<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[SecOps Unpacked: Friday SIEM]]></title><description><![CDATA[The weekly Friday SIEM post, originally published on LinkedIn: where the SIEM is heading, market moves, architecture, AI SOC and detection engineering.]]></description><link>https://blog.secops-unpacked.ai/s/friday-siem</link><image><url>https://substackcdn.com/image/fetch/$s_!xLGO!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5375acae-8a8c-4f56-a65b-11f2df6dc8a4_500x500.png</url><title>SecOps Unpacked: Friday SIEM</title><link>https://blog.secops-unpacked.ai/s/friday-siem</link></image><generator>Substack</generator><lastBuildDate>Fri, 18 Sep 2026 15:32:22 GMT</lastBuildDate><atom:link href="https://blog.secops-unpacked.ai/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Filip Stojkovski]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[secopsunpacked@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[secopsunpacked@substack.com]]></itunes:email><itunes:name><![CDATA[Filip Stojkovski]]></itunes:name></itunes:owner><itunes:author><![CDATA[Filip Stojkovski]]></itunes:author><googleplay:owner><![CDATA[secopsunpacked@substack.com]]></googleplay:owner><googleplay:email><![CDATA[secopsunpacked@substack.com]]></googleplay:email><googleplay:author><![CDATA[Filip Stojkovski]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Friday SIEM #30: AI Agent Builder or Agent Studios for a SIEM]]></title><description><![CDATA[Friday SIEM post, apparently this is my 30th release &#128588;]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-29-ai-agent-builder-or</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-29-ai-agent-builder-or</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 18 Sep 2026 14:46:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!m5PD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Friday SIEM post, apparently this is my 30th release &#128588; </span><br><br><span>Before I go into the topic, many reached out saying they really enjoy my Friday SIEM posts, so one of my recent projects was to make this part of my blog as a dedicated section. So now Friday SIEM is on Substack as well. And yes, I migrated my whole blog there too.</span><br><br><span>Now back to this week&#8217;s topic: AI Agent Builders, or Agent Studios as part of the SIEM. </span><br><br><span>I wrote about this a </span><a href="https://blog.secops-unpacked.ai/p/friday-siem-12-siem-ate-the-soar"><span>while ago</span></a><span> because I see it as one of the next big trends across SIEMs. And no surprises there, we are already seeing more and more SIEM vendors adding them.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m5PD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m5PD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 424w, https://substackcdn.com/image/fetch/$s_!m5PD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 848w, https://substackcdn.com/image/fetch/$s_!m5PD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 1272w, https://substackcdn.com/image/fetch/$s_!m5PD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m5PD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png" width="1456" height="820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:410291,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/216314922?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m5PD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 424w, https://substackcdn.com/image/fetch/$s_!m5PD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 848w, https://substackcdn.com/image/fetch/$s_!m5PD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 1272w, https://substackcdn.com/image/fetch/$s_!m5PD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F282bf05e-ffe0-4c9d-ae06-43e0b86a9ea9_1467x826.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br><br><span>And yes, don&#8217;t jump on me for the vendors in the visual. When I say SIEM, I include both the more traditional ones and the SIEM alternatives, next-gen, decoupled, integrated SecOps, whatever we decide to call them this week.</span><br><br><span>There is also a really cool blog from the </span><a href="https://www.elastic.co/security-labs/blog/alert-triage-agentic-soc-self-correcting-agents"><span>Elastic team</span></a><span>, a proper deep dive into how they run this internally, with some great insights. One that stood out was how much they improved agent accuracy, not by changing the model, but by giving the agent better context.</span><br><br><span>That part matters a lot.</span><br><span>Overall, don&#8217;t use agents for everything. Go deterministic where you can and where it makes sense. Agents are useful, but they are not some magical replacement for every workflow just because we discovered the word &#8220;agentic.&#8221;</span><br><span>They also touch on why dumping walls of AI-generated text in front of analysts is not particularly useful. But that is a topic for another Friday SIEM post, because the UX disaster we are creating around AI in SecOps deserves its own rant.</span><br><br><span>Overall, I think we will see most, if not all, SIEM vendors adding some form of Agent Studio.</span><br><br><span>What surprised me is that not many added this capability through acquisition. A lot of them seem to be building it in-house. I still suspect we will see at least one acquisition in this space, maybe even this year.</span><br><br><span>And just to separate two things that are getting mixed together a lot.</span><br><br><span>When I say AI SOC, I usually mean the pre-built stuff. Investigation agents, triage agents, response agents, all ready to go.</span><br><br><span>When I say Agent Studio, I mean the build-your-own part. You get templates, tools, connectors and some building blocks, but you can create or customize the agents yourself.</span><br><br><span>So yes, SIEM added SOAR, then AI SOC, and now Agent Studios as well.</span><br><br>Have a siemless weekend ahead!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://lnkd.in/p/gMP4tvu9&quot;,&quot;text&quot;:&quot;Read the Linkedin Post and comments&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://lnkd.in/p/gMP4tvu9"><span>Read the Linkedin Post and comments</span></a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.secops-unpacked.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading SecOps Unpacked! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #29: Where attack emulation fits in the new SIEM architecture]]></title><description><![CDATA[Where attack emulation fits in the new SIEM architecture. Pipelines and detections break quietly. Continuous validation is the resilience layer under agents.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-30-where-attack-emulation</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-30-where-attack-emulation</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 11 Sep 2026 15:29:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IQbW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>And we have this week&#8217;s Friday SIEM post.<br>This week I wanted to talk about something that has been sitting in the back of my head for a while: where does attack emulation / simulation actually fit in the new SIEM architecture, whether we call it decoupled SIEM, Integrated SecOps, or whatever new acronym we invent next.</p><p>I think more people are finally realizing how important detection engineering is. Bad detections create a ton of pain downstream. But if we go even further left, the data pipeline matters just as much. Garbage in, garbage out still applies, even if the garbage is now being investigated by an AI agent with expensive frontier model .</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IQbW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IQbW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 424w, https://substackcdn.com/image/fetch/$s_!IQbW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 848w, https://substackcdn.com/image/fetch/$s_!IQbW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!IQbW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IQbW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg" width="1280" height="564" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:564,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107257,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786178?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IQbW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 424w, https://substackcdn.com/image/fetch/$s_!IQbW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 848w, https://substackcdn.com/image/fetch/$s_!IQbW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!IQbW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe11d500e-ad93-4677-b455-a80a090caaba_1280x564.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>If I had to put the SecOps lifecycle on a scale of importance, I&#8217;d probably put more weight on the left side. The funny part is that the left side is also the quiet one. Alerts, investigations and incidents usually make it obvious when something is wrong.</p><p>Pipelines and detections, on the other hand, can be broken for weeks without anyone noticing.</p><p>In most SIEMs, you won&#8217;t find out until an alert is supposed to fire, assuming it ever does.<br>By default, not many SIEMs give you particularly good pipeline monitoring(SIEM vendors don't jump now to convince me yours has the best one), so you need continuous testing to catch broken ingestion, parsing or detection logic before the attacker does.</p><p>And this is where I think attack emulation, detection validation, pipeline monitoring and the broader SecOps resilience bucket become really important.</p><p>Because if you don&#8217;t continuously test whether your detections actually catch what they were designed to catch, you basically have two options: trust that they work, or let the attacker QA them for you.<br>Neither is a great strategy.</p><p>Same for pipelines. If logs stop arriving, fields change, parsers break or some connector quietly dies, you might still have a beautiful SIEM dashboard. It just happens to be beautifully wrong.</p><p>Attack emulation has obviously been around for a long time, so none of this is particularly revolutionary. What I think is changing is that the category starts to expand. Automated red teaming, BAS, attack emulation, detection validation and probably parts of pipeline validation start converging into something closer to a continuous SecOps resilience layer.</p><p>And I think that becomes even more important as the SOC gets more automated. If agents are going to investigate, triage and eventually make more decisions for us, someone still needs to make sure the foundations underneath them are not held together with duct tape and three broken API integrations.</p><p>Does attack emulation remain its own category, or does it eventually become a native part of the SIEM / SecOps architecture?</p><p>Have a great weekend ahead!</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 11 September 2026<br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7504166539735220224"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #28: RunReveal to ClickHouse: both sides converge on the SIEM]]></title><description><![CDATA[ClickHouse acquires RunReveal and moves into SIEM. Data-layer vendors move right, AI SOC and SOAR vendors move left, and both converge on the same spot.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-28-runreveal-to-clickhouse</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-28-runreveal-to-clickhouse</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 04 Sep 2026 15:27:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EiW2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post is here, and this week comes with another acquisition.</p><p>In case you missed it, RunReveal got acquired by ClickHouse. Yes, you guessed it, this is ClickHouse moving into the SIEM space. They will say they remain a neutral foundation for everyone building security products on top of them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EiW2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EiW2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EiW2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EiW2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EiW2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EiW2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg" width="1280" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:115657,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786175?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EiW2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EiW2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EiW2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EiW2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc251a94a-b559-4730-b6e5-b5f3a00d6f1d_1280x795.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>This is the shift I predicted. Companies that sat on the far left of the secops shift map (data layer, storage, query) are moving right. First they become a SIEM, then they add the rest: AI SOC, SOAR, agent builder.</p><p>On the other side, vendors that started in AI SOC and SOAR/automation are now heading toward the SIEM.</p><p>Both sides are converging on the same spot. The SIEM space is going through real disruption.</p><p>I will say, AI SOC as a technology was the catalyst that triggered the SIEM migration as well. Or AI is the catalyst for rethinking your SecOps stack.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 4 September 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7501625397344735233"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #27: SOC-CMM 2026: SOAR won automation, lost the screen]]></title><description><![CDATA[SOC-CMM 2026: the SIEM is still the single pane of glass (45% vs 24% for SOAR) while SOAR won automation. Why AI adoption numbers in surveys are understated.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-27-soc-cmm-2026-soar</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-27-soc-cmm-2026-soar</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 28 Aug 2026 15:25:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PPqt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post, and this week it is about the new SOC-CMM 2026 SOC maturity report</p><p>Great work as always by Rob van Os</p><p>There are few things caught my attention, and the first one is a SIEM story.</p><p>The SIEM is still the single pane of glass for most SOCs. 45% vs 24% for SOAR.<br>And I think I know why SOAR lost this battle.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PPqt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PPqt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 424w, https://substackcdn.com/image/fetch/$s_!PPqt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 848w, https://substackcdn.com/image/fetch/$s_!PPqt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 1272w, https://substackcdn.com/image/fetch/$s_!PPqt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PPqt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png" width="1076" height="1276" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1276,&quot;width&quot;:1076,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171783,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786171?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PPqt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 424w, https://substackcdn.com/image/fetch/$s_!PPqt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 848w, https://substackcdn.com/image/fetch/$s_!PPqt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 1272w, https://substackcdn.com/image/fetch/$s_!PPqt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bc1cde-4c81-4653-828e-03ee2856d27a_1076x1276.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>&#128312; Most SOAR platforms had way better case management than any SIEM. But it never connected well enough with the SIEM. In the end you had to  jump back and forth to run queries and investigate, and if your investigation lives in one tool and your case lives in another, you consolidate on the one where you you have all the data to get the job done. That usually ends up being the SIEM in this case.<br>Funny enough, the same report shows SOAR has taken over as the primary automation tool (70% vs 45% for SIEM).<br>So SOAR won automation, lost the screen.</p><p>&#9643;&#65039;Second, only 27% say they use AI embedded in existing tooling. Show me a security tool in 2026 that doesn't ship AI summaries by default. EDR, SIEM, email security, everything has an LLM baked in whether you asked for it or not. My read is not that the rest don't use AI, it's that they don't register it as using AI. When AI is a feature instead of a decision, it becomes invisible. Which also means every AI adoption number in every survey out there is probably understated.</p><p>&#9643;&#65039; Third, the AI value numbers. Around 60% report seeing some value from AI in the SOC. But 57% also say they have no AI adoption strategy at all. So who answered the value question? If it's everyone, then people without a strategy (and possibly without real usage) are rating value, and of course you see no value in something you don't use. If it's only the AI users, then the value picture is a subset and shouldn't be read as "AI delivers limited value in the SOC". Before we conclude AI is underdelivering, I want to know the denominator.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 28 August 2026<br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3AugcPost%3A7499070845785645056"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #26: We crunch the numbers]]></title><description><![CDATA[SOC numbers change with every report: alerts per analyst, investigation time, automation savings. Some are made up. Practitioner research, no vendor agenda.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-26-we-crunch-the-numbers</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-26-we-crunch-the-numbers</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 21 Aug 2026 15:23:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xLGO!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5375acae-8a8c-4f56-a65b-11f2df6dc8a4_500x500.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post is here.<br>This week, we crunch the numbers.</p><p>You&#8217;ve probably seen the posts and blogs from Rafa&#322; Kitab about the very different numbers floating around the SOC. How many alerts analysts handle, how long investigations take, how much time is wasted, how much automation saves.</p><p>And somehow, depending on which report you read, the numbers can be very different.</p><p>I think some of them are made up. Or, to be nicer, calculated in ways that serve very different purposes.</p><p>So we want to see what the reality actually looks like.</p><p>No vendor benchmark. No hidden agenda. No &#8220;AI saves analysts 97.3% of their day&#8221; conclusion already written before we collect the data.</p><p>Just practitioner research.</p><p>If you&#8217;re a SOC leader and want to participate, let us know.</p><p>On the plus side, I feel like I&#8217;m seeing fewer of those wild reports lately. Not sure if all the ranting changed how the market publishes these numbers, or LinkedIn finally learned to stop serving them to me &#128516;</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 21 August 2026<br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7496581733220499456"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #25: The flavors of SIEM, or SIEM-not-SIEM]]></title><description><![CDATA[Five SIEM flavors: traditional, decoupled, integrated SecOps, federated, standalone. Each is an operating model. Choose on people, process and technology.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-25-the-flavors-of-siem</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-25-the-flavors-of-siem</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 14 Aug 2026 15:22:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s0bd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post, and this week it is about the flavors of SIEM. Or as it was put much better than I could: SIEM-not-SIEM.</p><p>Alex Hurtado put out a really good breakdown of the SIEM operating models this week . Traditional, Decoupled, Integrated SecOps, Federated, and Standalone.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s0bd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s0bd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 424w, https://substackcdn.com/image/fetch/$s_!s0bd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 848w, https://substackcdn.com/image/fetch/$s_!s0bd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!s0bd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s0bd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg" width="1280" height="676" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:676,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121207,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786167?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s0bd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 424w, https://substackcdn.com/image/fetch/$s_!s0bd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 848w, https://substackcdn.com/image/fetch/$s_!s0bd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!s0bd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb0c388a-4eb6-4901-976a-70507a182bb0_1280x676.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Love the visual, and yes, I think these are currently all the flavors and I see it as operating model map.</p><p>Every decision starts with questions about your environment. Your telemetry footprint. Your engineering capacity. Your ecosystem. Whether you&#8217;re rebuilding or optimizing. Whether you&#8217;re cloud native or still carrying legacy.</p><p>Choosing a SIEM it should depend on your PPT. Not the PowerPoint deck you&#8217;ll use to present your new SIEM, but your People, Processes, and Technology.</p><p>Changing the SIEM platform is only one piece.</p><p>Every one of these architectures assumes a different way of operating.</p><p>Different workflows. Different responsibilities. Different levels of engineering maturity. In many cases, a completely different skill set within the team.</p><p>Some models make perfect sense for lean teams that want simplicity and automation. Others only become practical when you have a larger team with dedicated engineering resources.</p><p>So now you have a great resource to help you with this &#128512;</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 14 August 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7494052244275912706"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #24: Black Hat edition]]></title><description><![CDATA[Black Hat 2026 through the SIEM lens: close to 60 companies advertising AI SOC, SIEM barely a headline, and why a decoupled SIEM is still the core of the SOC.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-24-black-hat-edition</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-24-black-hat-edition</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 07 Aug 2026 15:20:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JLqg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post: BlackHat edition</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JLqg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JLqg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JLqg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JLqg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JLqg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JLqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg" width="500" height="810" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:810,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68283,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786039?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JLqg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JLqg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JLqg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JLqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d48c5e5-9d46-47d5-9d38-fd8058adc5fd_500x810.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Back at BlackHat after a long pause. It was great catching up in person with peers, prospects and customers.</p><p>Full impressions post next week. Right now I am past 24 hours on the road thanks to canceled flights.</p><p>First time attending as a vendor, but also as an analyst and researcher of this space. Two different lenses on the same show floor.</p><p>First observation. The expo is frown a lot. Maybe even bigger than RSAC, and shorter, so you do not get enough time to walk it properly and see everyone.</p><p>Second observation. AI SOC dominated. 40 plus vendors positioning directly in the category. Add 13 SIEM vendors that now claim AI SOC capability and were loud about it. Add EDR vendors. Add NDR vendors, and there were enough of them claiming it that we added a dedicated AI SOC capability field for NDR on our tracker. Put it together and we are close to 60 companies advertising AI SOC in some shape or form. If you want the nuances, you know where to find them SecOps Unpacked.</p><p>Now the SIEM part, because this is the SIEM post.</p><p>SIEM did not have strong presence at least not as a headline. One of the most widely deployed technologies in security, and it was not heavily advertised. Some rip and replace messaging, as always.</p><p>My take. You can break SIEM apart. You can decouple storage, pipeline, detection, search. But what you end up with is still SIEM, just a different deployment model. SIEM is not a product category anymore, it is the core of the SOC.</p><p>AI SOC was the theme of this Black Hat. It will be even louder at the next RSAC. Because it is the thing driving the largest transformation of the SOC in the last decade.</p><p>And if you walked some of those booths and still cannot make sense of the messaging, the full evaluation framework is on SecOps Unpacked.</p><p>More next week.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 7 August 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7491475044318064641"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #24: Data pipelines to SIEM to AI SOC]]></title><description><![CDATA[Cribl buys CardinalOps: data pipelines move into SIEM and AI SOC while AI SOC vendors move left. Three plays: platform, decoupled point solutions, MDR on top.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-24-data-pipelines-to</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-24-data-pipelines-to</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 17 Jul 2026 15:18:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Zf_J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post is here! This week: data pipelines to SIEM to AI SOC.<br>You probably saw the news, Cribl acquired CardinalOps (congrats to both teams).</p><p>The play makes a lot of sense.</p><p>Cribl has been moving toward the SIEM space for a while and the detection layer was the missing piece. CardinalOps gives them detection engineering, coverage assessment, finding broken and noisy rules. Not a full SIEM yet, but the direction is clear.</p><p>And they are not the only ones heading this route. We are seeing more and more players that started as data pipelines moving into SIEM and adding AI SOC on top. The AI SOC piece is what makes them compelling. In the past you needed SOAR-like capabilities to offer the investigation piece, now the agents cover that.</p><p>On the other side we see vendors that started as AI SOC moving left into the SIEM piece. Far left into data pipelines is harder to get. But that's where the demand is. Many orgs looking into AI SOC don't just want triage, they want to replace or consolidate their SIEM, MDR and SOAR costs. Every AI SOC conversation is a consolidation conversation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zf_J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zf_J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zf_J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zf_J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zf_J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zf_J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg" width="1280" height="639" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:639,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95922,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786036?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zf_J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zf_J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zf_J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zf_J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F481426d5-a7c9-419c-a3a6-b1fddbca12d3_1280x639.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>How I see this playing out, three types of implementations:</p><p>&gt;&gt; Platform play. This is where the ISOC category is getting stronger. The usual large players that offer everything.</p><p>&gt;&gt; Point solutions and decoupled SIEM. Many smaller solutions added to the stack, combo of vendors plus build it yourself.</p><p>&gt;&gt; Existing stack plus MDR and/or AI SOC on top. For those that want minimal tech disruption. And here I think the demand is high, AI SOC with MDR or MDR with AI SOC capabilities.</p><p>If you some additional play let me know, writing a full blog piece on this topic.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 17 July 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7483805619083288576"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #22: Almost every SIEM has AI SOC]]></title><description><![CDATA[32 vendors now pair SIEM with AI SOC. The capability is commoditized, but nobody agrees what it means. Four components it needs, from 200 practitioner talks.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-22-almost-every-siem</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-22-almost-every-siem</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 10 Jul 2026 15:15:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vjSw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM: Almost every SIEM Has AI SOC<br>We currently track 32 vendors with both SIEM and AI SOC capabilities. But not all AI SOC pure play vendors has a SIEM (this is different category)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vjSw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vjSw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vjSw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vjSw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vjSw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vjSw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg" width="800" height="943" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:943,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72531,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786032?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vjSw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vjSw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vjSw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vjSw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2cd32cb-e067-4fb3-b6dc-f068763d2f80_800x943.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Look at the large players (some might say traditional SIEM). They all have AI SOC now. It became that commoditized.</p><p>Some will argue it's not as deep as the pure-play AI SOC vendors.</p><p>You're right. It's not.</p><p>But what even is AI SOC?</p><p>Over the past year I spoke with over 200 practitioners, and AI SOC meant something different to almost every one of them.</p><p>In general, I hear: autonomous triage. Close what's noise, escalate what's worth investigating. But triage itself means different things to different people.</p><p>Some see basic enrichment. Some expect AI SOC to go deep, even run forensics. Others expect remediation steps staged and ready, so they just approve execution.</p><p>I tried creating key components few times, maybe one day they get standardized and we all agree what it should have until than every SIEM can say it has AI SOC.</p><p>In my view it should have:<br>-Data Ingestion and Normalization Engine<br>-Knowledge Graph (Context is everything)<br>-Investigation Engine (combo of automations, LLM rules)<br>-Response (Remediation actions and Feedback Loop)</p><p>So yes, every SIEM has AI SOC. How good, how broad, how deep is up to you to decide. On SecOps Unpacked we tagged it, so you can see which vendors expand further and which stay at basic triage.</p><p>And guess what. A SIEM with SOAR, AI SOC, and all the other bells and whistles is still called a SIEM. I don't think the name changes anytime soon.</p><p>Do you think we should have this checkbox on SecOps unpacked profiles for AI SOC vendors? Does it even matter to you?</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 10 July 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7481363003171311616"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #20: The checkbox problem]]></title><description><![CDATA[We track 40 SIEM vendors. Bundled SOAR, UEBA and case management is mostly checkbox, built to survive an RFP. SIEMs win on detection, query speed and cost.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-20-the-checkbox-problem</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-20-the-checkbox-problem</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 19 Jun 2026 15:11:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6Vli!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM: The checkbox problem<br>We track 40 SIEM vendors at SecOps Unpacked. That number surprised me also.</p><p>29 are pure-play SIEM with an AI SOC layer. The rest are AI SOC platforms that added SIEM to round out the portfolio.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6Vli!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6Vli!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6Vli!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6Vli!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6Vli!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6Vli!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg" width="800" height="1013" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1013,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80810,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215785284?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6Vli!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6Vli!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6Vli!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6Vli!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd05a9d-61ca-4f0e-bd75-9aeda27d2961_800x1013.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>What stands out is how many other categories they touch. Buy a SIEM from one of the larger players and you get SOAR, UEBA, case management, threat intel, vulnerability context, and 15 other things on top of it.</p><p>Most of it is checkbox. It exists to survive an RFP, avoid losing a deal, and give the account team an upsell conversation. I do not blame them. I do the same as a practitioner: I check what my SIEM does natively before I go looking for a point solution. &#128517;</p><p>But good enough is doing a lot of work there.</p><p>The SIEM wins or loses on detection quality, query performance, and cost at scale. Everything else is table stakes.</p><p>What makes this interesting is that when you map all these capabilities across vendors, many are converging on the same footprint. That is exactly what Gartner's ISOC category describes.</p><p><a href="https://lnkd.in/drpSJ7zC">https://lnkd.in/drpSJ7zC</a></p><p>So yeah, is there checkbox feature in your SIEM that you really like?</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 19 June 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7473752324075708416"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #20: SIEM readiness: who actually owns it?]]></title><description><![CDATA[SIEM readiness: who owns pipeline and detection health? SIEM engineering sets it up, detection engineering finds it broken, and the gap stays open for months.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-20-siem-readiness-who</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-20-siem-readiness-who</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 12 Jun 2026 15:09:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NUm2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post is here. This week I talk about SIEM readiness, or just call it health checks. Who actually owns it?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NUm2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NUm2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NUm2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NUm2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NUm2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NUm2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:244283,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786028?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NUm2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NUm2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NUm2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NUm2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f297bb6-950d-492a-aa3a-c04dd983c877_1280x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>What I refer to as readiness is monitoring the health of your pipeline. Are the log sources you ingest in good shape? Are your detections in good shape?</p><p>I was thinking about a topic for this week and this came to mind. Then I went back through my experience over the years, just to realize the process was almost always broken.</p><p>Why I say this: SIEM is usually managed by your engineering team. They implement, fine tune and configure the platform (in some cases even external contractors). They set up the log sources, schemas etc. And they monitor if the data flows as expected, no sharp drops or spikes.</p><p>Then it falls on the detection engineering team, or even SOC analysts, to say when something is broken.<br>Because when you build detections you realize the data is missing key fields or is not parsed properly.<br>Or as a SOC analyst you see alerts with minimal context, or rules that stopped firing a long time ago. You tell detection eng, they go back to SIEM eng.</p><p>In other words, your pipeline can be broken for a very long time and no one will know. Because everyone is too busy doing triage, or building detections for the latest security article that doesn't affect you at all, but you want to show you are covered.</p><p>Is it just my experience, or others noticed this problem let's say even trend?</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 12 June 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7471220556093345792"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #21: SIEM onboarding: threat intel informs detections, detections inform data]]></title><description><![CDATA[Most SIEM projects fail on planning, not technology. Threat modeling first, then detection strategy, then decide which logs belong in the SIEM. In that order.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-22-siem-onboarding-threat</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-22-siem-onboarding-threat</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Wed, 10 Jun 2026 15:13:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FqCG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Another Friday SIEM post, hot off the blog stove. Almost as hot as the heat wave cooking Europe right now. &#9728;&#65039;</p><p>This week: SIEM onboarding</p><p>Most SIEM projects don't fail on technology. They fail on planning.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FqCG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FqCG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FqCG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FqCG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FqCG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FqCG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg" width="1280" height="848" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:848,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786030?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FqCG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FqCG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FqCG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FqCG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8160e37b-f7f3-4156-bb6c-81e5c4f87d2a_1280x848.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Connect as many systems as possible. Ingest whatever logs you can. Switch on a pile of detections. Then burn the next few months tuning.</p><p>The irony is that almost every project kicks off with a detailed implementation plan. Then reality hits. Timelines slip, priorities shift, and the team drifts right back into this reactive loop.</p><p>Start with threat assessment and threat modeling.<br>Know who you're defending against and which techniques actually matter in your environment.</p><p>From there:<br>Build your detection strategy.<br>Identify the data those detections require.<br>Then, and only then, decide what logs belong in the SIEM.</p><p>Threat intel informs detections. Detections inform data. In that order.</p><p>Having the right data and structure together with Detection engineering is the foundation.</p><p>Get it right and everything downstream gets easier. Get it wrong and you'll spend months chasing false positives, hoarding data you don't need, and tuning rules that should never have existed.</p><p>There are solid tools now for detection engineering, attack mapping, and validation.</p><p>Not everything is a crown jewel. If every system is business critical, none of them are.</p><p>Rafa&#322; Kitab Kitab wrote the definitive version of this, built on 30+ SIEM onboarding projects. He breaks the work into three 30-day phases (centralize and learn, build detections, protect crown jewels) and makes the case for why threat intel drives the whole thing.</p><p><a href="https://lnkd.in/eQCt3FWC">https://lnkd.in/eQCt3FWC</a></p><p>I won't ask the question, but I know you will be tempted to share a story, or maybe not &#128515;</p><p style="text-align: center;"><strong>Originally posted on LinkedIn on 26 June 2026. <br><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7476245855906369536">Read the original post and the comments</a>.</strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #18: SIEM migration: the process change is the work]]></title><description><![CDATA[Latio's 2026 SecOps report and a take on SIEM migration: check if your SIEM already does decentralized data, ask why you are moving, plan for process change.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-18-siem-migration-the</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-18-siem-migration-the</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 05 Jun 2026 15:07:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HQjY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>After conference week we have the Friday SIEM post. Even though I was not on InfoSec or Gartner summit this year, this week flew by.</p><p>So I will start with the Latio report, I went over it yesterday. For those that didn't see it..</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HQjY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HQjY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HQjY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HQjY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HQjY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HQjY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg" width="800" height="983" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:983,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112661,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HQjY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HQjY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HQjY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HQjY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c25acb3-3fc1-456a-9094-6a9cb06928cf_800x983.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>They just dropped their 2026 Security Operations report. Good work. I like how they break the categories, clean and honest about where the lines blur.</p><p>I really like  "The Guide to Modernizing a SOC Program." visual. That flowchart is the report. It starts in the right place: do you already have a way to ingest and search log data? Everything branches from there.</p><p>Adding my take.</p><p>If you are running a SIEM migration, or call it SOC modernization, the first question is usually: should I go decentralized data? And in many cases yes, it makes sense. Cheaper. Sometimes faster.</p><p>But do not rush.</p><p>First check if your current SIEM already supports decentralized data. A lot of them added bring your own bucket and federated search in the last two years. You might already own the thing you are about to migrate for.</p><p>Then ask. Why do you want to change the SIEM in the first place? Is it just cost?</p><p>If cost is the only reason, fix the data pipeline and the storage tier. You do not need a new platform for that.</p><p>If it is more than cost, detection portability, query speed, analyst experience, then maybe you do need different tech.</p><p>But understand what you are signing up for. New tech means new processes. You will re-tune detections, retrain analysts, rebuild runbooks.</p><p>The migration is the easy part. The process change is the work.</p><p>The report sequences it well: optimize the pipeline, decouple the detection engine, then move the data. Half-finished migrations are how teams end up with logs sprawled across three places and nobody sure where they live.</p><p>And only then look at where AI SOC fits your case. Agents sit downstream of your data. Bad data in, hallucinations out. No AI analyst fixes a broken data architecture.</p><p>More on my next release of the SecOps Shift Map.</p><p>LI anyways hates links,so just dropping them here anyhow probably I rolled the dice on low engagement because I want to share links &#128517;</p><p>In case you missed my blog from yesterday around Agent Builders for SecOps: <a href="https://lnkd.in/eefyJPjD">https://lnkd.in/eefyJPjD</a></p><p>And Latio report: <a href="https://lnkd.in/eKGa8bKW">https://lnkd.in/eKGa8bKW</a></p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 5 June 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7468676742510088192"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #17: How many times has SIEM survived the 'SIEM is dead' wave?]]></title><description><![CDATA[UEBA, XDR and the data lake all claimed to kill SIEM. ISOC does not: it is the SIEM. Why the category absorbs its challengers and what actually kills a SIEM.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-17-how-many-times-has</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-17-how-many-times-has</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 29 May 2026 15:04:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SxW1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post. This week: how many times has SIEM survived the "SIEM is dead" wave?</p><p>I saw a post this week about email being dead. Email is still here. Same with SIEM. Every few years a new category shows up to bury it, and every time SIEM is still standing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SxW1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SxW1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SxW1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SxW1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SxW1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SxW1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238377,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786025?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SxW1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SxW1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SxW1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SxW1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e2a1d2-3c70-43db-bbb3-6e6e93259bdc_1280x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The waves:<br>UEBA (2014 to 2016). Gartner coined the term. The pitch was that behavioral analytics and ML would make rules-based correlation obsolete. People forget this one, but it was the first real "SIEM is dead" push.</p><p>XDR (2018 to 2021). The loudest wave. Nir Zuk of Palo Alto Networks coined the term in 2018 at Ignite, and Cortex XDR shipped in early 2019. Palo Alto's line was literally that SIEM needs to be eliminated and replaced.</p><p>Security Data Lake / decoupled SIEM (2020 to 2023). The argument: SIEM is just an overpriced database. So decouple storage from analytics, bring your own lake, and put a detection engine on top.</p><p>And now Gartner has a name for the next one: ISOC, the integrated SOC. SIEM, SOAR and AI SOC in one platform, positioned as the next-gen SIEM.</p><p>Notice the difference. UEBA, XDR and the data lakes all claimed to kill SIEM. ISOC does not. The new term IS the SIEM.</p><p>SIEM does not die. It absorbs the challenger and takes its name.</p><p>So will ISOC be the SOC revolution everyone wants? My bet: no. Not because the tech is bad, but because the thing that kills a SIEM was never the category.</p><p>Like Rafa&#322; Kitab said in a recent post <a href="https://lnkd.in/dRQMFsZN">https://lnkd.in/dRQMFsZN</a>  your SIEM won't die because of a new term. Your processes and your people can kill it, through bad implementation.</p><p>Side note: on the SecOps Unpacked list I now track 36 vendors that pair SIEM with AI SOC. The category is not dying. It is eating its challengers.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 29 May 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3AugcPost%3A7466153238778744832"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #16: The Agent Builder layer and ISOC]]></title><description><![CDATA[SIEM added SOAR, then AI SOC, now Agent Builder. Gartner's ISOC may become the name for next-gen SIEM. Why Integrated beat Intelligent, and what that signals.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-16-the-agent-builder</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-16-the-agent-builder</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 22 May 2026 15:01:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8FIA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post is here , this week I wanted to bring to your attention The Agent Builder Layer and ISOC.</p><p>If you caught last month post, the SIEM ate the SOAR entree, is finishing the AI SOC main dish, and agent builder is now on the dessert menu.</p><p>CrowdStrike, Datadog, Databricks, Elastic, Google SecOps, Palo Alto and many others are adding this. Most are beta or pre-GA, but the direction is clear.</p><p>How this has layered over time:<br>SIEM &#8594; added SOAR &#8594; added AI SOC &#8594; now adding Agent Builder<br>(and many other things in between but for the sake of the argument I keep it simple)</p><p>The SIEM has also been going through major re-architecture in the past few years, and today I was reading a great post by David Bizeul who mentioned that Gartner is working on a new category: <strong>ISOC (Integrated Security Operations Center</strong>).<br><a href="https://lnkd.in/dxUDfjxq">https://lnkd.in/dxUDfjxq</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8FIA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8FIA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8FIA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8FIA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8FIA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8FIA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg" width="1280" height="854" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:854,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:148661,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215786023?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8FIA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8FIA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8FIA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8FIA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bc6dbb-0c55-4249-ac25-3d96b5ce2cff_1280x854.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This can grow into the new term for next-gen SIEM platforms. Because we all know calling it "next-gen" is lame.</p><p>How many years will it take for the new term to stick? Who knows.<br>But I see SIEM vendors going with "SIEM is dead, long live ISOC" sooner than later.</p><p>Side note: if you ask me, I would have gone with Intelligent over Integrated.</p><p>But Gartner probably has reasoning behind that choice. Integrated signals the convergence of multiple tools into one platform, which is a safer analyst framing than betting on AI staying central to the definition long term.</p><p>Working on a more in-depth piece on this for the blog next week.</p><p>Until then, have a great SIEMless weekend.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 22 May 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7463567443983134721"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #15: Vibe check: which AI use cases in SIEM are actually in production?]]></title><description><![CDATA[Vibe check: beyond alert triage, which AI use cases in SIEM actually run in production? Query generation, parsers and OCSF mapping, detections, dashboards.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-15-vibe-check-which-ai</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-15-vibe-check-which-ai</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 15 May 2026 14:59:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GIXf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This week we have the Vibe check Friday SIEM post<br>Outside of alert triage, AI use cases in SIEM are everywhere in the marketing decks. But what's actually landing in production?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GIXf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GIXf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GIXf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GIXf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GIXf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GIXf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg" width="1280" height="466" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:466,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112948,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215785815?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GIXf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GIXf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GIXf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GIXf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c1667c-4588-4a6b-9892-bae9fc6b2ba2_1280x466.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A few questions I'm curious about:</p><p>&#9642;&#65039; SIEM Query Language. Is anyone still writing it by hand? Or are your analysts just typing English and letting the LLM generate the query underneath? And when the generated query is wrong, who catches it?</p><p>&#9642;&#65039;Parsers. Are you still building custom parsers for your messy log sources, or do you trust AI to handle schema translation and OCSF mapping? How is it working on the weird vendor-specific stuff?</p><p>&#9642;&#65039;Detections. Anyone still constructing detections by hand for the rules that matter? Or is AI writing them now? What about the existing rule estate, are you using AI to find broken or stale rules?</p><p>&#9642;&#65039;Dashboards. Is the old way of building custom dashboards gone? Are you letting the SIEM generate visuals on the fly during investigations? What about your operational dashboards, SOC wall, exec metrics, compliance reports, are those still hand built?</p><p>Curious to here where we stand with these?</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 15 May 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7461093101072211968"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a>.</strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #14: Shift left, then use AI]]></title><description><![CDATA[Bad data plus bad process plus AI means bad outcomes at 100x scale. Bolting AI onto alerts is the wrong, expensive place to start. Shift left, then use AI.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-14-shift-left-then-use</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-14-shift-left-then-use</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 08 May 2026 14:57:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aXUD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friday SIEM post is here.<br>This week on the plate: SIEM AI enablement, transformation, or whatever fancy word we want to call it this quarter.</p><p>Where AI Actually Belongs in Your Pipeline?</p><p>We have been saying this for years. Bad data plus bad processes plus automation equals bad outcomes, faster.<br>With AI, the same applies. The only catch is now you get it 10x faster and at 100x scale.</p><p>Every time I say this on the blog, a podcast, or at a conference, someone asks: "OK, but what's the fix?"</p><p>And yes, I&#8217;m a big believer in not just pointing at problems without offering a direction forward.</p><p>What worked for me throughout my career is simple:<br>Use the right tools for the right job.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aXUD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aXUD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aXUD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aXUD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aXUD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aXUD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg" width="1280" height="852" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:852,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:201593,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215785814?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aXUD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aXUD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aXUD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aXUD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76d1a90-b008-4419-bf2b-61b6812221c9_1280x852.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Most teams default to the path of least resistance. They bolt AI onto the end of the pipeline, which in SIEM terms means alerts. It feels like the obvious move. Alerts are where the pain is visible. But it's the wrong place to start, and now it's also the expensive place to start.</p><p>We moved from user-based pricing, where you pay a flat rate regardless of activity, to usage-based pricing, where every query, every token, every inference call costs something. That shift makes tool selection a financial decision, not just a technical one.</p><p>Burning tokens on noisy, low-quality alerts is not just inefficient. It is a budget problem.</p><p>The right sequence is this. Use AI first where it compounds. Start with your data pipeline. Fix structure, normalization, and coverage gaps. Then move to detections. Improve logic, reduce noise, raise signal quality. Only after that should you apply AI to triage and analysis.</p><p>If you skip straight to the alert layer, you are not accelerating your SOC. You are paying to automate a broken process.</p><p>Shift left. Then use AI.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 8 May 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7458504145545871360"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #13: To log or not to log]]></title><description><![CDATA[To log or not to log: log everything, minimal coverage to pass the audit, or the sweet middle that looks good on paper and ends up paying close to option one.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-13-to-log-or-not-to-log</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-13-to-log-or-not-to-log</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 01 May 2026 14:46:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0XET!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>My Friday SIEM post is here, to log or not to log!<br>Getting Shakespeare vibes, I know. From what I have seen in my career there are 3 approaches.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0XET!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0XET!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0XET!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0XET!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0XET!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0XET!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg" width="1280" height="697" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:697,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:287557,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215785812?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0XET!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0XET!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0XET!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0XET!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffde5444d-ce87-48cf-89c8-9fa24c15f6a8_1280x697.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>LOG EVERYTHING. I know for some of you this might be scary, you see cash burning instantly, million dollar bills. And yes, depending on the size of the company and the SIEM they use, this might be doable. I have been part of orgs where it was, I loved it. You get a new log source, try to pull as much as possible.</p><p>Best part was whenever I needed to create a new detection I would just get everything I needed, no need to go through the log onboarding process again. Additional logs for forensics or deep investigation, I get them right away. Audit comes, we have everything, pass it on the fly.</p><p>Then there is the least optimistic way, onboard whatever we need just to have basic coverage and pass an audit or get a cert. Minimal coverage. I think in this case you are better off just using an MDR or MSSP, don't even bother. Anyhow you have partial coverage with them.</p><p>And we have the sweet middle, where you onboard just what you need, increase and decrease logs based on usage, you have a nicely balanced bill. In my opinion this one looks good on paper. In reality, adding logs is never easy, simply because of other stakeholders, and you will always have audit findings that need to be prioritized over engineering work. You end up paying close to option 1 and getting close to option 2.</p><p>Maybe I'm missing some other approach, let me know.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 1 May 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7455985489771163649"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #12: SecOps agents inside the SIEM versus standalone]]></title><description><![CDATA[Originally posted on LinkedIn, 24 April 2026]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-12-secops-agents-inside</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-12-secops-agents-inside</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 24 Apr 2026 14:53:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gEXb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>My Friday SIEM post is here, probably at this point I should add an edition number &#129300;<br>Today I wanted to discuss the difference between SecOps Agents and AI SOC inside a SIEM versus in a standalone product or SOAR.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gEXb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gEXb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 424w, https://substackcdn.com/image/fetch/$s_!gEXb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 848w, https://substackcdn.com/image/fetch/$s_!gEXb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 1272w, https://substackcdn.com/image/fetch/$s_!gEXb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gEXb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif" width="480" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:480,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:241917,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215785808?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gEXb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 424w, https://substackcdn.com/image/fetch/$s_!gEXb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 848w, https://substackcdn.com/image/fetch/$s_!gEXb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 1272w, https://substackcdn.com/image/fetch/$s_!gEXb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe78274f0-7ef8-4919-bd2c-6895b3edf6bc_480x853.gif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>SIEMs own the data, so they have the upper hand here.</p><p>Especially for teams that send everything into the SIEM, you will get amazing triage results inside it, simply because the SIEM has all the data. If done right, they can query that data the fastest and most optimized way to get you the best results. Timeline analysis, blast radius, all the bells and whistles.</p><p><strong>But ONLY if you get all the data there</strong>.</p><p>This means enrichments as well.</p><p>Then you will be limited on response.</p><p>As I explained in my previous posts, SIEM vendors were smart to play the SOAR card. The bad part is that they never invested enough to make it shine. In my opinion, unless you have all response in a single ecosystem, you need a vendor agnostic agentic, automation, and orchestration layer.</p><p>Where the pure play and SOAR vendors have the upper hand is when you don't send everything to your SIEM.</p><p>They do enrichment better, but they are somewhat limited on what APIs they have available with the SIEM to run queries and retrieve data, or with any other system from which you ingest alerts and detections.</p><p>And SOAR-like vendors will shine with the response. Slapping MCP for response won't make the cut.</p><p>On this and more, I will join Chris Hughes on May 4th  where we will discuss this and other fun topics.</p><p><a href="https://lnkd.in/dXzpAJiy">https://lnkd.in/dXzpAJiy</a></p><p>&#668;&#7424;&#7456;&#7431; &#7424; &#610;&#640;&#7431;&#7424;&#7451; &#7457;&#7431;&#7431;&#7435;&#7431;&#628;&#7429;!</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 24 April 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7453456590277500928"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Friday SIEM #11: SIEM ate the SOAR entree, AI SOC is the main dish, Agent Builder is dessert]]></title><description><![CDATA[SIEM ate SOAR, is eating AI SOC, and Agent Builder is dessert. Acquired vs built SOAR in SIEMs, why AI SOC fragments the same way, and the one-vendor trap.]]></description><link>https://blog.secops-unpacked.ai/p/friday-siem-12-siem-ate-the-soar</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/friday-siem-12-siem-ate-the-soar</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 17 Apr 2026 07:58:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NdOb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Back from vacation and hitting my Friday SIEM post. This week theme is: SIEM ate the SOAR entree, is eating AI SOC as a main dish, and planning for Agent Builder as dessert.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NdOb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NdOb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NdOb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NdOb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NdOb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NdOb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg" width="1280" height="698" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:698,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:135059,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.secops-unpacked.ai/i/215785805?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NdOb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NdOb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NdOb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NdOb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c3a1674-8457-4976-ad37-28ca95c95333_1280x698.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br></p><p><strong>The SOAR entree</strong>. Most if not all large SIEMs shipped their own SOAR. Latest was Elastic announcing Elastic Workflows this March. They're calling it the end of the "SOAR automation tax."</p><p>The patterns split into a few categories.</p><p><strong>Acquisition path</strong>: Palo Alto (Demisto), Splunk (Phantom), Google SecOps (Siemplify), Fortinet (CyberSponse).</p><p>Took years for some to even get a unified UI. Separate infra, a lot of stitching, you could sense it. Development slowed or got abandoned. What's left is mostly case management with basic automation and integrations stuck within the vendor ecosystem.</p><p><strong>Built from scratch</strong>: Elastic and Datadog developed natively. Worked with Datadog's for a few months. Decent, simple, but not a true automation platform. More case management orchestration.</p><p><strong>EDR turned SIEM turned SOAR</strong>: CrowdStrike and SentinelOne. Checkbox items. Great at basic case orchestration within their own ecosystem and automating notifications. That's about it.</p><p><strong>The AI SOC main dish</strong>. Most major SIEM players now have some form of AI SOC. I expect the same pattern as SOAR. Some acquire, others build. Same fragmentation likely. This connects to what Ross Haleliuk wrote recently about AI agents challenging the SIEM business model. SIEMs charge for ingestion. AI agents don't care if data is centralized. People expect analytics and workflow automation, not just storage.</p><p><strong>Agent Builder as dessert</strong>. CrowdStrike, Palo Alto, Databricks all have agent builder capabilities now. Most still early beta but that's the direction. Building an agent framework natively inside a SIEM is hard and I don't think most vendors are there yet.</p><p>Standalone automation platforms have a real advantage here. Being on the builder side and seeing what it takes, the complexity is significant. I expect many SIEM vendors will go the acquisition route. Same playbook as SOAR.</p><p>And we might end up in the same place too. SIEM vendors building agent builders around their own ecosystems rather than connecting to everything. Agents that only work within one vendor's stack defeats the whole purpose.</p><p>A SOC doesn't run on one vendor.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Originally posted on LinkedIn on 17 April 2026. <br></span><a href="https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A7450908856735502336"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Read the original post and the comments</span></a><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">.</span></strong></p>]]></content:encoded></item></channel></rss>