Elastic scanned 14,500 assets in under 5 minutes. What took days was done in minutes, with accuracy that saved dozens of hours in manual triage.
Elastic is the company behind Elasticsearch, the open-source search and analytics engine powering millions of applications. Since launching in 2012, Elastic has grown into a global, publicly traded company (NYSE: ESTC) with almost 4,000 employees and a fast-expanding suite of products spanning search, observability, and security.
Its flagship Elastic Stack (formerly the ELK Stack: Elasticsearch, Logstash, and Kibana) helps thousands of organizations, from startups to Fortune 500s, monitor, secure, and gain insights from massive volumes of data.
Elastic runs on a truly global infrastructure, with around 50,000 servers deployed across AWS, Azure, and GCP. That kind of scale introduces complexity that most traditional security tools just weren’t built to handle.
With assets constantly shifting and threats evolving daily, Elastic’s security team faced growing pressure to stay proactive and precise. Among the key challenges:
Before going all-in on ProjectDiscovery Cloud, Elastic had already embraced Nuclei, the open-source vulnerability scanner built for customization and speed, along with other ProjectDiscovery tools like naabu and httpx.
Nuclei gave the team a strong foundation. They could create custom detection templates and tap into rapid community contributions without the noise of false positives. But operating it at scale came with trade-offs.
“The ease of use and strong community backing are huge advantages. With Nuclei, I can easily write my own templates while benefiting from rapid coverage provided by community-driven templates.”
— Clement Fouque, Principal Information Security Analyst at Elastic
Their setup started out simple with bash scripts, cron jobs, and a devbox running scheduled scans. But over time, challenges emerged:
What started as a simple DIY solution became a bottleneck. The team needed the power of Nuclei, but without the drag of running it themselves.
ProjectDiscovery Cloud delivered exactly what Elastic needed: the scalability of an enterprise platform with the flexibility and speed of open source.
Having already used Nuclei extensively, the switch felt less like a migration and more like a natural evolution.
“We were already invested in Nuclei. ProjectDiscovery Cloud was the missing piece that let us scale it seamlessly across our environment,” said Clement Fouque, Principal Information Security Analyst at Elastic.
ProjectDiscovery’s philosophy also matched Elastic’s open-source DNA. Their team valued:
With ProjectDiscovery Cloud, Elastic's detection workflows were transformed almost overnight.
“ProjectDiscovery Cloud’s scanning performance is outstanding: fast, consistent, and reliable at scale. The proactive partnership we have with the ProjectDiscovery engineering team is rare and invaluable, enabling rapid improvements and swift responses to emerging threats.”
Clement Fouque
Principal Information Security Analyst
Elastic’s experience demonstrates how lean security teams can effectively manage vulnerability detection at massive scale by strategically leveraging open-source innovation, community-driven insights, and automation.
Elastic isn’t slowing down. With the foundation in place, the team is already planning new ways to extend and scale their detection capabilities, including:
As their environment grows, so does their confidence, supported by a scalable detection platform that evolves with them.
Discover how Elastic went from open-source experimentation to enterprise-ready detection.