Notifications
Clear all
Topic starter
21/07/2026 8:14 pm
Hey everyone! I've been trying to get a better handle on securing our SaaS apps (we use a bunch like Salesforce, HubSpot, and Google Workspace). I saw Elastic Security rolled out a bunch of new pre-built rules focused on "SaaS app compromise" and got really excited! 😊
I'm still pretty new to this side of things though. Has anyone had a chance to test these out? I'm curious if they're actually useful for catching real-world stuff, like weird login patterns or data exfiltration from these platforms.
What's the setup like? Do they work well out of the box, or do they need a ton of tweaking? Also, are they covering the main apps most businesses use? I'd love to hear if anyone has any early experiences or even gotchas.