惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Y
Y Combinator Blog
O
OpenAI News
K
Kaspersky official blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Hacker News: Ask HN
Hacker News: Ask HN
S
SegmentFault 最新的问题
L
Lohrmann on Cybersecurity
S
Securelist
C
CERT Recently Published Vulnerability Notes
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
IT之家
IT之家
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
V
Vulnerabilities – Threatpost
量子位
爱范儿
爱范儿
I
Intezer
博客园 - 叶小钗
The Hacker News
The Hacker News
N
News and Events Feed by Topic
Project Zero
Project Zero
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy & Cybersecurity Law Blog
Google Online Security Blog
Google Online Security Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Heimdal Security Blog
NISL@THU
NISL@THU
V
Visual Studio Blog
The Last Watchdog
The Last Watchdog
Know Your Adversary
Know Your Adversary
Cisco Talos Blog
Cisco Talos Blog
P
Proofpoint News Feed
M
MIT News - Artificial intelligence
Stack Overflow Blog
Stack Overflow Blog
The Cloudflare Blog
小众软件
小众软件
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
S
Schneier on Security
雷峰网
雷峰网
B
Blog RSS Feed
美团技术团队
T
Threat Research - Cisco Blogs
Engineering at Meta
Engineering at Meta
Recent Announcements
Recent Announcements
N
Netflix TechBlog - Medium
月光博客
月光博客
S
Security Affairs

Databricks

How lakebase architecture delivers 5x faster Postgres writes Why Talent Transformation Is the Missing Focus of Enterprise AI Public Health Intelligence Shouldn't Require a Data Scientist First-party audience data is the ad sales relationship now Rethinking Distributed Systems for Serverless Performance and Reliability The AI Scaling Gap Hiding in Digital Native Companies 10 trillion samples a day: Scaling beyond traditional monitoring infra at Databricks AI success starts with clean data, not just better models How nOps Rebuilt Their Cloud Optimization Platform on Databricks Lakebase, and Why Other ISVs Should Too Peril Predicts: Precision Payouts for a Volatile World The foundation of AI scalability: one team, one platform, one operating model The Federal Data Paradox: Rich in Data, Poor in Access Driving Budapest Forward: How BKK Uses Databricks to Transform City Mobility LLM Vs AI: A Practical Guide to Differences, Use Cases, and Tools Model Risk Governance Is Not the Same as Risk Intelligence Generative AI for Business: A Complete Strategy and Implementation Guide Data Science vs Data Engineering: Choosing Analysis or Infrastructure AI Applications: Tools, Use Cases, and Platforms MLOps vs DevOps: A Practical Guide for Data Scientists and IT Teams Top Data Warehouse Tools For Modern Data Analytics Unlocking SAP Business Context in Databricks with Semantic Metadata Delta Sharing The marketing activation gap has a fix: Databricks and Stitch partner to turn data infrastructure into marketing performance Alert Fatigue Is a Business Risk Backstage with Lakebase Shipping Faster isn’t Learning Faster Why Your OEE Dashboard Is Lying to You The Turbine That Tried to Tell You It Was Failing Predicting Readmissions Isn't Enough. Acting in Time Is. Clinical Trials Run Longer Than They Have To. That's a Patient Problem Network Quality Is a Revenue Problem, Not a Technical One Shelf Availability Starts with Better Demand Visibility When Predicting the Next Hit Requires More Than Intuition Approximate Answers, Exact Decisions: New Sketch Functions for Analytics Companies Winning with AI Built the Data Layer First Rethinking SQL ETL for modern data platforms Stripe data now available on Databricks via Databricks Marketplace Databricks and Stripe Projects: Infrastructure Built for Agents Agents are ready but your architecture probably isn't Interoperability Between Unity Catalog and Google BigQuery via Catalog Federation Built In, Not Bolted On: What AI-Native Actually Means in Cybersecurity Operationalizing AI for public sector fraud prevention From months to minutes: Building real-time clinical data pipelines with natural language Agentic Data Engineering with Genie Code and Lakeflow Securely send first-party conversion signals with Snapchat Conversions API on Databricks Marketplace How leading tech companies are killing the builder’s tax with Lakebase Inside one of the first production deployments of Lakebase: LangGuard's agentic workflow governance engine The next generation of Databricks Genie Model Risk Management in 2026: A Banker’s Guide to the Revised Interagency Guidance OpenAI GPT-5.5 now available on Databricks, fully-governed through Unity AI Gateway Operational databases: How they work and when to use them Databricks partners with OpenAI on GPT-5.5 Announcing the Public Preview of Lakeflow Designer Are LLM agents good at join order optimization? How conversational analytics removes the BI bottleneck How to transform document activation workflows with Genie and Agent Bricks Beyond the spreadsheet: how Databricks is delivering the modern CFO in Financial Services AI App Development: Guide To Building AI-Powered Apps IoT in Manufacturing: Strategy, Components, Use Cases, and Challenges Stop Hand-Coding Change Data Capture Pipelines Multimodal Data Integration: Production Architectures for Healthcare AI Personalization Strategies for Media Companies A Modern AI Risk Management Framework Introducing the Databricks Excel Add-in for Business Users Real-Time Decisioning for AI Agents: Why you Need a Customer Context Layer First A Practical Guide to LLM Fine Tuning AI Data Transformation Guide for Data Engineers and Data Scientists Concurrency Control in DBMS: How Locking, MVCC and Optimistic Strategies Keep Data Consistent Bridging data science and marketing: Databricks unveils Delta Sharing integration for Adobe Experience Platform and agentic marketing workflows Take Control: Customer-Managed Keys for Lakebase Postgres Get hands on with agents, vibe coding and more at Data+ AI Summit Mercedes-Benz Builds a Cross-Cloud Data Mesh with Delta Sharing and Intelligent Replication, Cutting Costs by 66% What Is a Transactional Database? Introducing Genie Agent Mode Governing coding agent sprawl with Unity AI Gateway Governing Coding Agent Sprawl with Unity AI Gateway What is pgvector? Banks Don’t Have an AI Problem – They Have a Data Platform Problem Open Platform, Unified Pipelines: Why dbt on Databricks is Accelerating Why Your Agents Can’t Read Enterprise Documents — and How to Fix It Building with Databricks Document Intelligence and Lakeflow Databricks on Google Cloud: Innovate Faster. Smarter. Together. Introducing the Databricks Connector for Google Sheets: Real-Time, Governed Lakehouse Data in the Sheets Users Love Unity AI Gateway: How to connect agents to external MCPs securely Expanding agent governance with Unity AI Gateway Agentic reasoning in practice: Making sense of structured and unstructured data Agent Bricks: The Governed Enterprise Agent Platform 8 AI and data trends shaping financial services in 2026 Building real-time product search on Databricks Lovable + Databricks: Build Data-Driven Apps at the Speed of Thought Memory scaling for AI agents Powering clinical research innovation: How TriNetX uses Databricks to accelerate drug development Database Branching in Postgres: Git-Style Workflows with Databricks Lakebase How Zalando built a unified data foundation for AI and analytics on Databricks The next era of the open lakehouse: Apache Iceberg™ v3 in Public Preview on Databricks How FSIs eliminate silos between clients, operations, and finance How MakeMyTrip achieved millisecond personalization at scale with Databricks A multi-agent approach to audience intelligence AiChemy: Next-generation agent with MCP, skills and custom data for drug discovery Accelerate business insights with Lakeflow Connect, now with a Free Tier Unlocking Next-Gen Customer Experiences with Data Intelligence for Marketing
Mean Time to Detect Is a Data Access Problem
2026-05-07 · via Databricks

USE CASE
SOC Efficiency & Incident Investigation Intelligence

Security operations metrics have gotten more sophisticated over the past decade. MTTD, MTTR, false positive rates, analyst utilization — the operational performance of security operations centers is now measured with the rigor of any other business function. And when those metrics are analyzed, a consistent pattern emerges: a disproportionate amount of analyst time is spent on data assembly rather than analysis.

An analyst investigating a suspicious alert needs to pull log data from multiple sources, cross-reference user identity records, check asset information for the systems involved, review prior alerts on related entities, and correlate timeline data across sources. Each of those data pulls requires a different query, a different system, and a different syntax.

Why Mean Time to Detect Stalls in Most SOCs

Security operations leaders have invested in SIEM platforms, SOAR automation, and threat intelligence integration to address this problem. Those investments have made real improvements. What they haven't solved is the fundamental data fragmentation problem: when the authoritative version of an investigation-relevant question requires joining data across systems that weren't designed to talk to each other, the analyst becomes the integration layer.

A Level 2 analyst who can ask any question about an incident and get the answer in seconds is doing five times the analysis of an analyst who has to query three systems to get each piece of the picture.

Genie and Lakewatch for SOC Investigation

Genie serves as the agentic interface within Lakewatch, leveraging the advanced reasoning of Anthropic Claude models to deliver agentic security operations. By integrating Claude’s reasoning capabilities, Lakewatch can correlate complex signals across security, IT, and business data in seconds. This allows analysts to deploy defensive security agents that don't just search for data, but understand the context of the investigation to surface high-fidelity threats faster than manual workflows ever could.

Genie serves as the agentic interface within Lakewatch, allowing analysts to pivot from human-in-the-loop to human-at-the-helm. Instead of writing complex SQL or learning proprietary search languages, analysts use Genie to orchestrate autonomous agents that can hunt, summarize, and cross-reference petabytes of data in seconds.

Genie enables security operations teams to ask investigation questions in natural language across their full security data environment. An analyst can ask: 'Show me all authentication events for user X in the past 7 days, the systems they accessed, any associated file access events on sensitive data stores, and any related alerts from our EDR.' That investigation synthesis surfaces in a single conversational response.

The MTTD Math: From 200 Days to Minutes

Reducing MTTD isn't just a goal; it's a survival requirement. As Ali Ghodsi, co-founder and CEO of Databricks, highlighted during his RSA keynote, we are witnessing a massive secular shift in the threat landscape. The Zero Day Clock shows that in 2018, the average time from CVE to weaponized exploit was over two years. Today, that window has collapsed to just 1.3 days.

This 1.3-day exploit window is the 'architectural dead end' for legacy SIEMs. While recent data suggests the median breach detection time has compressed dramatically, that median often masks a 'long tail' of sophisticated threats that remain undetected for months due to visibility gaps. Humans alone cannot keep up with this speed of weaponization. We are facing swarms of AI agents that attack anywhere, while defenders are still constrained by manual workflows and the 'security tax' that forces them to discard up to 75% of their data.

Metric

Full Name

Definition

Business Significance

MTTD

Mean Time to Detect

The average time it takes for your security tools or team to identify a potential security incident.

Critical: High MTTD indicates a "visibility gap" where attackers can operate freely (the "long tail" problem).

MTTR

Mean Time to Respond

The average time from when an alert is triggered to when the initial response or mitigation begins.

Measures SOC agility and the effectiveness of your automated playbooks.

MTTC

Mean Time to Contain

The average time it takes to isolate a threat and prevent it from spreading further across the network.

The primary metric for limiting the "blast radius" and potential data exfiltration.

MTTI

Mean Time to Investigate

The average time an analyst spends verifying an alert and determining its root cause and scope.

Highlights the "analyst bottleneck" caused by manual data joining across fragmented systems.

To fight a swarm, you need a swarm. Lakewatch and Genie represent a fundamental shift. Lakewatch deploys swarms of defensive agents that automate detection, triage, and investigation natively where your data lives. We are moving from human-paced triage to machine-speed defense, positioning the defender at the helm to orchestrate autonomous defense across the enterprise.

DATABRICKS GENIE · KEY DIFFERENTIATORS
Built for your data, governed by your rules, answerable to any business leader.

  • Unified security data lake: All security telemetry in one place — SIEM, EDR, NDR, IAM, CSPM data in a single query environment.
  • Timeline reconstruction: Genie can assemble chronological event timelines across data sources — reducing the manual work of incident reconstruction.
  • Entity context: User, device, and application context is always available alongside event data — investigations get enriched context automatically.
  • Analyst-level access controls: Junior and senior analysts access the data appropriate to their role — investigation capability scales with appropriate governance.

See What Genie Can Do for Your Team

Databricks Genie is available today. See how your industry peers are using it to reimagine how they access and act on their data.