã®éå¶ã審å€ãè¡ãããŒã ã§ããã«ãŒã«ç®¡çãè©äŸ¡ãå
šäœçµ±å¶ãæ
åœããŸãã Elastic Defend Elasticã®ãšã³ããã€ã³ãé²åŸ¡ã»å¯èŠåæ©èœã§ãã端æ«äžã®æåãç£èŠããè
åšæ€ç¥ã調æ»ã«åœ¹ç«ãŠãŸãã PCAP ãããã¯ãŒã¯éä¿¡ã®äžèº«ãèšé²ããããŒã¿åœ¢åŒã§ããã©ããªéä¿¡ãæµããŠãããã詳ãã調ã¹ããšãã«äœ¿ããŸãã ææ
åæ ããã¹ãããããã®å
容ãããžãã£ãããã¬ãã£ãããæããç²åŽã®åŸåãããããªã©ãåæããæ¹æ³ã§ãã Rocket.Chat ãã£ãããããŒã ã³ãã¥ãã±ãŒã·ã§ã³ã«äœ¿ãããŒã«ã§ããSlackã®ãããªåœ¹å²ãæã€ãœãããŠã§ã¢ã§ãã ãŒãã·ã§ããNLP äºåã«çްãã远å åŠç¿ãããŠããªãåé¡ã§ããAIãæç« ã®æå³ãèŠãŠããŒããã«ããŽãªã倿ããæ¹æ³ã§ãã NLPïŒNatural Language ProcessingïŒ èªç¶èšèªåŠçã®ããšã§ãã人éã®èšèãAIãã³ã³ãã¥ãŒã¿ã§æ±ããããã«ããæè¡åéã§ãã ãã¯ãã«å æç« ãç»åããAIãæ¯èŒããããæ°å€ã®åœ¢ã«å€æããããšã§ãã ã¯ã©ã¹ã¿ãªã³ã° 䌌ãŠããããŒã¿ãèªåã§ã°ã«ãŒãåãããåæææ³ã§ãã äººçææš ã·ã¹ãã ã®æ°åã ãã§ã¯ãªãã人ã®ç²åŽãæ··ä¹±ã士æ°ã®å€åãªã©ã衚ã芳ç¹ã§ããéçšã®çŸå Žã§ã¯ããããã人ã®ç¶æ
ãéèŠãªå€æææã«ãªããŸãã The post DCM26äºäŸïŒåœé²çäž»å¬ã®å€§èŠæš¡æŒç¿ãæ¯ããElasticã»ãã¥ãªãã£ã®åºç€èšèšãšAIæ¯æŽ first appeared on Elastic Portal .
ã¯ããã« 2026幎3æ26æ¥ãåã®è©Šã¿ãšããŠããªã¯ã«ãŒãæ¬ç€Ÿãªãã£ã¹ã«ãŠ ãç£åŠé£æºæè¡äº€æµäŒã ãéå¬ããŸãããæ¬ã€ãã³ã



















