











The modern SOC is getting better at closing alerts. It is still bad at remembering them.
Alerts are multiplying. Innovation has been focused on machines that can triage, correlate, and recommend a response at a much elevated scale. The queue indeed is moving faster than ever. Alert in, verdict out, case closed.
Attackers do not work case by case. A scan on Tuesday, an exploit attempt on Thursday and an unfamiliar login the following week may, in fact, be pieces of the same campaign. But once the SOC closes a case, what it learned does not carry forward to the next investigation.
That gap is becoming more consequential as attackers blend into legitimate activity. CrowdStrike found that 82 percent of detections in 2025 were malware-free, with adversaries relying on valid credentials, trusted identity flows and approved SaaS integrations. In that environment, history is not background. It is evidence.
What is absent is not more detection or faster triage. It is a way to keep an investigation alive—to carry its subjects, evidence and reasoning forward so that what arrives tomorrow can change what yesterday meant.
That is the argument Command Zero brought to Black Hat USA 2026. I sat down in Las Vegas with CEO Dov Yoran and CTO Dean De Beer to talk about Throughline, the capability the Austin company launched at the show. For a full drill-down, please give the accompanying podcast a listen. Here is what I took away from it.
Five alerts, one attack
It starts routinely enough. Five phishing emails arrive at one company over five days. Each targets a different employee. Each is tailored to the department where it lands.
Handled one at a time, each message opens its own investigation. No single case carries enough evidence to change the verdict, so the analyst closes it and moves on.
The SOC does its job five times and still misses what happened once.
Read together, the five were a single campaign, aimed by department. The earlier verdicts were not wrong. They were incomplete, because the decisive evidence lived in the relationship among them.
That is the gap Throughline is built to close. When a new alert lands, its subjects — the users, machines, addresses and domains named in it — are matched against recent history. Duplicate work gets suppressed. A closed case that picks up meaningful new evidence reopens, its window extends, and the investigative questions run again against the wider record.
De Beer described it as giving an investigation a living memory. The case no longer disappears into the archive when the ticket closes.
Yoran told me some early deployments have cut case volume by more than 40 percent, as new alerts attach to existing investigations instead of opening fresh ones. That figure is the company’s and has not been independently audited. The gain, if it holds, does not come from closing 40 percent more cases. It comes from recognizing that many of them were never separate.
The gap grew
None of this is an accident.
Security operations centers run in shifts, and junior analysts get first look at every warning. They judge what’s in front of them, not what they judged yesterday. Most of the innovation of the past decade went into automating exactly that job, because the warnings kept multiplying and the floor couldn’t keep up.
As that automation took root, the attacks shifted. The industry calls it this: attackers stopped breaking in and started logging in. They buy a stolen password, sign in like an employee, and the security tools see a valid login. No virus to catch, no malicious file to flag. Catching it means knowing what that account normally does and noticing that this time is different.
Spotting that difference takes memory — and that, Yoran and De Beer argue, is what the automated layer was never built to have. It judges one warning at a time.
Attackers have also gotten faster, and they’re staying longer.
CrowdStrike now measures the gap between a break-in and the attacker’s first move deeper into the network in minutes.
Mandiant finds attackers going undetected longer than they did the year before, with some intrusions persisting nearly 400 days—far beyond standard 90-day log-retention windows. So the attack arrives faster than an analyst can read the alert, and lasts longer than the evidence does.
Films, not stills
Yoran has a shorthand for it. Attackers work in films. Defenders look at still pictures.
Every case is treated in isolation, De Beer said, and when it’s done it’s forgotten. All that work should have been a data source.
Keeping an investigation alive creates a second requirement: every decision has to stay explainable. Command Zero records the questions asked, the data sources queried, the log records collected, the tool calls made and the evidence behind a verdict. De Beer’s shorthand was show your homework.
The homework is what lets the system go back. Every alert leaves behind a file — who was involved, which machines and accounts, what the system asked, what it found. The files stay open instead of going into a drawer. So when a new alert shares some of those details, the system recognizes the overlap, pulls the earlier case back up and runs its questions again with the new evidence added.
Without that record, there’s nothing to go back to. The case is closed and that’s the end of it.
“You cannot make a decision without citing the information you use to inform that decision,� De Beer said.
Where AI fits
I asked De Beer how much of this runs on AI. Less than you’d expect at a show where everyone was selling it.
Ordinary code and older machine-learning methods handle the first pass, cutting the raw log data down to the subset that matters. What survives that becomes the evidence. Only then do the language models come in, and they arrive as a set of specialized agents rather than one system — some writing code to analyze the logs, others taking what’s been analyzed and handing it up with context to an orchestrator that assembles the verdict and cites what it used.
De Beer’s reasoning is that language models are worth having but never fully predictable, so anything that can be done deterministically should be. He was emphatic that the older machine-learning techniques haven’t been superseded. He said they matter more now than they ever did.
For a CISO, the payoff isn’t a faster queue. It’s being able to say the team spotted an attack pattern that would have gone unseen even while every case was handled correctly, and show the work behind it.
Closing every case correctly clears the queue. Remembering them is what catches the attack.
I’ll keep watch and keep reporting.
Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.
(Editor’s note: This journalist-led report was produced with underwriting support from the featured company, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)
August 31st, 2026 | Black Hat | Black Hat Podcasts | Podcasts | Top Stories
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。