惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Jina AI
Jina AI
The Cloudflare Blog
V
Visual Studio Blog
博客园_首页
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
博客园 - 司徒正美
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
博客园 - Franky

The Last Watchdog

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight | The Last Watchdog News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws | The Last Watchdog News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026 | The Last Watchdog GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it | The Last Watchdog News alert: OpenMatter adds secure routing for OpenAI, Anthropic and Google models | The Last Watchdog LW ROUNDTABLE: OpenAI’s test agents self-organized into a rogue swarm no one anticipated | The Last Watchdog News alert: Bright Security launches AI PT, AI-powered penetration testing that cuts weeks to hours | The Last Watchdog MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits | The Last Watchdog NEWS ALERT: Lunar Cyber tracks stolen API keys, ties them to infected employer devices | The Last Watchdog NEWS ALERT: SRA makes SOC AI license-free — customers pay only for the Azure compute they use | The Last Watchdog News alert: Airlock Digital IRAP assessment bolsters trust for sensitive Australian deployments | The Last Watchdog News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week | The Last Watchdog MY TAKE: Black Hat 2026 Part 3 — Agentic AI can do the work, but somebody has to prove it | The Last Watchdog MY TAKE: Black Hat 2026 Part 2 — Security shifts to deciding in advance what an AI agent may reach | The Last Watchdog MY TAKE: Black Hat 2026 Wrap-up Part 1 — AI is forcing security and operations to merge in the SOC | The Last Watchdog News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures | The Last Watchdog BLACK HAT ROUNDTABLE: Security pros dissect fallout from Hugging Face’s double guardrail failure | The Last Watchdog News alert: Airlock extends endpoint control to govern AI agents and define operating boundaries | The Last Watchdog News alert: Mallory links threat intelligence to governed response as exploit timelines shrink | The Last Watchdog News alert: Community voting shapes 2026 Cybersecurity Excellence Awards | The Last Watchdog BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate | The Last Watchdog News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations | The Last Watchdog News alert: Insignary’s on-demand SBOM verification boosts software supply chain security | The Last Watchdog News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions | The Last Watchdog News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI | The Last Watchdog News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk | The Last Watchdog News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks | The Last Watchdog News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks | The Last Watchdog News alert: OpenMatter launches platform to verify AI activity across enterprise systems | The Last Watchdog News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies | The Last Watchdog
BLACK HAT FIRESIDE CHAT: How linking SOC alerts cuts nois...
bacohido · 2026-08-31 · via The Last Watchdog

By Byron V. Acohido

The modern SOC is getting better at closing alerts. It is still bad at remembering them.

Alerts are multiplying. Innovation has been focused on machines that can triage, correlate, and recommend a response at a much elevated scale. The queue indeed is moving faster than ever. Alert in, verdict out, case closed.

Attackers do not work case by case. A scan on Tuesday, an exploit attempt on Thursday and an unfamiliar login the following week may, in fact, be pieces of the same campaign. But once the SOC closes a case, what it learned does not carry forward to the next investigation.

That gap is becoming more consequential as attackers blend into legitimate activity. CrowdStrike found that 82 percent of detections in 2025 were malware-free, with adversaries relying on valid credentials, trusted identity flows and approved SaaS integrations. In that environment, history is not background. It is evidence.

What is absent is not more detection or faster triage. It is a way to keep an investigation alive—to carry its subjects, evidence and reasoning forward so that what arrives tomorrow can change what yesterday meant.

That is the argument Command Zero brought to Black Hat USA 2026. I sat down in Las Vegas with CEO Dov Yoran and CTO Dean De Beer to talk about Throughline, the capability the Austin company launched at the show. For a full drill-down, please give the accompanying podcast a listen. Here is what I took away from it.

Five alerts, one attack

It starts routinely enough. Five phishing emails arrive at one company over five days. Each targets a different employee. Each is tailored to the department where it lands.

Handled one at a time, each message opens its own investigation. No single case carries enough evidence to change the verdict, so the analyst closes it and moves on.

The SOC does its job five times and still misses what happened once.

Read together, the five were a single campaign, aimed by department. The earlier verdicts were not wrong. They were incomplete, because the decisive evidence lived in the relationship among them.

That is the gap Throughline is built to close. When a new alert lands, its subjects — the users, machines, addresses and domains named in it — are matched against recent history. Duplicate work gets suppressed. A closed case that picks up meaningful new evidence reopens, its window extends, and the investigative questions run again against the wider record.

De Beer described it as giving an investigation a living memory. The case no longer disappears into the archive when the ticket closes.

Yoran told me some early deployments have cut case volume by more than 40 percent, as new alerts attach to existing investigations instead of opening fresh ones. That figure is the company’s and has not been independently audited. The gain, if it holds, does not come from closing 40 percent more cases. It comes from recognizing that many of them were never separate.

The gap grew

None of this is an accident.

Security operations centers run in shifts, and junior analysts get first look at every warning. They judge what’s in front of them, not what they judged yesterday. Most of the innovation of the past decade went into automating exactly that job, because the warnings kept multiplying and the floor couldn’t keep up.

As that automation took root, the attacks shifted. The industry calls it this: attackers stopped breaking in and started logging in. They buy a stolen password, sign in like an employee, and the security tools see a valid login. No virus to catch, no malicious file to flag. Catching it means knowing what that account normally does and noticing that this time is different.

Spotting that difference takes memory — and that, Yoran and De Beer argue, is what the automated layer was never built to have. It judges one warning at a time.

Attackers have also gotten faster, and they’re staying longer.

CrowdStrike now measures the gap between a break-in and the attacker’s first move deeper into the network in minutes.

Mandiant finds attackers going undetected longer than they did the year before, with some intrusions persisting nearly 400 days—far beyond standard 90-day log-retention windows. So the attack arrives faster than an analyst can read the alert, and lasts longer than the evidence does.

Films, not stills

Yoran has a shorthand for it. Attackers work in films. Defenders look at still pictures.

Every case is treated in isolation, De Beer said, and when it’s done it’s forgotten. All that work should have been a data source.

Keeping an investigation alive creates a second requirement: every decision has to stay explainable. Command Zero records the questions asked, the data sources queried, the log records collected, the tool calls made and the evidence behind a verdict. De Beer’s shorthand was show your homework.

The homework is what lets the system go back. Every alert leaves behind a file — who was involved, which machines and accounts, what the system asked, what it found. The files stay open instead of going into a drawer. So when a new alert shares some of those details, the system recognizes the overlap, pulls the earlier case back up and runs its questions again with the new evidence added.

Without that record, there’s nothing to go back to. The case is closed and that’s the end of it.

“You cannot make a decision without citing the information you use to inform that decision,� De Beer said.

Where AI fits

I asked De Beer how much of this runs on AI. Less than you’d expect at a show where everyone was selling it.

Ordinary code and older machine-learning methods handle the first pass, cutting the raw log data down to the subset that matters. What survives that becomes the evidence. Only then do the language models come in, and they arrive as a set of specialized agents rather than one system — some writing code to analyze the logs, others taking what’s been analyzed and handing it up with context to an orchestrator that assembles the verdict and cites what it used.

De Beer’s reasoning is that language models are worth having but never fully predictable, so anything that can be done deterministically should be. He was emphatic that the older machine-learning techniques haven’t been superseded. He said they matter more now than they ever did.

For a CISO, the payoff isn’t a faster queue. It’s being able to say the team spotted an attack pattern that would have gone unseen even while every case was handled correctly, and show the work behind it.

Closing every case correctly clears the queue. Remembering them is what catches the attack.

I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: This journalist-led report was produced with underwriting support from the featured company, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

August 31st, 2026 | Black Hat | Black Hat Podcasts | Podcasts | Top Stories