惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
小众软件
小众软件
B
Blog RSS Feed
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
Engineering at Meta
Engineering at Meta
人人都是产品经理
人人都是产品经理
Microsoft Security Blog
Microsoft Security Blog
Last Week in AI
Last Week in AI
H
Help Net Security
爱范儿
爱范儿
云风的 BLOG
云风的 BLOG
博客园 - 司徒正美
Y
Y Combinator Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Azure Blog
Microsoft Azure Blog
L
LangChain Blog
WordPress大学
WordPress大学
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
腾讯CDC

Infoblox Blog

You Don’t Need a Locksmith: Preparing for the Root Zone Key Signing Key (KSK) Rollover in October 2026 AI Agent Security: DNS-AID and Protective DNS | Infoblox Illegal Gambling Sites Reveal Three Types of Cybercrime Infoblox vNIOS on AWS China | Unified DDI Across Global and China Cloud Environments DNS-AID: Securing AI Agents and the Future of Agentic Commerce Modernizing Federal Networks Without Compromise | Infoblox DNS at IETF 126 To Open Weight or Not to Open Weight - That Should NOT be the question AI Governance with DNS Security | Infoblox Infoblox Supports the Next Generation of Cybersecurity Talent at Cyber Battle Australia The Second Life of Expired Domains Illegal Streaming Fronts a $7M Dropcatch Domain Operation Expired Malicious Domains Bring New Threats to Life How Many AI Agents Are Running in Your Organization? Infoblox IQ for DDI Is Now Generally Available | AI for Network Operations Kentik Joins Infoblox: Network Observability & AI Cybercrime Trends and Threat Intelligence | Infoblox AI’s First Move Is a Name Lookup External Attack Surface Management: See What Attackers See | Infoblox FedRAMP DDI Management with Infoblox Government Cloud Inside a Global Procurement-Themed AiTM Phishing Campaign The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play NIST Maps DNS Security to the Cybersecurity Framework 2.0 Trusted Infrastructure Data for AI and AgenticOps | Infoblox
Meet Your Security Analyst’s New AI Teammate | Infoblox IQ
Krupa Srivatsan · 2026-06-29 · via Infoblox Blog

When Threats Move at AI Speed, You Need to Respond at AI Speed

Threat investigation and response has always been a complex, cumbersome process. Alerts came in; analysts triaged them mostly manually, painstakingly looking at logs, trying to identify which ones were critical and then kicking off remediation actions again with a lot of manual effort. It is time-consuming and error prone.

That whole rhythm is now coming under even greater stress. Attackers now use AI to automate reconnaissance, generate single-use malware, personalize campaigns at scale and mutate their infrastructure faster than defenders can keep up. The result is a flood of alerts and a shrinking window to make the right call before the business is exposed. Analysts have very little time to understand what’s happening, decide what matters and act to contain threats.

The numbers tell the story. Alert volume increased over the prior year for 88 percent of organizations, and 64 percent say detection, triage and investigation remain heavily manual.1 Meanwhile, analysts pivot across an average of 10.9 consoles to piece together a single investigation, 46 percent of alerts turn out to be false positives and 42 percent never get investigated at all.2 It’s no wonder 75 percent of security leaders worry their security operations center (SOC) is losing pace with new cyberthreats.1

And the final tipping point is the fact that the average “attacker breakout time” is now only 29 minutes,3 meaning it takes only that amount of time from initial network access to lateral movement and further escalation of the threat.

Adding more tools or pushing more raw data into the security information and event management (SIEM) hasn’t solved this. It has often made it worse. What teams need is a way to cut through the noise at the earliest control point, connect related activity into something meaningful, simplify the whole investigation process and help analysts act faster with confidence.

That’s exactly what we built Infoblox IQ for Threat Defense to do.

The Real Barriers to Security Efficiency

Talk to almost any security team and the same three challenges surface again and again.

The first is simply dealing with alerts. Analysts sift through overwhelming volumes of noisy alerts, and false positives bury the real issues. Traditional prioritization methods just aren’t keeping pace with alert growth, so too much time goes to triaging things that never deserved a deeper look.

The second is complex investigations. To reconstruct what happened, analysts pivot across DNS, network, endpoint, cloud and identity tools, stitching context together manually. That slows investigations, adds operational friction and drives up SIEM and downstream processing costs.

The third is doing the work with the staff and skills on hand. Short-staffed teams struggle to keep up with investigation, tuning and integrations, while too much analyst time goes to low-value manual work instead of real risk reduction. Burnout and turnover make consistency even harder to maintain. These aren’t problems you solve by working harder. They’re problems you solve by changing how the work gets done.

An Agentic AI Teammate for Easier and Faster Investigations

Infoblox IQ for Threat Defense helps security and networking teams defend the business against AI-driven and other advanced threats more effectively. At its core, it helps security teams focus on the threats that matter most.

The idea comes down to three things: See what matters first. Investigate faster and with ease. Respond in one automated workflow.

See what matters first. Instead of flooding analysts with more noise, Infoblox IQ for Threat Defense uses DNS intelligence, network data and AI-driven threat correlation to surface the threats and anomalies that actually deserve attention. Analysts start in the right place rather than digging for it.

Investigate easier and faster with full context that reveals the who, what and when behind every event. Analysts can simply ask questions in natural language about detected events and access correlated DNS, network, asset, user and security context—without pivoting across multiple tools, screens or logs. Asset/user attribution becomes very easy and guided next steps help accelerate investigation and response from a single workspace.

Move from detection to response in one-click automated workflow. When an issue surfaces, analysts can investigate, decide and act in one connected, automated experience rather than bouncing between separate tools, queues and handoffs. Actions can be automated, but analyst control, approvals and auditability stay central.

Why does DNS give us such an advantage here? Because most modern attacks depend on it. Flexible attacker infrastructure and dynamic command-and-control systems use DNS to reach victims, move laterally and maintain communications. That reliance turns DNS into an early, high-value control point for spotting and stopping malicious activity, and Infoblox has spent years researching and generating original threat intelligence to use in DNS systems.

Just as important is what this approach protects against: black-box automation. Because the stakes are higher in an AI-driven threat landscape, human oversight matters more, not less. Analysts stay in control of higher-risk decisions, actions remain visible and auditable, and AI handles the low-value manual work so people can focus on real risk.

There’s a broader story here too. Infoblox IQ for Threat Defense is part of Infoblox IQ, which means the same assistant, actions and context work more consistently across the entire Infoblox platform, giving teams a simpler, more unified workspace rather than yet another disconnected dashboard.

A Smarter Way to Go from Detection to Action

The answer to better security isn’t to ask already-stretched analysts to absorb more noise, more tools and more manual work. It’s to give them a teammate that helps them focus on what matters, understand it faster and act on it with confidence.

That’s the promise of Infoblox IQ for Threat Defense: better security outcomes with less manual triage, less swivel-chair work and a clearer path from signal to investigation to remediation, all while amplifying the SIEM, security orchestration, automation and response (SOAR) and security investments teams already have.

In a world where every organization is increasingly a target, and threats evolve by the minute, that combination of speed, simplicity and control is exactly what modern security teams need. We’re excited to put it to work for your team.

Footnotes

  1. Pulse of the AI SOC Report 2025. Devry, Jane. Cybersecurity Insiders. August 26, 2025.
  2. Microsoft State of the SOC. Lefferts, Rob. Microsoft Security. February 17, 2026.
  3. CrowdStrike 2026 Global Threat Report. CrowdStrike, 2026.