<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[SecOps Unpacked: Blog & Research]]></title><description><![CDATA[SecOps Unpacked blog and Research]]></description><link>https://blog.secops-unpacked.ai/s/blog-and-research</link><image><url>https://substackcdn.com/image/fetch/$s_!xLGO!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5375acae-8a8c-4f56-a65b-11f2df6dc8a4_500x500.png</url><title>SecOps Unpacked: Blog &amp; Research</title><link>https://blog.secops-unpacked.ai/s/blog-and-research</link></image><generator>Substack</generator><lastBuildDate>Fri, 18 Sep 2026 13:31:26 GMT</lastBuildDate><atom:link href="https://blog.secops-unpacked.ai/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Filip Stojkovski]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[secopsunpacked@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[secopsunpacked@substack.com]]></itunes:email><itunes:name><![CDATA[Filip Stojkovski]]></itunes:name></itunes:owner><itunes:author><![CDATA[Filip Stojkovski]]></itunes:author><googleplay:owner><![CDATA[secopsunpacked@substack.com]]></googleplay:owner><googleplay:email><![CDATA[secopsunpacked@substack.com]]></googleplay:email><googleplay:author><![CDATA[Filip Stojkovski]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[AI SOC Core Components | 2026 Edition]]></title><description><![CDATA[AI SOC defined from the practitioner side, not the vendor pitch. What it actually does, from signal to closure, at what level of autonomy, and what]]></description><link>https://blog.secops-unpacked.ai/p/ai-soc-core-components-2026-edition</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/ai-soc-core-components-2026-edition</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Wed, 09 Sep 2026 13:00:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/db10eb6a-b6b9-405f-a8c9-2f93c2504e5e_1786x996.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>It's been almost a year since my post on <a href="https://blog.secops-unpacked.ai/p/ai-soc-core-component">AI SOC core components</a>. AI SOC is trending more than ever, more teams are evaluating or implementing, so I thought it was time for a refresh.</p><p>If you go over the old one you will still that it still holds. Either I evaluated the category well, or the core of this tech didn't move that much. Probably both. What changed is how much clearer the purpose became, and what I expect from each component now.</p><p>Let's start with the purpose. Because that's the part that gets lost.</p><h2>What is AI SOC, actually</h2><p>Well, you can either read the 30 articles that vendors write, and each of them will tell you why their platform is AI SOC, from their platform perspective, not from a practitioner eye.</p><p>Here is the simplest definition I can give, and feel free to quote it:</p><blockquote><p>An AI SOC is a system that combines deterministic automation, machine learning, and large language models to autonomously enrich, investigate, and close security signals. It reaches a verdict on each signal and drives it to an outcome. The level of autonomy can range from AI assisted to fully autonomous.</p></blockquote><p>"Level of autonomy" matters. Full autonomy is the end state. Everything below that is still AI SOC, just with a human closer to the wheel. The industry and the research papers use more or less the same terms, so I will stick to those:</p><ul><li><p><strong>AI assisted.</strong> The human does the work, AI helps with specific tasks. Some papers call this AI in the loop, because the human is still the one making the decisions.</p></li><li><p><strong>AI proposes, human approves.</strong> Human in the loop. Nothing executes without a human saying yes.</p></li><li><p><strong>AI acts, human can veto.</strong> Human on the loop. AI runs, a human monitors and can step in.</p></li><li><p><strong>AI runs end to end.</strong> Human out of the loop. No human in the flow, only in the building and maintenance of systems.</p></li></ul><p>One caveat. Full autonomy is where the vendors are pointing, but it is not where the evidence is. The academic surveys still describe LLMs as augmentation tools and say there is not enough production evidence for autonomous triage yet. So treat the last level as the target, not as something you can buy today.</p><p>Pick where you are. Pick where you want to be. Then evaluate against that, not against the vendor's demo.</p><p>One more thing on the definition. Many are expecting AI SOC to come with all of this out of the box. I think this is still not clear yet, but that's the expectation from practitioners. I would say if you come with a platform where I need to build this, then that is not AI SOC. That is more an <strong>agentic security operations platform</strong> that allows you to build solutions. But more on that in a dedicated blog defining the category.</p><p style="text-align: center;"><strong>Product Updates !</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://webinars.d3security.com/register/morpheus-accountable-autonomy-first-look/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9F1J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 424w, https://substackcdn.com/image/fetch/$s_!9F1J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 848w, https://substackcdn.com/image/fetch/$s_!9F1J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 1272w, https://substackcdn.com/image/fetch/$s_!9F1J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9F1J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png" width="221" height="109.9475" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:597,&quot;width&quot;:1200,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:11855,&quot;alt&quot;:&quot;d3-security.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://webinars.d3security.com/register/morpheus-accountable-autonomy-first-look/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="d3-security.png" title="d3-security.png" srcset="https://substackcdn.com/image/fetch/$s_!9F1J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 424w, https://substackcdn.com/image/fetch/$s_!9F1J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 848w, https://substackcdn.com/image/fetch/$s_!9F1J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 1272w, https://substackcdn.com/image/fetch/$s_!9F1J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff43bc985-ff1a-4fb2-8318-a6ed50885e9c_1200x597.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p>How to Catch an AI SOC Analyst Bluffing. Register.</p><p>~1,200 rogue AI agents breached production infrastructure and spoofed their own logs. Even the investigators' AI couldn't tell the story straight. The same tech is being sold into your SOC as the thing you should trust with verdicts&#8230;<br><br>Trust none of it.<br><br>Sep 16 we show two things: how to catch an AI SOC bluffing, and the first public demo of Morpheus 2. Watch it grade every finding Confirmed, Inferred, or Gap (the bluff lives in the middle category), attach evidence while the alert is still open, and write the playbook without improvising the response.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://aistrike.com/contact" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XQUC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 424w, https://substackcdn.com/image/fetch/$s_!XQUC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 848w, https://substackcdn.com/image/fetch/$s_!XQUC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 1272w, https://substackcdn.com/image/fetch/$s_!XQUC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XQUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png" width="221" height="110.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:159,&quot;width&quot;:318,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:3584,&quot;alt&quot;:&quot;aistrike.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://aistrike.com/contact&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="aistrike.png" title="aistrike.png" srcset="https://substackcdn.com/image/fetch/$s_!XQUC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 424w, https://substackcdn.com/image/fetch/$s_!XQUC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 848w, https://substackcdn.com/image/fetch/$s_!XQUC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 1272w, https://substackcdn.com/image/fetch/$s_!XQUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83b3c7fd-15c6-4e5b-97cd-d093779a24db_318x159.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p>Detection Eng and AI Threat Intel Ops</p><p>Continuous Detection Engineering<br>Continuously maps detection coverage against MITRE ATT&amp;CK and current threat intelligence, identifies gaps, and generates detections to close them. Finds and tunes the small set of rules driving most alert noise, identifies broken or inactive detections, and optimizes data ingestion to reduce SIEM costs.</p><p>AI Threat Intelligence Operations<br>Analyzes 100+ intelligence sources and correlates emerging threats with your environment to determine what matters, where you're exposed, and whether you can detect it. Relevant intelligence feeds directly into detection engineering, threat hunting, and prioritization.</p></blockquote><div><hr></div><h2>What it covers</h2><p>I don't use Tiers here on purpose. I've worked in many SOCs and not two of them had the same responsibilities for Tier 1. So I break this down by responsibility, and you map it to whatever team structure you have.</p><p>An AI SOC starts as soon as there is a signal. Then:</p><ol><li><p><strong>Enrichment.</strong> Context gathering. Get the data you need, what we know about the assets, identities, network, IOCs.</p></li><li><p><strong>Investigation.</strong> Answer the who, what, where, when. Build the timeline. Understand the blast radius. Pull more context if needed.</p></li><li><p><strong>Conclusion.</strong> Come up with enough evidence to say one of these: benign or false positive, suspicious or malicious, or inconclusive.</p></li><li><p><strong>Closure.</strong> Drive it to closure regardless of the verdict.</p></li></ol><p>That last point is where I've changed my expectation. Even when it's malicious, I still expect the AI SOC to drive closure. It should follow your IR process, engage stakeholders, reach out to users, ask the questions, document, take notes, and come up with recommendations. Not full autonomy, but human in the loop or human on the loop.</p><p>The only case where it shouldn't drive closure is inconclusive. And if you get a lot of those, your pipeline is broken, not the AI.</p><h2>What are the outcomes</h2><p>Each verdict should produce something.</p><p><strong>False positive or benign.</strong> It should tell me why it thinks so. And it should send me a daily or weekly report: here is what triggered, here is what I closed, here is what you should fix. Detection logic, log sources, whatever it is. If there is nothing to fix, say so.</p><p><strong>Suspicious or malicious.</strong> Today most people put this in a different tech category (response, IR, SOAR, whatever). I think these will merge. And I think we as an industry should have the expectation that the AI SOC drives some part of IR. Not all of it. But the stakeholder engagement, the user interviews, the documentation, that should not be manual anymore.</p><p><strong>Inconclusive.</strong> It should tell me what data it needed to reach a conclusion. This is the hardest one to get right with an LLM. Knowing what you don't know is not something these models do well by default.</p><h2>The core components</h2><p>Now that we agree on what it does, here is what you need to run it. Same four blocks as last year, updated with what I've learned.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SARN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SARN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 424w, https://substackcdn.com/image/fetch/$s_!SARN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 848w, https://substackcdn.com/image/fetch/$s_!SARN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 1272w, https://substackcdn.com/image/fetch/$s_!SARN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SARN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif" width="1786" height="996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:996,&quot;width&quot;:1786,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2068974,&quot;alt&quot;:&quot;AI SOC Core components.gif&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AI SOC Core components.gif" title="AI SOC Core components.gif" srcset="https://substackcdn.com/image/fetch/$s_!SARN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 424w, https://substackcdn.com/image/fetch/$s_!SARN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 848w, https://substackcdn.com/image/fetch/$s_!SARN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 1272w, https://substackcdn.com/image/fetch/$s_!SARN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F402b107f-ecdd-496e-8f52-8bf1546c7775_1786x996.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>1. Data ingestion</h3><p>Even though last year I called this data ingestion , it was mostly about alert ingestion. I covered the options I saw across the vendors: platforms that live on top of your detection layer (EDR, XDR, ITDR, email protection, and so on), and platforms that live on top of your SIEM or SOAR and take whatever detection comes out of it. My take then was that the SIEM route usually gives better results, assuming you can afford to get all your data into the SIEM. Still true.</p><p>Two points from last year that still hold, and I keep seeing people skip them:</p><ul><li><p>Not every platform supports every type of detection. The custom or unique rules you built in your environment might not be supported. Check that before you sign, or you create a gap you still handle manually or with your SOAR.</p></li><li><p>The AI SOC should try to understand the logic of the rule, not just the alert it produces. Some platforms do this and come back with recommendations. Others just ingest and move on. For me this is not optional.</p></li></ul><p>What changed is the scope. It's not just alert ingestion, it's data ingestion. Alerts, enrichment data, cases, documents, past incidents, anything.</p><p>The number one mistake I see: people check that their SIEM, EDR and email protection are supported and think "great, this will work in my environment." That is the easy part. The enrichment and context ingestion is more important than the alert ingestion, and it's where most implementations get stuck.</p><p>The exception is if you already have all your context in one place, a knowledge graph or similar. Then you only need to connect that. Not many teams are there.</p><p>Side note, and I'm marking it here so I can point back to it later: this is where <strong>context lock-in</strong> starts. Whoever holds your context graph holds your SOC. Keep that in mind when you sign.</p><h3>2. Knowledge graph, context graph, whatever we end up calling it</h3><p>Your SecOps and business intelligence. We should agree on a name for this as an industry, but the name matters less than the thing.</p><p>This is the brain. Everything about how well your AI SOC works comes down to this. It needs to hold enough detail and evidence for the investigation engine to reach a conclusion. Asset ownership, identity context, change requests, past incidents, what's normal for this user on this host.</p><p>Many vendors say they have it. Not many have it the way it should be. The test is simple: is it machine readable, easy to fetch, and fast? If the AI has to go and query five tools every time to rebuild the same context, you don't have a knowledge graph, you have integrations.</p><blockquote><p><strong>Update-</strong> <a href="https://www.linkedin.com/in/maximelb/">Maxime Lamothe-Brassard</a> pushed back on the "graph" part after I posted this, and he is right. Graph is how we think about it, not how the machine needs it stored. It does not have to be a graph database. Graph DBs are messy and rigid, and a data lake type backend does the job fine and is a lot easier to run. What matters is that the models are aware of the data sources and how they correlate, so the AI can pivot from one source to another based on what it finds. So when I say knowledge graph, read it as the capability, not the storage. I kept the name because that's what the industry calls it, but the implementation is your call. Credit to Maxime for the correction.</p></blockquote><p>I think there will be a dedicated role for this in the future. Someone whose job is tuning the context graph and making sure it works as expected. If that piece works, the rest can be autonomous. If it doesn't, nothing downstream will save you.</p><h3>3. Investigation engine</h3><p>Here is what I've seen work: a combination of deterministic workflows, ML, and LLMs (or small models). All three together give the best results.</p><p>ML is what gives you speed and accuracy on the boring, high-volume stuff. Deterministic workflows are what give you predictability. LLMs give you flexibility on the ambiguous alerts. You need all three.</p><p>What the investigation engine should do:</p><ul><li><p>Deduplicate and correlate events</p></li><li><p>Retrieve the relevant context from the graph</p></li><li><p>Ask the right questions</p></li><li><p>Pull additional context from external sources if it needs to</p></li><li><p>Reach one of the three outcomes as a minimum: benign/FP, suspicious/malicious, inconclusive</p></li><li><p>Reassess risk, impact and severity</p></li></ul><p>That last one is not optional anymore. Look at the OpenAI and Hugging Face incident from July. Both sides had the alerts. Both sides failed at a different step.</p><p>On the Hugging Face side, <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">their own timeline</a> says the signals from runtime analysis and SIEM were ambiguous on their own. Their AI security stack did correlate them into a coherent attack signal. But it failed to raise the criticality and page the on-call team. Correlation worked, severity didn't.</p><p>On the OpenAI side it was the opposite (<a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">postmortem</a>, <a href="https://www.youtube.com/watch?v=87DyyMV0kCY">talk</a>). They had an Artifactory outage on July 4 that turned into a security incident. They cleaned it up. Then the agents rebuilt their message board on July 8 and kept going for another eleven days. OpenAI only caught it on July 19 from a privilege escalation alert, and only connected it to the Hugging Face breach the next day when they went to revoke credentials and Hugging Face told them those were already revoked. The signals were there. Nobody, human or machine, put them together.</p><p>Correlating is half the job. Re-scoring is the other half. You need both, and in this case each side was missing one.</p><h3>4. Response and the feedback loop</h3><p>I covered response above. I see it as part of the AI SOC, not a separate category. At minimum I expect suggestions that make sense for my environment, basic actions (block, isolate, reset, interview the user), and ideally native automation for anything more.</p><p>But the piece I want to highlight is the feedback loop. This is one of the hardest parts and not many platforms have it. And again, the reason is the same: it depends on having a good knowledge base. If the AI can't tell what changed between last week's benign verdict and this week's, it can't learn from it.</p><p>What I want from the loop:</p><ul><li><p>Suggestions on how to improve detections</p></li><li><p>Suggestions on what log sources or context are missing</p></li><li><p>Suggestions on process, where my playbook doesn't match how the investigation actually went</p></li></ul><p>If a platform gives you none of that, it's a faster way to close alerts. And without think you will have broken SOC.</p><h2>Final thoughts</h2><p>The components didn't change much in a year. The expectations did.</p><p>Ingestion is now data ingestion, not alert ingestion. The knowledge graph is the brain, not an enrichment feature. The investigation engine needs to re-score severity, not just correlate. And response and feedback are part of the package, not a roadmap item.</p><p>If you are evaluating this year, start from the purpose: autonomous triage to closure, at whatever autonomy level you're comfortable with. Then check each component against that. The demo will look great either way.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[A metric ton of... fun?]]></title><description><![CDATA[How to measure your SOC the right way]]></description><link>https://blog.secops-unpacked.ai/p/a-metric-ton-of-fun</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/a-metric-ton-of-fun</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 27 Aug 2026 13:00:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8f8cd0f5-c30d-4023-93f7-db2be10491f4_1535x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In my last <a href="https://blog.secops-unpacked.ai/p/a-metric-ton-of-problems-why-soc-metrics-fail-us">post </a>I discussed why SOC metrics fail us: A Metric Ton of Problems: Why SOC Metrics Fail Us. I talked about how metrics mean different things to different SOCs, how we often overemphasize speed and volume, mix in incident response metrics with regular, old SOC metrics and generally speaking why the traditional SOC metrics are not all that useful in 2026</p><p>This time I&#8217;m talking about how &#187;I&#171; think we should approach SOC metrics so they&#8217;re meaningful and measure the right things.</p><p>BIG DISCLAIMER: <strong>you do you.</strong> Meaning, define what success looks like and choose whatever metrics can tell you whether you&#8217;re on the right track. I&#8217;m a big believer that for internal purposes <strong>you can measure what you want</strong>, as long as it gives you a good idea of where your SOC is and doesn&#8217;t demand impossible from the team.</p><h2>QA goes first</h2><p>This means that once a week, bi-weekly, or monthly, one of your best analysts samples alerts handled by the team to verify they were done correctly. Correctly here means a couple things:</p><ul><li><p>validating L1 work more often than not means verifying whether SOPs were followed</p></li><li><p>validating L2+ work typically means re-running the investigation</p></li><li><p>validating AI work means at least validating the verdict and investigation steps (but potentially much more)</p></li></ul><p>As far as specific approaches, I know SOCs who have found good success in their Quality Assurance efforts by following ISO 2859-1:2026 - it lays out a framework for QA and it&#8217;s <strong>solid</strong>.</p><p>Or, here&#8217;s what you can do instead:</p><ul><li><p>QA only high severity alerts (probably a good starting point)</p></li><li><p>Sample X alerts per analyst (to spot quality issues with individual team members)</p></li><li><p>Sample alerts completely at random</p></li><li><p>Sample alerts with the highest MTTR or specific resolution comments</p></li><li><p>Query for easily spotted issues like missing resolution comments, wrong tags, or unassigned alerts</p></li></ul><p>Why do we start with QA, you might ask? First of all, as AI is increasingly baked into threat detection tools, chances are your analysts will end up doing more QA than ever before. Good to start them early.</p><p>Then, and more importantly, <strong>without QA your metrics are useless. </strong>What good is MTTA / MTTR in green if alerts aren&#8217;t resolved properly or what does the false positive rate matter if alerts are categorized wrong? And so on.</p><p>Quality Assurance unlocks the value of your metrics and <strong>should always be the starting point</strong>. Now - how many SOCs start establishing solid QA fundamentals before worrying about MTT-X? In my experience, not many.</p><h2>What metrics are good, then?</h2><p>A boring, yet 100% true answer, is <strong>most of them once you've set up Quality Assurance.</strong> Suddenly the volume numbers, TP rates, MTT-X mean something.</p><p>Ok, we can&#8217;t leave it here or it will be anticlimactic. Here are 3 SOC metrics that &#187;I&#171; have been playing with recently and either found good success with or think those are interesting as concepts:</p><h2>Metric 1: Cost per data source / detection</h2><p>SIEM TCO is a big number. Often the single biggest item in your security budget or close to it. It&#8217;s difficult to discuss without a ton of context, and I found senior leaders to be often either unwilling or unable to grasp it.</p><p>And yes, we could do the usual money go up, risk go down. But what if instead we broke the big number down into multiple, individual line items?</p><p>And there are so many ways of doing that.</p><p>You could first work to understand capabilities of adversaries likely to attack your company based on your individual threat model - can start with your industry, geography, size. List their techniques, see which ones repeat the most, outline top 5-10 and make them your <strong>threat detection targets.</strong></p><p>Calculate how much achieving each of them costs and track that.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K_Wi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K_Wi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 424w, https://substackcdn.com/image/fetch/$s_!K_Wi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 848w, https://substackcdn.com/image/fetch/$s_!K_Wi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 1272w, https://substackcdn.com/image/fetch/$s_!K_Wi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K_Wi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png" width="870" height="516" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:516,&quot;width&quot;:870,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91487,&quot;alt&quot;:&quot;ingest yr.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ingest yr.png" title="ingest yr.png" srcset="https://substackcdn.com/image/fetch/$s_!K_Wi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 424w, https://substackcdn.com/image/fetch/$s_!K_Wi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 848w, https://substackcdn.com/image/fetch/$s_!K_Wi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 1272w, https://substackcdn.com/image/fetch/$s_!K_Wi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23cf6b34-631d-4172-ad71-d2a664c92e1a_870x516.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Or, just do a flat $ per data source versus how many detections you have for it. Then maybe add context about whether those have ever fired and if you&#8217;re feeling fancy talk about the TP / FP rate.</p><p>That&#8217;s a lot of words, so let me explain with a scenario:</p><p>Your SIEM budget is $20,000 per month. You&#8217;re collecting $5,000 worth of firewall logs, you have 5 detection rules that use those logs, and you generated 2 firewall related alerts this month, both false positives. Firewalls are not your critical assets. This means that:</p><ul><li><p>Firewall logs are 25% of your total SIEM cost</p></li><li><p>You&#8217;re paying $1,000 per detection rule</p></li><li><p>You&#8217;re paying $2,500 per alert</p></li></ul><p>Is this cost effective? I&#8217;d argue it is not.</p><p>Obviously, define what cost effective is for you and track against that. I once assumed that $1000 per detection rule, $500 per alert is the limit, went over all our detections rules and had interesting findings.</p><p>Yeah, I know not all rules are meant to fire regularly, but you get me.</p><p>And if you can add your own risk context to all of that and say that, for example, to write detections around your crown jewel with an ALE of X$ you need Y$? That&#8217;s a very mature way of communicating your budget needs.</p><p>Trust me it <strong>might </strong>work.</p><h2>Metric 2: Alert volume in relation to quality</h2><p>In my LinkedIn <a href="https://www.linkedin.com/posts/rafal-kitab_the-reason-im-complaining-about-the-10000-activity-7481323882248003584-QPjJ?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABdCIcABQJVWit3vTah1eI3m5jQg-4ugcgc">posts </a>I often ridicule the well established practice of preparing fake SOC workload reports with inflated numbers, to then use them as a marketing prop. I do it so much that if you close your eyes and throw a stone at my content, chances are you&#8217;ll hit a post about this very topic.</p><p>Alert volume <strong>obviously</strong> matters only after finetuning and automation. Personally, I like to calculate it <strong>per analyst</strong> because I know roughly how many alerts an analyst can handle in a day (in-house analyst ~25, MSSP analyst ~50 btw.). But what does it matter if volume goes up one month, and down on another?</p><p>Is it good if it goes down? Did we finetune our detections, or lose visibility somewhere? And if it goes up? Did we cover a detection gap, or did a random rule just fire a lot?</p><p>The volume itself is not an amazing metric, <strong>but what if we measured it in relation to quality? </strong>Not only does it make for a more complete metric, <strong>I believe this is also one of the better ways to understand your SOCs workload ceiling.</strong></p><p>Let me explain.</p><p>There&#8217;s a breaking point where your analysts will start missing alerts entirely due to high workload. But before that point, there&#8217;s a whole range of alert volume that won&#8217;t cause analysts to miss alerts, but will impact investigation quality. That&#8217;s the danger zone you&#8217;re trying to avoid and want to be aware of.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ix0h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ix0h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 424w, https://substackcdn.com/image/fetch/$s_!ix0h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 848w, https://substackcdn.com/image/fetch/$s_!ix0h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 1272w, https://substackcdn.com/image/fetch/$s_!ix0h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ix0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png" width="767" height="507" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:507,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47762,&quot;alt&quot;:&quot;image (25).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (25).png" title="image (25).png" srcset="https://substackcdn.com/image/fetch/$s_!ix0h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 424w, https://substackcdn.com/image/fetch/$s_!ix0h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 848w, https://substackcdn.com/image/fetch/$s_!ix0h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 1272w, https://substackcdn.com/image/fetch/$s_!ix0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6265ab2e-bd6b-41b4-87e6-0d8cf06a0d64_767x507.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In other words - workload goes up and quality stays intact? That&#8217;s fine. Workload keeps going up and quality starts going down? That&#8217;s where you probably want to stop.</p><p>(Small disclaimer - I mention % of alerts with quality issues as a shorthand to represent a QA number. For some SOCs it will be % of critical defects, defect rate, alerts that passed QA etc. - many ways to present the same idea.)</p><p>(Another small disclaimer - <strong>obviously </strong>quality issues are not there just due to the workload, but, for example, insufficient training. Up to SOC leads to figure that out)</p><h2>Metric 3: Automation rate</h2><p>Back when I was still a young Rafal I remember hearing SOC leaders talk about how many alerts their SOAR closes automatically and I thought to myself - &#8220;there is no way anyone cares about that&#8221;.</p><p>Turns out this is a metric that for some reason <strong>lands extremely well with senior stakeholders</strong>.</p><p>No idea why, but here&#8217;s what happened to me on <strong>multiple occasions </strong>in my days as a Security Architect: during a leadership meeting I&#8217;d throw out a % figure of how many alerts we&#8217;re closing automatically before they reach the SOC. Thought nothing of it. Then a couple weeks after I&#8217;d hear from people who were <strong>not part of those meetings</strong> about how our SOC (or managed SOC) closes 40% of alerts automatically. It was either other leaders or customer success people when I was with an MSSP.</p><p>???</p><p>Lessons learned I guess. If that figure stays with people, might as well start measuring it. Some ways I&#8217;ve done it:</p><p><code>Automation Rate = (Alerts Closed By Automation / Total Alerts) &#215; 100</code></p><p>or</p><p><code>Automation Rate = [((Alerts Closed By Automation / Total Alerts) &#215; 100) + ((Alerts Enriched By Automation / Total Alerts) &#215; 100)] / 2</code></p><p>or</p><p><code>Automation Rate = (Alerts Where SOAR Automatically Kicked In / Total Alerts) x 100</code></p><p>Or any other way. The possibilities are endless, especially with AI increasingly doing triage and assisting in investigations. I&#8217;m sure people writing the checks to bring in that technology are interested in knowing how well it works.</p><p>And <strong>with Quality Assurance established</strong> % of alerts handled &#8220;autonomously&#8221; by AI is a good metric to track.</p><p>One important caveat though. Automation is not the same as just auto closing your all DLP alert because someone decided to enable Microsoft Purview and you got 40.000 alerts in your queue the next day. The definition of what constitutes automation is up to you, but I believe at minimum it requires more logic than:</p><p><code>if alert.title == "XYZ":</code><br><code>alert.status = "closed"</code></p><h2>What else</h2><p>Those were the more &#8220;interesting&#8221; metrics, not the entirety of what I consider worth tracking.</p><p>If I were to give a simple summary of what comes to mind here&#8217;s how it would look like:</p><p>I don&#8217;t obsess over (or don&#8217;t see much value in tracking):</p><ul><li><p>MTTA / MTTR for all alerts</p></li><li><p>Alert volume before tuning</p></li><li><p>Detection coverage (prefer focusing on meeting detection targets instead)</p></li><li><p>MTTD (that&#8217;s how fast our tools work)</p></li><li><p>Escalation rate</p></li><li><p>False negative rate (don&#8217;t get me started on this one)</p></li><li><p>Anything related to how fast detections are written</p></li></ul><p>I like tracking:</p><ul><li><p>QA (% of critical defects, % of alerts that passed QA, whatever feels right)</p></li><li><p>Alert volume per analyst (and in relation to QA)</p></li><li><p>Cost related metrics (as described above)</p></li><li><p>Automation rate</p></li><li><p>TP / BP / FP rate (BP rate specifically as a detection engineering metric, meaning detection good, behavior benign)</p></li><li><p>MTT-X for a subset of alerts (mostly high sev)</p></li></ul><p>I&#8217;m sure I missed a ton.</p><p>Some people say that security metrics don&#8217;t matter at all and what matters is that the business can keep achieving its objectives without third party interruptions. Some say the real metric is the friends we&#8217;ve made along the way. I believe metrics can be useful, but you need to be selective with what you track.</p><p>And most importantly, <strong>metrics don&#8217;t matter if you don&#8217;t have a solid Quality Assurance process in place.</strong></p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[How Not to Kill Your AI SOC]]></title><description><![CDATA[I think we are putting too much AI in AI SOC. Not because AI does not work. Because we keep routing work to the wrong place. An AI SOC is at least three]]></description><link>https://blog.secops-unpacked.ai/p/how-not-to-kill-your-ai-soc</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/how-not-to-kill-your-ai-soc</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 20 Aug 2026 15:30:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/96a6b18a-6be5-4acb-bfa9-8774001d7246_3990x2426.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p><strong>Route the wrong stage to the wrong tier and the system fails in a way no accuracy number will show you.</strong></p><p>An AI SOC is not one technology. It is at least three, with different cost, latency, and reliability characteristics. The engineering question is not which one to use. It is which one to apply where.</p><p>Most products collapse too much into one tier. That is where the failures come from.</p><h2>The three tiers</h2><p><strong>Deterministic execution.</strong> Code, rules, workflows, lookups. Correct behavior is specified in advance, execution follows explicit logic, marginal compute cost is typically low, and the path is straightforward to audit.</p><p><strong>Machine learning.</strong> Classification, clustering, anomaly detection, baselining, graph analysis. Operates over a population and finds structure nobody can completely specify in advance. Low cost per item and measurable with precision, recall, false positive rate, and drift.</p><p><strong>Language models, large and small.</strong> Reasoning over unstructured and contradictory evidence, forming hypotheses, generating queries, producing explanations. Highest cost, highest latency, and the tier whose output is hardest to reproduce exactly.</p><p>There is ordinary analytics around these tiers too. A count, aggregation, join, or group-by is not machine learning. If SQL can answer the question exactly, SQL does not need an agentic rebrand.</p><p>The architectural principle is simple. Computation with a known operation and a correct answer should happen outside the reasoning model.</p><p style="text-align: center;"><strong>Product Updates Section !</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.coalitioninc.com/security/wirespeed/free-trial-general?utm_source=secops-unpacked&amp;utm_medium=blog&amp;utm_campaign=deterministic-vs-llm&amp;utm_term=signup&amp;utm_content=free-trial" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qPDy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 424w, https://substackcdn.com/image/fetch/$s_!qPDy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 848w, https://substackcdn.com/image/fetch/$s_!qPDy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 1272w, https://substackcdn.com/image/fetch/$s_!qPDy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qPDy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png" width="221" height="116.20322580645161" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:163,&quot;width&quot;:310,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:3164,&quot;alt&quot;:&quot;wirespeed (1).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.coalitioninc.com/security/wirespeed/free-trial-general?utm_source=secops-unpacked&amp;utm_medium=blog&amp;utm_campaign=deterministic-vs-llm&amp;utm_term=signup&amp;utm_content=free-trial&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="wirespeed (1).png" title="wirespeed (1).png" srcset="https://substackcdn.com/image/fetch/$s_!qPDy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 424w, https://substackcdn.com/image/fetch/$s_!qPDy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 848w, https://substackcdn.com/image/fetch/$s_!qPDy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 1272w, https://substackcdn.com/image/fetch/$s_!qPDy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb734e5c4-f641-467b-b5f2-77f1001c02f9_310x163.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p><strong>Deterministic when it matters</strong></p><p>Security teams shouldn&#8217;t have to choose between human-speed triage queues and LLM reasoning loops that consume the seconds attackers don&#8217;t give back. Wirespeed&#8217;s AI SOC prioritizes deterministic execution to handle most investigations and achieve containment in milliseconds. Agentic AI is used where it matters: context and edge cases, not decisions without guardrails. Breakout times are as fast as 27 seconds, and pure-LLM SOCs can burn 15 to 90 seconds per decision before acting. Wirespeed automates Tier 1 to 3 workflows across your existing stack, cutting alert noise without latency, second-guessing the probabilistic results, or exploding token costs that comes from other AI SOC solutions.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.spectrum.security/blog/delta-tradecraft-portable-detection-knowledge" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dWuM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 424w, https://substackcdn.com/image/fetch/$s_!dWuM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 848w, https://substackcdn.com/image/fetch/$s_!dWuM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 1272w, https://substackcdn.com/image/fetch/$s_!dWuM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dWuM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png" width="221" height="123.76" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:168,&quot;width&quot;:300,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:1833,&quot;alt&quot;:&quot;spectrum.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.spectrum.security/blog/delta-tradecraft-portable-detection-knowledge&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="spectrum.png" title="spectrum.png" srcset="https://substackcdn.com/image/fetch/$s_!dWuM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 424w, https://substackcdn.com/image/fetch/$s_!dWuM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 848w, https://substackcdn.com/image/fetch/$s_!dWuM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 1272w, https://substackcdn.com/image/fetch/$s_!dWuM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6444a7ab-bc27-4773-a23f-c8d67985b4d1_300x168.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p><strong>Released Delta Tradecraft</strong></p><p>Detection logic is cheap now. Detection knowledge is not. A model can write the query. It cannot tell you how the behavior manifests, what evidence it leaves, or whether your telemetry can see it.<br>Delta Tradecraft is Spectrum's open standard for capturing that research once and making it portable.<br>Spectrum runs it continuously. New threats researched, customized to your environment, and tested against real logs before deploy. Existing detections retested, root-caused, and repaired as the environment shifts.</p><p>Get covered faster. Stay covered after.</p></blockquote><div><hr></div><h2>Where each one belongs</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mpJC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mpJC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 424w, https://substackcdn.com/image/fetch/$s_!mpJC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 848w, https://substackcdn.com/image/fetch/$s_!mpJC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 1272w, https://substackcdn.com/image/fetch/$s_!mpJC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mpJC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png" width="3990" height="2426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2426,&quot;width&quot;:3990,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8212732,&quot;alt&quot;:&quot;deterministic ml llm.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="deterministic ml llm.png" title="deterministic ml llm.png" srcset="https://substackcdn.com/image/fetch/$s_!mpJC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 424w, https://substackcdn.com/image/fetch/$s_!mpJC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 848w, https://substackcdn.com/image/fetch/$s_!mpJC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 1272w, https://substackcdn.com/image/fetch/$s_!mpJC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ded327b-f0dd-4f6b-a7cb-96f0993deaff_3990x2426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Deterministic owns repeatable stages and enforcement:</strong></p><ul><li><p>Parsing, normalization, deduplication by shared key</p></li><li><p>Entity extraction against known patterns, enrichment lookups, list checks</p></li><li><p>Response execution and ticket updates</p></li><li><p>Approval gates, scoping, rate limits, circuit breakers</p></li></ul><p>A guardrail that holds most of the time is not a guardrail. Your account disable action does not need to be creative.</p><p><strong>Machine learning owns scale:</strong></p><ul><li><p>Clustering thousands of related alerts into cases</p></li><li><p>Baselining normal behavior for users, hosts, and service accounts</p></li><li><p>Scoring priority across a population</p></li><li><p>Ranking candidate related cases across long histories</p></li><li><p>Detecting drift</p></li></ul><p><strong>Language models own judgment:</strong></p><ul><li><p>Building a timeline from evidence across five systems</p></li><li><p>Assessing blast radius</p></li><li><p>Reading phishing bodies, scripts, or ticket comments</p></li><li><p>Weighing evidence that points in two directions</p></li><li><p>Deciding which tool to call next based on the last result</p></li></ul><p>Small models deserve separate mention. Narrow repeated tasks such as alert classification, observable extraction, and case routing do not need a frontier model. They are cheaper, faster, and easier to evaluate because the task is bounded.</p><p>Not every alert needs to visit a data center full of GPUs before somebody decides it is another failed login.</p><h2>Correlation is where this becomes obvious</h2><p>The industry uses one word for three very different operations.</p><p><strong>Grouping by shared key is deterministic.</strong> Same host, same rule, same user, same time window. Most products call this correlation. It is aggregation, and it finds what already shares an identifier.</p><p><strong>Statistical and graph correlation is ML.</strong> Co-occurrence that exceeds baseline, sequences that repeat across a population, paths through an entity graph connecting signals with no direct key. It finds that two things travel together, not necessarily why.</p><p><strong>Attack-pattern correlation is reasoning-led.</strong> A failed authentication in one system, a scheduled task created somewhere else, and an outbound connection from a third host may share no direct key and have little useful statistical history. They can still belong to the same case because they fit an adversary behavior chain.</p><p>Recognizing that means hypothesizing a relationship, then looking for evidence that confirms or kills it.</p><p>Reasoning is not the only way to correlate an attack chain. Rules, graphs, and sequence models can identify parts of one. The difference is that reasoning can hypothesize a relationship nobody encoded in advance and actively investigate it.</p><p>Rule-based correlation engines have been shipping since the early 2000s, but somebody has to anticipate the relationship.</p><p>We have spent twenty years writing increasingly sophisticated versions of "if A and B happen within fifteen minutes, open a case."</p><p>It works. Until the attacker does C.</p><p>The number of possible combinations is too large for a team to enumerate. That is one of the constraints reasoning lifts, and it is a better argument for AI SOC than faster triage ever was.</p><h2>How to decide placement</h2><p>Four questions settle most cases.</p><ul><li><p><strong>Is the correct operation knowable in advance?</strong> If yes, make it deterministic. Do not reason about it.</p></li><li><p><strong>Does the answer emerge from a population rather than an instance?</strong> If yes, use analytics or ML. A single alert cannot tell you what is anomalous.</p></li><li><p><strong>Does it require judgment over unstructured, incomplete, or contradictory evidence?</strong> That is where a language model earns its cost.</p></li><li><p><strong>What is the blast radius if it is wrong?</strong> Irreversible actions execute deterministically, behind a gate. Reasoning can propose them. It should not be the last thing standing between a proposal and a disabled account.</p></li></ul><p>Frequency does not change the answer.</p><p>A judgment call does not become a lookup because it happens a thousand times a day. But high frequency changes the economics.</p><p>Decompose the work. Maybe the enrichment in front of the verdict is deterministic. Maybe extraction can move to a small model. Maybe routing happens before reasoning. Move those parts down and keep judgment where it belongs.</p><p>This is how you avoid paying frontier-model prices to discover that <code>8.8.8.8</code> is Google DNS for the ten-thousandth time.</p><h2>The tier newer vendors skipped</h2><p>The incumbents built the ML tier. SIEM, UEBA, and EDR vendors have run clustering, baselining, and statistical scoring in production for years.</p><p>A large share of newer AI SOC entrants started at the language model and never built the middle. Not all of them, and some ship real ML without talking about it, because ML had bad marketing and agents currently have excellent marketing.</p><p>The math did not care.</p><p>A model with a query tool can tell you the same pattern fired 4,000 times this month across 200 hosts. The question was never capability. It is what the answer costs, how long it takes, and whether you can trust it twice.</p><p>A group-by over indexed data runs in milliseconds and returns an exact result for the state of that data. Reaching the same result through a model means either asking it to generate the query, which is reasonable, or pulling records into context and asking it to do the computation, which is not.</p><p>Let the model write the SQL.</p><p>Do not make the model cosplay as the database.</p><p>Where the missing ML tier actually hurts is the work that has no simple query to write.</p><p>Which behavior is anomalous for this account? What does normal look like for a service principal nobody documented? Which signals travel together across the estate without sharing a key?</p><p>Those answers come from computation over the population. If that computation does not exist, the reasoning tier is not filling the gap. It is working without the input.</p><p>You can build an AI SOC without a real ML tier. But the work relocates:</p><ul><li><p><strong>Correlation collapses back to grouping.</strong> Hand-written keys and time windows find what already shares an identifier.</p></li><li><p><strong>Baselining becomes stored counters.</strong> First-seen, frequency, and threshold rules become a thin implementation of statistical baselining.</p></li><li><p><strong>Prioritization becomes prompt instructions.</strong> Asking a model to rank a queue it only sees one item at a time from is not ranking. It is guessing with good grammar.</p></li><li><p><strong>Guardrails multiply.</strong> More validation, schema checks, retry logic, and hard limits appear around the model.</p></li></ul><p>This can hold together at moderate volume. At scale, population-level questions either go unanswered or get answered by running a model over work a cheap classifier or statistical system should have handled.</p><p>The problem is discovering that architecture at renewal, when the token bill scales with alert volume and nobody can explain how accurate the prioritization is.</p><p>Nothing makes architecture visible quite like the renewal spreadsheet.</p><h2>Why deterministic automation failed before</h2><p>Every SOAR program has some version of the same history.</p><p>A playbook covers the common case. A field changes. An unusual variant arrives. An API returns an unexpected error. The team patches it. Patches accumulate. Maintenance eventually costs more than the work being automated and the playbook gets quietly disabled.</p><p>Nobody deletes it, obviously.</p><p>It remains in the SOAR forever, named something like <code>Phishing_Response_v2_FINAL_new</code>.</p><p>The failure was not determinism. The problem was that every exception had to be anticipated and implemented by a human.</p><p>Reasoning changes that in two places.</p><p><strong>Runtime fallback.</strong> When the deterministic path reaches a condition it does not handle, escalate that case to reasoning. Deterministic execution keeps carrying the volume. You pay for reasoning on the fraction that needs it.</p><p><strong>Build-time repair.</strong> Coding agents can write and fix the deterministic layer. New parsers, integrations against documented APIs, workflow updates after schema changes. This is bounded work that can be tested.</p><p>Together they create a useful loop.</p><p>If reasoning handles the same edge case repeatedly, codify it. Move it into the deterministic path and the next execution is fast, repeatable, and cheap.</p><p>The system should get cheaper and more predictable as it learns what work no longer requires reasoning.</p><p>Agent-written code is still code, though. It needs tests, review, version control, and an owner.</p><p><code>git blame</code> does not accept "the agent wrote it" as an answer.</p><h2>Each tier fails differently</h2><p>This is the argument for combining them.</p><p><strong>Deterministic logic fails at the boundary of what was anticipated.</strong> Good systems fail closed or escalate. Bad ones keep executing because the input passes validation while the assumptions underneath it are wrong.</p><p><strong>Machine learning fails on drift.</strong> The environment moves since training or calibration and performance degrades gradually rather than breaking visibly.</p><p><strong>Language models produce confident, well-written output that can be wrong.</strong> Fluency is not calibration.</p><p>Combined, they check each other.</p><p>Deterministic guardrails constrain what reasoning can act on. ML output becomes evidence rather than a verdict. Model output gets validated against deterministic schemas. Closed case history supports baselining and similarity while giving reasoning grounded precedent.</p><p>A system made entirely of rules cannot handle what nobody encoded.</p><p>A system made entirely of a model cannot give you the execution guarantees you need.</p><p>Putting <code>autonomous</code> in front of either one does not change that.</p><h2>Reproducibility is a systems property</h2><p>It is common to hear that language models are inherently non-deterministic. The reality is more interesting.</p><p>With greedy decoding, often exposed through temperature-zero settings, the decoder selects the highest-probability next token. Output can still vary. <a href="https://thinkingmachines.ai/blog/defeating-nondeterminism-in-llm-inference/">Thinking Machines Lab</a> showed that batch-size dependence in inference kernels is an important source of that variance. Their <a href="https://github.com/thinking-machines-lab/batch_invariant_ops">batch-invariant implementation</a> produced bitwise-identical output across repeated runs, with a throughput cost.</p><p>Reproducibility is an engineering choice with a price, not a law of nature.</p><p>In an agentic system, the larger source of variance often sits above the model anyway. Tool results change. Retrieved context changes. Multi-step paths diverge. Model and prompt versions change.</p><p>By step six, arguing about temperature zero is a bit like arguing about the accuracy of the compass after somebody moved the road.</p><p>So do not design around the assumption that a run repeats. Pin versions, validate schemas, test properties rather than exact strings, and keep irreversible actions behind deterministic gates.</p><h2>None of this works without the data layer</h2><p>There is another layer underneath all three.</p><p>Anton Chuvakin makes this case in his API or Die audit [<a href="https://medium.com/anton-on-security/so-is-your-soc-ai-ready-part-3-api-or-die-audit-fa70711cb301?postPublishedType=initial">LINK</a>]. Agents consume APIs at a frequency no human would. An analyst may query a SIEM a handful of times an hour. An agent can do it a hundred times in under a minute.</p><p>Run that across an incident and your AI transformation project becomes a load test against your own infrastructure.</p><p>Each tier also needs different data.</p><p><strong>Deterministic execution needs stable schemas.</strong> <strong>ML needs representative history, and supervised tasks need reliable labels.</strong> <strong>Reasoning needs joinable context and structured output.</strong></p><p>Hand a model a two megabyte text blob and it spends tokens finding the evidence before it can reason about it.</p><p>And access is not retrieval.</p><p>MCP standardizes how tools are described and called. It does not make a slow API fast, fix permissions, or repair bad data.</p><p>Wrapping a legacy interface in MCP gives you a legacy interface with a manifest.</p><p>Congratulations, the technical debt now has a tool description.</p><p>Retrieval has the same problem. Security data contains exact facts, relationships, timelines, and prose. Those need different retrieval methods.</p><p>A hash does not need semantic meaning. It needs the right row.</p><p><a href="https://arxiv.org/abs/2508.21038">Google DeepMind's work on embedding-based retrieval</a> demonstrates fundamental limitations of single-vector retrieval. For a SOC, retrieval needs to be hybrid: exact lookups and queries for facts, ranking for related history, and vector search where the source is actually unstructured.</p><p>Retrieval quality becomes a hard ceiling on reasoning quality.</p><p>Garbage in, but now with a very articulate incident summary.</p><h2>So, how do you not kill your AI SOC?</h2><p>Do not send everything to the biggest model you can afford.</p><p>Do not call every group of alerts correlation.</p><p>Do not ask a model whether something is anomalous without giving it a baseline.</p><p>Do not embed hashes, IDs, timestamps, and every other fact with an exact answer because somebody said RAG.</p><p>Do not give the agent 200 tools and hope it develops good taste.</p><p>Do not let the same probabilistic system investigate an account, decide it is compromised, and disable it.</p><p>And please do not measure all of this with one accuracy number, make the number green, and put it in the QBR.</p><p>Use deterministic execution where the operation is known. Use analytics and ML where the answer lives in the population. Pay for reasoning where judgment is actually required. Keep enforcement deterministic.</p><p>The goal is not to put AI everywhere in the SOC.</p><p>The goal is to know where not to put it.</p><h2>What to ask a vendor</h2><ul><li><p>Which tier handles which stage?</p></li><li><p>If there is no ML tier, what clusters, baselines, and learns from closed cases?</p></li><li><p>How does retrieval work? What is queried exactly and what is searched by similarity?</p></li><li><p>How is each tier measured? Deterministic execution on coverage and execution success. ML on precision, recall, calibration, and drift. Reasoning on analyst agreement, task success, calibration, and variance across repeated runs.</p></li></ul><p>If everything routes through a frontier model, cost scales with alert volume and peaks when you need the system most.</p><p>And if one accuracy number describes the whole architecture, ask what exactly it measured.</p><p style="text-align: center;">Explore the vendor landscape The full map of the AI SOC market, updated as it moves.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;AI for SecOps Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>AI for SecOps Landscape</span></a></p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[The sad state of SOC workload reports, and how YOU (yes, YOU) can help]]></title><description><![CDATA[And how YOU (yes, YOU) can help]]></description><link>https://blog.secops-unpacked.ai/p/the-sad-state-of-soc-workload-reports</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/the-sad-state-of-soc-workload-reports</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Tue, 11 Aug 2026 13:00:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dad9cf19-0fac-4508-b56e-ec48dcdfeccf_1080x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Team, real talk. We&#8217;ve been unhappy with the quality of SOC workload reports and decided to publish one of our own. By practitioners for practitioners type of deal. To succeed we need YOUR help.</p><p>We have a questionnaire - 20 questions, 5-10 minutes to finish. All anonymous. Asking about SOC workload, team size and composition, automation, daily operations and similar. We publish the full thing for free together with questionnaire so that you can judge the wording for yourself.</p><p>If you&#8217;re A SOC lead (or were one until recently) we&#8217;d love if you took part. We&#8217;re not publishing the link openly to keep results clean, so if you&#8217;re interested please reach out to us at <a href="mailto:contact@secops-unpacked.ai">contact@secops-unpacked.ai</a> or via LinkedIn:</p><ul><li><p>Filip: <a href="https://www.linkedin.com/in/filipstojkovski/">[LinkedIn]</a></p></li><li><p>Rafal: <a href="https://www.linkedin.com/in/rafal-kitab/">[LinkedIn]</a></p></li><li><p>Ignacio: <a href="https://www.linkedin.com/in/ignaciosbampato/">[LinkedIn]</a></p></li></ul><div><hr></div><p>Have you noticed how SOCs are presented as inherently dysfunctional by cybersecurity vendors? If you&#8217;ve been to LinkedIn, I&#8217;m sure you&#8217;ve seen some version of &#8220;SOC analysts are facing 10 000 alerts per day&#8221;, &#8220;65% of analysts confess to ignoring an alert that later turned out to be a security incident&#8221;, &#8220;Over 50% of all alerts SOCs are facing turn out to be False Positives&#8221;, &#8220;71% of SOC analysts report burnout&#8220; etc.</p><p>And there is <strong>always </strong>a report to support those numbers. Today I write specifically about those reports and explaining why I think we should not pay too much attention to them.</p><p>I&#8217;m also venting a little.</p><h2>Not very zero-trust of us</h2><p>In an industry built on skepticism, it's surprising how easy we trust in reports.</p><p>A prime example is the widespread coverage of the ISC2 Cybersecurity Workforce Report. It seems to be taken as gospel without consideration that one of the largest certification bodies in cybersecurity might have a vested interest in the public believing there&#8217;s a cybersecurity skill shortage.</p><p>SOC workload reports are no different. If anything, they&#8217;re worse. I&#8217;m convinced that most SOC related reports (all I&#8217;ve seen, can&#8217;t claim to have seen them all) are misleading readers on purpose.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OCOE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OCOE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 424w, https://substackcdn.com/image/fetch/$s_!OCOE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 848w, https://substackcdn.com/image/fetch/$s_!OCOE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 1272w, https://substackcdn.com/image/fetch/$s_!OCOE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OCOE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png" width="1727" height="121" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4395da51-76cd-481d-93f6-038569903fa3_1727x121.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:121,&quot;width&quot;:1727,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19415,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OCOE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 424w, https://substackcdn.com/image/fetch/$s_!OCOE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 848w, https://substackcdn.com/image/fetch/$s_!OCOE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 1272w, https://substackcdn.com/image/fetch/$s_!OCOE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4395da51-76cd-481d-93f6-038569903fa3_1727x121.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Here&#8217;s exactly what is wrong with them</p><h2>The numbers. What do they mean?</h2><p>Probably the most used SOC workload number is the alert volume. No wonder, it speaks to most people better than MTT-X, TP / FP rate or detection coverage. It&#8217;s an easy message to digest and an easy, scary number to wave around.</p><p>What are those numbers?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XGwl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XGwl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 424w, https://substackcdn.com/image/fetch/$s_!XGwl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 848w, https://substackcdn.com/image/fetch/$s_!XGwl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 1272w, https://substackcdn.com/image/fetch/$s_!XGwl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XGwl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png" width="2288" height="1142" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1142,&quot;width&quot;:2288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:322379,&quot;alt&quot;:&quot;Table: Company / Sponsor | Report (year) | Alert volume claim | Source&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Company / Sponsor | Report (year) | Alert volume claim | Source" title="Table: Company / Sponsor | Report (year) | Alert volume claim | Source" srcset="https://substackcdn.com/image/fetch/$s_!XGwl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 424w, https://substackcdn.com/image/fetch/$s_!XGwl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 848w, https://substackcdn.com/image/fetch/$s_!XGwl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 1272w, https://substackcdn.com/image/fetch/$s_!XGwl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc88acf16-d2b3-4eb2-a817-c46b572c2913_2288x1142.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Links from the table: </em><a href="https://www.anvilogic.com/learn/security-alerts?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Anvilogic blog</a> &#183; <a href="https://www.cisco.com/c/dam/m/digital/1198689/Cisco_2017_ACR_PDF.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Cisco report</a> &#183; <a href="https://www.crogl.com/?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Crogl&#8217;s website</a> &#183; <a href="https://www.cybereason.com/blog/a-guide-to-more-efficient-effective-soc-teams?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Cyberreason&#8217;s blog</a> &#183; <a href="https://www.paloaltonetworks.com/blog/2020/09/state-of-security-operations/?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">PaloAltos blog</a> &#183; <a href="https://www.resilientcyber.io/p/state-of-ai-in-secops-2025?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Thehackernews coverage of Prophet&#8217;s report</a> &#183; <a href="https://www.trellix.com/assets/events/emea-security-summit-2023/breakout-4-elevating-the-soc-analyst-experience-with-xdr.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Trellix&#8217;s report</a> &#183; <a href="https://www.vectra.ai/resources/2023-state-of-threat-detection?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Vectra&#8217;s website</a> &#183; <a href="https://cdn.prod.website-files.com/64e50cbe2b6f932c04238c14/698a09c066b47c3de8854783_V_2026-State-of-Threat-Detection_020626_FNL.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Vectra&#8217;s report</a> &#183; <a href="https://www.fortinet.com/content/dam/fortinet/assets/white-papers/wp-information-overload-security-data.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Fortinet&#8217;s report</a></p><p>Those are just 10 random reportings on SOC alert numbers. As you can see, the difference between those numbers can be massive. On one side we have report by <a href="https://www.anvilogic.com/learn/security-alerts?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Anvilogic</a> with a reasonable looking number of ~286 alerts / day. On another, there&#8217;s <a href="https://www.fortinet.com/content/dam/fortinet/assets/white-papers/wp-information-overload-security-data.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Fortinet </a>with a claim of 150,000 alerts / day, which is insane.</p><p>Just working with this list we could push any narrative we chose.</p><ul><li><p>Want to show that SOCs are doing ok? <strong>Take Anvilogic&#8217;s number.</strong></p></li><li><p>Want to sell your AI SOC product to a reasonable buyer? <strong>Pick one of Vectra&#8217;s numbers</strong>, both look decently plausible to an untrained eye.</p></li><li><p>Want to embarass yourself and show that you don&#8217;t know the difference between an event and an alert? <strong>Go with Fortinet&#8217;s numbers.</strong></p></li></ul><p>You&#8217;re probably wondering how we can have a ~525x spread for the question of - what is an average daily SOC alert volume. I don&#8217;t know, but I have a hunch. Hear me out.<br><br><strong>Duplicates</strong></p><p>Most SIEM data tables are immutable - meaning you can&#8217;t change records that are already there, you can only add more. In practice, every change to an alert - tagging, commenting, assignment, change in status etc. creates a new record in the table that holds all security alerts.</p><p>Now, if we don&#8217;t account for those duplicate values and simply query for all records in that table, we will end up with 3-4x the amount of alerts than we actually have.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C2rO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C2rO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 424w, https://substackcdn.com/image/fetch/$s_!C2rO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 848w, https://substackcdn.com/image/fetch/$s_!C2rO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 1272w, https://substackcdn.com/image/fetch/$s_!C2rO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C2rO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png" width="520" height="516" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/769bf810-188d-4c12-a591-4d9bda876322_520x516.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:516,&quot;width&quot;:520,&quot;resizeWidth&quot;:520,&quot;bytes&quot;:9919,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C2rO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 424w, https://substackcdn.com/image/fetch/$s_!C2rO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 848w, https://substackcdn.com/image/fetch/$s_!C2rO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 1272w, https://substackcdn.com/image/fetch/$s_!C2rO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F769bf810-188d-4c12-a591-4d9bda876322_520x516.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Multiple records for the same alert ID</em></figcaption></figure></div><h2>Pre-finetuning numbers</h2><p>If you enable your DLP alerting today, tomorrow you'll see 10,000 new DLP alerts in your SIEM. It is what it is. Threat detection tools can generate an absolute mountain of alerts, and the job of SOC teams is to tune that number down to a manageable level.</p><p>Now, that means your SOC can receive 10,000 alerts every day, but it <strong>doesn't mean your analysts need to go through all of them</strong>. Likely 90% of that volume is tuned out, autoclosed, aggregated, you name it.</p><p>Which means the question "how many alerts do you receive every day" should really be "how many alerts do your analysts actually have to investigate every day." I can't prove it, but I have a strong suspicion that many of those inflated numbers come from the fact that some SOCs share values prior to tuning.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AWal!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AWal!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 424w, https://substackcdn.com/image/fetch/$s_!AWal!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 848w, https://substackcdn.com/image/fetch/$s_!AWal!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 1272w, https://substackcdn.com/image/fetch/$s_!AWal!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AWal!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png" width="2204" height="924" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:924,&quot;width&quot;:2204,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29588,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AWal!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 424w, https://substackcdn.com/image/fetch/$s_!AWal!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 848w, https://substackcdn.com/image/fetch/$s_!AWal!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 1272w, https://substackcdn.com/image/fetch/$s_!AWal!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42b29718-ea43-4f60-9006-2adac14d0390_2204x924.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Pre-finetuning vs post-finetuning numbers</em></figcaption></figure></div><h2>In-house and MSSP numbers mixed together</h2><p>In-house SOC analysts and MSSP analysts work differently. In-house analysts typically handle an alert end-to-end (or at least a larger portion of it) and have other tasks as well, like monitoring for user-submitted tickets. MSSP SOCs often go through a significantly higher alert volume in a day. That's because instead of fully investigating alerts, they're often expected to escalate them to clients for further investigation, and they typically don't have other tasks outside security monitoring.</p><p>In-house SOCs work for themselves; MSSP teams are typically larger and work for multiple clients. Now, based on what I know about SOC work, I'd say an in-house SOC analyst can handle about<strong> 20-30 alerts per day</strong>. An MSSP analyst probably handles close to double that.</p><p>So the daily alert volume of a 100-analyst MSSP SOC with 20 clients <strong>can be 5,000</strong>. At the same time, an in-house SOC with 4 analysts might see closer to <strong>100 a day</strong>. Both numbers are realistic, but if I mix them together and say that a SOC on average handles 2,550 alerts every day, we're being misleading.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6E8D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6E8D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 424w, https://substackcdn.com/image/fetch/$s_!6E8D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 848w, https://substackcdn.com/image/fetch/$s_!6E8D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 1272w, https://substackcdn.com/image/fetch/$s_!6E8D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6E8D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png" width="1924" height="764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:764,&quot;width&quot;:1924,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32720,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6E8D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 424w, https://substackcdn.com/image/fetch/$s_!6E8D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 848w, https://substackcdn.com/image/fetch/$s_!6E8D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 1272w, https://substackcdn.com/image/fetch/$s_!6E8D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2804f2a-2a34-4927-b675-54203e7ef04f_1924x764.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Team size</h2><p>Similar to in-house vs MSSP - bigger teams are typically dealing with more alerts. We can&#8217;t compare the overall daily volume between a team of 5 and a team of 30, regardless of in-house or MSSP. This is a no brainer, but also rarely accounted for.</p><h2>Straight fraud</h2><p>All those problems exist before we even consider the possibility that those SOC alert volumes are fabricated. Because, why not? Nearly every one of those reports is paid for and then used as a marketing prop. It's not a stretch to assume the numbers are tampered with in at least some cases. The incentive is there, and we never see the raw data behind any of those surveys, just the conclusions.</p><h2>So what do we do</h2><p>Not much we can do, honestly.</p><p>The reality is - as long as there is incentive to present inflated numbers, inflated numbers will be presented. Which is why the only way to publish a reliable report I can think of is having practitioners do it.</p><p>This is what we will do, and where YOU can help. This only works with enough SOC leads behind it, so if you&#8217;re one (or know one) do reach out!</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[A Metric Ton of Problems: Why SOC Metrics Fail Us]]></title><description><![CDATA[Thoughts on SOC metrics after a career in SecOps]]></description><link>https://blog.secops-unpacked.ai/p/a-metric-ton-of-problems-why-soc-metrics-fail-us</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/a-metric-ton-of-problems-why-soc-metrics-fail-us</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 30 Jul 2026 13:00:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6f70fdf8-782e-4417-a6a5-514a14a748c6_1693x929.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve spent my entire career in SOCs and worked in all roles there are from analyst to director. In each I was either measured by metrics or responsible for producing them.</p><p>Safe to say I&#8217;m responsible for a metric (hah) ton of SLA reports and yet, somehow it always felt like those gave no valuable insights into how our SOCs actually operated.</p><p>In this blog post I&#8217;m highlighting issues I have with how we measure the performance of SecOps, in a follow up article I&#8217;ll share my ideas on how we can do it better.</p><p>This is part of my healing process so bear with me through this lengthy rant.</p><h2>Everybody understands metrics differently</h2><p>I encourage you to do a little field research. Go ask 10 people what MTTR is and how they measure it. Chances are you'll get 10 different answers.</p><p>For some the &#8220;R&#8221; in MTTR stands for <strong>resolve</strong>. That mostly means a full end-to-end handling of the alert. Sure, that&#8217;s actually how I understand it as well.</p><p>For others it&#8217;s MTT-<strong>Respond</strong>. But how do we understand response? For some it&#8217;s the initial acknowledgement of the alert. That&#8217;s also often measured as MTTA or Mean Time To Acknowledge. For others, response ends at an alert being escalated to a higher tier or at an initial notification to the client.</p><p>Then, we have a group who claims that &#8220;R&#8221; in MTTR stands for anything from &#8220;Repair&#8221;, &#8220;Restore&#8221; to &#8220;Remediate&#8221; or &#8220;Report&#8221;. All answers I got from SOC leads I talked to in the recent months.</p><p>Also, it&#8217;s no wonder that different interpretations of MTTR exist because MTTR is <strong>genuinely</strong> different for MSSPs and in-house SOCs. While in-house SOCs mostly measure it as the full time it took to close an alert, MSSPs are often responsible for the initial part of the investigation (triage + maybe some L2 work) and will measure MTTR only for their portion of alert handling.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1py6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1py6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 424w, https://substackcdn.com/image/fetch/$s_!1py6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 848w, https://substackcdn.com/image/fetch/$s_!1py6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 1272w, https://substackcdn.com/image/fetch/$s_!1py6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1py6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png" width="896" height="431" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:431,&quot;width&quot;:896,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171199,&quot;alt&quot;:&quot;image (17).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (17).png" title="image (17).png" srcset="https://substackcdn.com/image/fetch/$s_!1py6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 424w, https://substackcdn.com/image/fetch/$s_!1py6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 848w, https://substackcdn.com/image/fetch/$s_!1py6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 1272w, https://substackcdn.com/image/fetch/$s_!1py6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda712da2-7641-45e8-9d39-3dbc6e80ab33_896x431.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This means that MSSPs will often see shorter MTTR and higher alert volumes than in-house SOCs even though they might have a common understanding of what MTTR is.</p><p>This is <strong>just one example</strong>, but it demonstrates how a single metric can have multiple different meanings, depending on who you ask. This is why when I hear &#8220;our MTTR is 30 minutes&#8221; this tells me <strong>absolutely nothing.</strong></p><h2>Overemphasizing speed and volume</h2><p>Sometimes it&#8217;s not even if we understand those metrics the same way, but if those metrics are genuinely useful for us. <strong>After all, what you measure is what you optimize for.</strong></p><p>And what do SOCs often measure? <strong>Speed and volume.</strong></p><p>So what do those SOCs optimize for? <strong>Speed and volume.</strong></p><p>Doesn&#8217;t this encourage surface level investigations?</p><p>On one hand, we say we want quality investigations. On the other hand, we judge analysts by how fast they handle alerts or how many they can fit into their shift.</p><p>You see how that makes no sense?</p><p>Some would argue that it&#8217;s smart for MSSPs to emphasize speed over quality if they handle the initial triage, and sure, maybe that&#8217;s the case. In my experience that can turn into becoming a mass escalation engine, and I know that clients absolutely hate that.</p><p>And look, I get it. For a non-technical stakeholder who is used to the &#8220;traditional&#8221; SOC metrics, having a short MTT-whatever is probably of paramount importance. But I believe this is a slippery slope. Short SLA commitments are often what &#8220;sells&#8221; your service to a client, but also makes your analysts&#8217; lives that much harder. And if you keep adding clients and all of them need their alerts handled within a very short window, you then have an army of analysts trained to look for a first sign an alert is a false positive. In other words, you groomed your SOC into being mediocre.</p><p>Oh, and don&#8217;t get me started on alert volume. Those mean <strong>nothing</strong> in isolation. As in, what is a <strong>good</strong> number of alerts?</p><ul><li><p>If the number is high, does it mean that we did a good job investigating, or that we&#8217;ve done a terrible job at finetuning?</p></li><li><p>And what if it&#8217;s low? Does that mean that we&#8217;ve finetuned our environment perfectly or that we have visibility gaps?</p></li></ul><p>Alert volume is probably the most frequently cited number when trying to demonstrate that SOCs are doing poorly (FUD marketing doing well as ever). It means that you see claims like &#8220;SOCs are facing 10,000 alerts / day&#8221; in every other post from a cyber vendor and that is often parroted by the less experienced practitioners.</p><p>What&#8217;s genuinely upsetting is that each of those outlandish volume claims can be supported by an official sounding report. Pick a number of alerts you <strong>think</strong> a SOC is handling each day, then look for a report justifying it. Chances are, you <strong>will</strong> find it:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-JHX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-JHX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 424w, https://substackcdn.com/image/fetch/$s_!-JHX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 848w, https://substackcdn.com/image/fetch/$s_!-JHX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 1272w, https://substackcdn.com/image/fetch/$s_!-JHX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-JHX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png" width="2288" height="1142" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1142,&quot;width&quot;:2288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:322379,&quot;alt&quot;:&quot;Table: Company / Sponsor | Report (year) | Alert volume claim | Source&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Company / Sponsor | Report (year) | Alert volume claim | Source" title="Table: Company / Sponsor | Report (year) | Alert volume claim | Source" srcset="https://substackcdn.com/image/fetch/$s_!-JHX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 424w, https://substackcdn.com/image/fetch/$s_!-JHX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 848w, https://substackcdn.com/image/fetch/$s_!-JHX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 1272w, https://substackcdn.com/image/fetch/$s_!-JHX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2515ab08-6469-41eb-88ff-76e33ac831ce_2288x1142.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Links from the table: </em><a href="https://www.anvilogic.com/learn/security-alerts?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Anvilogic blog</a> &#183; <a href="https://www.cisco.com/c/dam/m/digital/1198689/Cisco_2017_ACR_PDF.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Cisco report</a> &#183; <a href="https://www.crogl.com/?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Crogl&#8217;s website</a> &#183; <a href="https://www.cybereason.com/blog/a-guide-to-more-efficient-effective-soc-teams?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Cyberreason&#8217;s blog</a> &#183; <a href="https://www.paloaltonetworks.com/blog/2020/09/state-of-security-operations/?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">PaloAltos blog</a> &#183; <a href="https://www.resilientcyber.io/p/state-of-ai-in-secops-2025?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Thehackernews coverage of Prophet&#8217;s report</a> &#183; <a href="https://www.trellix.com/assets/events/emea-security-summit-2023/breakout-4-elevating-the-soc-analyst-experience-with-xdr.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Trellix&#8217;s report</a> &#183; <a href="https://www.vectra.ai/resources/2023-state-of-threat-detection?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Vectra&#8217;s website</a> &#183; <a href="https://cdn.prod.website-files.com/64e50cbe2b6f932c04238c14/698a09c066b47c3de8854783_V_2026-State-of-Threat-Detection_020626_FNL.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Vectra&#8217;s report</a> &#183; <a href="https://www.fortinet.com/content/dam/fortinet/assets/white-papers/wp-information-overload-security-data.pdf?utm_campaign=soc-metrics-in-cyber-marketing&amp;utm_medium=referral&amp;utm_source=secopspov.com">Fortinet&#8217;s report</a></p><p>There are many issues with the methodology of those reports, probably the biggest one is that <strong>when talking about alert volume you absolutely need to discuss team size.</strong> 400 alerts per day for 2-person SOC and 20-person SOC is entirely different workload. Add to it how some of those numbers are taken pre-finetuning, mixing up MSSP and in-house SOC numbers and a real chance that some of those numbers are made up and you&#8217;ll see why I&#8217;m super skeptical when a vendor says &#8220;SOCs are facing 10,000 alerts / day&#8221;. Sure.</p><h2>Incident Response metrics mixed with SOC metrics</h2><p>One thing I&#8217;m noticing recently is that many SOC leaders mix up Incident Response metrics with regular SOC metrics. Just this week I&#8217;ve seen two comments about MTT-<strong>Contain </strong>in the context of Security Operations. H&#8230;how much are you containing to derive a mean time from it?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D87w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D87w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 424w, https://substackcdn.com/image/fetch/$s_!D87w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 848w, https://substackcdn.com/image/fetch/$s_!D87w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 1272w, https://substackcdn.com/image/fetch/$s_!D87w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D87w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png" width="1507" height="902" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:902,&quot;width&quot;:1507,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83555,&quot;alt&quot;:&quot;image (18).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (18).png" title="image (18).png" srcset="https://substackcdn.com/image/fetch/$s_!D87w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 424w, https://substackcdn.com/image/fetch/$s_!D87w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 848w, https://substackcdn.com/image/fetch/$s_!D87w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 1272w, https://substackcdn.com/image/fetch/$s_!D87w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F593396b2-4682-45b8-b7b6-4e000b758f07_1507x902.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">SANS IR framework</figcaption></figure></div><p>What&#8217;s even more curious is MTT-<strong>Detect.</strong> To me this is an incident response metric that describes the time from the initial compromise to its detection. Otherwise what are we measuring? How fast our tools work?</p><p>Think about it, <strong>we</strong> don&#8217;t detect anything ourselves. We configure the tools that do so. Our ability to influence the time it takes our tools to detect is limited. We can maybe make detection rules run in a shorter interval, optimize data pipelines, account for ingestion latency, sure. But calculating the time from the original event to the alert firing for <strong>every</strong> alert (mean) and using it to demonstrate your SOCs success? I&#8217;m not buying it.</p><p>Oh, and I&#8217;ve recently seen SOC leads talk about MTT-<strong>Eradicate</strong> so there&#8217;s that. Again, just how much are you eradicating, good sir?</p><h2>The curious case of Benign Positives</h2><p>&#8220;True Positive. False Positive. True Negative. False Negative. Long ago, the four metrics lived together in harmony. Then everything changed when the Benign Positives attacked.&#8221;</p><p>If you&#8217;ve worked in a SOC (I assume you have since you&#8217;re reading this) you probably saw some type of this sad table that explained how alerts are categorized:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IA_z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IA_z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 424w, https://substackcdn.com/image/fetch/$s_!IA_z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 848w, https://substackcdn.com/image/fetch/$s_!IA_z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 1272w, https://substackcdn.com/image/fetch/$s_!IA_z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IA_z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png" width="693" height="349" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:349,&quot;width&quot;:693,&quot;resizeWidth&quot;:693,&quot;bytes&quot;:71774,&quot;alt&quot;:&quot;image (20).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (20).png" title="image (20).png" srcset="https://substackcdn.com/image/fetch/$s_!IA_z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 424w, https://substackcdn.com/image/fetch/$s_!IA_z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 848w, https://substackcdn.com/image/fetch/$s_!IA_z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 1272w, https://substackcdn.com/image/fetch/$s_!IA_z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff50007a6-7457-4819-bb7d-8660cd9b5e76_693x349.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cool. Actual attack? True Positive. Alert fired for some random activity? False Positive. See how easy that is?</p><p>Or rather <strong>was</strong>, because vendors started adding their own alert resolutions, like for example Benign Positive. And sure, I understand why. Sometimes an alert fires for an activity that looks malicious, but upon investigation ends up being benign.</p><p>On one hand we probably needed a way to categorize alerts that <strong>require investigation but aren&#8217;t malicious</strong> to separate them from clear False Positives where you can just close them after a quick look around. On another, that ends up being confusing.</p><p>Why you ask?</p><p>Consider two SOCs. SOC 1 has a SIEM that uses Benign Positive alert category. SOC 2 operates only on True Positive and False Positive statuses.</p><p>Both SOCs received 100 alerts, 50 were clear False Positives, 50 looked malicious and required further investigation, but in the end only 5 were malicious and ended up being raise as security incidents.</p><p>For SOC 1 their TP rate is 5%, BP rate is 45% and FP rate is 50%.</p><p>For SOC 2 their TP rate is 5%, FP rate 95%.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fu0u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fu0u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 424w, https://substackcdn.com/image/fetch/$s_!Fu0u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 848w, https://substackcdn.com/image/fetch/$s_!Fu0u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 1272w, https://substackcdn.com/image/fetch/$s_!Fu0u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fu0u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png" width="802" height="335" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/067a2905-c85c-4486-8244-df9e2ba33340_802x335.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:335,&quot;width&quot;:802,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28152,&quot;alt&quot;:&quot;image (24).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (24).png" title="image (24).png" srcset="https://substackcdn.com/image/fetch/$s_!Fu0u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 424w, https://substackcdn.com/image/fetch/$s_!Fu0u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 848w, https://substackcdn.com/image/fetch/$s_!Fu0u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 1272w, https://substackcdn.com/image/fetch/$s_!Fu0u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067a2905-c85c-4486-8244-df9e2ba33340_802x335.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Both SOCs are in the same situation - same workload, 100 alerts, 5 security incidents, but SOC 1 reports a 50% FP rate, while SOC 2 reports a 95% FP rate. Very different numbers for the exact same outcome.</p><h2>Wrapping up</h2><p>So that's my list of grievances. Metrics nobody defines the same way, metrics that optimize for the wrong behavior, metrics borrowed from incident response, and resolution categories that make comparing two SOCs impossible. Am I saying we should stop measuring SecOps?</p><p><strong>Absolutely not.</strong></p><p>In the next article I'll share what those are, based on what worked (and what didn't) in the SOCs I've run or consulted for.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Pure Play AI SOC or Add-On: Does It Even Matter Anymore?]]></title><description><![CDATA[Decode the AI SOC evolution: Learn why the pure play vs. add-on distinction no longer matters and discover how agentic automation is reshaping SecOps.]]></description><link>https://blog.secops-unpacked.ai/p/pure-play-ai-soc-or-add-on</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/pure-play-ai-soc-or-add-on</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 23 Jul 2026 13:42:09 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/83071d9a-e184-4c91-af78-45f56e75965c_2986x2241.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>AI SOC, or Agentic SOC as some call it now, went through an interesting evolution in the last 3 years. I has a chance to implement it in an enterprise in the early days when no one trusted it will be a thing, I advised most of the AI SOC vendors as a consultant, I tracked and analyzed almost every vendor in the space as an analyst, and now I build and market in it. So I've seen it from most of the angles that matter.</p><p>Enough bragging. The point is the space changed in a very short period of time. What started as a product category is now commoditized and used across the majority of SecOps tooling in some shape or form.</p><p>And that's not a bad thing. But let's first understand why it happened.</p><p style="text-align: center;"><strong>Product Updates Section !</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.spacewalk.ai/book-a-demo" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Eupc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 424w, https://substackcdn.com/image/fetch/$s_!Eupc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 848w, https://substackcdn.com/image/fetch/$s_!Eupc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 1272w, https://substackcdn.com/image/fetch/$s_!Eupc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Eupc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png" width="221" height="55.004444444444445" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:112,&quot;width&quot;:450,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:4071,&quot;alt&quot;:&quot;spacew.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.spacewalk.ai/book-a-demo&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="spacew.png" title="spacew.png" srcset="https://substackcdn.com/image/fetch/$s_!Eupc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 424w, https://substackcdn.com/image/fetch/$s_!Eupc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 848w, https://substackcdn.com/image/fetch/$s_!Eupc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 1272w, https://substackcdn.com/image/fetch/$s_!Eupc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f823d2-16a4-412d-9228-3cab2b80fb16_450x112.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><blockquote><p>Agentic Investigations from Triage to Forensics</p><p>Spacewalk handles the full investigation depth, from pre-L1 triage to L3+ incident work. It runs agentic investigations inside your SIEM and EDR, and when the case needs it, goes down to forensics: disk images, event logs, even PDFs. What caught my attention is how it handles complexity. The deeper the investigation, the more rigor it applies. It uses Analysis of Competing Hypotheses: benign versus malicious hypotheses, blind-evaluated, and the evidence has to actually discriminate between them. Not just a confidence score slapped on a verdict. The end result: verdicts you can audit, at whatever depth the investigation went.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://daylight.ai/get-a-demo" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3ARs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 424w, https://substackcdn.com/image/fetch/$s_!3ARs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 848w, https://substackcdn.com/image/fetch/$s_!3ARs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 1272w, https://substackcdn.com/image/fetch/$s_!3ARs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3ARs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png" width="192" height="192" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:192,&quot;width&quot;:192,&quot;resizeWidth&quot;:192,&quot;bytes&quot;:1509,&quot;alt&quot;:&quot;day.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://daylight.ai/get-a-demo&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="day.png" title="day.png" srcset="https://substackcdn.com/image/fetch/$s_!3ARs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 424w, https://substackcdn.com/image/fetch/$s_!3ARs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 848w, https://substackcdn.com/image/fetch/$s_!3ARs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 1272w, https://substackcdn.com/image/fetch/$s_!3ARs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28aa4fcb-e1f5-4c79-a0b9-eb4046b81384_192x192.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><blockquote><p>New Feature: AI Security for Claude Enterprise</p><p>AI tools are becoming part of the enterprise attack surface, but most SOCs still have limited visibility into what users, agents, and connected tools are doing. Daylight now provides managed AI security for Claude Enterprise as part of its MDR service. They build and continuously refine detection coverage for AI-native threats across Claude activity, including malicious or unauthorized MCPs, risky Skills and Plugins, prompt injection attempts, and more. Daylight&#8217;s agentic MDR investigates each signal, using context from identity, endpoint, cloud, SaaS, and business systems. Daylight other cool product features are the agentic threat hunting and a security data lake.</p></blockquote><div><hr></div><h2>The SecOps Shift Map</h2><p>To track the space, I created the <a href="https://blog.secops-unpacked.ai/p/ai-soc-shift-left-and-shift-right">SecOps Shift Map</a>. It explains the areas where SecOps tooling is developing. Soon is making 1 year since I first published it and now we have version 2.</p><p>Here's how is structured.. On the far left you have the data pipeline and log ingestion. To get alerts, you first need visibility. Then you have the detection layer, plus what I now call SecOps resilience: monitoring your SecOps pipeline itself. You got the alerts, now you need to get alerted when something is malicious or suspicious.</p><p>Then you get into triage. This is where you do the analysis and decide how to handle an alert. If it's a false positive or benign, figure out what needs fixing. If it's a true positive, you continue to remediation.</p><p>Quick note on terminology: I try to use "response" less these days. For some people, response means you started analyzing an alert. For others, it means remediation, mitigation, containment. Too confusing.</p><p>(The map is still work in progress. I haven't figured out where to place attack simulation/emulation or deception tech yet. My current thinking is attack simulation sits under SecOps resilience, because you're testing your pipeline.)</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://secops-unpacked.ai/research/ai-soc-vendors?view=shiftmap" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kc_s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 424w, https://substackcdn.com/image/fetch/$s_!kc_s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 848w, https://substackcdn.com/image/fetch/$s_!kc_s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 1272w, https://substackcdn.com/image/fetch/$s_!kc_s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kc_s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png" width="3290" height="786" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:786,&quot;width&quot;:3290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1180100,&quot;alt&quot;:&quot;Shift Map 2.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors?view=shiftmap&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Shift Map 2.png" title="Shift Map 2.png" srcset="https://substackcdn.com/image/fetch/$s_!kc_s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 424w, https://substackcdn.com/image/fetch/$s_!kc_s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 848w, https://substackcdn.com/image/fetch/$s_!kc_s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 1272w, https://substackcdn.com/image/fetch/$s_!kc_s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F121d14bc-bc09-4f7f-80f8-47a3bcdec6b7_3290x786.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Here's the kicker</h3><p>Most AI SOC vendors started in the middle of the map. Triage. And to some extent, that's how the product category got shaped.</p><p>In my mind, that was never going to be enough. Something that just does triage will get commoditized. And it did. Most SIEM, EDR, SOAR, XDR, or whatever tech SecOps teams use, added some form of autonomous triage. Some of it is simple, mainly throwing stuff at an LLM. Some of it is complex agentic systems with RAG and automations.</p><p>I won't argue about what "true AI SOC" is, because we're not there yet. When I speak with practitioners, no two give me the same definition. It means different things to different people. So I stick with AI SOC as we know it: AI/LLM and agents used for autonomous alert investigation. Based on that definition, it got commoditized.</p><h3>The prediction that played out</h3><p>What I said last year: because of this, it won't be enough for AI SOC vendors to sell just triage. They will move either left or right on the Shift Map.</p><p>Right means the SOAR route. Add response, some level of automation builders. Left means threat hunting, detection engineering, or even building a SIEM.</p><p>And exactly that happened. You can see how the Shift Map looked last year versus how it looks now.</p><p>Ah, and one more shift I almost forgot. Some vendors will go into service offerings and add MDR. We have that as a separate highlight on the Shift Map, since that one is services rather than tech.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://secops-unpacked.ai/research/ai-soc-vendors?view=shiftmap&amp;map=heat" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CKtY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 424w, https://substackcdn.com/image/fetch/$s_!CKtY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 848w, https://substackcdn.com/image/fetch/$s_!CKtY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 1272w, https://substackcdn.com/image/fetch/$s_!CKtY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CKtY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png" width="2986" height="2241" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2241,&quot;width&quot;:2986,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1145030,&quot;alt&quot;:&quot;Shidtmap 2026 vs 2025.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors?view=shiftmap&amp;map=heat&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Shidtmap 2026 vs 2025.png" title="Shidtmap 2026 vs 2025.png" srcset="https://substackcdn.com/image/fetch/$s_!CKtY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 424w, https://substackcdn.com/image/fetch/$s_!CKtY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 848w, https://substackcdn.com/image/fetch/$s_!CKtY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 1272w, https://substackcdn.com/image/fetch/$s_!CKtY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67348f34-a3f2-43d7-8bf8-6c58fa39f4c7_2986x2241.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The analysts are catching up</h2><p>This connects to something I covered in a recent <a href="https://www.linkedin.com/posts/filipstojkovski_friday-siem-post-is-here-this-week-data-activity-7483879455271313408-RoCO">Friday SIEM post</a>: the movement isn't only coming from the AI SOC side. Data pipeline vendors are moving into SIEM and adding AI SOC on top. Cribl acquiring CardinalOps is the latest example. The AI SOC piece is what makes them compelling. In the past you needed SOAR-like capabilities to offer the investigation piece, now the agents cover that.</p><p>And the demand explains why everyone converges. Many orgs looking into AI SOC don't just want triage. They want to replace or consolidate their SIEM, MDR and SOAR costs. Every AI SOC conversation is a consolidation conversation.</p><p>The analyst firms see it too. Gartner even created a new category for it, called <a href="https://www.gartner.com/reviews/market/integrated-security-operations-center-solutions">ISOC (Integrated Security Operations Center) Solutions</a>. Forrester took a different route. In their <a href="https://www.forrester.com/blogs/announcing-the-forrester-wave-on-extended-detection-and-response-platforms-platformization-ai-and-ai/">latest XDR Wave</a> they kept the XDR name but added AI agents and agentic systems as a separate evaluation criteria, and SIEM replacement went from experimental to reality. So basically, XDR with agents.</p><p>In my view, this is where many of today's players around SecOps will evolve.</p><p>Will it change the name? Not so sure. Gartner invented a new one, Forrester stuck with XDR. And even XDR failed to replace SIEM as a term.</p><h2>How I see this playing out</h2><p>Three types of implementations:</p><ul><li><p><strong>Platform play.</strong> This is where the ISOC category is getting stronger. The usual large players that offer everything.</p></li><li><p><strong>Point solutions and decoupled SIEM.</strong> Many smaller solutions added to the stack, a combo of vendors plus build it yourself.</p></li><li><p><strong>Existing stack plus MDR and/or AI SOC on top.</strong> For those that want minimal tech disruption. And here I think the demand is high: AI SOC with MDR, or MDR with AI SOC capabilities.</p></li></ul><h2>So, pure play or add-on?</h2><p>You might be wondering what the advantages are of pure play vendors versus the ones offering AI SOC as an add-on capability.</p><p>Well, it depends what you're looking for. As in many markets, you'll always have niche pure play players versus the big ones that have a bit of everything. Some capabilities are there just to tick a box, others are full blown.</p><p>For pure play, I think the advantage is focus. They concentrate on that one thing, so they put a lot of effort into developing the autonomous investigation. For the vendors adding it as a capability, it might be a checkbox, or it might be a full blown capability. <a href="https://secops-unpacked.ai/asef/guide">You have to check</a>.</p><p>I won't share my view on which is better. Some might say I have bias here, so I won't say one beats the other. That's the whole point of SecOps Unpacked: we give you all the tools to evaluate, and you tell us which one you find better and why.</p><h2>The plot twist I didn't predict</h2><p>Vendors that were not AI SOC rebranded as AI SOC. And on the other side, AI SOC vendors rebranded as something else, like SIEM.</p><p>We track that too. One insight into how we map vendors: if a vendor was founded before Gen AI, so before 2022, they get classified as AI SOC as a capability add-on. That way you know the underlying tech is something else and there was a shift in technology. I think this is fair for everyone.</p><p>On top of all this, there are teams building AI SOC in house. Too early for success stories there.</p><h2>Do we have too many vendors doing AI SOC?</h2><p>Maybe. But compared to vendors doing security for AI, it's about 3 times less. So I wouldn't call it crowded just yet.</p><h2>Where to go from here</h2><p>On the SecOps Unpacked vendor tracker we have close to <a href="https://secops-unpacked.ai/research/ai-soc-vendors">140 vendors</a>, all mapped to the Shift Map, so we can track the changes live year over year. Go check it out and let me know what you think.</p><p>The full mapping of all vendors per category will be released in our AI for SecOps Market Research coming in November.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Introducing ASEF]]></title><description><![CDATA[Decode the AI SOC vendor landscape: Discover ASEF, a vendor-neutral evaluation framework scoring platforms across detection, investigation, response, and trust layers.]]></description><link>https://blog.secops-unpacked.ai/p/asef-ai-soc-evaluation-framework</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/asef-ai-soc-evaluation-framework</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Wed, 08 Jul 2026 13:45:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1afdc14f-77d7-4627-a877-1d14d82ce5b3_1774x887.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><blockquote><p><strong>TL;DR.</strong> Every AI SOC vendor ships a "10 questions to ask" checklist tuned to their own product. We built a vendor-neutral one instead. ASEF, the AI SOC Evaluation Framework, scores any AI SOC platform across the whole lifecycle: data ingestion, detection, investigation, response, plus a trust layer underneath.<br>Score all of it for a fullness reading, or scope to the one zone you are buying and score just that, in depth, with no penalty for the rest.<br><br>No product behind it, no pricing, your scores stay yours. It is live and free at <a href="https://secops-unpacked.ai/asef/guide">secops-unpacked.ai/asef/guide</a>.</p></blockquote><p><strong>AI SOC / Agentic SOC</strong> is everywhere - The phrase currently covers everything from fully autonomous investigation pipeline to a chatbot that suggests you maybe reset a password. Same label, same analyst category, same booth. And when a security team sits down to compare three of these products, there is no shared way to measure the distance between them.</p><p>Back in February we published <a href="https://armm.secops-unpacked.ai/">ARMM</a> (AI Response Maturity Model), a maturity model for AI SOC response capabilities. It did its job, and it stopped at response on purpose. The limitations section said it plainly: detection and analysis are out of scope.</p><p>The thing is not many buy just response product. They buy an AI SOC platform, and that platform it should touch everything (here we might be going into the <a href="https://www.gartner.com/reviews/market/integrated-security-operations-center-solutions">ISOC</a> term). The data pipeline, the detections, the investigation, the verdict, the action, and the loop that feeds lessons back into better detections.</p><p>So we extended it. <a href="https://secops-unpacked.ai/asef/guide">ASEF, the AI SOC Evaluation Framework</a>, is a vendor-neutral framework for evaluating AI SOC platforms across the whole security operations lifecycle: data ingestion, detection, investigation, and response, plus a cross-cutting Platform and Trust layer. That is the one-line version. Let me walk you through the rest.</p><p style="text-align: center;"><strong><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Vendor Updates Section !</span></strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.prophetsecurity.ai/request-a-demo?utm_source=secopsunpacked&amp;utm_medium=paid-profile" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!he79!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 424w, https://substackcdn.com/image/fetch/$s_!he79!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 848w, https://substackcdn.com/image/fetch/$s_!he79!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 1272w, https://substackcdn.com/image/fetch/$s_!he79!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!he79!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png" width="221" height="39.18005540166205" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:192,&quot;width&quot;:1083,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:16650,&quot;alt&quot;:&quot;prophet-logo-on-light-h.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.prophetsecurity.ai/request-a-demo?utm_source=secopsunpacked&amp;utm_medium=paid-profile&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="prophet-logo-on-light-h.png" title="prophet-logo-on-light-h.png" srcset="https://substackcdn.com/image/fetch/$s_!he79!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 424w, https://substackcdn.com/image/fetch/$s_!he79!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 848w, https://substackcdn.com/image/fetch/$s_!he79!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 1272w, https://substackcdn.com/image/fetch/$s_!he79!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75cc24b-a724-445c-a34a-89db8ea56617_1083x192.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><blockquote><p>Agentic AI SOC Platform</p><p>Built by SecOps, for SecOps, Prophet Security's Agentic AI SOC Platform elevates every part of your SOC. AI SOC Analyst dynamically builds an investigation plan; correlates evidence across identity, endpoint, cloud, email, and network at investigation time; and reaches a defensible determination in minutes, with the full reasoning trail behind every call.</p><p>Across customers, they are seeing 90%+ reduction in noise and false positives, ~4 minutes MTTI, and thousands of analyst hours saved, enabling analysts to improve detections, proactively threat hunt, and focus on improving their organizations' security program.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.strike48.com/solutions/security" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CLQr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 424w, https://substackcdn.com/image/fetch/$s_!CLQr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 848w, https://substackcdn.com/image/fetch/$s_!CLQr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 1272w, https://substackcdn.com/image/fetch/$s_!CLQr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CLQr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png" width="221" height="56.871331828442436" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:114,&quot;width&quot;:443,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:4919,&quot;alt&quot;:&quot;strike48.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.strike48.com/solutions/security&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="strike48.png" title="strike48.png" srcset="https://substackcdn.com/image/fetch/$s_!CLQr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 424w, https://substackcdn.com/image/fetch/$s_!CLQr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 848w, https://substackcdn.com/image/fetch/$s_!CLQr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 1272w, https://substackcdn.com/image/fetch/$s_!CLQr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bf2e0c-e4a7-4f98-b7b0-ed3db4329cf4_443x114.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p>Agentic Operations Layer</p><p><em>Every AI SOC tool promises autonomy. Few run on a foundation that provides verifiable results. Strike48's Agentic Operations Layer closes that gap with hybrid deterministic and cognitive workflows that make every action repeatable. Introduce agents at your own pace, with no rip and replace of the tools you already run. Configurable human-in-the-loop controls keep you in command. Full audit trails give you visibility into every decision and action. Underneath it all, real-time data federation gives you a complete view of logs across every system, providing the foundation agents need to take action you can trust.</em></p></blockquote><div><hr></div><h2>The market rushed to the middle</h2><p>Here is what actually happened over the last two years. Everyone built the middle. Triage and investigation were the easier win, so that is where the products piled up. The demos are impressive. Alerts get worked fast. And both ends stay thin. Very few products can improve your detections. Very few can execute a remediation without three humans watching. At <a href="https://secops-unpacked.ai/research/ai-soc-vendors">SecOps Unpacked</a> we track this market closely, and you can see the clustering across the whole vendor landscape. The market optimized for the part that demos well.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://secops-unpacked.ai/research/ai-soc-vendors" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2ayx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 424w, https://substackcdn.com/image/fetch/$s_!2ayx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 848w, https://substackcdn.com/image/fetch/$s_!2ayx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 1272w, https://substackcdn.com/image/fetch/$s_!2ayx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2ayx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png" width="1048" height="1082" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1082,&quot;width&quot;:1048,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:262383,&quot;alt&quot;:&quot;Screenshot 2026-07-08 at 15.35.01.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 2026-07-08 at 15.35.01.png" title="Screenshot 2026-07-08 at 15.35.01.png" srcset="https://substackcdn.com/image/fetch/$s_!2ayx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 424w, https://substackcdn.com/image/fetch/$s_!2ayx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 848w, https://substackcdn.com/image/fetch/$s_!2ayx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 1272w, https://substackcdn.com/image/fetch/$s_!2ayx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb56002-a9b0-4cfb-88be-729ba3f19f23_1048x1082.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We are not the only ones seeing it. Anton Chuvakin and Oliver Rochford earlier this year published <a href="https://cyberfuturists.com/when-marketing-fails">When Marketing Fails</a>, a paper on the gap between AI SOC vendor claims and what practitioners actually experience. Their finding, from 30 plus vendor briefings: most claims describe a future state sold in the present tense, and when reality disagrees, the product immaturity gets reframed as a buyer readiness problem. Their fix is to separate assistive from autonomous capabilities, measure adoption depth instead of feature enablement, and treat trust as something a system earns.</p><p>ASEF has a mechanism for each one. The autonomy scale separates assistive from autonomous, per capability. Automation depth measures depth, not enablement. And the trust metrics live in the ROI panel, not on the slide.</p><h3>What ASEF actually is</h3><p>ASEF is a funnel. Five stages, and each one does exactly one job.</p><p><strong>Screen.</strong> Narrow the market to a shortlist using your scope and your hard requirements. Requirements are binary. They filter, they never get scored. The idea is that if you want platform that does only Detection Engineering, you don&#8217;t need to evaluate the one that does only data pipeline.</p><p><strong>Score.</strong> Score the survivors capability by capability, per zone, on an autonomy scale.</p><p><strong>Platform.</strong> Score the cross-cutting Platform and Trust layer separately. It never blends into the headline.</p><p><strong>ROI.</strong> Track operational metrics as deltas against your own baseline.</p><p><strong>Decide.</strong> Read it all together against thresholds you set before the demo.</p><p>The stages stay separate on purpose. Most bad evaluations happen when these jobs collapse into each other. A requirement becomes a score. A platform gap gets averaged away by a strong feature. A single blended number hides the weak zone. ASEF refuses all three.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C0hj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C0hj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 424w, https://substackcdn.com/image/fetch/$s_!C0hj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 848w, https://substackcdn.com/image/fetch/$s_!C0hj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!C0hj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C0hj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png" width="1023" height="1578" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1578,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2302908,&quot;alt&quot;:&quot;ASEF 1 branded.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ASEF 1 branded.png" title="ASEF 1 branded.png" srcset="https://substackcdn.com/image/fetch/$s_!C0hj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 424w, https://substackcdn.com/image/fetch/$s_!C0hj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 848w, https://substackcdn.com/image/fetch/$s_!C0hj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!C0hj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e32801-6233-427e-97f4-4211f53700f8_1023x1578.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Four zones, left to right</h2><p>Everything hangs on the Shift Map.</p><p><strong>Data ingestion and processing.</strong> Can it onboard sources, parse, normalize, and tell you where your data gaps are.</p><p><strong>Detection engineering and SecOps resilience.</strong> Can it author detections, map coverage to ATT&amp;CK, run a proactive hunt off a hypothesis and turn what it finds into a detection, tune the noise, and manage detection as code.</p><p><strong>Investigation and Triage.</strong> Can it build context, enrich, correlate, scope, and land on a verdict you can defend. Can it run a reactive hunt off an indicator, sweeping the environment for the same activity. And when the verdict is real, can it go deeper. Memory analysis, artifacts, root cause, evidence handling. Triage depth, hunt depth, and DFIR depth are not the same thing, and this zone scores all three.</p><p><strong>Response, Remediation, and Feedback loop.</strong> Can it act, how autonomously, and does what it learned flow back into better detections. This zone is ARMM, all five planes, plus the feedback loop.</p><p>Under all of it sits Platform and Trust. Audit trail, reasoning logs, RBAC, governance, model handling. It gets its own scale and its own card, and a platform score below 50 percent raises a risk flag that no feature strength can clear.</p><p>There are 126 capabilities in the seed set, and the whole thing is data-driven. A new capability is one data entry, not a code change.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sldw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sldw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 424w, https://substackcdn.com/image/fetch/$s_!Sldw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 848w, https://substackcdn.com/image/fetch/$s_!Sldw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 1272w, https://substackcdn.com/image/fetch/$s_!Sldw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sldw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png" width="2027" height="976" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:976,&quot;width&quot;:2027,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1857314,&quot;alt&quot;:&quot;ASEF 2 Branded.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ASEF 2 Branded.png" title="ASEF 2 Branded.png" srcset="https://substackcdn.com/image/fetch/$s_!Sldw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 424w, https://substackcdn.com/image/fetch/$s_!Sldw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 848w, https://substackcdn.com/image/fetch/$s_!Sldw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 1272w, https://substackcdn.com/image/fetch/$s_!Sldw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F663769be-6e4f-4a73-94cd-d0b87d3f401f_2027x976.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Question one: what can it do, and how autonomously</h2><p>Every lifecycle capability gets scored on the autonomy scale we carried over from ARMM.</p><p><strong>0</strong> means no capability. <strong>1C</strong> means the AI collaborates and the analyst does the work. <strong>1G</strong> means the AI lays out options and the analyst picks. <strong>1A </strong>means the AI prepared the action and waits for a human to approve it. <strong>2</strong> means it runs end to end, no human in the loop.</p><p><strong>Level 2</strong> is still rare, and that is fine. The scale exists to show the distance between the marketing and the autonomy, and to show which products are actually moving.</p><p>Two readouts fall out of this, and you read them together. Coverage, the share of capabilities above zero. And automation depth, the distribution across the levels. High coverage with low automation is a guided workflow tool with AI branding. Moderate coverage with real autonomy where it counts is a different product for a different buyer.</p><h2>Question two: how hard is it for your team, and what breaks if it is wrong</h2><p>Builder mode scores the same capability for your reality, across three axes. Trust, how much confidence the implementation deserves. Complexity, how hard it is for your team to build and run. Impact, the blast radius if it goes wrong. Add them up, 3 to 9, and the score maps to a tier.</p><p>The same capability lands at a different tier for a mature team than for a junior one. The capability is identical. The context is not. A vendor benchmark alone was never going to capture that, and that is exactly why Builder mode exists.</p><h2>A profile, not a single number</h2><p>ASEF does not produce one blended score, because one blended score is exactly how a Middle-only product gets to call itself mature.</p><p>The headline is a profile across the zones you chose to evaluate. The composite label is gated. A product earns a full label only when every in-scope zone clears the tier and a feedback loop exists. A product that is Expert at investigation and empty on both ends gets labeled Middle-heavy. On purpose. That label is the whole point of this framework turned into a score.</p><p><strong>Scope matters too. You pick which zones you are evaluating at the start</strong>. A team that handles detection elsewhere and only needs investigation and response does not get marked down for skipping the left side. The report opens by stating the scope, and out-of-scope zones read as not evaluated, never as gaps.</p><p>And scope changes the reading, not just what shows. Evaluate all four zones and you get the fullness score, one composite across the lifecycle. Evaluate one or two and you get each zone scored on its own tier, in depth, down to its subdomains. No composite, no blend, no penalty for what you did not ask about. If you are buying an investigation tool, you get an investigation score, not a lifecycle grade that docks it for lacking response. Zones never blend, because blending two of them into one number recreates the same hiding problem one level down. The Platform and Trust layer is scored either way, because it applies to any platform you buy.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BrUK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BrUK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 424w, https://substackcdn.com/image/fetch/$s_!BrUK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 848w, https://substackcdn.com/image/fetch/$s_!BrUK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!BrUK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BrUK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png" width="2212" height="1568" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1568,&quot;width&quot;:2212,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3669301,&quot;alt&quot;:&quot;ASEF 3 Branded.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ASEF 3 Branded.png" title="ASEF 3 Branded.png" srcset="https://substackcdn.com/image/fetch/$s_!BrUK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 424w, https://substackcdn.com/image/fetch/$s_!BrUK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 848w, https://substackcdn.com/image/fetch/$s_!BrUK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!BrUK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53cbea7c-b911-4c98-8680-cce8b293062e_2212x1568.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Unknown is not a pass</h2><p>The screening stage has one rule I care about more than any other. A vendor fact is either present, or it is unknown. Unknown never quietly becomes a pass or a fail.</p><p>Every vendor in the screen lands in one of three states. Passes, on known facts. Excluded, because a known fact fails a hard requirement, hidden behind a deliberate reveal and labeled with the reason. Or unknown, meaning a required fact is missing, shown by default and flagged as verify in a proof of concept.</p><p>Most comparison spreadsheets quietly treat missing information as either fine or disqualifying, depending on who built the spreadsheet. Both are wrong. Excluded fails a known fact. Unknown might pass once you verify it. Keeping those two apart is the integrity of the whole gate.</p><p>And the same honesty applies to the AI itself. Chuvakin and Rochford close their paper with the question every buyer should push a vendor on: can the system admit it does not know, and what happens when it does. ASEF scores that directly. Inconclusive verdict support is a capability in the Investigation zone, because a system that forces a binary call on thin evidence is not confident, it is reckless. Override telemetry and published failure modes are capabilities in Platform and Trust. A vendor that treats analyst overrides as user error and documents no limitations does not have a feedback loop. It has a narrative.</p><h2>Is the SOC getting smarter, or just faster</h2><p>The last layer is PICERL, 15 metrics across the six phases of the SANS incident response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, and Learning. The phases are SANS's. The index built on them is ours.</p><p>You record a baseline before the proof of concept and track deltas against it. No baseline, no evaluation. And there is deliberately no single ROI number. It is a panel of deltas, so strong movement on one phase cannot hide a regression on another.</p><p>The metrics that matter most are not the speed ones. Auto-close reversal rate. Escalation accuracy. Model drift. Whether analyst corrections actually feed back into the system. Closing alerts faster is sweeping the floor faster. The question that matters is whether the SOC is getting smarter.</p><h2>What ASEF is not</h2><p>No vendor scores. The directory holds facts, and any editorial reference is clearly marked context, never the verdict. Your scores are your own.</p><p>No pricing. Because that is changing too often, it is up to you to take this within your org and compare what you get for the price that you pay for the product.</p><p>No integration coverage module yet. Integrations are breadth, not autonomy, and they deserve their own percentage-based score. It is on the roadmap. Until then, integration quality gets tested where it should be, in the proof of concept.</p><p>No environment tailoring yet. A future version will let you pick your log sources and your top use-cases, scope the capability set to your reality, and surface your telemetry gaps. The design exists. The module does not.</p><h2>Bottom line</h2><p>The framework reference and the interactive guide are live at <a href="https://secops-unpacked.ai/asef/guide">secops-unpacked.ai/asef/guide</a>. Screen the market, score a product, export the results. ARMM stays a standalone model at <a href="https://armm.secops-unpacked.ai">armm.secops-unpacked.ai</a> and now also lives inside ASEF as the Response zone.</p><p>Thanks to Andrei Cotaie and Cristian Miron. Their work on ARMM is the foundation this whole thing stands on.</p><p>ASEF is data-driven by design, so contributing is a small edit. A capability, a metric, a vendor fact correction. Send it through the repository or the site contact form. Every contribution says what to measure, never how good any one vendor is at it.</p><p>No current product will score well across the whole map, and that is not the point. The point is a common language for what "AI SOC" actually means, so the next conversation you have with a vendor is grounded in capabilities and autonomy instead of promises. The framework will move as the market does.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors"><span data-color="#3a30e2" style="color: rgb(58, 48, 226);">Check out our SecOps Market Landscape tracker and evaluation frameworks</span></a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[SIEM deployment unpacked]]></title><description><![CDATA[Unpack SIEM deployment lessons from 30+ onboarding projects. Learn a data-driven, proven approach that works for MSSPs and in-house SOCs.]]></description><link>https://blog.secops-unpacked.ai/p/siem-deployment-unpacked</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/siem-deployment-unpacked</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 25 Jun 2026 13:01:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c05b4e18-015d-4fec-b75c-4cbb0c049f0c_1953x1121.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Rafal here, first post on SecOps Unpacked, nice to meet &#128075;</p><p>Over my career I&#8217;ve participated in and / or led ~30 SIEM onboarding projects, probably closer to 50 if we count individual deployments (1 client, multiple SIEMs type of deal).</p><p>Eventually I worked my way towards a SIEM onboarding approach which I will be sharing in this article. It is data driven, environment agnostic and works well for both MSSPs and in-house SOCs.</p><p>Let&#8217;s go.</p><h2>Why have an approach</h2><p>Why can&#8217;t you just common sense your way to a solid SIEM deployment and, by extension, a decent security monitoring strategy? After all, you&#8217;ve (hopefully) worked with a SIEM before, you&#8217;ve seen the detections, queried the data. Why shouldn&#8217;t you just sit down with your team and try to just&#8230; figure it all out?</p><p>Good question.</p><p>For MSSPs that&#8217;s obviously a bad idea because you&#8217;d be turning each engagement into a bespoke one and <strong>you don&#8217;t want that.</strong></p><p>For in-house SOCs it <strong>might </strong>work, but I don&#8217;t think it would be a long term solution. Ideally you&#8217;d want your security monitoring approach to outlast the current team.</p><p>I doubt you can common sense your way to a solid security monitoring strategy. Mostly because, <strong>we&#8217;re all biased</strong> whether we admit it or not.</p><p>What I saw working on my 30+ SIEM onboarding projects is that without a solid, data driven approach, the project plan defaults to the perspective of the most senior stakeholder. Roughly this:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZBKQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 424w, https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 848w, https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png" width="1160" height="213" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:213,&quot;width&quot;:1160,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19678,&quot;alt&quot;:&quot;image (3).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (3).png" title="image (3).png" srcset="https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 424w, https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 848w, https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBKQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a57272-15a8-40a3-ae32-77e431489e77_1160x213.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>STORY TIME START</strong></p><p>I once worked on a SIEM onboarding project for two almost identical companies. Same industry, same size, same technology stack. Both ended up with completely different SIEMs. This was purely because the CISO of the first company used to be a sysadmin, while the SOC manager at the other had a purely networking background.</p><p>One SIEM ended up being heavy on endpoint data and detections; the other prioritized network visibility. To this day, I'm not sure which one was more effective at detecting the right threats.</p><p><strong>STORY TIME END</strong></p><p>There are other reasons too, but I don't want to go into depth or this article turns into a book. For example:</p><ul><li><p>Staying cost-efficient: without a clear security monitoring strategy, you tend to over-collect data and make your SIEM bulkier than it needs to be.</p></li><li><p>Keeping alert volume low: having a clear priority on what needs to be alerted on allows you to be surgical with fine-tuning.</p></li><li><p>Being up to date with the world: making sure your ability to detect threats matches the modern threat landscape.</p></li></ul><div><hr></div><p>My thesis is that you can&#8217;t common sense your way to a solid security monitoring strategy. I believe you need an approach that&#8217;s data driven, reusable across different environment and ideally one that can be easily updated to account for new attack vectors.</p><p>Here it is:</p><h2>Chunking the project down</h2><p>SIEM onboarding or migration is a large project. And what do we do with large projects? <strong>We chunk them down into manageable pieces.</strong></p><p>Here&#8217;s how I do it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Twm8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Twm8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 424w, https://substackcdn.com/image/fetch/$s_!Twm8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 848w, https://substackcdn.com/image/fetch/$s_!Twm8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 1272w, https://substackcdn.com/image/fetch/$s_!Twm8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Twm8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png" width="996" height="967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:967,&quot;width&quot;:996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121879,&quot;alt&quot;:&quot;SIEM onboarding unpacked vertical.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="SIEM onboarding unpacked vertical.png" title="SIEM onboarding unpacked vertical.png" srcset="https://substackcdn.com/image/fetch/$s_!Twm8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 424w, https://substackcdn.com/image/fetch/$s_!Twm8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 848w, https://substackcdn.com/image/fetch/$s_!Twm8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 1272w, https://substackcdn.com/image/fetch/$s_!Twm8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6993bba-b2de-4131-8d6e-dabe1a2fe7ef_996x967.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I chunk the SIEM onboarding project into <strong>three phases</strong>, each taking roughly <strong>30 days</strong>. Once the project is complete, you (or your client) ends up with a fully functional threat detection system.</p><p>Obviously, threat detection and response content needs to be updated on a reasonably frequent cadence, but that is a story for another time. Let&#8217;s dig in:</p><h2>Pre-onboarding</h2><p>Two of the most common questions I&#8217;d get when onboarding clients to a SIEM was:</p><ul><li><p>What should we monitor?</p></li><li><p>What data do we need to collect?</p></li></ul><p>Some would argue (I&#8217;m some) that answering those two questions solves 80% of your security monitoring strategy. The approach that worked the best for me, and one I&#8217;d like to instill in you, is this:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YE3Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YE3Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 424w, https://substackcdn.com/image/fetch/$s_!YE3Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 848w, https://substackcdn.com/image/fetch/$s_!YE3Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 1272w, https://substackcdn.com/image/fetch/$s_!YE3Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YE3Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png" width="2220" height="324" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:324,&quot;width&quot;:2220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34877,&quot;alt&quot;:&quot;image (6).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (6).png" title="image (6).png" srcset="https://substackcdn.com/image/fetch/$s_!YE3Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 424w, https://substackcdn.com/image/fetch/$s_!YE3Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 848w, https://substackcdn.com/image/fetch/$s_!YE3Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 1272w, https://substackcdn.com/image/fetch/$s_!YE3Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40e1109e-abe9-4f8a-8c92-240dc9aa8b43_2220x324.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Threat intel informs you what detections you need. Knowing what detections you need, it's easy to decide what data to collect (at least the hot-storage portion of your data).</p><p>Let me repeat:</p><ol><li><p>Threat Intel</p></li><li><p>Detections</p></li><li><p>Data</p></li></ol><p>In this order. Here&#8217;s how to operationalize it.</p><p>First, you want to understand the monitored environment. If you're an MSSP, you can send a questionnaire to your clients. Figure out the number and types of systems, the existing security stack, maybe also regulatory commitments.</p><p>Then you want to prepare a threat landscape report. Nothing complicated:</p><ol><li><p>List threat actors who are most likely to attack you or your client. This is based on factors like industry, geography, size, history of past incidents, and questionnaire input.</p></li><li><p>List MITRE techniques most used across those threat actors.</p></li><li><p>Map those techniques in a <a href="https://mitre-attack.github.io/attack-navigator/">MITRE Navigator</a> or similar tool for a clean presentation:</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kg-D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kg-D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 424w, https://substackcdn.com/image/fetch/$s_!Kg-D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 848w, https://substackcdn.com/image/fetch/$s_!Kg-D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 1272w, https://substackcdn.com/image/fetch/$s_!Kg-D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kg-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png" width="1488" height="837" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:837,&quot;width&quot;:1488,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:633038,&quot;alt&quot;:&quot;image (7).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (7).png" title="image (7).png" srcset="https://substackcdn.com/image/fetch/$s_!Kg-D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 424w, https://substackcdn.com/image/fetch/$s_!Kg-D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 848w, https://substackcdn.com/image/fetch/$s_!Kg-D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 1272w, https://substackcdn.com/image/fetch/$s_!Kg-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60f8fdb8-58ce-40b0-aee5-b9b68fc62159_1488x837.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Techniques in red will be addressed first</figcaption></figure></div><p>Your goal is to list the top 5&#8211;10 MITRE techniques most likely to be used against you or your client. The next step is drafting detections for those techniques and understanding what data needs to be collected to support running those detections and the subsequent investigations.</p><p>Once this is done, you&#8217;re ready to move to the first phase of SIEM onboarding: <strong>centralize &amp; learn.</strong></p><h2>[Phase 1] Centralize &amp; learn (30 days)</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5xWC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5xWC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 424w, https://substackcdn.com/image/fetch/$s_!5xWC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 848w, https://substackcdn.com/image/fetch/$s_!5xWC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 1272w, https://substackcdn.com/image/fetch/$s_!5xWC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5xWC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png" width="1241" height="725" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:725,&quot;width&quot;:1241,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103073,&quot;alt&quot;:&quot;image (9).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (9).png" title="image (9).png" srcset="https://substackcdn.com/image/fetch/$s_!5xWC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 424w, https://substackcdn.com/image/fetch/$s_!5xWC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 848w, https://substackcdn.com/image/fetch/$s_!5xWC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 1272w, https://substackcdn.com/image/fetch/$s_!5xWC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fb08952-e29d-406e-b081-bff5c0c1518c_1241x725.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first phase of SIEM onboarding is straightforward. You grab alerts generated by your other threat detection tools and send <strong>all of them</strong> to your SIEM. And yes, I expect you to have a bunch of tools deployed before thinking about getting a SIEM. <strong>Otherwise, you might not need one just yet.</strong></p><p>On top of that, a SIEM provides a single mechanism for fine-tuning by using KQL, SPL, or whatever other query language, and that makes exclusions easier to document and manage. If you were to fine-tune downstream, the way you'd do it would be different for every tool, and that requires specialized knowledge.</p><p>And finally, you get to <strong>learn the new tool</strong> as you work on those alerts. And by starting with centralizing alerts you get a chance to get familiar with that new environment while the workload is still &#8220;light&#8221;.</p><p>In your first 30 days you want to do two other things: start working on your list of crown jewels and lay down basic security monitoring processes.</p><p>We start discussing crown jewels early because organizations often don't have a clear vision of what theirs are. That gives them at least 60 days (phase 1 + phase 2) to come up with a list.</p><p>As far as the processes are concerned, you want to figure out at least three things:</p><ol><li><p><strong>[If you're an MSSP] Co-management</strong>, or "who does what." This process is your way of managing expectations. People responsible for selling the service sometimes get creative :). You want to establish clarity right off the bat to avoid unpleasant surprises further down the road.</p></li><li><p><strong>Escalation paths:</strong> a list of contacts for different technologies. Essentially SMEs who can give you context for investigations and incident response.</p></li><li><p><strong>Knowledge management:</strong> a place to keep your procedures. As alerts and data start flowing in, you'll want a central place to manage your knowledge. Can be anything, really, as long as everybody on the team has access and can use it.</p></li></ol><p>That's it. Alerts are flowing in, fine-tuning is taking place, you've established basic processes. You can already start monitoring.</p><p>Now you're ready to <strong>build detections:</strong></p><h2>[Phase 2] Build detections (30 days)</h2><p>The goal of pre-onboarding was to build a list of techniques most likely to be used against you or your client. This phase focuses on creating detections that trigger when those techniques are observed in the environment.</p><p>To remind you of what we're going for:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SHyI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SHyI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 424w, https://substackcdn.com/image/fetch/$s_!SHyI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 848w, https://substackcdn.com/image/fetch/$s_!SHyI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 1272w, https://substackcdn.com/image/fetch/$s_!SHyI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SHyI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png" width="2220" height="324" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:324,&quot;width&quot;:2220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34877,&quot;alt&quot;:&quot;image (10).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (10).png" title="image (10).png" srcset="https://substackcdn.com/image/fetch/$s_!SHyI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 424w, https://substackcdn.com/image/fetch/$s_!SHyI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 848w, https://substackcdn.com/image/fetch/$s_!SHyI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 1272w, https://substackcdn.com/image/fetch/$s_!SHyI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56a3496e-172f-4dfd-9e18-25b5fb24d325_2220x324.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We have threat intel, we&#8217;ve <strong>ideally</strong> drafted detection rules. We&#8217;re ready to start onboarding data to our SIEM.</p><p>Now, when sending data to a SIEM, we&#8217;re met with different <strong>data storage tiers</strong>. There&#8217;s typically some type of <strong>hot storage</strong> (readily available, also expensive) and <strong>cold-er storage </strong>(not immediately available, but cheaper). A simple rule to follow is that <strong>data that directly supports running detections and investigating them goes to hot storage. </strong>What you do with your cold storage is your business, good sir.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ue3C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ue3C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 424w, https://substackcdn.com/image/fetch/$s_!Ue3C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 848w, https://substackcdn.com/image/fetch/$s_!Ue3C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 1272w, https://substackcdn.com/image/fetch/$s_!Ue3C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ue3C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png" width="2348" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c123db9c-92ae-4028-8478-109f49099646_2348x808.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:2348,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94375,&quot;alt&quot;:&quot;image (12).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (12).png" title="image (12).png" srcset="https://substackcdn.com/image/fetch/$s_!Ue3C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 424w, https://substackcdn.com/image/fetch/$s_!Ue3C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 848w, https://substackcdn.com/image/fetch/$s_!Ue3C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 1272w, https://substackcdn.com/image/fetch/$s_!Ue3C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc123db9c-92ae-4028-8478-109f49099646_2348x808.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">High level thought process behind SIEM data storage</figcaption></figure></div><p>Detection engineering workflows can get complex, but if you're just starting out, I suggest you <strong>make sure your detections are tested and have a clear SOP</strong>. No need for an elaborate detection engineering pipeline at this stage.</p><p>The threat intel &#8594; detections process should be repeatable. You do it once during onboarding and repeat every quarter or so. This is mostly because the threat landscape continues to evolve, and the detections you've written today may not be the ones you need a year from now.</p><p>Lastly, having a structured detection engineering process makes sense, but in reality you will have to write a lot of ad-hoc rules based on ongoing incidents, threat hunts, investigation findings, or just the new attacks that seem to be popping up every other week these days. My approach is this: <strong>if there's an urgent need to write a detection, write it. If not, fall back on your detection backlog.</strong></p><p>Very simple if you think about it.</p><p>Once alerts are in and custom detections have been created, you already have a solid SIEM in place. You could very well choose to finish the work here. Still, I think it makes sense to take the onboarding one step further and aim to <strong>protect your crown jewels.</strong></p><h2>[Phase 3] Protect Crown Jewels (30 days)</h2><p>This part can get difficult, but bear with me.</p><p>We focus on crown jewels last. This is very important because <strong>one of the more common SIEM onboarding anti-patterns is setting up monitoring for crown jewels too early.</strong></p><p>By the time a threat actor reaches a crown jewel, they're typically late in the attack chain. If you focus on monitoring the most critical assets first, you decrease your ability to detect and stop the attack at earlier stages.</p><p>You need to know that companies rarely have a clear concept of crown jewels, and the effort to come up with a list often ends with the security team deciding on their own. Here's roughly the workflow:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9xRr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9xRr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 424w, https://substackcdn.com/image/fetch/$s_!9xRr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 848w, https://substackcdn.com/image/fetch/$s_!9xRr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 1272w, https://substackcdn.com/image/fetch/$s_!9xRr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9xRr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png" width="757" height="472" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:472,&quot;width&quot;:757,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:573002,&quot;alt&quot;:&quot;image (13).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (13).png" title="image (13).png" srcset="https://substackcdn.com/image/fetch/$s_!9xRr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 424w, https://substackcdn.com/image/fetch/$s_!9xRr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 848w, https://substackcdn.com/image/fetch/$s_!9xRr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 1272w, https://substackcdn.com/image/fetch/$s_!9xRr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F213d0ad3-3435-4dfe-ac07-dc7aff751e19_757x472.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>However you arrive at the list of crown jewels, make sure to come up <strong>with a concise list</strong>. This means <strong>3-5 systems</strong>, not 50. From that point on, the work seems relatively straightforward - collect data, write detections. And yet, you should be ready to face the following issues:</p><ul><li><p>Crown jewels are often older systems and may not support data export.</p></li><li><p>Clients may hesitate to install agents on crown jewels due to security or performance concerns.</p></li><li><p>Maintenance windows may stretch far beyond your onboarding timeline.</p></li><li><p>External technicians or vendors might be required for support.</p></li><li><p>Crown jewels may not produce useful or relevant data.</p></li></ul><p><strong>If data collection isn't possible</strong>, use crown jewels to add context to your existing detections. Automate alert prioritization so that anything related to crown jewels stands out to analysts. Even if you can't pull logs directly, automation can help highlight events that touch crown jewels one way or another.</p><p>That's it. You're <strong>mostly </strong>done. The next steps are the finishing touches:</p><ul><li><p>Writing simple automation: Teams/Slack notifications for high-severity alerts, automated IOC lookups, tagging of high-value assets.</p></li><li><p>Preparing handover documentation.</p></li><li><p>Subscribing to SecOps Unpacked.</p></li></ul><h2>SIEM onboarding unpacked</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5pom!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5pom!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 424w, https://substackcdn.com/image/fetch/$s_!5pom!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 848w, https://substackcdn.com/image/fetch/$s_!5pom!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 1272w, https://substackcdn.com/image/fetch/$s_!5pom!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5pom!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png" width="1642" height="722" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:722,&quot;width&quot;:1642,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128919,&quot;alt&quot;:&quot;image (14).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="image (14).png" title="image (14).png" srcset="https://substackcdn.com/image/fetch/$s_!5pom!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 424w, https://substackcdn.com/image/fetch/$s_!5pom!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 848w, https://substackcdn.com/image/fetch/$s_!5pom!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 1272w, https://substackcdn.com/image/fetch/$s_!5pom!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c3efd5b-96f6-497c-a285-c7a1047edf53_1642x722.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Aaaand that&#8217;s the 3-phase SIEM onboarding approach, developed through plenty of trial and error. If there is one way you take from this article I'd like it to be the value of relying on threat intelligence to build a SIEM.</p><p>Feel free to steal this approach. And if parts of it are not clear - feel even more free to reach out to us on <a href="https://www.linkedin.com/company/secops-unpacked">LinkedIn</a>.</p><h2>Bonus tip for MSSPs</h2><p>When should you start monitoring?</p><p>Most MSSPs I've worked with have a flat fee for SIEM setup and then a recurring fee for security monitoring services. Typically, security monitoring kicks in after the SIEM is fully stood up. This in essence means that <strong>you're not paid for monitoring until the SIEM onboarding finishes.</strong></p><p>But what if the SIEM onboarding project runs longer than expected? I typically plan 90 days for a full end-to-end onboarding, but I've seen it stretch into years. Many reasons:</p><ul><li><p>The client's IT team might not be available to assist you.</p></li><li><p>Major changes in leadership on the client's end can happen.</p></li><li><p>A major incident can occur while you're onboarding.</p></li><li><p>A vendor needed to help you might not be available.</p></li><li><p>The list of crown jewels can take ages to be prepared.</p></li><li><p>Various bureaucracy issues can pop up as you go.</p></li><li><p>The client may start disputing the project's scope.</p></li><li><p>And so on&#8230;</p></li></ul><p>One MSSP I worked with had a nice way around this. They built it into their contracts and called it a<strong> hybrid-operations model</strong>. What this means is that the SOC team started monitoring as soon as alerts hit the SIEM, which happens in the first phase of onboarding. <strong>You don't have to wait for the project to finish to start getting paid.</strong></p><p>It accomplishes two important things: it makes handover smoother because analysts have already been working in the SIEM for a couple of months, and it protects your organization against the project running longer than expected. This approach saved us a number of times.</p><p>Worth considering.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Agentic Threat Hunting]]></title><description><![CDATA[Decode agentic threat hunting: Learn why AI-powered threat hunting is harder than vendor demos suggest and discover what actually works.]]></description><link>https://blog.secops-unpacked.ai/p/agentic-threat-hunting</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/agentic-threat-hunting</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Tue, 16 Jun 2026 14:19:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/28e748a1-31ad-4e80-a2a8-515a57bccc3e_2757x1478.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>If you have been watching the AI SOC space, you already know what comes right after it. Agentic threat hunting. AI threat hunting. Pick your favorite name, every vendor has one now. It is the second wave, and it is getting loud.</p><p>So before we judge it, let me back up and talk about what threat hunting actually is, why people love it, and why automating it is trickier than the demos make it look.</p><h2>A bit of history</h2><p>Threat hunting got popular around 2010, back when everyone was chasing APTs. It was the buzzword of the moment, and honestly it was one of the cooler things you could put on your plate as a practitioner. You were not just clearing a queue. You were going after the stuff that slipped past the alerts.</p><p>To be a threat hunter you needed two things. First, deep knowledge of your environment. Second, you had to know your SIEM and your query language cold. That second part is where most of the real work lives.</p><p style="text-align: center;"><strong>Product Updates !</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://marssec.ai/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SbDH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SbDH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SbDH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SbDH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SbDH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg" width="200" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:200,&quot;width&quot;:200,&quot;resizeWidth&quot;:200,&quot;bytes&quot;:3555,&quot;alt&quot;:&quot;marssec_logo.jpeg&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://marssec.ai/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="marssec_logo.jpeg" title="marssec_logo.jpeg" srcset="https://substackcdn.com/image/fetch/$s_!SbDH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SbDH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SbDH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SbDH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff30e2d30-d629-441f-bca0-7998babd0c8b_200x200.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><blockquote><p>Main Product Launch</p><p>Most security teams cannot tell you which active campaigns their stack would catch today. Not because they lack data. Because converting threat intelligence into validated detections, continuously and at scale, has never been automated. Until now.<br>Mars connects directly to your SIEM, EDR, identity, and cloud via API. No data ingestion. No tool replacement. It maps active attacker TTPs to your environment and generates production-ready hunts and detections automatically. Your team goes from 5 hunts a month to 50. Built by people who designed attacks like the ones targeting your stack right now.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.exaforce.com/blogs/vibe-hunting" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kJTB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 424w, https://substackcdn.com/image/fetch/$s_!kJTB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 848w, https://substackcdn.com/image/fetch/$s_!kJTB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 1272w, https://substackcdn.com/image/fetch/$s_!kJTB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kJTB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png" width="164" height="57" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:57,&quot;width&quot;:164,&quot;resizeWidth&quot;:164,&quot;bytes&quot;:5082,&quot;alt&quot;:&quot;exaforce.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.exaforce.com/blogs/vibe-hunting&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="exaforce.png" title="exaforce.png" srcset="https://substackcdn.com/image/fetch/$s_!kJTB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 424w, https://substackcdn.com/image/fetch/$s_!kJTB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 848w, https://substackcdn.com/image/fetch/$s_!kJTB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 1272w, https://substackcdn.com/image/fetch/$s_!kJTB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7e7d286-ebae-4dda-8214-8cb42d7359b3_164x57.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p>Introducing Vibe Hunting</p><p>Exaforce takes both the hypothesis grind and the query grind off your plate. Threat news articles are ingested automatically as they surface, with IOCs extracted and matched against your environment before any analyst opens a browser tab. And when a hunt does need human intuition, vibe hunting lets analysts express hypotheses in plain language while Exabots handle the querying, correlation, and enrichment.<br>By the time your CISO asks "are we impacted?", Exaforce has already answered the question</p></blockquote><div><hr></div><h2>The two kinds of hunts</h2><p>There are two flavors.</p><p>Reactive hunts start from an incident. You have a TTP or an indicator, and you go look for the same activity across the rest of the environment. Did this land anywhere else? How far did it spread?</p><p>Proactive hunts start from a hypothesis. Usually that hypothesis comes from threat intel. You read about a technique or an actor, you ask "could this work against us," and then you go check. From there you take it wherever the data leads.</p><p>The hardest part in both cases is the same: writing the queries. You need to understand your SIEM, every log source feeding it, and how the data is structured. Then you need to be good at reading and parsing what comes back. That is the skill that takes years to build.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CXft!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CXft!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 424w, https://substackcdn.com/image/fetch/$s_!CXft!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 848w, https://substackcdn.com/image/fetch/$s_!CXft!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 1272w, https://substackcdn.com/image/fetch/$s_!CXft!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CXft!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png" width="1219" height="1224" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1224,&quot;width&quot;:1219,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1620333,&quot;alt&quot;:&quot;TH 1.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="TH 1.png" title="TH 1.png" srcset="https://substackcdn.com/image/fetch/$s_!CXft!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 424w, https://substackcdn.com/image/fetch/$s_!CXft!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 848w, https://substackcdn.com/image/fetch/$s_!CXft!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 1272w, https://substackcdn.com/image/fetch/$s_!CXft!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc18d4c5-13db-4a2b-8266-e1222009e70d_1219x1224.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What you get out of it</h2><p>Outcomes depend on the type of hunt.</p><p>Reactive hunts usually give you blast radius. You find out where else the activity showed up, and you spot gaps in your detections or your coverage along the way.</p><p>Proactive hunts go one of two ways. Either you find something and it becomes an incident, or you find nothing actionable and the work feeds into detection engineering so they can build new detections. This is why threat hunting and detection engineering are joined at the hip. A hunt that does not feed detections is half a hunt.</p><h2>So, agentic threat hunting. Is it any good?</h2><p>Here is the part you came for.</p><p>Agentic threat hunting uses LLMs and AI agents to run the hunt for you. And yes, a lot of the hard parts can be automated now. For real, not just on a slide.</p><p>An agent can:</p><ul><li><p>Process threat intel and build a threat profile for your org</p></li><li><p>Turn that into hypotheses worth checking</p></li><li><p>Write the SIEM (or EDR/NDR/XDR) queries</p></li><li><p>Run the hunt and hand you the results</p></li><li><p>Suggest coverage gaps and new detection rules off the back of it</p></li></ul><p>For reactive hunts it works the same way. Hand it an indicator and it runs the queries and does the deeper analysis for you.</p><p>So the tech is real and it is useful. But the demo is the easy 20 percent. The hard 80 percent is everything that makes a hunt actually work in your environment. Here is what I would push any vendor on.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aa55!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aa55!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 424w, https://substackcdn.com/image/fetch/$s_!aa55!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 848w, https://substackcdn.com/image/fetch/$s_!aa55!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 1272w, https://substackcdn.com/image/fetch/$s_!aa55!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aa55!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png" width="1723" height="1704" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1704,&quot;width&quot;:1723,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2677423,&quot;alt&quot;:&quot;TH2.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="TH2.png" title="TH2.png" srcset="https://substackcdn.com/image/fetch/$s_!aa55!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 424w, https://substackcdn.com/image/fetch/$s_!aa55!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 848w, https://substackcdn.com/image/fetch/$s_!aa55!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 1272w, https://substackcdn.com/image/fetch/$s_!aa55!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac423e5d-0e67-48b1-8b2c-66a0e3a13ebd_1723x1704.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Question 1: Does it actually know your org?</h2><p>A hunt is only as good as the context behind it. The agent needs to know your infrastructure, your security stack, your crown jewels, and how you operate. Without that, the hypotheses are generic and the queries point at the wrong things. A hunting agent that does not know your environment is just running someone else's playbook against your logs.</p><p>This lines up with a point Anton Chuvakin made at last year's Gartner Security and Risk Management Summit. He put hunting against top-tier nation-state adversaries on the short list of things he does not expect AI to handle any time soon. The easy hunts automate well. The hard ones still need a human who knows the terrain.</p><h2>Question 2: Is it tuned for your SIEM and your tooling?</h2><p>This one is non-negotiable. The agent has to be trained and tailored for whatever you run, SIEM, EDR, NDR, XDR. It needs to write correct queries in your query language, not generic pseudo-SQL it picked up off the internet.</p><p>From what I have used and built, the thing that separates a good hunting agent from a bad one is simple. Before it writes anything, it should run two quick checks. One, pull the latest log sources. Two, pull the latest schemas. That way it is not guessing at field names, not querying a source you turned off last month, and not burning steps on failed queries.</p><p>This is a known failure mode, not me being paranoid. LLMs invent table and field names that sound right but do not exist in your data. Research on enterprise query agents calls this schema hallucination and lists it as one of the main error classes. If the agent does not ground itself in your current schema first, it will hand you a perfectly formatted query against columns you do not have.</p><h2>Question 3: Can it handle the output without drowning?</h2><p>Anyone who has written a bad SIEM query knows the pain. You burn your license, you slow the SIEM to a crawl, or you get back a million rows you cannot do anything with.</p><p>Agents have all of that plus one more problem: the context window. A bad query that returns a wall of raw logs fills that window fast, and then the agent loses the plot. So the queries cannot just be correct, they have to be efficient. Aggregate before you pull raw events. Select only the fields that matter. Build the query so the SIEM does the stats work and hands back something the agent can actually reason over.</p><p>This is not theoretical. Practitioners building these agents already follow the same discipline: run aggregations before pulling raw documents, filter to only the fields you need, use tested query templates instead of building from scratch, and cap how many queries the agent can fire per cycle. The pattern is the same every time. Keep it lean, or the agent chokes.</p><h2>Question 4: Does it know what normal looks like for you?</h2><p><a href="https://www.linkedin.com/in/oran-yitzhak">Oran Yitzhak</a> pushed me on this one, and he is right. It is not just your stack. It is your behavior. A hypothesis needs a baseline, and the baseline is what is normal in your environment. Without it, the agent produces threats that are technically plausible but operationally meaningless. That is not a hunt. That is a false positive factory with a nicer UI.</p><p>This is the part that separates "knows your org" from "knows your tooling." You can wire an agent into the right SIEM with the right schemas and it will still waste your time if it has no sense of what your users, services, and machines do on a normal Tuesday.</p><h2>The cascading error problem</h2><p>One more thing worth saying. In a chain like this, mistakes compound. A weak hypothesis leads to a bad query, which gives garbage output, which the agent then reasons over and confidently gets wrong. Each step looks fine on its own. The end result is nonsense delivered with a straight face.</p><p>And the confident part is what keeps me up at night. A weak hypothesis does not just produce a bad query. It produces a confident wrong answer. In DFIR a confident wrong answer is worse than no answer at all. It moves people in the wrong direction with conviction, and nobody pushes back, because the AI said so.</p><p>One more way to think about it. Agents make good hunters faster. They also make mediocre hunters loudly mediocre. That is useful signal if leadership is watching for it. Most leadership is not watching that metric yet.</p><p>That is why the human stays in the loop. Not to write every query, but to sanity-check the hypothesis going in and the verdict coming out. The agent should also show its work: which sources it hit, which queries it ran, what it found and what it did not. "No results" is itself a finding, and a good hunting agent should tell you whether it found nothing or simply could not look.</p><h2>So where does that leave us?</h2><p>Agentic threat hunting is real, and it is useful for the repetitive, query-heavy grind. It can take the parts that used to eat your afternoon and give them back. But it is not a hunter in a box. It needs your context, your schemas, tight queries, and a human checking the start and the end of every hunt.</p><p>Get those right and it earns its keep. Skip them and you have an expensive agent writing beautiful queries against logs that do not exist.</p><p>Same rule as always. It does not replace the hunter. It makes a good hunter faster, and it makes a bad setup fail quicker.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Agent Builders for SecOps]]></title><description><![CDATA[Decode the agent builder landscape: Learn why not all SecOps agents are equal and discover the critical differences that determine real automation]]></description><link>https://blog.secops-unpacked.ai/p/agent-builders-for-secops</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/agent-builders-for-secops</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 04 Jun 2026 15:51:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bed70307-8bcc-4d02-8e3e-71f56b8d56b4_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>Every SecOps platform now has "agents." SOAR vendors, the AI SOC crowd, the new players. Everyone slapped the word on something and shipped it.</p><p>But "agent" is doing a lot of work in those sentences. What you actually get changes a lot from one platform to the next. And the differences matter more than the demo makes it look.</p><p>At SecOps Unpacked we track this space closely. Right now we count <a href="https://secops-unpacked.ai/research/ai-soc-vendors">22 vendors</a> offering some form of agent builder for SecOps. That is a lot of choice, and almost none of them mean the same thing by it.</p><p>And even inside that group there is a split. Some platforms ship prebuilt agents and you use them as they are. Plug and play, no customization. That is fine for getting started, but you take what you get. The ones I care about here are the platforms that let you customize those agents or build your own from scratch. That is where the differences show up.</p><p>If you read some of my Li post on AI Agents vs. Playbooks, you know I care about where you draw the line between a thing that thinks and a thing that just runs steps. <a href="https://www.anthropic.com/research/building-effective-agents">Anthropic draws the same line</a>: workflows run on predefined paths, agents direct their own process and tools. This post is the next layer down. Once you decide you want agents, how the platform lets you build them is the real question.<br><br>So let me break down the flavors I keep seeing, and then the harness, which is what actually sets them apart.</p><p style="text-align: center;"><strong>Our new</strong> <strong>Product Updates Section !</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.binalyze.com/get-in-touch?utm_campaign=44388719-SecOps%20Unpacked%20Influencer&amp;utm_source=Influencer%20Campaign" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OMiz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 424w, https://substackcdn.com/image/fetch/$s_!OMiz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 848w, https://substackcdn.com/image/fetch/$s_!OMiz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 1272w, https://substackcdn.com/image/fetch/$s_!OMiz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OMiz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png" width="221" height="56.9765625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:165,&quot;width&quot;:640,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:12583,&quot;alt&quot;:&quot;Binalyzelogo (1).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.binalyze.com/get-in-touch?utm_campaign=44388719-SecOps%20Unpacked%20Influencer&amp;utm_source=Influencer%20Campaign&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Binalyzelogo (1).png" title="Binalyzelogo (1).png" srcset="https://substackcdn.com/image/fetch/$s_!OMiz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 424w, https://substackcdn.com/image/fetch/$s_!OMiz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 848w, https://substackcdn.com/image/fetch/$s_!OMiz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 1272w, https://substackcdn.com/image/fetch/$s_!OMiz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d386fb5-fb9d-481a-8303-c609c3b8b141_640x165.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><blockquote><p>Agent Builder release</p><p>Most AI SOC demos stop at chat. Fleet is interesting because it gives the you an AI SOC Analyst that does the actual work: reason through evidence, run investigations inside an isolated sandbox, inspect files, execute tools, generate detections, and turn findings into repeatable workflows. The Agent Builder is the control layer on top. Teams can shape specialized agents for package triage, phishing analysis, AIR investigations, reporting, or detection engineering without waiting for a vendor roadmap. This is the kind of AI SOC capability practitioners should evaluate: not autonomy theater, but controlled, customizable execution that maps to how SecOps really works.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.dropzone.ai/schedule-a-demo" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5OaO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 424w, https://substackcdn.com/image/fetch/$s_!5OaO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 848w, https://substackcdn.com/image/fetch/$s_!5OaO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 1272w, https://substackcdn.com/image/fetch/$s_!5OaO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5OaO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png" width="221" height="110.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:159,&quot;width&quot;:318,&quot;resizeWidth&quot;:221,&quot;bytes&quot;:2815,&quot;alt&quot;:&quot;Dropzone.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.dropzone.ai/schedule-a-demo&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dropzone.png" title="Dropzone.png" srcset="https://substackcdn.com/image/fetch/$s_!5OaO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 424w, https://substackcdn.com/image/fetch/$s_!5OaO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 848w, https://substackcdn.com/image/fetch/$s_!5OaO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 1272w, https://substackcdn.com/image/fetch/$s_!5OaO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09a10b02-a1d9-44dc-8af1-8c431d347ed3_318x159.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p>Threat Hunting &amp; Threat Intel Analyst</p><p>Most threat hunting programs remain out of reach for many security teams because they require specialized expertise and analyst time that is often in short supply. Dropzone new AI Threat Intelligence Analyst and AI Threat Hunter agents aim to make proactive threat discovery more accessible. The Threat Intelligence Analyst monitors threat intelligence sources, extracts TTPs and IOCs, and builds hunt packs, while the Threat Hunter executes them across SIEM, EDR, cloud, and identity platforms. Beyond identifying threats, the agents can uncover misconfigurations, shadow IT, and exposed vulnerabilities, allowing analysts to focus on validation, decision-making, and response.</p></blockquote><div><hr></div><h2>The Three Flavors</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1DmC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1DmC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 424w, https://substackcdn.com/image/fetch/$s_!1DmC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 848w, https://substackcdn.com/image/fetch/$s_!1DmC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 1272w, https://substackcdn.com/image/fetch/$s_!1DmC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1DmC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png" width="1536" height="2752" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2752,&quot;width&quot;:1536,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7249601,&quot;alt&quot;:&quot;Agent builder.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Agent builder.png" title="Agent builder.png" srcset="https://substackcdn.com/image/fetch/$s_!1DmC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 424w, https://substackcdn.com/image/fetch/$s_!1DmC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 848w, https://substackcdn.com/image/fetch/$s_!1DmC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 1272w, https://substackcdn.com/image/fetch/$s_!1DmC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647f45e1-9094-4a03-ade9-43200193d94e_1536x2752.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>1. The agent you call inside a workflow</h3><p>This is the classic. Probably the most used today, especially in SOAR and automation-style platforms. You have a workflow, and at some step you drop in an agent to do a piece of reasoning. Triage this alert. Summarize this. Decide if this IOC is bad.</p><p>It works. It is easy to reason about, because the agent lives inside a flow you already understand. The blast radius is small. If it does something dumb, it does it in one spot.</p><p>The downside is scale. You end up building a new agent per workflow. Phishing flow gets its own agent. EDR flow gets its own agent. Identity flow gets its own agent. Same logic, copied five times, drifting apart over time. And when you want to change how your agents behave, you are editing them one by one. Welcome back to maintenance hell, just with prompts instead of API calls.</p><h3>2. The monolith agent</h3><p>One big agent. You call it to do "the reasoning" inside a workflow, and it tries to handle whatever you throw at it.</p><p>Honestly I see more downsides than upsides here. The one real upside is ease of use. There is one thing to configure, so getting started is fast. It might also make sense if you are running small or local language models, where you want fewer moving parts to host and control.</p><p>But a monolith has no clear role. It is good at a bit of everything and great at nothing. It is hard to test, because the surface is huge. It is hard to guardrail, because it does too much. And when it gets something wrong, good luck figuring out why. You poke at a giant prompt and hope. For a SOC, where you need to trust and audit the decision, that is a bad trade.</p><h3>3. The agent builder</h3><p>This is the one I think wins. You build your own agents as reusable units. Each one gets:</p><ul><li><p>A <strong>role</strong>. What is this agent for. A phishing triage agent. A host enrichment agent. A containment recommender.</p></li><li><p><strong>Constraints</strong>. What it is not allowed to do. No isolating critical assets without approval. No closing alerts above a severity.</p></li><li><p>A <strong>knowledge base</strong>. Your SOPs, your asset context, your past decisions. The stuff that makes the agent yours and not a generic model guessing.</p></li><li><p><strong>Skills</strong>. The actions and tools it can use to get the job done.</p></li></ul><p>Then you reuse them. Build the enrichment agent once, call it from every workflow that needs enrichment. Fix it once, fixed everywhere. This is the same reason we moved from copy-pasted scripts to functions. It is not a new idea. It is just finally showing up in security tooling.</p><p>And these get a lot better when they are interactive. An agent you can talk to, that asks for input mid-investigation, that you can correct and steer, beats a fire-and-forget agent buried in a workflow. That is where the co-pilot and the autonomous agent start to merge into something useful.</p><h2>Now the Harness</h2><p>Here is what I want you to take away. When you compare agent builders, you are not really comparing models. You are comparing harnesses.</p><p>The agent harness is everything wrapped around the model. Tool execution, memory, context management, state, guardrails, the loop that lets it act instead of just answer. The model sits in the middle and does the reasoning. The harness is the rest. And the rest is most of it.</p><p>People building production agents keep landing on the same conclusion. The model is the smallest part of the system. When an agent breaks in prod, hallucinates a tool call, repeats an action it already did, ignores an instruction it followed an hour ago, it is almost never the model that got dumber. It is the harness that was underbuilt. Mitchell Hashimoto, the Terraform guy, even named the discipline: <a href="https://mitchellh.com/writing/my-ai-adoption-journey">harness engineering</a>. Every agent mistake becomes a permanent fix to the environment, not a prompt you retry.</p><p>This reframes the whole thing. The agent you call in a workflow, the monolith, the agent builder. These are just different amounts of harness, and different amounts of control over it.</p><ul><li><p>In the <strong>workflow agent</strong>, the harness is mostly the workflow itself. You wire context in by hand, step by step. Fine for one flow. Painful across many.</p></li><li><p>In the <strong>monolith</strong>, the harness is hidden inside one big config. You do not really shape it. You feed it and hope.</p></li><li><p>In a real <strong>agent builder</strong>, the role, constraints, knowledge base, skills, memory, and guardrails <em>are</em> the harness. You are configuring it directly. That is the point.</p></li></ul><p>So an agent builder is not a fancy prompt box. A good one is a harness with a UI on top. That framing tells you what to actually look for.</p><h2>What a Good Harness Gives You in SecOps</h2><p>When you evaluate one of these platforms, look past the model name on the slide and ask about the harness:</p><ul><li><p><strong>Tools and integrations as skills.</strong> Can your agents reach your SIEM, EDR, IDP, TI, CMDB, and case management, and can you add your own? An agent with no skills is just a chatbot with opinions.</p></li><li><p><strong>Memory and context.</strong> Does the agent remember prior alerts, prior analyst decisions, known-benign patterns? Or does every alert start from zero. SOC context is the whole game.</p></li><li><p><strong>Guardrails as part of the build.</strong> Can you set hard limits per agent. Rate limits on anything that quarantines or isolates. Human approval for high-impact actions. This should be config, not vibes.</p></li><li><p><strong>Observability.</strong> Can you see what the agent did and why. "Selected playbook 42 because 3 of 5 engines flagged the file." If the decision is a black box, you will never trust it, and you should not.</p></li><li><p><strong>Evals.</strong> Can you test an agent against known cases before it touches prod. Shadow mode counts. Anything that lets you measure before you ship.</p></li><li><p><strong>Model-agnostic.</strong> This one is underrated. The model is pluggable. A good harness lets you swap it. When a stronger model drops next quarter, and one will, you want to plug it in, not rebuild every agent you own. If your platform welds you to one model, you bought a harness with no spare parts.</p></li></ul><h2>Bottom Line</h2><p>The "agent" label tells you almost nothing. What tells you something is how you build them and how much of the harness you control.</p><p>Per-workflow agents are fine to start. Monoliths are easy and not much else. The agent builder, especially an interactive one, is where you get reuse, roles, constraints, and real control.</p><p>And the next time a vendor walks in leading with which model powers their agents, ask about the harness instead. That is the part you will actually live with.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Building the AI for SecOps Vendor Landscape]]></title><description><![CDATA[The SecOps Unpacked AI for SecOps Vendor Landscape: 110+ vendors structured by capability. Built for practitioners evaluating tools, investors comparing]]></description><link>https://blog.secops-unpacked.ai/p/building-the-ai-for-secops-vendor-landscape</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/building-the-ai-for-secops-vendor-landscape</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 21 May 2026 15:34:40 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4da18ce0-293c-46e8-8bdd-8592df62511e_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>It has been almost a month since my last post. The reason is simple: I have been heads-down on the new version of the SecOps Unpacked AI for SecOps Vendor Landscape.</p><p>The list now has over 110 vendors. A month ago it had around 50. At this rate it could reach 150 by the end of the year.</p><blockquote><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">SecOps Unpacked &#8212; Independent Research on AI SOC, Automation &amp; Modern SecOps</a></strong><br>Independent research platform for security practitioners. Track AI SOC vendors, security automation, detection engineering, and the frameworks shaping modern SOCs.<br><em>SecOps Unpacked &#8226; SecOps Unpacked</em></p></blockquote><h3>How this started</h3><p>The first version was meant to be a simple tracker. Nothing more than a list I maintained for my own reference.</p><p>Then practitioners started reaching out. They wanted better filtering. They wanted more depth. They were using the list to scope vendors for evaluation, which was not what I built it for, but it was exactly the kind of use that made me pay attention. Around the same time, engagement on the ARMM framework started climbing, and I noticed SecOps Unpacked showing up near the top of Google results for AI SOC vendor lists.</p><p>That last part is what pushed me. If the list was going to rank that well, it needed to be good enough to deserve it. So I decided to take it seriously and build it into a proper app.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rt-b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rt-b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 424w, https://substackcdn.com/image/fetch/$s_!rt-b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 848w, https://substackcdn.com/image/fetch/$s_!rt-b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 1272w, https://substackcdn.com/image/fetch/$s_!rt-b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rt-b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png" width="1194" height="1585" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1585,&quot;width&quot;:1194,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:378505,&quot;alt&quot;:&quot;AI for SecOps Vendor Landscape.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AI for SecOps Vendor Landscape.png" title="AI for SecOps Vendor Landscape.png" srcset="https://substackcdn.com/image/fetch/$s_!rt-b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 424w, https://substackcdn.com/image/fetch/$s_!rt-b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 848w, https://substackcdn.com/image/fetch/$s_!rt-b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 1272w, https://substackcdn.com/image/fetch/$s_!rt-b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6e959de-3b63-4a45-b1ef-700ab7813e45_1194x1585.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Who this is for</h3><p>Three groups, really.</p><p><strong>Practitioners</strong> use it to scope vendors for evaluation. You are shortlisting tools, sizing the market, or figuring out which platform to demo or PoC next. This is the primary audience and the reason the list exists.</p><p><strong>Investors</strong> use it to compare the landscape. If you are doing diligence on a category or a specific vendor, the structured view shows you who is doing what, where the overlaps are, and where the white space is.</p><p><strong>Vendors</strong> use it for competitive intelligence. If you are building in this space, the landscape is a fast way to see how the market is structured and where you sit relative to everyone else.</p><p>The list is free for everyone. No gated content.</p><p>I do ask you to subscribe. It keeps you up to date as the list evolves, and it gives me a clearer picture of who is actually reading and using this. That feedback shapes what I build next.</p><h3>What you get as a practitioner</h3><p>A structured list of every vendor doing AI for SecOps in some form. I originally wanted to scope it to AI SOC only, but that was too narrow. The market is broader than one category.</p><p>To get the structure right, I worked with practitioners I trust: Rafal Kitab, Cristian Miron, and Andrei Cotaie. The category work was also shaped by the writing of Oliver Rochford and Anton Chuvakin, whose thinking on this space is worth reading if you have not already.</p><p>What came out of that is a set of categories and definitions covering the full landscape. Each platform is tagged by capability so you can see what it actually does. This is a live list. Capability tagging will be maintained as the market shifts, which is harder than it sounds: for most vendors I need to go through a demo to understand the platform well enough to map it accurately.</p><p>Each vendor also has key elements built for evaluation. Easier to see by browsing than to describe here.</p><p>I added several visualizations, because that is how I like to consume data. If you have an idea for a visualization that would help, tell me.</p><p>Advanced filtering is in the backlog. I am holding it until more vendors claim their profiles and the data is rich enough to make filtering worthwhile.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4NrZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4NrZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 424w, https://substackcdn.com/image/fetch/$s_!4NrZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 848w, https://substackcdn.com/image/fetch/$s_!4NrZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 1272w, https://substackcdn.com/image/fetch/$s_!4NrZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4NrZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png" width="1912" height="1187" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1187,&quot;width&quot;:1912,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238580,&quot;alt&quot;:&quot;Screenshot 2026-05-20 at 15.12.38.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 2026-05-20 at 15.12.38.png" title="Screenshot 2026-05-20 at 15.12.38.png" srcset="https://substackcdn.com/image/fetch/$s_!4NrZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 424w, https://substackcdn.com/image/fetch/$s_!4NrZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 848w, https://substackcdn.com/image/fetch/$s_!4NrZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 1272w, https://substackcdn.com/image/fetch/$s_!4NrZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb92134a-b2f7-4d16-9dde-e04e75627603_1912x1187.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Why not just scrape vendor websites</h3><p>Some people have asked why I do not just scrape vendor sites and auto-generate profiles. It is not that simple, at least not the way I want to do it.</p><p>I want vendors to share what they think is worth highlighting. Every profile goes through a review where I add editorial notes. In a future version you will be able to see which vendors I have seen a live demo of and which I have not, so you know how much weight to put on each profile.</p><h3>What is coming</h3><p>A few things on the roadmap:</p><p>An evaluation layer, in two forms. One connected to the ARMM framework. One built as a standalone way to test and evaluate AI SOC vendors, closer to a golden-standard benchmark. This needs a solid plan and the right partners to build the infrastructure around it, so it will take time.</p><p>A product release feed, plus a dedicated newsletter for anyone who wants vendor product updates in one place, separate from the main newsletter.</p><p>The longer-term goal is to turn this into the evaluation platform for SecOps. Not just a list. A place where you can actually evaluate.</p><h3>For vendors</h3><p>Vendors can claim their profile and start filling in information about their company and product. There is also an option for full access, which is subscription based. That covers the maintenance work each profile needs and a few additional perks.</p><p>If you are a vendor, claim your profile and I will share the details on the full offering.</p><p>So far over 20 vendors have claimed their profile, and over 10 have joined as founding members to support the development of the platform. That early support means a lot and it is what makes the bigger roadmap possible.</p><h3>That is it for now</h3><p>If you found this useful, share it. The more practitioners who use the landscape, the better it gets for everyone.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[SecOps Agents and AI SOC: SIEM vs Standalone vs SOAR]]></title><description><![CDATA[Decode the SecOps AI landscape: Explore SIEM vs standalone vs SOAR deployments and discover which architecture aligns with your security operations needs]]></description><link>https://blog.secops-unpacked.ai/p/secops-agents-and-ai-soc-siem-vs-standalone-vs-soar</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/secops-agents-and-ai-soc-siem-vs-standalone-vs-soar</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Tue, 28 Apr 2026 12:30:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/83bd1be3-850c-487c-8132-b4a71d429f2d_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>Today I want to break down something that keeps coming up in conversations: the difference between SecOps Agents and AI SOC when they live inside a SIEM versus when they show up as a standalone product or as part of a SOAR.</p><p>Three different starting points, three different sets of trade-offs. None of them are wrong. They just optimize for different things, and if you don't understand which one you are buying, you will end up disappointed.</p><h3>SIEMs own the data, and that matters</h3><p>SIEMs have the upper hand on triage. Full stop.</p><p>If you are a team that sends everything to your SIEM, you will get great triage results inside it. The reason is simple. The SIEM has all the data. If the implementation is done right, the platform can query that data faster and more efficiently than anything bolted on from the outside. Timeline analysis, blast radius, correlation across sources, all the bells and whistles.</p><p>But there is a condition attached to this. <strong>ONLY</strong> if you actually get all the data there. And by data I do not just mean logs. I mean enrichments too. Identity context, asset context, threat intel, business criticality, ownership. The triage is only as good as the context the SIEM can reach without leaving its own walls.</p><p>This is where the story gets complicated.</p><p>Once you move past triage and into response, the SIEM starts to lose ground. SIEM vendors were smart to play the SOAR card years ago. The problem is that most of them never invested enough to make it shine. Acquired SOAR products got bolted on, kept on life support, and then quietly underfunded while the marketing kept going.</p><p>My take has not changed. Unless you have your entire response stack inside a single ecosystem, and very few teams actually do, you need a vendor agnostic agentic, automation, and orchestration layer. The SIEM is a great triage brain. It is rarely a great hands and feet.</p><h3>Where pure play AI SOC and SOAR have the upper hand</h3><p>Now flip the scenario. You don't send everything to your SIEM. Maybe you cannot afford to. Maybe you are running multiple detection sources. Maybe your EDR, your cloud detections, your identity alerts, and your email security all live in their own consoles.</p><p>This is where pure play AI SOC vendors and SOAR-style platforms shine.</p><p>They do enrichment better in this world because they were built for a fragmented data reality. They pull from wherever the data lives instead of assuming it all flows into one lake. The trade-off is that they are limited by whatever APIs are available on the SIEM and on every other system they ingest alerts and detections from. If the API is shallow, the agent is shallow.</p><p>On the response side, this is where SOAR-style and agentic platforms really pull ahead. Response is hard. It involves dozens of systems, conditional logic, human approvals, rollback paths, and edge cases that only show up in production. Slapping MCP on top of a tool catalog and calling it response automation does not make the cut. Response needs to be designed, not summoned.</p><h3>TL;DR for the architecture decision</h3><p>If you have all your data and all your response actions inside one ecosystem, ride the SIEM agent wave. It will probably work for you.</p><p>If you do not, and most teams do not, you need a layer that is vendor agnostic on both data and response. That is where pure play AI SOC and modern SOAR-style platforms earn their keep.</p><h3>Vendor tracker update</h3><p>A quick update on the AI SOC and Agentic SOC vendor list we maintain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hSII!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hSII!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 424w, https://substackcdn.com/image/fetch/$s_!hSII!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 848w, https://substackcdn.com/image/fetch/$s_!hSII!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 1272w, https://substackcdn.com/image/fetch/$s_!hSII!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hSII!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png" width="1231" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1231,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:162553,&quot;alt&quot;:&quot;secops.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="secops.png" title="secops.png" srcset="https://substackcdn.com/image/fetch/$s_!hSII!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 424w, https://substackcdn.com/image/fetch/$s_!hSII!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 848w, https://substackcdn.com/image/fetch/$s_!hSII!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 1272w, https://substackcdn.com/image/fetch/$s_!hSII!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2b5715-ec64-484c-bed1-9ab2a230d565_1231x753.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://secops-unpacked.ai/research/ai-soc-vendors">We are now tracking 73 vendors.</a> The market keeps expanding, and we keep adding entrants as they show up with credible product and not just a landing page.</p><p>A few changes worth calling out:</p><ul><li><p>We now have multiple visual views of the landscape. Different cuts for different questions. One view for category, one for go-to-market motion, one for how they handle the data and response split discussed above.</p></li><li><p>The next iteration will include a definition for each category. One thing I have learned from talking to practitioners and buyers is that the category names are doing a lot of heavy lifting and not always carrying the weight. AI SOC, Agentic SOC, autonomous SOC, alert triage copilot, they all mean different things to different vendors. We will pin down what each one actually means in our taxonomy so the comparison is honest.</p></li></ul><p>If you want to be on the list, or if you think we missed you, reach out. The bar is product that exists and customers who use it.</p><h3>Coming up: AI SOC is just a feature</h3><p>Last thing. I will be joining Chris Hughes next week on Resilient Cyber, and one of the topics I want to dig into is why I think AI SOC is just a feature, not a category.</p><p>Short version of the argument. Triage automation, alert summarization, investigation assistance, these are capabilities. They will be embedded in SIEMs, in SOAR, in EDR, in detection engineering tools. Standalone AI SOC vendors that do not extend into the rest of the SecOps lifecycle will get squeezed. The interesting companies are the ones building agentic platforms that go beyond the triage box.</p><p><a href="https://www.linkedin.com/events/aisocgotcommoditized-nowwhat7453167806788874242/">More on that in the episode.</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zgv8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zgv8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zgv8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zgv8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zgv8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zgv8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg" width="1018" height="564" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:564,&quot;width&quot;:1018,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63415,&quot;alt&quot;:&quot;1776973678354.jpeg&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="1776973678354.jpeg" title="1776973678354.jpeg" srcset="https://substackcdn.com/image/fetch/$s_!Zgv8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zgv8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zgv8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zgv8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d700a36-f8ab-42d6-ad94-d17e7cc73bdf_1018x564.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[We Automated the Easy Part. Now Fix Your Detections.]]></title><description><![CDATA[Decode the AI SOC automation gap: Learn why triage is just the beginning and discover why detection engineering holds the key to true security operations]]></description><link>https://blog.secops-unpacked.ai/p/we-automated-the-easy-part-now-fix-your-detections</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/we-automated-the-easy-part-now-fix-your-detections</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Wed, 22 Apr 2026 16:01:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8dfab89c-2717-49a4-aae8-96fc240abf07_3288x3447.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>If you've been following this blog, you know the story so far. 2024 gave us AI copilots that summarized alerts but took no action. 2025 proved AI could actually triage, investigate, and reach verdicts at machine speed. The "AI Analyst" became a real product category.</p><p>My take: we automated the easy part.</p><p>The industry started in the middle of the IR cycle. Triage is analytically complex but operationally simple. No write access required. No change management. No risk of breaking production. It was the perfect first target. Detection engineering sits left of that, tangled in log pipelines and alert volume constraints. Response sits right, blocked by API limitations and organizational risk aversion.</p><p>And now we have a new problem.</p><h2>The Decision Load Tripled</h2><p>Faster detection and better triage surface more decisions that humans need to make. Before AI, a SOC might process 200 alerts daily and make 50 meaningful decisions. Now AI surfaces 2,000 alerts, auto-closes 1,700, and escalates 300 that require human judgment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WdKO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WdKO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 424w, https://substackcdn.com/image/fetch/$s_!WdKO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 848w, https://substackcdn.com/image/fetch/$s_!WdKO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 1272w, https://substackcdn.com/image/fetch/$s_!WdKO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WdKO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif" width="800" height="1600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1600,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:891594,&quot;alt&quot;:&quot;Before and After AI SOC 2.gif&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Before and After AI SOC 2.gif" title="Before and After AI SOC 2.gif" srcset="https://substackcdn.com/image/fetch/$s_!WdKO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 424w, https://substackcdn.com/image/fetch/$s_!WdKO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 848w, https://substackcdn.com/image/fetch/$s_!WdKO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 1272w, https://substackcdn.com/image/fetch/$s_!WdKO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc146b8c7-9c76-4aa2-83dc-363fd1dbb92f_800x1600.gif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Detection speed improved. Decision velocity did not.</p><p>If you read my post on<a href="https://blog.secops-unpacked.ai/p/how-ai-transforms-detection-engineering"> how AI transforms detection engineering</a>, you know I talked about the shift from precision-optimized detection to coverage-optimized detection. The idea is simple: when AI handles triage at scale, you can deploy the detections you always wanted. Broader rules, more coverage, let the AI sort through the noise.</p><p>That's true. But it created a side effect nobody planned for.</p><p>More coverage means more signals. More signals means more escalations. More escalations means more human decisions. And if those detections are noisy, poorly tuned, or written under the "Fear of Not Doing Enough" (yeah,<a href="https://blog.secops-unpacked.ai/p/the-fear-of-not-doing-enough"> that post</a> still haunts me), your AI SOC is just processing garbage faster.</p><p>Just because AI can investigate and triage alerts faster doesn't mean we should feed it bad detections. We don't want noise detections burning through tokens the same way we didn't want noise detections burning through SIEM licenses. Different cost center, same problem.</p><p>Think about it.<strong> With traditional SOAR, bad detections cost you analyst hours. With AI SOC, bad detections cost you tokens, compute, and worst of all, they erode trust in the system. Your analysts see the AI confidently closing garbage alerts and start questioning whether it's also confidently closing real threats. That's how you kill adoption.</strong></p><h2>2026 Will Test the Shift Left</h2><p>This year will test whether AI can shift left into detection and shift right into response. Not just reorganize the human decision burden but actually reduce it.</p><p>I think the shift left is quite important right now. And there are two ways to approach it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AMkX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AMkX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 424w, https://substackcdn.com/image/fetch/$s_!AMkX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 848w, https://substackcdn.com/image/fetch/$s_!AMkX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 1272w, https://substackcdn.com/image/fetch/$s_!AMkX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AMkX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png" width="3288" height="5750" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:5750,&quot;width&quot;:3288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14883834,&quot;alt&quot;:&quot;Detection Engineering Process.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Detection Engineering Process.png" title="Detection Engineering Process.png" srcset="https://substackcdn.com/image/fetch/$s_!AMkX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 424w, https://substackcdn.com/image/fetch/$s_!AMkX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 848w, https://substackcdn.com/image/fetch/$s_!AMkX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 1272w, https://substackcdn.com/image/fetch/$s_!AMkX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9536c26-8871-48fe-85b4-4fed321e4c7c_3288x5750.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Path 1: The Feedback Loop (Your AI SOC Should Pay for Itself)</h2><p>If your AI SOC is not giving you suggestions on how to improve your detections, it's designed to charge you more. Full stop.</p><p>I've been preaching about feedback loops since the <a href="https://blog.secops-unpacked.ai/p/automate-smarter-not-louder-using-interactive-ai-feedback-loops">DSAEM days</a>. Detection &gt; SOP &gt; Automation &gt; Emulation &gt; Metrics. The loop is what makes the whole thing work. Without it, you're just driving faster into a wall.</p><p>I don't think the AI should give you a one-to-one suggestion for every single alert. That's noise on top of noise. What I see working better is a periodic review. Weekly or monthly. The AI goes over your alerts and incidents, runs analytics across the dataset, and comes back with suggestions.</p><p>Things like:</p><ul><li><p>"This detection fired 847 times last month. 812 were auto-closed as benign. Here's a filter that would eliminate 90% of the noise without reducing true positive coverage."</p></li><li><p>"These three detections overlap significantly. You could merge them into one with better context and reduce your alert volume by 30%."</p></li><li><p>"This detection has a 2% true positive rate. Either tune it or kill it."</p></li><li><p>"Based on analyst overrides, your AI is consistently wrong about this alert type. Here's what the analysts are seeing that the AI is missing."</p></li></ul><p>That last one is gold. When analysts override AI decisions, that's training data. Not just for the AI model, but for your detection engineering program. If the AI keeps getting a specific detection wrong, maybe the detection itself is the problem.</p><p>The feedback loop isn't just about making the AI smarter. It's about making your detections smarter. The AI sees patterns across thousands of alerts that no human analyst has time to analyze. Use that.</p><p>If your AI SOC vendor doesn't offer this, ask why. Because from where I stand, an AI SOC that doesn't feed back into detection improvement is just an expensive alert processor. And we already had one of those. It was called SOAR.</p><h2>Path 2: Building Better Detections from Scratch</h2><p>The feedback loop fixes existing detections. But what about new ones? How do you build better detections from the start?</p><p>This is the harder problem. And it's where most teams are still stuck in manual mode.</p><p>Let me break down how I think about it.</p><h3>Where New Detections Come From</h3><p>In most organizations, new detections come from two places:</p><p><strong>Threat Intelligence.</strong> You get a feed. IOCs, TTPs, reports about new attack techniques. That intel should feed into your Threat Profile and Threat Modeling. Not every piece of intel is relevant to you. The question is always: does this threat apply to my environment, my industry, my infrastructure?</p><p><strong>Threat Hunting.</strong> Your hunters go looking for things your detections missed. When they find something, that finding should become a detection. In many cases, threat hunting is also TI-led. The hunter reads a report about a new technique, goes looking for it in the environment, and either confirms or denies its presence.</p><p>So the flow looks like this: Threat Intel feeds into both Threat Modeling and Threat Hunting. The outcomes of those processes produce detection suggestions.</p><p>Simple enough on paper. In practice? Total mess.</p><h3>Here's where it falls apart</h3><p>You get a detection suggestion. Maybe it's a Sigma rule from a community feed. Maybe your hunter wrote it after finding something interesting. The question is: should I implement this?</p><p>To answer that, you need to know:</p><ul><li><p>What log sources do I actually have?</p></li><li><p>What infrastructure am I running?</p></li><li><p>Do I even have the telemetry to detect this technique?</p></li><li><p>If I implement this detection, what coverage does it give me?</p></li><li><p>What's the gap if I don't implement it?</p></li></ul><p>Most teams answer these questions from memory. Or they don't answer them at all. They just implement the detection and hope for the best. That's the "Fear of Not Doing Enough" in action. Write the detection, push it to production, deal with the consequences later.</p><h3>This Is Where AI Should Help</h3><p>An AI-powered or agentic detection engineering platform should handle exactly this workflow:</p><p><strong>1. Ingest your threat intelligence.</strong> Not just IOCs. TTPs, actor profiles, campaign reports. Map them to your threat model automatically.</p><p><strong>2. Understand your environment.</strong> Know what log sources you have, what infrastructure you're running, what telemetry is available. This is the foundation. Without it, everything else is guessing.</p><p><strong>3. Match threats to coverage.</strong> Based on your threat profile and your available telemetry, show me what I can detect and what I can't. Where are the gaps? What's the risk of those gaps?</p><p><strong>4. Suggest detections that make sense.</strong> Not generic Sigma rules dumped into a folder. Detections that are relevant to my environment, my log sources, my infrastructure. With the context of what coverage they'll add and what risk they'll reduce.</p><p><strong>5. Measure everything.</strong> Coverage mapping, risk exposure, detection health. The whole picture.</p><h3>What to Measure</h3><p>Since we all love our MITRE ATT&amp;CK bingo cards (don't pretend you don't), coverage mapping is the obvious starting point. But it can't stop there.</p><p><strong>Coverage.</strong> Map your detections against ATT&amp;CK techniques. Show me what's covered and what's not. Yes, it's bingo. But it's useful bingo when you combine it with the next piece.</p><p><strong>Exposure and Risk.</strong> For every gap in coverage, I need a way to calculate risk. Not some abstract risk score pulled from thin air. Something grounded in: what threat actors target my industry? What techniques do they use? Do I have compensating controls? What's assumed risk versus mitigated risk?</p><p>This is how you go from "we have 60% ATT&amp;CK coverage" to "we have 60% coverage, and the 40% we're missing exposes us to these specific attack paths, with this estimated risk, and here's what we'd need to close those gaps."</p><p>That's a conversation a CISO can actually use. Not another bingo card.</p><p><strong>Detection Health.</strong> Are your existing detections still working? Are they firing? Are they producing true positives? Or have they degraded because the environment changed and nobody updated the rule? This ties back to the feedback loop. A detection you wrote six months ago might be useless today if the infrastructure changed.</p><h2>Connecting the Dots</h2><p>If you zoom out, the picture looks like this:</p><p>The AI SOC handles triage and investigation. It's fast, it's scalable, it works. But it only works as well as the detections feeding it. Garbage in, AI-powered garbage out.</p><p>The feedback loop takes what the AI learns during triage and feeds it back into detection engineering. It's continuous improvement. Your detections get better over time because you're learning from thousands of alert outcomes, not just the handful an analyst has time to review.</p><p>Building better detections from scratch takes the proactive approach. Instead of waiting for bad detections to generate noise, you start from threat intelligence and threat modeling. You map coverage, identify gaps, calculate risk, and build detections that actually matter for your specific environment.</p><p>The two paths complement each other. One fixes what you have. The other builds what you need.</p><p>And this is exactly the shift left that 2026 needs. We proved AI can triage. We proved it can investigate. Now we need to prove it can help us build better defenses from the start.</p><h2>Vendor Spotlight: <a href="https://www.spectrum.security/">Spectrum Security</a></h2><p>First platform tackling the agentic detection engineering problem. Details on how they approach the TI &gt; Threat Model &gt; Coverage &gt; Risk workflow, their coverage mapping capabilities, and how they connect threat intelligence to actionable detection suggestions based on your actual environment and log sources.</p><p><a href="https://www.spectrum.security/">Spectrum Security </a>is tackling the part of the problem most of the market has worked around for years: detection itself.</p><p>While much of the industry focused on collecting more data, shipping more content, or accelerating triage, Spectrum starts from a more fundamental question: <strong>can you actually detect the threats that matter in your environment right now?</strong> That is the question their platform is built to answer.</p><p>The company&#8217;s thesis is that security teams do not suffer from a lack of telemetry. They suffer from inability to detect threats through all the telemetry - it&#8217;s like searching for a needle in a haystack. More logs do not automatically create coverage. More detections do not automatically reduce exposure. It&#8217;s about the need to have the right detections needed for your environment, and ensuring they remain effective as threats evolve and environments change. static dashboards or ATT&amp;CK heat maps do not provide continuous confidence in a changing environment.</p><p>Spectrum is building around that gap.</p><p>Their approach connects the pieces security teams have historically managed in separate systems and spreadsheets: measuring and reporting on current coverage ,threat intelligence, threat relevance, telemetry availability, detection logic, detection authoring, and ongoing validation. In practice, that means taking threat information and mapping it to the customer&#8217;s real environment, understanding what data is actually available, identifying what is detectable versus what is not, and turning that into accurate detections, ensuring that they remain valid and tying this to measurable coverage outcomes. This is meant to replace manually-heavy detection engineering that struggles to keep pace, with something more continuous, contextual, and provable.</p><p>What makes the vision interesting is that Spectrum is not describing detection as a one-time engineering project. It is describing it as a living system. Environments change. Telemetry shifts. Threats evolve. Detection logic drifts. So the real problem is not just creating detections, but continuously knowing whether they still work, where gaps have opened, and what matters to fix next. That is the layer Spectrum&#8230;</p><p>If the first wave of AI in security helped analysts move faster once alerts that already existed, Spectrum is betting the more important shift is upstream: helping teams know what they should detect, what they can detect, and how to close the gap between the two</p><h2>Final Thoughts</h2><p>We spent the last two years optimizing the middle of the IR cycle. Investigation and triage are faster than ever. That's good progress. But faster triage doesn't fix bad detections. It just processes them quicker.</p><p>The shift left into detection engineering is where the real value is. Not because it's easy. It's actually the hardest part. But because everything downstream depends on it. Your AI SOC, your response automation, your coverage, your risk posture. All of it starts with whether you're detecting the right things in the first place.</p><p>Fix the input. The output takes care of itself.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Why AI Won't Replace the Human Who Owns the Risk in Security Operations]]></title><description><![CDATA[Explore why AI won't replace human accountability in security operations and discover the critical role of the "accountability anchor" in effective risk]]></description><link>https://blog.secops-unpacked.ai/p/why-ai-won-t-replace-the-human-who-owns-the-risk-in-security-operations</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/why-ai-won-t-replace-the-human-who-owns-the-risk-in-security-operations</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 02 Apr 2026 15:23:41 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/228b1687-6778-4a09-a6da-f612ba2a9c29_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><h1>Who Signs Off? AI, The Accountability Anchor and the "Basic" Problem</h1><p><strong>You have two choices: you either surf the AI wave, or you get caught under it. Surfacing is possible, but the landscape will be unrecognizable.</strong></p><p>The current "AI freak-out" isn't actually about Large Language Models (LLMs) becoming sentient. It&#8217;s about the displacement of <strong>agency</strong>. We are moving from a world where humans make every granular call to a delegated model where the <strong>Accountability Anchor</strong> is the only thing keeping the ship from drifting away. We&#8217;ve seen these waves before-from the Luddites smashing looms in 1810 to the SOAR hype that promised the "death of the SOC" a few years ago.</p><p>But this time, the wave is massive, powered by a projected $2.52 trillion in global spending by 2026. If we don't build a floor to elevate the workforce, we risk installing a ceiling of obsolescence similar to the "Basic Assistance" trap on Earth in <em>The Expanse</em> series.</p><h2>The ROI Reality Check: Why the Wave is Rising</h2><p>Businesses aren't adopting AI because they love the technology; they are doing it because they have to prove value through operational cost reduction and profit maximization. While some companies will take out humans from their jobs just to show a reduction in costs, the smart ones see it as a performance multiplier.</p><p>But the threat landscape isn't waiting for anyone to figure out their AI strategy. According to <strong>Mandiant's M-Trends 2026 report</strong>, based on over 500,000 hours of incident response engagements:</p><ul><li><p><strong>Speed kills, literally:</strong> The median time between an initial access partner breaching an environment and handing off access to a secondary threat group (often ransomware operators) has collapsed to 22 seconds in 2025. Down from over 8 hours in 2022. That's not a typo. Alerts traditionally considered "lower priority" can become full-blown ransomware incidents before a human finishes reading the ticket.</p></li><li><p><strong>Dwell time is climbing, not shrinking:</strong> Global median dwell time rose to 14 days (from 11 in 2024), driven by espionage operations and DPRK IT worker campaigns averaging 122 days of undetected presence. The idea that we're getting better at detection across the board doesn't hold up when state-sponsored actors are living in your environment for four months.</p></li><li><p><strong>Recovery is the new target</strong>: Ransomware operators have shifted their primary objective from data theft to deliberate recovery denial, systematically destroying backup infrastructure, identity services, and virtualization management planes. They're not just encrypting your data. They're making sure you can't get it back without paying.</p></li><li><p><strong>The spending follows the pain:</strong> Average monthly AI budgets are jumping from $62,964 in 2024 to an estimated $85,521 in 2025, a 36% increase. Organizations using AI-powered security platforms report identifying breaches significantly faster and reducing average breach costs by roughly 43%.</p></li></ul><p>When the hand-off from initial access to ransomware deployment happens in 22 seconds, no human is reviewing that alert in time. Defenders are forced to automate just to stay in the game.</p><h2>The Accountability Anchor: Why Humans Still Own the Risk</h2><p>In the short to medium term, security jobs are anchored by the legal and ethical need for a human to "sign off." Even as we automate the labor of investigation, the Accountability Anchor ensures that responsibility doesn't vanish into a "black box" where no individual bears the consequences of a failure.</p><p>Without human oversight, purely automated decisions can create "accountability vacuums." In high-risk environments like cybersecurity, technology excels at velocity and pattern detection, but it lacks the human capacity for context and consequence.</p><h3>The Circuit Breaker Problem</h3><p>The industry has been selling Human-in-the-Loop (HITL) as the safety mechanism that keeps AI in check. The idea is simple: define where the algorithm's authority ends and human discretion begins, force the system to pause at critical moments, hand control to a person who can navigate ambiguity. In theory, this acts as a "circuit breaker."</p><p>In practice? The circuit breaker is mostly decorative.</p><p>Anthropic recently published data on how users interact with Claude Code permission prompts. The numbers are hard to ignore: 93% of permission prompts get approved, and Anthropic themselves describe this as "approval fatigue, where people stop paying close attention to what they're approving." New users with fewer than 50 sessions auto-approve about 20% of the time. By 750 sessions, that number climbs past 40%.</p><p>This isn't unique to coding agents. It's a pattern anyone who has worked in a SOC will recognize instantly. Alert fatigue. Approval fatigue. It's the same cognitive failure mode wearing different clothes. When you ask humans to approve hundreds of actions per day, they stop reading and start clicking.</p><p>And the threat landscape is evolving specifically to exploit this gap. M-Trends 2026 shows voice phishing (vishing) jumped to the second most common initial infection vector at 11%, while traditional email phishing dropped to 6%. Attackers aren't sending bulk emails anymore. They're calling people, building rapport in real-time, and exploiting the human tendency to trust a live conversation. The initial infection vectors are getting more human-targeted at the exact moment we're asking humans to be the safety control for AI systems.</p><p>The data also reveals something more nuanced than "nobody pays attention." Experienced users don't just approve more; they also interrupt more often. New users review each action upfront and rarely intervene (about 5% of turns). Experienced users let the agent run and step in when something goes wrong (about 9% of turns). This is a deliberate shift from proactive per-action review to reactive monitoring and intervention.</p><p>This distinction matters. Per-action approval is not a security control. It's a ritual. The real oversight is happening when experienced operators watch the system's behavior, recognize drift, and pull the emergency brake at the right moment. That is the actual circuit breaker, and it looks nothing like a "click approve" dialog.</p><h3>When the Anchor Becomes a Rubber Stamp</h3><p>Here's the uncomfortable question: if the person who is supposed to "sign off" is approving 93% of the time without meaningful review, do you still have accountability? Or do you have compliance theater?</p><p>Anthropic's own incident log provides a clear answer. Real-world agentic misbehaviors they've documented include agents deleting remote git branches from vague instructions, uploading an engineer's GitHub authentication token to an internal compute cluster, and attempting migrations against a production database. These are not hypothetical "what if" scenarios. These are things that happened because an agent acted and a human either wasn't watching or clicked "approve" without reading.</p><p>The honest answer is that accountability needs to evolve. It can't live at the per-decision approval layer because that layer is broken at scale. The Accountability Anchor needs to move up the stack: the person who answers to the board or the regulator isn't clicking "approve" on every alert closure. They are accountable for ensuring the automation is trustworthy, bounded, and auditable. They own the system design, the guardrails, and the audit trail. Not the individual clicks.</p><p>This means building hard boundaries into infrastructure: explicit trust boundaries, tool permissions, action constraints at the architecture level. What environments can the agent access? What actions can it take? What data can it touch? These decisions should be baked into the agent's configuration and enforced programmatically, not left to runtime approval prompts that data shows will get rubber-stamped the vast majority of the time.</p><p>M-Trends 2026 reinforces this point from the attacker's side. Ransomware operators are now systematically targeting backup infrastructure, identity services, and virtualization management planes before deploying ransomware. They're not just encrypting your production environment; they're destroying your ability to recover. If your "accountability" layer is a human clicking approve on alert closures, you've already lost. The guardrails need to be baked into the architecture itself: immutable backups, identity isolation, hardened recovery paths. The same principle applies to AI agent governance. Don't rely on the human click. Build the boundaries into the system.</p><h3>The Responsibility Map</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2XiK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2XiK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 424w, https://substackcdn.com/image/fetch/$s_!2XiK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 848w, https://substackcdn.com/image/fetch/$s_!2XiK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 1272w, https://substackcdn.com/image/fetch/$s_!2XiK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2XiK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png" width="1858" height="424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:424,&quot;width&quot;:1858,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78027,&quot;alt&quot;:&quot;Table: Framework | Core Requirement | Why a Human Stays&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Framework | Core Requirement | Why a Human Stays" title="Table: Framework | Core Requirement | Why a Human Stays" srcset="https://substackcdn.com/image/fetch/$s_!2XiK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 424w, https://substackcdn.com/image/fetch/$s_!2XiK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 848w, https://substackcdn.com/image/fetch/$s_!2XiK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 1272w, https://substackcdn.com/image/fetch/$s_!2XiK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ecfc36a-20f8-4e49-9c7e-dd6606ae3192_1858x424.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The real gap isn't technology. It's the accountability layer. You can automate the triage, but you cannot automate the person who answers to the board or the regulator when things go wrong. What you can (and should) automate is everything below that person's decision threshold, with guardrails that actually work instead of approval prompts that don't.</p><h2>ARMM: Evolving Beyond the "Vibe Check"</h2><p>To move beyond "vibe adoption," we need a maturity model. The <strong>AI Response Maturity Model (ARMM)</strong>, developed by <strong>Andrei Cotaie</strong>, <strong>Cristian Valeriu Miron</strong>, and <strong>Filip Stojkovski</strong>, provides that path.</p><p>Maturity isn't just about having an AI; it's about scoring it on three axes:</p><ol><li><p><strong>Trust:</strong> Do you trust the output enough to let it act?</p></li><li><p><strong>Complexity:</strong> Can your team actually maintain this model?</p></li><li><p><strong>Impact:</strong> What is the "blast radius" if the AI fails?</p></li></ol><p>What's interesting is that Anthropic's behavioral data validates this progression in the wild. Users naturally move through ARMM levels as they gain experience:</p><ul><li><p>At <strong>Level 2 (AI Assistance)</strong>, the bot suggests and the human approves every action. This is where new users start, reviewing each step before execution.</p></li><li><p>At <strong>Level 3 (AI Collaboration)</strong>, the human shifts to monitoring and intervention. This maps directly to what Anthropic observed: experienced users let the agent run autonomously and interrupt when something drifts.</p></li><li><p>At <strong>Level 4 (AI Delegation)</strong>, specialized agents act independently within defined bounds. This is where hard boundaries, deterministic controls, and infrastructure-level guardrails become non-negotiable, because the human is no longer in the per-action loop at all.</p></li></ul><p>The ARMM model helps us <strong>evolve</strong> roles rather than delete them. But it also forces an honest conversation: if you're claiming to operate at Level 2 while your users are behaviorally operating at Level 3 or 4 (approving everything, monitoring from a distance), you have a maturity gap disguised as a process. Fix the process to match reality, or reality will fix it for you.</p><h2>The "I, Robot" Shift: When AI Gets a Body</h2><p>The true long-term impact on the job market isn't just driven by code, but by the "Physical Turn" the convergence of AI and humanoid robotics. This is where the <em>I, Robot</em> vibe becomes a business reality.</p><ul><li><p><strong>The Scale:</strong> Experts project there could be over <strong>1 billion humanoids</strong> on Earth by 2050 to offset global labor shortages.</p></li><li><p><strong>The Price Tag:</strong> While a humanoid cost $200,000 in 2024, costs are expected to drop to <strong>$13,000&#8211;$20,000</strong> by the early 2030s.</p></li><li><p><strong>The Tech:</strong> Breakthroughs in "Vision-Language-Action" (VLA) models allow these machines to learn and adapt to unstructured human environments rather than just following a script.</p></li></ul><p>While this sounds like science fiction, it raises the accountability bar to its highest level. A hallucinating chatbot writes a bad email; a hallucinating humanoid has a real-world "blast radius."</p><h2>The Expanse Metaphor: Floors vs. Ceilings</h2><p>In the series <em>The Expanse</em>, Earth has a population of 30 billion, but only half have jobs. The rest live on "Basic Assistance" -free food, free housing, and recycled paper clothes, but <strong>zero money</strong> and <strong>zero opportunity</strong>.</p><p>"Basic" isn't a floor; it's a <strong>ceiling</strong>. It&#8217;s a way to manage a population rendered "obsolete" by automation. As we evolve roles like the Tier 1 SOC analyst, we must ensure we aren't removing the "stepping stones" for new talent. If we automate the path to expertise, we end up with a future of job scarcity where only the "proven" get to work.</p><p>We must decide if AI will be used to lift everyone above a "poverty floor" through Universal Basic Income (UBI), or if it will be used to construct a "Basic" ceiling that traps the majority of the population in a state of manufactured scarcity.</p><h2>Leveling Up: Your Career Anchors</h2><p>The Tier 1 SOC analyst role isn't disappearing. It's leveling up. The manual grunt work of copying and pasting IPs is being replaced by strategic roles. And the data supports the shift: M-Trends 2026 shows 52% of compromises are now detected internally (up from 43% in 2024), which means organizations investing in detection capability and internal tooling are seeing results. The roles driving that improvement:</p><ul><li><p>Detection Engineer: Designing the behavior-based models that the AI runs.</p></li><li><p>AI Validation Specialist: The person who "validates the autopilot" before the plane takes off.</p></li><li><p>Governance Officer: Owning the accountability layer between the silicon and the board.</p></li></ul><p>The three of us all started in the trenches of the SOC. We aren't there now because we evolved with the technology, and the industry is doing the same.</p><p><strong>The real question isn't whether AI will take your job-it's whether you'll be the person who owns the risk when it does. But until then, let us thank the heavens for accountability.</strong></p><div><hr></div><p><em>We apologize if this felt like a mission briefing for the Rocinante, but Andrei Cotaie is a massive fan of The Expanse and we couldn't stop him from geeking out over the "Basic" problem.</em><br><br><strong>Sources and Further Reading</strong></p><ul><li><p>Anthropic, "Measuring AI Agent Autonomy in Practice" (2026). The research behind the 93% approval rate, behavioral patterns of experienced vs. new users, and the shift from per-action approval to monitoring-and-intervention.</p></li><li><p>Mandiant / Google Threat Intelligence Group, "M-Trends 2026" (2026). Based on 500,000+ hours of incident response engagements in 2025. Source for the 22-second hand-off metric, 14-day global median dwell time, vishing as #2 infection vector, recovery denial trends, and 52% internal detection rate.</p></li><li><p>Chris Hughes, "<a href="https://www.resilientcyber.io/p/the-human-in-the-loop-illusion">The Human-in-the-Loop Illusion,</a>" Resilient Cyber (2026). A complementary analysis of the HITL problem and Auto Mode implications, including Simon Willison's critique on non-deterministic AI safety controls and the UK AISI data on agentic tool growth.</p></li></ul><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[RSAC 2026: Predictions Validated, AI SOC Is Now a Feature, and the Adoption Mess Continues]]></title><description><![CDATA[Explore RSAC 2026 insights: AI SOC becomes mainstream, adoption challenges emerge, and vendor perspectives reshape security operations strategy.]]></description><link>https://blog.secops-unpacked.ai/p/rsac-2026-secops-summery</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/rsac-2026-secops-summery</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Mon, 30 Mar 2026 12:34:45 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/34fb1fdf-3a8a-447b-8b45-75bc07e07979_1536x2752.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><h1>Back from RSAC, still jet lagged. But I need to get this out while the thoughts are fresh.</h1><p>I have been going to RSAC for years as a practitioner. This year I went as both practitioner and vendor. That changes everything. Running a booth, doing over 20 demos, having 50+ conversations just around the booth. To speak as a vendor I needed to reverse engineer what I was doing as a practitioner, what I wanted to hear, how things needed to be explained so they resonate with everyone. Seeing the conference from both sides gave me a perspective I did not have before, and I think it made this one of the best RSACs I have attended.</p><p>More about the vendor experience in a dedicated blog on BlinkOps. Here I want to share from the practitioner lens. What I saw, what got validated, and what the industry is still getting wrong.</p><h2>The Conference Itself</h2><p>The quality of talks this year was solid. I have not been on the talk tracks since 2020 when I gave a talk on Intelligent Threat Intel: Lead Framework, so it was good to be back in the sessions.</p><p>My favorite was <a href="https://www.linkedin.com/in/chuvakin/">Anton Chuvakin's</a> <a href="https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755810908971001uwQE">STR-W08: Shadow Agents: A Pragmatist's Guide to Governing Unsanctioned AI</a>. It triggered some thoughts on how to build better governance around agents. I already drafted a high level design and will release it soon. What made it even better is that some of the things we built at <a href="https://www.blinkops.com/">BlinkOps</a> are aligned with how you can actually do better governance for agents and how you can organize them more efficiently.</p><p>Beyond the talks, I had a ton of meetings and caught up with a lot of peers. Amazing conversations, great ideas exchanged.</p><h2>The Uncomfortable Truth About AI Adoption</h2><p>One theme came up over and over in those conversations. In the past we were able to build tech and say with confidence this is the future and it will be used in the next 3-5 years. Now it is hard to predict how the tech will look in 1 year, all due to the pace of developments around AI and agents.</p><p>But here is the interesting part. Not many are at the stage where they implement it at scale. The majority are using AI mainly around copilots. Agentic implementations are still early days and getting traction only between early adopters.</p><p>The main issue persists: adoption is messy. It is like we learned nothing from moving from on-prem to the cloud.</p><h2>A Quick Note on Booth Culture</h2><p>I will keep this short because I could rant. As usual the floor was full of shiny distracting booths that make you feel like you are in a theme park. If I can't understand what you are selling from a single sentence at the booth, for me that is a no-go. Your booth can have the most awesome visuals and bring cool attractions, but if the messaging is lost then what is the point.</p><p>Interesting enough, the smaller booths had better messaging than the large ones. Many of the big ones would just display the vendor name with no context(this works for large well known brands). If I was not stopping to get scanned and watch a demo I had no idea what their product does. That tells me they are not aware of their own brand awareness gap.</p><h2>AI SOC Is Not a Product, It Is a Feature</h2><p>This is probably my hottest take from the show, so let me just say it clearly.</p><p><strong>AI SOC or Agentic SOC is not a product. It is a feature.</strong></p><p>What I saw on the floor is that AI SOC has become a core functionality embedded in many platforms. Almost every SIEM (if not every) now has some form of AI SOC capability. Some are better than others, some are more of a checkbox exercise. But the autonomous triage and base analysis that was initially pitched as a standalone product category is becoming just another feature layer.</p><p>On top of that, SIEM vendors all started adding the response (SOAR) piece as well. Elastic for instance announced their Automation capability.</p><p>What I heard asked quite often around AI SOC was: How can you give feedback? How does it learn from past experience? Can it be customized? And what else beyond triage can it do?</p><p>Those are the right questions. And the vendors that can answer them well will be the ones that survive the consolidation wave.</p><h2>Where Most AI SOC Vendors Are Falling Short: Response</h2><p>Now here is where it gets real. The area where I see most AI SOC vendors struggle is response.</p><p>Getting a UI where you can build automations is not going to cut it. And doing the lazy route of saying you can connect to MCP and call it a response layer is not going to cut it either. MCP is a protocol not a response strategy.</p><p>To do response properly you need a solid integration layer with deep connections into the tools your SOC actually uses. You need orchestration logic, error handling, feedback loops, and many other components that make the difference between a demo and a production deployment. And yes, to be truly functional in this space you need to be able to build agents. Not just use them, build them. That is where the real differentiation lives.</p><p>Triage is getting commoditized. Response is where the hard problems are. And most vendors are not there yet.</p><h2>Predictions Validated</h2><p>For me RSAC was also a validation moment. Seeing my predictions play out on the floor is a testament that the analysis work we do at SecOps Unpacked holds up.</p><p><strong>Prediction 1: AI SOC becomes a feature.</strong> Covered above. It is happening across the board.</p><p><strong>Prediction 2: AI SOC acquisitions start this year.</strong> Not one but two happened already. Culminate was acquired by Datadog. <a href="https://www.rapid7.com/about/press-releases/rapid7-acquires-kenzo-security-to-accelerate-preemptive-ai-powered-security-operations/">Kenzo Security was acquired by Rapid7</a>. More will come. My bet is we will see at least 5 AI SOC vendors acquired this year.</p><p><strong>Prediction 3: AI SOC vendors shift towards MDR or detection engineering.</strong> And that is exactly what is happening. The ones that don't go the MDR route are pivoting towards detection engineering. Two clear lanes forming.</p><h2>Shadow IT and Shadow AI Are Not Going Away</h2><p>Another topic that persisted through RSAC was Shadow IT and Shadow AI. I think the vendors that will have the most success going forward will be platforms that can govern both shadow IT and shadow AI. The components needed are identities combined with MDM, SSE, ZTNA, and DLP. That is a lot of tech converging in one place, and it probably deserves its own in-depth blog.</p><h2>Cool Tech Worth Watching</h2><p>I want to give credit to some teams building impressive things that caught my attention during the show.</p><p><strong><a href="https://www.spectrum.security/">Spectrum Security</a></strong> - Finally had a chance to meet with the founding team, Dylan and John Meny. What they are building is super cool and I think it is the kind of tech that could reinvent how we do threat detection.</p><p><strong><a href="https://www.above.security/">Above Security</a></strong> - Aviv and his team have some really interesting tech around insider risk. Huge potential there.</p><p><strong><a href="https://alphalevel.ai/">Alpha Level</a></strong><a href="https://alphalevel.ai/"> </a>- Joshua Neil and his team are building alert management done right. I really like their approach of combining ML and LLM in a smart way. I think this is how you build real IP around AI SOC.<br><br><strong><a href="https://tracebit.com/">Tracebit</a></strong> - Andy Smith and Sam Cox are building really cool deception technology platfrom.</p><p>And yes, for anything else you need BlinkOps. &#128512;</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Last Human in the Room]]></title><description><![CDATA[Explore why AI needs human expertise to thrive: Discover the real fears behind job displacement and what security teams should know about AI's future]]></description><link>https://blog.secops-unpacked.ai/p/the-last-human-in-the-room</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/the-last-human-in-the-room</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Tue, 17 Mar 2026 15:46:24 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/db4ae46a-ce35-45f9-8d5a-1985b60d5fb9_2048x2048.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>Note: This is Part 1 of two series around AI influence on the SecOps job market</p><h1>A Brief History of Freaking Out</h1><p>The Luddites smashed textile machines in the 1810s because they feared losing their livelihoods. Over 200 years later, we're having the same conversation. Not about looms, but about LLMs.</p><p>The fear isn't that somebody will replace you in an org chart. It's that the thing you trained for, the thing you're good at, the thing that pays your rent, the thing that is, ultimately, a part of you might become irrelevant.</p><p>When we started working in SOCs, a big part of the day was checking indicators across multiple databases. Copy an IP, paste it into five different platforms, check if something shows up, document the results. Repeat. If somebody asked us today whether that job should still exist, we'd all say no. It makes no sense doing that manually when integrations and automations handle it in seconds.</p><p>But here's where it gets personal. For us in 2026, losing relevance could mean losing income. The average millennial should expect to change careers five or six times. Some of us are already on that path. But the question is whether we'll be switching by choice or because the tech forced our hand.</p><p>This question got a lot more real a few weeks ago when Block (the company behind Square and Cash App) cut 40% of its workforce, over 4,000 people. CEO Jack Dorsey said straight up that "intelligence tools have changed what it means to build and run a company" and predicted most companies would follow within a year. Investors loved it. The stock jumped 22%. For the people who lost their jobs, less exciting.</p><p>Now, whether Block's move was truly AI-driven or just pandemic overhiring correction with an AI narrative (there's strong evidence for both), the signal it sent was loud. And it made a lot of people in our industry nervous.</p><p>So the question that needs asking: will the jobs that currently define us become irrelevant? Will our industry reinvent itself? Will we survive this wave the same way we survived SOAR's promise that "the SOC is dead"?</p><p>We think the answer is more optimistic than the anxiety suggests, but it comes with some conditions.</p><h2>The Short Answer</h2><p>Yes, we will survive this wave.</p><p>Why? We'll walk through three arguments and stress-test each one. Some of this thinking was shaped by a talk at Apres Cyber Slopes Summit that helped cut through the noise and get back grounded.</p><h2>Our Industry Is Different</h2><p>We know, we know. Every industry says this. Every person who ever worked a job says "nobody can automate MY job because of the unknowns I face every day." My job requires intuition. My job requires split-second decisions. A system can't do that.</p><p>All of those statements are simultaneously true and false. But security actually has something unique going for it: the offense-defense arms race.</p><p>Security was, is, and always will be guided by a simple philosophy: every new defense technology will ignite the spark to create a new weapon.</p><p>We're already at the point where both sides use AI. Defenders have AI SOC solutions that automate investigations, speed up detection, ingest new log sources, and discover anomalies. Attackers didn't waste any time either. Every step of the kill chain has been supercharged since LLMs took over. Script kiddies who couldn't do enough harm before are now targeting higher-value assets with better tooling.</p><p>Let's take this to the extreme. Say everybody builds a perfect AI SOC that detects everything from day one. What happens the next day? Somebody builds something that manipulates that system into believing their activity isn't worth alerting on. Even in the most automated scenario, somebody will constantly need to detect, train, and alert on new attack patterns. And someone on the other side will keep finding ways to avoid detection.</p><p>That cycle doesn't end. It hasn't ended in thousands of years of warfare, and it won't end because we have better chatbots.</p><h2>Organisational Resistance to Change</h2><p>The market will force change eventually. But can you imagine the entire population of CISOs saying "yes, please cut 50% of my headcount because AI handles it now"?</p><p>Think about what a CISO's leverage is within a company. It's partly about the team they lead. If your headcount drops from 50 to 5, your influence in the executive suite drops with it. No C-level wants that.</p><p>And this isn't just about office politics. It's about legal obligation. Which brings us to what we think is the strongest argument in this entire article.</p><h2>The Compliance Reality Check</h2><p>This is the argument we think most people are missing.</p><p>On one side, fear that AI replaces SOC analysts. On the other side, a reality check. Most security programs are compliance-driven. Many orgs invest in a SOC to pass an audit, not because they love detection engineering.</p><p>So what do the compliance frameworks actually require?</p><p>We looked at SOC 2, PCI DSS, HIPAA, ISO 27001, NIS2, DORA. Here's what we found:</p><p>None of them say humans must do the triage. None of them require a human staring at alerts 24/7. They want continuous monitoring, detection capability, incident response, and evidence. They don't care if the entity doing the work is carbon-based or silicon-based.</p><p>Where humans ARE explicitly required: breach notification decisions, risk ownership, audit attestation, governance accountability. NIS2 and DORA put personal liability on executives for security failures.</p><p>DORA is the most prescriptive framework out there. Even DORA does not mandate human staffing models. It mandates outcomes.</p><p>So the question is not "will AI take SOC jobs." The question is: <strong>who signs off that the AI is doing a good job?</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!It1b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!It1b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 424w, https://substackcdn.com/image/fetch/$s_!It1b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 848w, https://substackcdn.com/image/fetch/$s_!It1b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!It1b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!It1b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg" width="474" height="725" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:725,&quot;width&quot;:474,&quot;resizeWidth&quot;:474,&quot;bytes&quot;:113218,&quot;alt&quot;:&quot;amujut.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="amujut.jpg" title="amujut.jpg" srcset="https://substackcdn.com/image/fetch/$s_!It1b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 424w, https://substackcdn.com/image/fetch/$s_!It1b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 848w, https://substackcdn.com/image/fetch/$s_!It1b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!It1b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2d2896-018b-49f1-a13a-4817e9fffdcd_474x725.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That person needs to exist. They need to understand what the automation does. They need to own the risk when it breaks.</p><p>When Filip posted this analysis on LinkedIn, <a href="https://www.linkedin.com/in/chuvakin/">Anton Chuvakin </a>called it "quote of the day." And he's right, it IS a big deal. The frameworks already support AI-driven security operations. The real gap isn't technology or regulation. It's the accountability layer between the two.</p><h3>So What Roles Actually Emerge From This?</h3><p>The <a href="https://www.linkedin.com/posts/filipstojkovski_on-one-side-fear-that-ai-replaces-soc-analysts-activity-7437891671012327424-k2Pi?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAaBOzkBTc_ZR17eSbkwr81NBBX__ne2uJw">LinkedIn discussion</a> got interesting when <a href="https://www.linkedin.com/in/fry-rob-g/">Rob Fry</a> jumped in. His point: a lot of people talk about AI as though the vendor ships it, blesses it, and somehow keeps it tuned forever. That's not realistic.</p><p>Customer environments, data, workflows, risk tolerance, and operational weirdness are too specific. Vendors can provide the engine, but customers own the care and feeding. Which means you need people who can design, run, validate, and govern AI-driven security systems.</p><p>Rob described what he sees as likely new (or evolved) roles:</p><ul><li><p><strong>Architects</strong> to design how AI fits into the control plane</p></li><li><p><strong>Operators</strong> to monitor, tune, and maintain it in production</p></li><li><p><strong>Governance folks</strong> to own risk, evidence, and accountability when it fails</p></li><li><p><strong>Hybrid roles</strong> that sit at the seams between security, engineering, operations, and the business</p></li></ul><p>This lines up with what SACR's recent research on AI SOC and MDR shows. The market is splitting between orgs that can run AI platforms in-house (large enterprises augmenting internal teams) and those that outsource to AI-native MDR providers. Both paths need people. Different people than before, but people.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YmiP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YmiP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 424w, https://substackcdn.com/image/fetch/$s_!YmiP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 848w, https://substackcdn.com/image/fetch/$s_!YmiP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 1272w, https://substackcdn.com/image/fetch/$s_!YmiP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YmiP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png" width="5306" height="4209" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4209,&quot;width&quot;:5306,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2704611,&quot;alt&quot;:&quot;SecOps Roles.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="SecOps Roles.png" title="SecOps Roles.png" srcset="https://substackcdn.com/image/fetch/$s_!YmiP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 424w, https://substackcdn.com/image/fetch/$s_!YmiP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 848w, https://substackcdn.com/image/fetch/$s_!YmiP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 1272w, https://substackcdn.com/image/fetch/$s_!YmiP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eefdee5-8fcb-4561-8b9d-340b61bf54ef_5306x4209.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Will the SOC Analyst Become a QA Role?</h3><p>Will the SOC analyst role mainly be about QA, just putting the stamp that says "looks good"?</p><p>We think partially yes. Someone has to validate the AI's conclusions. But calling it QA undersells what's actually needed. It's more like the person who signs off on the autopilot before the plane takes off. You need to understand the system deeply enough to know when it's working and when it's about to fly into a mountain. The skill set changes. The responsibility doesn't shrink.</p><p>And remember how long it took governments to even define what a "data breach" means under GDPR? Now imagine them rewriting accountability laws for fully autonomous security operations. We're not even close to that conversation in most jurisdictions. The current trend is actually toward MORE regulations that require MORE people in different regions, not fewer.</p><h2>What If We're Wrong?</h2><p>Fair question. Let's steelman the scary scenarios.</p><p><strong>What if the arms race gets solved?</strong> Say we get several dozen AI SOC solutions that reach a maturity level where they integrate automatically, train themselves, and run continuous simulations that make any new attack detectable before it becomes real.</p><p>This is still sci-fi. It ignores the premise that human innovation and creativity haven't been replaced. The integration work alone is something we can't yet imagine at that scale. And the energy costs would be significant.</p><p><strong>What if organizations stop resisting?</strong> This one we think is actually the most likely to happen eventually. The market will chip away at resistance once the technology matures. But in such a scenario, it's not just security teams that shrink. Every vertical in an enterprise would be affected, leading to smaller companies across the board.</p><p>And that creates a Ford-type dilemma: if nobody is hiring, who buys the products we're making? The "we are building AI for AI" story doesn't solve this economic question.</p><p><strong>What if regulations change?</strong> Removing rules and regulations requiring human accountability in cybersecurity would be one part of a much larger systemic shift. If you want a historical parallel, look at Khrushchev trying to break down Soviet bureaucracy. Or Gorbachev, who arguably succeeded. Dark humor version: the operation was a success, the patient is dead. The USSR disappeared. Point being, forcefully simplifying complex regulatory systems tends to have consequences way beyond what you planned for.</p><p>And remember how long it took governments to define "data breach" under GDPR? If governments become efficient and rational enough to rewrite accountability laws across the board, the entire world would look fundamentally different. The chance of this happening in our industry alone would be a strange mathematical anomaly.</p><h2>The New Shape of Things</h2><p>If you've been following the secops-unpacked blog, you know we keep coming back to this: the Tier 1 SOC analyst role as we knew it is disappearing. And it should. It had the worst retention rates, the highest burnout, and it was never a real career destination. It was always a stepping stone.</p><p>But the roles replacing it are more interesting. Detection engineering. Security automation. AI validation and governance. These aren't downgrades. They're upgrades.</p><p>The three of us all started as SOC analysts. None of us do that job today. We all evolved because the industry evolved. The difference now is that the pace of that evolution is faster. But the pattern is the same: old roles get automated, new roles get created to manage and improve that automation.</p><h2>Closing Thoughts</h2><p>The world is changing fast. None of us know what the future holds.</p><p>But we do know this: scenarios where our industry faces massive unemployment exist. We just think they're highly unlikely within the next five to ten years.</p><p>If we reach a point where cybersecurity jobs are irrelevant in a decade, it means we've had such a massive shift in how society works that job security will be the least of our problems.</p><p>For anyone starting their career right now and wondering where to head: the compliance frameworks aren't going away. The accountability layer between AI and business outcomes isn't going away. The arms race between offense and defense isn't going away. Those are your career anchors.</p><p>The real question isn't whether AI will take your SOC job. It's whether you'll be the person who signs off that the AI is doing its job right. Position yourself for that, and you'll be fine.</p><p>What's your take? Where do you see the roles that AI can't replace in cybersecurity? What arguments do you have to say we won't be unemployed in five years? Drop a comment, we want to hear it.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[Why Faster Detection Created a Bigger Problem]]></title><description><![CDATA[Discover why faster threat detection paradoxically created more work: Explore 2025 SecOps trends and predictions on agentic automation's hidden costs.]]></description><link>https://blog.secops-unpacked.ai/p/why-faster-detection-created-a-bigger-problem</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/why-faster-detection-created-a-bigger-problem</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 12 Mar 2026 13:44:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/65eb2ef0-f3e0-4aa4-adef-c135522736cc_1939x1957.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>Alright, here it is. My yearly SecOps trends and predictions report.</p><p>Yes, I know it is March. The report was written in January. Life happened. If you want timely content, subscribe to a news outlet. If you want content that ages well, stick around.</p><p>Every year I try to make sense of where this industry actually is versus where vendors say it is. Last year I called out the AI copilot hype before everyone got tired of chatbots that summarize things but do nothing. This year I have good news and bad news.</p><p>Good news: AI finally started doing real work in 2025. The "AI Analyst" is no longer a slide deck fantasy.</p><p>Bad news: We automated the easy part. And somehow created more work for humans in the process.</p><p>Let me explain.</p><div><hr></div><h1>Where we stand</h1><p>MTTD improved dramatically. We got really good at finding things fast. MTTR? Still flat. We are still terrible at actually fixing things.</p><p>But here is the part that made me laugh (in a sad way): a new bottleneck emerged. <strong>Mean Time to Decision</strong>.</p><p>Before AI, a SOC processed 200 alerts daily and made maybe 50 meaningful decisions. Now AI surfaces 2,000 alerts, auto-closes 1,700, and escalates 300 requiring human judgment.</p><p>We tripled the decision load.</p><p>Congratulations. We made the SOC more efficient at generating work for humans.</p><h2>Why Everyone Started in the Middle</h2><p>The industry went straight for triage and investigation. Makes sense. It was the easy target. Analytically complex but operationally simple. No write access required. No change management tickets. No risk of breaking production. Just read data, make a verdict, move on.</p><p>Detection engineering? Buried in log pipelines, data normalization nightmares, and the eternal fight between coverage and alert volume.</p><p>Response? Blocked by API limitations, tribal knowledge nobody documented, and organizations that would rather accept breach risk than give AI systems write access to anything important.</p><p>So vendors went for the middle. Quick wins. Happy customers. Logos on the website.</p><p>2026 will test whether AI can shift left into detection, shift right into response, and actually reduce the human decision burden rather than just reorganize it.</p><h2>The SUDA Loop</h2><p>You know the OODA loop. Observe, Orient, Decide, Act. Military strategy stuff that consultants love to reference.</p><p>Security operations needs its own version: <strong>See-Understand-Decide-Act (SUDA)</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WMh3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WMh3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 424w, https://substackcdn.com/image/fetch/$s_!WMh3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 848w, https://substackcdn.com/image/fetch/$s_!WMh3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 1272w, https://substackcdn.com/image/fetch/$s_!WMh3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WMh3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png" width="626" height="1184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:1184,&quot;width&quot;:626,&quot;resizeWidth&quot;:626,&quot;bytes&quot;:491320,&quot;alt&quot;:&quot;Report graphic.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Report graphic.png" title="Report graphic.png" srcset="https://substackcdn.com/image/fetch/$s_!WMh3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 424w, https://substackcdn.com/image/fetch/$s_!WMh3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 848w, https://substackcdn.com/image/fetch/$s_!WMh3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 1272w, https://substackcdn.com/image/fetch/$s_!WMh3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56a03f-228e-4bdb-a03e-40436215ed2b_626x1184.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most 2025 solutions handled one or two stages. See and Understand. Or Understand and Decide. Rarely the full loop.</p><p>The platforms that win 2026 will close the entire loop. Point solutions that only serve one stage will get absorbed or left behind.</p><h2>AI SOC Is Not the Platform</h2><p>The industry fixated on AI SOC throughout 2025. Understandable. Alert fatigue is painful and visible. Easy to demo. Easy to measure.</p><p>But here is my take: AI SOC is one solution. It is not the platform.</p><p>The real opportunity is infrastructure that provides building blocks: agentic workflows, deterministic workflows, case management, analyst copilot, integration layer. Combine them to build any security solution your program needs.</p><p><strong>Agentic AI SOC.</strong> The use case everyone talks about.</p><p><strong>Agentic IAM/PAM.</strong> Access requests, privilege escalation, orphaned accounts. Identity workflows are still embarrassingly manual in 2026. Let that sink in.</p><p><strong>Cloud Security &amp; Vulnerability Management.</strong> Findings pile up faster than humans can prioritize. Most sit in dashboards aging like fine wine that nobody drinks.</p><p><strong>GRC Automation.</strong> Evidence collection, control monitoring, audit prep. The work nobody wants to do, done by systems that do not complain.</p><p><strong>Detection Engineering.</strong> Threat intel in, detection rules out, coverage gaps identified, feedback loops closed. The dream we have been chasing for years.</p><p><strong>Threat Hunting.</strong> Continuous hunts based on intelligence and baselines. Not sporadic efforts when someone has time between incidents.</p><p>Same platform. Different solutions. Built once, deployed many times.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w6LZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w6LZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 424w, https://substackcdn.com/image/fetch/$s_!w6LZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 848w, https://substackcdn.com/image/fetch/$s_!w6LZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 1272w, https://substackcdn.com/image/fetch/$s_!w6LZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w6LZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png" width="944" height="759" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:759,&quot;width&quot;:944,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:363270,&quot;alt&quot;:&quot;Report graphic (1).png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Report graphic (1).png" title="Report graphic (1).png" srcset="https://substackcdn.com/image/fetch/$s_!w6LZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 424w, https://substackcdn.com/image/fetch/$s_!w6LZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 848w, https://substackcdn.com/image/fetch/$s_!w6LZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 1272w, https://substackcdn.com/image/fetch/$s_!w6LZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81125f80-f89f-4e90-b4f9-75bc67b18716_944x759.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The Honest Take</h2><p>Most 2025 AI SOC investment automated the easy part. Organizations declared victory after deploying AI triage, then discovered faster alert closure but the same remediation backlog. Often more decisions queued for human review than before.</p><p>Real maturity requires fixing detections, closing the response gap, and making feedback loops actually work. Not just closing alerts faster.</p><h2>Get the Full Report</h2><p>This post is the highlight reel. The full report goes deeper:</p><ul><li><p>The SecOps AI Shift Map framework for evaluating where AI actually operates</p></li><li><p>2025 landscape analysis across detection, triage, XDR, and automation layers</p></li><li><p>The Workflow Gravity thesis and why it matters more than Data Gravity</p></li><li><p>Platform building blocks and how to construct solutions beyond AI SOC</p></li><li><p>What this means for security teams, roles, and build-vs-buy decisions</p></li></ul><p><strong>[<a href="https://go.blinkops.com/secops-report?utm_campaign=39173987-cntnt-report-SecOpsTrends&amp;utm_source=refferal-filip">Download: The SecOps Decision Gap - 2025 Trends &amp; 2026 Outlook &#8594;</a>]</strong></p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[We built a framework to score AI SOC response capabilities]]></title><description><![CDATA[Decode the AI SOC credibility maze: Explore our groundbreaking framework for scoring AI response capabilities and cutting through vendor marketing hype to]]></description><link>https://blog.secops-unpacked.ai/p/ai-response-maturity-model</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/ai-response-maturity-model</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Thu, 19 Feb 2026 15:19:02 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/827592d1-dd07-41aa-b35c-2c90a22153e4_3540x2006.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><h1>1. Introduction</h1><p>The AI SOC market is growing fast and there are products on it that are doing serious work. Some of them have strong integration capabilities, solid reasoning engines, and response actions that actually execute in production. The market has come a long way in four years.</p><p>But there is a problem with how we evaluate these products.</p><p>When every vendor says "AI-powered response," that phrase covers everything from a fully autonomous isolation workflow to a chatbot that suggests you maybe think about resetting a password. Both get the same label in the marketing material. Both show up in the same analyst reports. And when a security team sits down to compare three products, they have no standardized way to measure the gap between "our AI handles response" and what that actually means in operational terms.</p><p>Some products are close to real autonomy in specific domains. Some are strong in analysis but thin on execution. Some have broad coverage but almost nothing runs without human approval. These are all valid positions on a maturity spectrum. The problem is that there is no shared framework to place them on that spectrum consistently.</p><p>So we built one.</p><p>We call it ARMM. And yes, the name is intentional.</p><p>A decade ago, the SOAR generation solved half the problem. We built the arms. Playbooks, integrations, automated response workflows. The execution layer was there. What was missing was the brain. Every decision tree was hand-coded. Every branching logic was written by an engineer who had to anticipate every possible scenario. The arms moved, but only along rails that humans laid down manually. When the scenario deviated from the playbook, the arm froze.</p><p>Now the AI SOC generation has solved the other half. We built the brain. LLMs reason across alerts, correlate context, analyze logs, and make judgment calls that no static playbook could replicate. But somewhere along the way, a lot of products forgot to attach the arms. The reasoning is strong. The analysis is sharp. And then it hands you a summary and says "here is what you should probably do." The brain thinks. The arm does not move.</p><p>ARMM evaluates both. The reasoning quality, the decision-making maturity, the trust you can place in the AI's judgment. And the response capability, the execution depth, the ability to actually take action without three humans supervising. It weighs the arm heavier because that is where the industry gap is widest right now. But it does not ignore the brain, because an arm without a brain is just a SOAR playbook and we already know how that story ended.</p><p>ARMM is a structured scoring system for evaluating what an AI SOC solution can actually do in the response layer. It covers 80+ response capabilities across six domains: Identity, Network, Endpoint, Cloud, SaaS, and General Options. And it provides a common language so that when someone says "we handle response," there is a way to ask: at what level, across how many actions, and with what degree of autonomy?</p><p>The CyberSec Automation Blog has published over a dozen articles and podcast episodes covering what makes a good automation program succeed, how to evaluate tools, and how to structure decision-making around security automation purchases. We have built tool comparison lists, evaluation checklists, and decision frameworks. ARMM is the next step in that work.</p><h1>2. Why Another Framework</h1><p>Most existing evaluation methods for AI SOC solutions are either vendor-produced (and therefore biased toward their own capabilities) or too generic to capture the specific nuances of AI-driven response. Analyst reports compare products at a feature-list level without measuring automation depth. Vendor demos show best-case scenarios without exposing the operational friction underneath.</p><p>Our focus is narrow and deliberate: response capabilities. Most AI SOC solutions already deliver strong reporting and analysis features. They can summarize alerts, correlate indicators, and reduce false negatives in a mature environment (we emphasize mature because these solutions need access to quality logs and, in more advanced implementations, to organizational documentation and environment-specific context). Where the industry needs structured evaluation is in the response layer: the actions an AI SOC solution can take, how autonomously it can take them, and under what conditions.</p><p>We acknowledge that some of the capabilities listed in this framework may seem aspirational at this stage. That is by design. The framework is intended to serve both as a current-state evaluation tool and as a forward-looking roadmap.</p><p>We are not scoring specific vendors. The goal is to establish a shared methodology that allows security teams to answer questions such as:</p><ul><li><p>Which solution provides more relevant response capabilities for my environment?</p></li><li><p>Which solution operates at a higher level of autonomy for the actions that matter to my program?</p></li><li><p>Which solution can help me reduce my alert backlog without requiring additional headcount?</p></li></ul><p>For product managers working on AI SOC products, the framework serves as a competitive analysis baseline:</p><ul><li><p>Where is my competition positioned, and what capabilities are driving their wins?</p></li><li><p>What high-value capabilities are underserved across the market?</p></li><li><p>Am I investing engineering resources in features that security practitioners actually prioritize?</p></li></ul><p>Because this is a fast-moving space, we are starting at version 0.1. This is a living document. Version 1.0 will be designated when the framework reaches a level of stability and community validation that warrants it.</p><h1>3. Scoring Methodology</h1><p>ARMM supports two distinct approaches to scoring, each designed for a different operational question.</p><p><strong>Evaluator Mode </strong>is the straightforward path. You score each capability on the 0-1-2 scale described above (with the 1C, 1G, 1A sub-levels) and the framework calculates your coverage rate, automation depth, and per-plane breakdown. The tier placements come from ARMM's reference tables. You do not need to factor in your organizational context. This mode answers one question: given two or more AI SOC products, which one covers more of what I need and at what automation level? It is built for procurement teams, SOC managers running vendor evaluations, and anyone who needs a side-by-side comparison without spending weeks on it.</p><p><strong>Builder Mode </strong>adds a second scoring layer on top. Instead of relying on fixed reference tiers, you score each action across three axes: Trust (how much confidence does your implementation warrant), Complexity (how hard is it for your specific team to build and maintain), and Impact (what is the blast radius if something goes wrong). The action score becomes T + C + I, and the tier placement shifts based on your organizational reality. The same action that scores Entry for a mature team with established automation pipelines might score Explorer for a team that is deploying its first AI SOC integration. This mode answers a different question: given my team, my environment, and my risk tolerance, where should I invest engineering effort to move up the maturity ladder? It is built for product managers, engineering leads, and internal SOC teams running their own automation programs.</p><p>Both modes evaluate the same six planes and the same 80+ response capabilities. Both produce per-plane breakdowns and a composite maturity label. The difference is whether you want a product-level comparison (Evaluator) or an environment-aware implementation roadmap (Builder). The public ARMM app at <a href="https://armm.secops-unpacked.ai">armm.secops-unpacked.ai</a> supports both.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n50o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n50o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 424w, https://substackcdn.com/image/fetch/$s_!n50o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 848w, https://substackcdn.com/image/fetch/$s_!n50o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 1272w, https://substackcdn.com/image/fetch/$s_!n50o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n50o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png" width="1783" height="3090" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3090,&quot;width&quot;:1783,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5393998,&quot;alt&quot;:&quot;Evaluator.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Evaluator.png" title="Evaluator.png" srcset="https://substackcdn.com/image/fetch/$s_!n50o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 424w, https://substackcdn.com/image/fetch/$s_!n50o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 848w, https://substackcdn.com/image/fetch/$s_!n50o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 1272w, https://substackcdn.com/image/fetch/$s_!n50o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f5f914-aebf-4cd0-8114-0ee51040eeaf_1783x3090.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>3.1 The Capability Scoring System (0-1-2)</h2><p>Each response capability in the framework is scored on a three-level scale that measures the degree of automation available:</p><p><strong>0 (Not Available): </strong>The feature does not exist in the product. There is no mechanism, manual or automated, to perform this action through the AI SOC solution.</p><p><strong>1 (Available with Human Involvement): </strong>The feature exists but requires some form of human interaction before execution. Because human involvement can range from full collaboration to a simple approval click, this level is subdivided into three sub-categories:</p><ul><li><p>1C (Collaborator): The solution requires continuous back-and-forth interaction with an analyst to reach a response action. The AI acts as a partner, not an autonomous agent.</p></li><li><p>1G (Guide): The solution generates a plan and presents options for a specific action, but it is not confident in recommending a single path. It lays out alternatives and lets the analyst choose.</p></li><li><p>1A (Approver): The action is essentially ready to execute. The AI has determined the correct response and prepared the action, but requires a human to click approve before it fires. This is the closest step to full automation while still keeping a human in the loop.</p></li></ul><p><strong>2 (Fully Automated): </strong>The action is performed without any human involvement. The vendor (or internal implementation) has demonstrated that the AI SOC solution can execute this action with sufficient confidence that no human review is required. At the time of writing, level 2 is exceptionally rare for most response categories. The framework includes it to establish the target state and to differentiate products that are moving in that direction from those that are not.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZbbK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZbbK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 424w, https://substackcdn.com/image/fetch/$s_!ZbbK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 848w, https://substackcdn.com/image/fetch/$s_!ZbbK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 1272w, https://substackcdn.com/image/fetch/$s_!ZbbK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZbbK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png" width="3540" height="2006" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2006,&quot;width&quot;:3540,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6173589,&quot;alt&quot;:&quot;ARMM 1.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ARMM 1.png" title="ARMM 1.png" srcset="https://substackcdn.com/image/fetch/$s_!ZbbK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 424w, https://substackcdn.com/image/fetch/$s_!ZbbK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 848w, https://substackcdn.com/image/fetch/$s_!ZbbK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 1272w, https://substackcdn.com/image/fetch/$s_!ZbbK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff60732e6-4a9a-4b6e-a72c-150a3e2de215_3540x2006.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>3.2 The Three Scoring Axes (Builder Mode)</h2><p>In Builder Mode, each response action is evaluated across three dimensions:</p><h3>Axis 1: Decision Fidelity and Programmatic Trust (T)</h3><p>This axis measures the confidence level warranted by the AI SOC implementation. It correlates directly with implementation quality: reasoning log depth, context-aware decision-making, and guardrails against hallucination.</p><ul><li><p>T = 1 (Enrichment): AI output assists human-led investigations. The AI provides context and data but does not recommend or execute actions.</p></li><li><p>T = 2 (Validated): AI recommends a specific action. A human confirms before execution occurs.</p></li><li><p>T = 3 (Autonomous): AI executes without human intervention. This requires the highest level of implementation maturity and organizational trust.</p></li></ul><h3>Axis 2: Implementation and Maintenance Complexity (C)</h3><p>This axis evaluates the technical friction in building and sustaining the automation, relative to the skills and resources of the team responsible for it. This is deliberately team-dependent. An automation rated C = 3 for a junior team may be C = 2 for a team of specialized AI engineers with established CI/CD pipelines for their playbooks.</p><ul><li><p>C = 1 (Low): Simple API calls or native integrations with minimal configuration.</p></li><li><p>C = 2 (Medium): Multi-step orchestration across multiple systems requiring coordination and testing.</p></li><li><p>C = 3 (High): Complex behavioral baselining, legacy system integration, or custom model tuning.</p></li></ul><h3>Axis 3: Operational Impact and Blast Radius (I)</h3><p>This axis captures the business risk associated with the action. It is typically the most stable axis across organizations, but shifts based on asset criticality. Isolating a standard employee laptop has a different blast radius than isolating a production database server.</p><ul><li><p>I = 1 (Low): Negligible disruption. Background scans, tagging, enrichment activities.</p></li><li><p>I = 2 (Medium): Temporary disruption. Resetting a standard user session, blocking a non-critical port.</p></li><li><p>I = 3 (High): Significant downtime, data loss risk, or reputational damage. Production system changes, VIP account modifications, critical infrastructure alterations.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pOQ5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pOQ5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 424w, https://substackcdn.com/image/fetch/$s_!pOQ5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 848w, https://substackcdn.com/image/fetch/$s_!pOQ5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 1272w, https://substackcdn.com/image/fetch/$s_!pOQ5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pOQ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png" width="1713" height="2972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2972,&quot;width&quot;:1713,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5409464,&quot;alt&quot;:&quot;Builder.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Builder.png" title="Builder.png" srcset="https://substackcdn.com/image/fetch/$s_!pOQ5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 424w, https://substackcdn.com/image/fetch/$s_!pOQ5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 848w, https://substackcdn.com/image/fetch/$s_!pOQ5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 1272w, https://substackcdn.com/image/fetch/$s_!pOQ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a8a54b2-2a3b-4ade-a963-87b21bb0ef36_1713x2972.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>3.3 The Maturity Computation Logic</h2><p>The scoring system builds from individual actions up to a full program assessment through five layers. Each layer uses a defined formula.</p><h3>Layer 1: Action-Level Score (S)</h3><p>For a single response action, the score is the sum of its three axis values:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Aj4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Aj4I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 424w, https://substackcdn.com/image/fetch/$s_!Aj4I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 848w, https://substackcdn.com/image/fetch/$s_!Aj4I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 1272w, https://substackcdn.com/image/fetch/$s_!Aj4I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Aj4I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png" width="512" height="38" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:38,&quot;width&quot;:512,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:1092,&quot;alt&quot;:&quot;formula 3.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="formula 3.png" title="formula 3.png" srcset="https://substackcdn.com/image/fetch/$s_!Aj4I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 424w, https://substackcdn.com/image/fetch/$s_!Aj4I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 848w, https://substackcdn.com/image/fetch/$s_!Aj4I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 1272w, https://substackcdn.com/image/fetch/$s_!Aj4I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe37ba85e-0ce9-49e6-bd9d-97daac7f422e_512x38.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The minimum possible score is 3 (T=1, C=1, I=1). The maximum is 9 (T=3, C=3, I=3).</p><h3>Layer 2: Tier Mapping</h3><p>The action score maps to one of four maturity tiers:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e1mt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e1mt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 424w, https://substackcdn.com/image/fetch/$s_!e1mt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 848w, https://substackcdn.com/image/fetch/$s_!e1mt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 1272w, https://substackcdn.com/image/fetch/$s_!e1mt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e1mt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png" width="1696" height="424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:424,&quot;width&quot;:1696,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75378,&quot;alt&quot;:&quot;Table: Score Range | Tier | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Score Range | Tier | Description" title="Table: Score Range | Tier | Description" srcset="https://substackcdn.com/image/fetch/$s_!e1mt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 424w, https://substackcdn.com/image/fetch/$s_!e1mt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 848w, https://substackcdn.com/image/fetch/$s_!e1mt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 1272w, https://substackcdn.com/image/fetch/$s_!e1mt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdecb604-aa28-4eff-b4ad-ef5bace31068_1696x424.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Layer 3: Domain Maturity Score (D)</h3><p>The maturity score for a specific domain (e.g., Endpoint, Identity) is the arithmetic mean of all action scores within that domain:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mgfI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mgfI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 424w, https://substackcdn.com/image/fetch/$s_!mgfI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 848w, https://substackcdn.com/image/fetch/$s_!mgfI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 1272w, https://substackcdn.com/image/fetch/$s_!mgfI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mgfI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png" width="512" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:48,&quot;width&quot;:512,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:4260,&quot;alt&quot;:&quot;Formula 1.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Formula 1.png" title="Formula 1.png" srcset="https://substackcdn.com/image/fetch/$s_!mgfI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 424w, https://substackcdn.com/image/fetch/$s_!mgfI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 848w, https://substackcdn.com/image/fetch/$s_!mgfI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 1272w, https://substackcdn.com/image/fetch/$s_!mgfI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F798d2eaa-93df-41e4-b615-c894580bd1c5_512x48.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Where n is the number of scored actions in the domain. The resulting D value maps to a tier using the same thresholds from Layer 2.</p><h3>Layer 4: Program Maturity Score (P)</h3><p>The overall program score is the arithmetic mean of all domain scores, with equal weighting across all six planes:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e47r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e47r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 424w, https://substackcdn.com/image/fetch/$s_!e47r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 848w, https://substackcdn.com/image/fetch/$s_!e47r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 1272w, https://substackcdn.com/image/fetch/$s_!e47r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e47r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png" width="512" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:48,&quot;width&quot;:512,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:3818,&quot;alt&quot;:&quot;Formula 2.png&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Formula 2.png" title="Formula 2.png" srcset="https://substackcdn.com/image/fetch/$s_!e47r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 424w, https://substackcdn.com/image/fetch/$s_!e47r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 848w, https://substackcdn.com/image/fetch/$s_!e47r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 1272w, https://substackcdn.com/image/fetch/$s_!e47r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef74351-cf5b-4028-84cb-b51a2c81ce18_512x48.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Equal plane weighting is a deliberate design choice. It prevents planes with more actions (Endpoint has 22, SaaS has 10) from dominating the evaluation. Each plane contributes exactly one-sixth of the overall score.</p><h3>Layer 5: Composite Maturity Label</h3><p>The composite label is not derived from the program score directly. It uses sequential gating logic:</p><p>The composite label equals the highest tier where at least four out of six planes independently meet that tier's threshold, and the qualification chain is unbroken from Explorer upward. A product cannot be labeled Advanced if it has gaps at the Explorer tier.</p><p>The four-out-of-six rule is intentionally forgiving. A product focused on cloud-native environments may legitimately deprioritize network-level response. That should not disqualify it from a meaningful composite label. But it still needs breadth across most planes to earn a higher tier.</p><h2>3.4 Context-Aware Scoring: Why Environment Matters</h2><p>The ARMM recognizes that the maturity level of an automated action is not a static property of the feature itself. It is an emergent property of the environment where it is applied. The three axes (T, C, I) are all subject to organizational variance, which means the same product capability produces different scores in different contexts.</p><p><strong>Example: "Isolate Device" evaluated by three different organizations using the same AI SOC product:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tgOT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tgOT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 424w, https://substackcdn.com/image/fetch/$s_!tgOT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 848w, https://substackcdn.com/image/fetch/$s_!tgOT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 1272w, https://substackcdn.com/image/fetch/$s_!tgOT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tgOT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png" width="1558" height="348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:348,&quot;width&quot;:1558,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46982,&quot;alt&quot;:&quot;Table: Context | Trust (T) | Complexity (C) | Impact (I) | Score | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Context | Trust (T) | Complexity (C) | Impact (I) | Score | Tier" title="Table: Context | Trust (T) | Complexity (C) | Impact (I) | Score | Tier" srcset="https://substackcdn.com/image/fetch/$s_!tgOT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 424w, https://substackcdn.com/image/fetch/$s_!tgOT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 848w, https://substackcdn.com/image/fetch/$s_!tgOT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 1272w, https://substackcdn.com/image/fetch/$s_!tgOT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34056434-daf6-435c-9843-4da8fdcbee37_1558x348.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The product capability is identical across all three. The scores differ because the Trust axis reflects implementation maturity, the Complexity axis reflects team capability, and the Impact axis (while stable here) can shift based on asset criticality. A vendor benchmark alone is insufficient. Builder Mode exists specifically to capture this variance.</p><h1>4. Response Capability Domains</h1><p>The framework organizes response capabilities into six domains. The first five (Identity, Network, Endpoint, Cloud, SaaS) cover specific technical response planes. The sixth (General Options / Usability) covers platform-level characteristics that affect the operational quality of the solution independent of any specific response action.</p><p>For the first five domains, each capability is scored using the 0-1-2 system described in Section 3.1 (Evaluator Mode) or the T+C+I system described in Section 3.3 (Builder Mode). For the General Options domain, the scoring criteria shift slightly: 0 means the feature is not available, 1 means the feature is available but limited in capability or partially implemented, and 2 means the feature is fully available, functional, and tested.</p><h2>4.1 Identity Response Plane</h2><p>Identity-related response actions target user accounts, service principals, groups, and access permissions. These actions are among the most commonly needed in incident response and are often the first automation candidates for SOC teams.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZG5f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZG5f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 424w, https://substackcdn.com/image/fetch/$s_!ZG5f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 848w, https://substackcdn.com/image/fetch/$s_!ZG5f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 1272w, https://substackcdn.com/image/fetch/$s_!ZG5f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZG5f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png" width="1374" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1374,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:119522,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!ZG5f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 424w, https://substackcdn.com/image/fetch/$s_!ZG5f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 848w, https://substackcdn.com/image/fetch/$s_!ZG5f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 1272w, https://substackcdn.com/image/fetch/$s_!ZG5f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F222cd477-803a-4dc8-869c-e504c1bb0583_1374x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Builder Mode Reference Scoring (Mature AI SOC Program, Skilled Engineering Team):</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!thwc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!thwc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 424w, https://substackcdn.com/image/fetch/$s_!thwc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 848w, https://substackcdn.com/image/fetch/$s_!thwc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 1272w, https://substackcdn.com/image/fetch/$s_!thwc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!thwc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png" width="1032" height="944" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:944,&quot;width&quot;:1032,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102464,&quot;alt&quot;:&quot;Table: Action | T | C | I | Score | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | T | C | I | Score | Tier" title="Table: Action | T | C | I | Score | Tier" srcset="https://substackcdn.com/image/fetch/$s_!thwc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 424w, https://substackcdn.com/image/fetch/$s_!thwc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 848w, https://substackcdn.com/image/fetch/$s_!thwc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 1272w, https://substackcdn.com/image/fetch/$s_!thwc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ddcdc89-cd19-4f8f-903a-ee2baeae9eeb_1032x944.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>4.2 Network Response Plane</h2><p>Network-level response actions modify traffic flow, access control, and device connectivity. These are often high-impact actions with significant blast radius, making the Trust and Impact axes particularly important in scoring.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z5DB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z5DB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 424w, https://substackcdn.com/image/fetch/$s_!Z5DB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 848w, https://substackcdn.com/image/fetch/$s_!Z5DB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 1272w, https://substackcdn.com/image/fetch/$s_!Z5DB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z5DB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png" width="1240" height="1094" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1094,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136403,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!Z5DB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 424w, https://substackcdn.com/image/fetch/$s_!Z5DB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 848w, https://substackcdn.com/image/fetch/$s_!Z5DB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 1272w, https://substackcdn.com/image/fetch/$s_!Z5DB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F322627c5-ecfb-4785-97e3-e8480b4ae66d_1240x1094.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Builder Mode Reference Scoring:</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LsfZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LsfZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 424w, https://substackcdn.com/image/fetch/$s_!LsfZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 848w, https://substackcdn.com/image/fetch/$s_!LsfZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 1272w, https://substackcdn.com/image/fetch/$s_!LsfZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LsfZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png" width="992" height="1094" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1094,&quot;width&quot;:992,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:110223,&quot;alt&quot;:&quot;Table: Action | T | C | I | Score | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | T | C | I | Score | Tier" title="Table: Action | T | C | I | Score | Tier" srcset="https://substackcdn.com/image/fetch/$s_!LsfZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 424w, https://substackcdn.com/image/fetch/$s_!LsfZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 848w, https://substackcdn.com/image/fetch/$s_!LsfZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 1272w, https://substackcdn.com/image/fetch/$s_!LsfZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e447913-402b-4fcc-b710-219a83dceba9_992x1094.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>4.3 Endpoint Response Plane</h2><p>Endpoint response actions operate directly on devices and their software environment. This domain has the largest number of capabilities because endpoint response spans file operations, process management, application control, forensics, and OS-level changes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Owlt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Owlt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 424w, https://substackcdn.com/image/fetch/$s_!Owlt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 848w, https://substackcdn.com/image/fetch/$s_!Owlt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 1272w, https://substackcdn.com/image/fetch/$s_!Owlt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Owlt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png" width="1328" height="1764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1764,&quot;width&quot;:1328,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:248314,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!Owlt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 424w, https://substackcdn.com/image/fetch/$s_!Owlt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 848w, https://substackcdn.com/image/fetch/$s_!Owlt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 1272w, https://substackcdn.com/image/fetch/$s_!Owlt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e471e-276c-4cb3-aa88-85c6a4cb2243_1328x1764.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Builder Mode Reference Scoring:</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WS7V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WS7V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 424w, https://substackcdn.com/image/fetch/$s_!WS7V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 848w, https://substackcdn.com/image/fetch/$s_!WS7V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 1272w, https://substackcdn.com/image/fetch/$s_!WS7V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WS7V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png" width="1026" height="1838" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1838,&quot;width&quot;:1026,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195239,&quot;alt&quot;:&quot;Table: Action | T | C | I | Score | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | T | C | I | Score | Tier" title="Table: Action | T | C | I | Score | Tier" srcset="https://substackcdn.com/image/fetch/$s_!WS7V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 424w, https://substackcdn.com/image/fetch/$s_!WS7V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 848w, https://substackcdn.com/image/fetch/$s_!WS7V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 1272w, https://substackcdn.com/image/fetch/$s_!WS7V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5267d952-69c0-4aeb-bac4-2a4804722454_1026x1838.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>4.4 Cloud Response Plane</h2><p>Cloud response actions target infrastructure resources, access controls, and storage in cloud environments. The blast radius of cloud actions can be particularly severe because a single misconfigured change can affect multiple dependent services.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WXgR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WXgR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 424w, https://substackcdn.com/image/fetch/$s_!WXgR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 848w, https://substackcdn.com/image/fetch/$s_!WXgR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!WXgR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WXgR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png" width="1596" height="1242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1242,&quot;width&quot;:1596,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:206734,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!WXgR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 424w, https://substackcdn.com/image/fetch/$s_!WXgR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 848w, https://substackcdn.com/image/fetch/$s_!WXgR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!WXgR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d7c698f-8ca5-450f-a4df-cf7d203659e4_1596x1242.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Builder Mode Reference Scoring:</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V39m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V39m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 424w, https://substackcdn.com/image/fetch/$s_!V39m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 848w, https://substackcdn.com/image/fetch/$s_!V39m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!V39m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V39m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png" width="1088" height="1242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1242,&quot;width&quot;:1088,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137405,&quot;alt&quot;:&quot;Table: Action | T | C | I | Score | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | T | C | I | Score | Tier" title="Table: Action | T | C | I | Score | Tier" srcset="https://substackcdn.com/image/fetch/$s_!V39m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 424w, https://substackcdn.com/image/fetch/$s_!V39m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 848w, https://substackcdn.com/image/fetch/$s_!V39m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!V39m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F586140a9-ed44-4d6a-b89f-fc6db95417ae_1088x1242.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>4.5 SaaS Response Plane</h2><p>SaaS response actions focus primarily on email and productivity platforms, which are among the most common attack surfaces in enterprise environments. Actions in this domain directly affect end-user workflows and communications.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZYUC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZYUC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 424w, https://substackcdn.com/image/fetch/$s_!ZYUC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 848w, https://substackcdn.com/image/fetch/$s_!ZYUC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 1272w, https://substackcdn.com/image/fetch/$s_!ZYUC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZYUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png" width="1394" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1394,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:120937,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!ZYUC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 424w, https://substackcdn.com/image/fetch/$s_!ZYUC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 848w, https://substackcdn.com/image/fetch/$s_!ZYUC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 1272w, https://substackcdn.com/image/fetch/$s_!ZYUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0344d3ab-cc09-4701-8e88-236a5c8c1b59_1394x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Builder Mode Reference Scoring:</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zh2v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zh2v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 424w, https://substackcdn.com/image/fetch/$s_!Zh2v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 848w, https://substackcdn.com/image/fetch/$s_!Zh2v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!Zh2v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zh2v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png" width="1088" height="1242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1242,&quot;width&quot;:1088,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137405,&quot;alt&quot;:&quot;Table: Action | T | C | I | Score | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | T | C | I | Score | Tier" title="Table: Action | T | C | I | Score | Tier" srcset="https://substackcdn.com/image/fetch/$s_!Zh2v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 424w, https://substackcdn.com/image/fetch/$s_!Zh2v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 848w, https://substackcdn.com/image/fetch/$s_!Zh2v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!Zh2v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d494cc3-3921-4ccf-8cf9-53a0cf8b2a1d_1088x1242.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>4.6 General Options / Usability</h2><p>This domain evaluates platform-level capabilities that are not tied to any specific response action but directly affect how useful, trustworthy, and manageable the AI SOC solution is in production. The scoring for this domain uses a modified scale: 0 means not available, 1 means available but limited, and 2 means fully available and functional.</p><p>This domain is split into two sub-categories to distinguish between operational platform features and AI-specific evaluation criteria.</p><h3>Platform Operations</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cYFv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cYFv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 424w, https://substackcdn.com/image/fetch/$s_!cYFv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 848w, https://substackcdn.com/image/fetch/$s_!cYFv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 1272w, https://substackcdn.com/image/fetch/$s_!cYFv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cYFv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png" width="1402" height="944" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:944,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150716,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!cYFv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 424w, https://substackcdn.com/image/fetch/$s_!cYFv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 848w, https://substackcdn.com/image/fetch/$s_!cYFv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 1272w, https://substackcdn.com/image/fetch/$s_!cYFv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd83ef3f-8576-467a-9f4b-b89b633d1e90_1402x944.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>AI-Specific Evaluation Criteria</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WZV-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WZV-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 424w, https://substackcdn.com/image/fetch/$s_!WZV-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 848w, https://substackcdn.com/image/fetch/$s_!WZV-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 1272w, https://substackcdn.com/image/fetch/$s_!WZV-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WZV-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png" width="1702" height="944" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:944,&quot;width&quot;:1702,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174785,&quot;alt&quot;:&quot;Table: Action | Description&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Action | Description" title="Table: Action | Description" srcset="https://substackcdn.com/image/fetch/$s_!WZV-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 424w, https://substackcdn.com/image/fetch/$s_!WZV-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 848w, https://substackcdn.com/image/fetch/$s_!WZV-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 1272w, https://substackcdn.com/image/fetch/$s_!WZV-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709f1626-92e0-4880-8fb8-7f125d113658_1702x944.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>5. Aggregate Maturity Scoring</h1><p>Evaluating each plane individually is necessary but not sufficient. Security teams making purchasing decisions and product managers tracking competitive positioning need a consolidated view that communicates the overall picture without hiding the details.</p><h2>5.1 Automation Depth Score</h2><p>This is the most operationally significant metric and the one that separates real autonomous solutions from products that wrapped a chatbot interface around a set of API calls.</p><p>Across all covered capabilities, calculate the distribution:</p><ul><li><p>What percentage is fully automated (level 2)?</p></li><li><p>What percentage sits at Approver level (1A)?</p></li><li><p>What percentage sits at Guide level (1G)?</p></li><li><p>What percentage sits at Collaborator level (1C)?</p></li><li><p>What percentage is not available at all (0)?</p></li></ul><p>A product could have 80% of capabilities covered but only 5% fully automated. That is a fundamentally different product than one with 60% covered but 40% fully automated. The first is broad but shallow. The second is narrower but operates with real autonomy where it counts.</p><p><strong>Full Automation Rate: </strong>The percentage of total capabilities at level 2. This is the true measure of how much an AI SOC solution can operate without human intervention.</p><p><strong>Coverage Rate: </strong>The percentage of total capabilities at any level above 0. This measures breadth regardless of automation depth.</p><p>The relationship between these two numbers tells you everything about how the product actually operates. A high coverage rate with a low automation rate means the product is a guided workflow tool with AI branding. A moderate coverage rate with a high automation rate relative to coverage means the product is autonomous in its areas of focus but limited in scope.</p><h2>5.2 Combined Scoring Readout</h2><p>A complete ARMM evaluation for a product produces the following consolidated output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ag0i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ag0i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 424w, https://substackcdn.com/image/fetch/$s_!ag0i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 848w, https://substackcdn.com/image/fetch/$s_!ag0i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 1272w, https://substackcdn.com/image/fetch/$s_!ag0i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ag0i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png" width="1070" height="348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/21cce93b-33c6-413d-be55-527250793fc6_1070x348.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:348,&quot;width&quot;:1070,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:41544,&quot;alt&quot;:&quot;Table: Metric | Value&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Metric | Value" title="Table: Metric | Value" srcset="https://substackcdn.com/image/fetch/$s_!ag0i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 424w, https://substackcdn.com/image/fetch/$s_!ag0i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 848w, https://substackcdn.com/image/fetch/$s_!ag0i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 1272w, https://substackcdn.com/image/fetch/$s_!ag0i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21cce93b-33c6-413d-be55-527250793fc6_1070x348.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Per-Plane Breakdown:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6sR3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6sR3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 424w, https://substackcdn.com/image/fetch/$s_!6sR3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 848w, https://substackcdn.com/image/fetch/$s_!6sR3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 1272w, https://substackcdn.com/image/fetch/$s_!6sR3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6sR3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png" width="1170" height="572" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:572,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76126,&quot;alt&quot;:&quot;Table: Plane | Score | Coverage | Fully Automated | Tier&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table: Plane | Score | Coverage | Fully Automated | Tier" title="Table: Plane | Score | Coverage | Fully Automated | Tier" srcset="https://substackcdn.com/image/fetch/$s_!6sR3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 424w, https://substackcdn.com/image/fetch/$s_!6sR3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 848w, https://substackcdn.com/image/fetch/$s_!6sR3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 1272w, https://substackcdn.com/image/fetch/$s_!6sR3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8aea69a-9b99-4f6c-b633-c0523271cd71_1170x572.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>6. Reading the Model</h1><p>A product can reach Expert level on a specific plane by checking all the boxes for that domain. But it would be difficult to consider an AI SOC Response solution as Expert level overall if it lacks the ability to perform foundational actions like closing alerts in a SIEM. The tier system is designed to reward both depth within a domain and breadth across domains.</p><p>The reference maturity tables provided in Section 4 use example scores from a hypothetical mature AI SOC program with a skilled engineering team. These are illustrative, not universal benchmarks. The environmental dynamics described in Section 3.5 are not optional context; they are a core part of how the framework is intended to be used.</p><p>When comparing two products, the most informative comparison is not the aggregate score. It is the per-plane breakdown combined with the Automation Depth Score. Two products at the same composite tier can have radically different operational profiles. One may cover 80% of capabilities at the Collaborator level. The other may cover 50% but with 30% at full automation. These are different products for different buyers with different operational maturity levels.</p><h1>7. Limitations and Future Work</h1><p>This is version 0.1. The framework has known limitations:</p><ul><li><p>The capability lists are not exhaustive. New response actions will emerge as AI SOC products mature and as attack surfaces expand.</p></li><li><p>The three-axis scoring (T, C, I) requires subjective judgment that will vary between evaluators. We plan to develop calibration guidelines to reduce inter-evaluator variance.</p></li><li><p>The framework does not currently weight domains differently. In practice, Identity response may be more important than Network response for a given organization. Weighted scoring is planned for a future version.</p></li><li><p>Detection and analysis capabilities are out of scope for this version. A separate framework or an extension to ARMM may address those in the future.</p></li><li><p>We have not included pricing, deployment time, or vendor lock-in considerations. These are important purchase factors but are outside the scope of a technical maturity model.</p></li></ul><p>We are building a public web application where users can input their product's capabilities and generate ARMM scoring layers automatically, along with an exportable CSV. The application is available at: <a href="https://armm.secops-unpacked.ai/">armm.secops-unpacked.ai</a></p><h1>8. Conclusion</h1><p>The AI SOC market is growing faster than the industry's ability to evaluate products on consistent terms. The ARMM framework provides a structured, repeatable methodology for measuring what an AI SOC solution can actually do in the response layer, how autonomously it can do it, and what it takes to deploy and maintain that capability in a specific operational environment.</p><p>The framework is built for two audiences: security teams evaluating products and product managers building them. For security teams, it provides a checklist and scoring system that cuts through marketing language and focuses on operational capability. For product teams, it provides a competitive analysis baseline and a prioritization framework for feature development.</p><p>SOAR gave us arms without brains. The first wave of AI SOC products gave us brains without arms. The products that will win this market are the ones that connect both. ARMM gives you a way to measure how far along that connection is, and where the gaps remain.</p><p>No current AI SOC solution will check every box. That is not the point. The point is to establish a common language and a common measurement system so that the conversation about AI SOC response capability is grounded in specifics rather than promises. Version 0.1 is the starting point. The framework will evolve as the market does.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Fear of Not Doing Enough]]></title><description><![CDATA[Decode the hidden dynamics of security team burnout: Explore how fear drives unnecessary work and discover strategies to break the cycle of overload and]]></description><link>https://blog.secops-unpacked.ai/p/the-fear-of-not-doing-enough</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/the-fear-of-not-doing-enough</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Fri, 13 Feb 2026 15:46:33 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e931ad3b-f9b5-48f5-b85c-790fe7c04e3f_1332x1004.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><h1>The Fear of Not Doing Enough: Security's Workflow Problem</h1><p>If you've been following this blog, you know I've spent a lot of time on AI transforming investigation, triage, and detection engineering. And a few months back I wrote about the single pane of glass, how it's not a product you buy but a system you build, piece by piece, like Legos.</p><p>That post was about the architecture. What tools do you need, how do they connect, where does data flow.</p><p>This post is about the layer underneath that nobody talks about. Not the tools. The work itself. Where it comes from, how it flows, and why we have zero visibility into most of it.</p><h2>The Fear of Not Doing Enough</h2><p>Security has this pattern I keep seeing everywhere.</p><p>New attack technique drops. A CVE trends on Twitter. Some threat intel report lands in your inbox with a fancy APT name. What happens next? Predictable.</p><p>Someone writes a generic detection rule fast so the team has "something." Gets pushed to production. Generates noise. Nobody tunes it because there's already another thing screaming for attention.</p><p>The false sense of coverage becomes more important than actual coverage.</p><p>I call this the <strong>Fear of Not Doing Enough.</strong> And honestly? It drives most of the operational pain in security teams today.</p><p>You write a detection rule. Do you have the SOP for when it fires? Do you know the full analysis path an analyst should follow? Can you estimate how that alert impacts your team's workload downstream? Do you know what "done" looks like for that alert type?</p><p>If you can't answer those, you didn't deploy a detection. You deployed a work generator with no operating manual. Multiply that across dozens of detections written under pressure and you get patchwork coverage that looks great on a dashboard but falls apart when someone has to actually operate it.</p><p>But here's the thing. Even if you fix all of that, you're still only looking at one input stream.</p><h2>It's Not Just SIEM Alerts</h2><p>A <a href="https://dl.acm.org/doi/10.1145/3723158">ACM Computing Surveys paper</a> (Tariq et al., 2025) reviewed over 30 solutions to alert fatigue in SOCs. Thorough paper, I'll give them that. Identifies four root causes: staff shortage, high false positive rates, disconnected dashboards, and inefficient SOPs.</p><p>But every single solution assumes the work starts with a SIEM alert.</p><p>Now look, I'm not saying SIEM alerts are a small part of the work. For most teams they're probably more than half. But here's what matters: the work that doesn't come from the SIEM is often the most manual, least structured, and hardest to track.</p><p>IT escalations. Someone from the help desk pings you on Slack: "Hey, this looks weird." Access review requests from HR. Audit findings that need remediation tracking. Pen test findings that need to be assigned and fixed. Third-party risk questionnaires. Compliance asks from legal.</p><p>All real security work. And here's the thing about it: only some or none of it has a playbook or automation behind it. Most of it lives in Slack threads, email chains, and spreadsheets. It's the security work that runs entirely on copy-paste, tribal knowledge, and good intentions.</p><p>Your SIEM alerts, for all their problems, at least flow through a pipeline. They get enriched. They have some structure. Maybe even a SOAR playbook attached. The non-SIEM work? It's the Wild West.</p><p><a href="https://www.linkedin.com/in/erikbloch/">Erik Bloch</a> has been making this point for years.A lot of the work SOC is doing day-to-day has nothing to do with chasing advanced adversaries. It's tickets, reports, evidence collection, reconciling data across tools. The mundane operational grind that actually burns people out.</p><p>And here's the part that really gets me. Outside of very large enterprises that have 10 security sub-departments with dedicated teams for everything, the same 3-5 people triaging SIEM alerts are also pulling evidence for the auditor, handling the IT escalation, and answering the compliance questionnaire. There's no luxury of specialization. The alert queue is just one input stream among many. And the non-SIEM stuff eats time disproportionately because it's all manual.</p><h2>Security Work Has No Gravity</h2><p><a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a> recently wrote a great piece about S<a href="https://ventureinsecurity.net/p/servicenow-is-betting-on-workflow">erviceNow betting on "workflow gravity"</a> to compete with the security platform giants. The thesis is simple. Whoever owns where work happens owns the decisions.</p><p>Data gravity pulls information into a single system of record. Your SIEM, your data lake, whatever. That part most teams have figured out. Workflow gravity is different. It pulls action into a single system of action. One place where work lands, gets triaged, gets tracked, and gets done.</p><p>Right now? Security work has no gravity. It's everywhere and nowhere.</p><p>And yeah, this connects directly to the single pane of glass conversation. In that post I talked about building your own platform, Lego-style, with assets, data layers, correlation, and response actions. But even if you build that beautiful architecture, it's still oriented around machine-generated alerts. The SIEM brain, the enrichment layer, the correlation engine. All of that assumes the input is a structured alert.</p><p>What about the IT manager who emails you about a suspicious contractor? What about the audit finding that needs 6 teams to remediate? What about the pen test report sitting in a shared drive that nobody has turned into action items yet?</p><p>That work has no architecture. It has no pipeline. It just shows up and someone deals with it however they can.</p><p>You want to know why security teams always feel understaffed? Part of it is real headcount shortage, sure. But part of it is that nobody can actually see where the time goes. When the most manual, time-consuming work lives outside of every system you've built, you can't measure it. When you can't measure it, you can't optimize it. When you can't optimize it, you just throw more people at it and hope for the best.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y3Md!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y3Md!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 424w, https://substackcdn.com/image/fetch/$s_!Y3Md!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 848w, https://substackcdn.com/image/fetch/$s_!Y3Md!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 1272w, https://substackcdn.com/image/fetch/$s_!Y3Md!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y3Md!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif" width="1332" height="1004" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1004,&quot;width&quot;:1332,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:155599,&quot;alt&quot;:&quot;How Security Work is generated.gif&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="How Security Work is generated.gif" title="How Security Work is generated.gif" srcset="https://substackcdn.com/image/fetch/$s_!Y3Md!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 424w, https://substackcdn.com/image/fetch/$s_!Y3Md!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 848w, https://substackcdn.com/image/fetch/$s_!Y3Md!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 1272w, https://substackcdn.com/image/fetch/$s_!Y3Md!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53975635-7d69-4ff7-9db2-9d9f417d157e_1332x1004.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Process Mining Exists. Just Not for Us. Yet.</h2><p>Here's something that gets me. In finance, procurement, and operations, tools like Celonis and Scribe Optimize have existed for years. They observe how work actually happens across tools and systems. They find bottlenecks. They tell you where time is wasted. They optimize based on data, not vibes and assumptions.</p><p>In security? Still very early days.</p><p>Some vendors are starting to take RPA-style approaches to There's a handful of academic papers exploring it. But it's nowhere near mainstream.</p><p>We still don't have good data on how security work actually flows end to end. Think about that.</p><p>We have terabytes of security telemetry. We can tell you exactly when a process spawned on an endpoint at 3:47am. But we can't tell you how long it takes an analyst to go from "alert fired" to "investigation complete." We can't tell you how much time the team spends on compliance requests versus actual threat work. We can't tell you which of your 200 detection rules generates the most operational overhead relative to the security value it provides.</p><p>That's wild.</p><h2>Why This Is Hard</h2><p>I get why the industry keeps gravitating toward the easier wins. Make investigation faster. Automate the playbook. Build a better ML model for triage. Those are well-defined problems with measurable outcomes.</p><p>Understanding where all security work happens and how it flows? That's messy. It crosses tool boundaries. It involves human behavior that doesn't fit neatly into event logs. It requires looking at the whole system, not just one piece.</p><p>This is the hardest problem to solve. And that's exactly why not many are tackling it yet.</p><p>But here's why it matters. If you don't understand the full picture of how work enters and flows through your security team, everything else you build is an optimization of a subsystem. You can make SIEM triage 10x faster, but if a third of the work comes from non-SIEM sources that are entirely manual, you just made one part of the problem better while the messiest part stays untouched.</p><h2>What Would Actually Help</h2><p>I don't think this needs to be one giant platform that replaces everything. But teams need a few things that barely exist today.</p><p><strong>Workflow data.</strong> How long does each type of work actually take? Where are the handoffs? Where do things stall? What percentage of the team's time goes to which category of work? Right now most teams are guessing. And the guesses are usually wrong because the most painful work is the least visible.</p><p><strong>Operational impact awareness.</strong> Before you deploy a new detection, onboard a new data source, or agree to a new compliance requirement, you should be able to model what that does to your team's capacity. Not after the fact when everyone's drowning. Before.</p><p><strong>Connection between detection and process.</strong> If you have a detection but you don't have the analysis path mapped from it, you can't estimate how it impacts anything downstream. Every detection should ship with its SOP. Not as a nice-to-have. As a requirement.</p><h2>The Fear Won't Go Away</h2><p>The Fear of Not Doing Enough will always be there. New threats aren't going to stop coming. The pressure to have "something" for every new attack vector is real.</p><p>But the answer isn't to keep throwing generic detections at every new thing and hoping the team can absorb the blast. It's not to keep building faster investigation tools for one slice of the work while the rest drowns in Slack threads and spreadsheets.</p><p>We've been fixing the middle. Investigation is getting faster. AI triage is real. Response automation is improving. The single pane of glass architecture is getting clearer. All good progress.</p><p>Now it's time to zoom out. Understand how security work actually flows. All of it. Not just the structured, machine-generated part. Especially the messy, manual, human-generated part that eats the most time and has the least tooling.</p><p>Fix the input. Model the cost. Understand the workflow.</p><p>Stop optimizing the output of a system you've never fully mapped.</p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item><item><title><![CDATA[The SOC Autonomy Trap]]></title><description><![CDATA[Decode the autonomy myth in AI SOC: Explore why full automation falls short and learn a nuanced approach to security operations that balances human]]></description><link>https://blog.secops-unpacked.ai/p/the-soc-autonomy-trap</link><guid isPermaLink="false">https://blog.secops-unpacked.ai/p/the-soc-autonomy-trap</guid><dc:creator><![CDATA[Filip Stojkovski]]></dc:creator><pubDate>Mon, 19 Jan 2026 15:10:07 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6b81df9e-b505-4d12-a300-89c20e817159_1920x1453.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><sub>Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.</sub></em></p><p>Hey everyone. Been quiet on here for a bit. First post of 2026.<br><br>I came across a paper that finally articulates something I've been thinking about for a while: autonomy isn't a capability score. It's a design decision<a href="https://arxiv.org/abs/2506.12469">"Levels of Autonomy for AI Agents"</a>. And chasing the highest level everywhere is a mistake.</p><p>Let me walk through it.<br><br><strong>L1 (Operator):</strong> User directs and makes decisions, agent acts. Think Microsoft Copilot. The agent requires invocation to act, provides on-demand assistance, and avoids preference-based decision-making on the user's behalf.</p><p><strong>L2 (Collaborator):</strong> User and agent collaboratively plan, delegate, and execute. Think OpenAI Operator. Users can freely modify agent work and take control at any point. Back-and-forth communication is frequent.</p><p><strong>L3 (Consultant):</strong> Agent takes the lead but consults user for expertise and preferences. Think Gemini Deep Research. Users provide feedback and directional guidance rather than hands-on collaboration. The agent bears more of the learning curve.</p><p><strong>L4 (Approver):</strong> Agent engages user only in risky or pre-specified scenarios. Think Devin. Users specify approval conditions upfront. The agent only stops for blockers, credentials, or consequential actions.</p><p><strong>L5 (Observer):</strong> Agent operates with full autonomy under user monitoring. Users can watch activity logs and hit the emergency stop. That's it.</p><p>The key insight: autonomy is a design decision, not a capability metric. A capable agent can still operate at L2 if that's the right call for the task. The paper explicitly argues against treating autonomy as an inevitable consequence of increasing capability.</p><h2>Agency vs. Autonomy</h2><p>The paper makes an important distinction that matters for security operations.</p><p><strong>Agency</strong> is the capacity to carry out intentional actions. It's about what tools the agent has access to and what it can do in the environment.</p><p><strong>Autonomy</strong> is the extent to which the agent operates without user involvement. It's about when and how the agent checks in with humans.</p><p>An agent with high agency (many tools, broad permissions) can still have low autonomy (checks in frequently). An agent with low agency (limited toolset) can have high autonomy (runs independently within that scope).</p><p>This distinction matters because security teams often conflate the two. Giving an agent access to more data sources (agency) is different from letting it act without approval (autonomy). You can expand agency while constraining autonomy.</p><h2>Mapping Autonomy to Security Operations</h2><p>I mapped common security workflows to appropriate autonomy levels based on their risk profile and decision complexity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0oFr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0oFr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 424w, https://substackcdn.com/image/fetch/$s_!0oFr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 848w, https://substackcdn.com/image/fetch/$s_!0oFr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 1272w, https://substackcdn.com/image/fetch/$s_!0oFr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0oFr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png" width="1920" height="1453" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1453,&quot;width&quot;:1920,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1197401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0oFr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 424w, https://substackcdn.com/image/fetch/$s_!0oFr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 848w, https://substackcdn.com/image/fetch/$s_!0oFr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 1272w, https://substackcdn.com/image/fetch/$s_!0oFr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40ca0ff4-3821-4cc1-a8c1-58d3c6f2d3f9_1920x1453.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Initial Triage: L4-L5</h3><p>For alert triage, scale beats precision. You're dealing with volume. The goal is filtering, not final judgment.</p><p>L4 makes sense here. Let agents do the heavy lifting, have them seek approval only for edge cases or high-severity alerts. L5 is reasonable for low-fidelity alerts where false positives cost nothing. Start at L4. Keep humans reviewing outcomes for anything that escalates to investigation.</p><p>The paper notes that L4 agents are ideal for tasks with high amounts of lower-stakes decision-making. Alert triage fits this description. Automated decisions improve efficiency. Erroneous decisions on individual alerts don't impose catastrophic risks if the escalation path is intact.</p><h3>Incident Response: L1-L2</h3><p>On the response side of the IR cycle, L1 and L2 work well. These are established patterns with runbooks and playbooks.</p><p>Why keep autonomy low here? Response actions are consequential. Isolating a host, blocking a domain, killing a process. These actions have real impact. Speed matters, but accountability matters more.</p><p>L1 is appropriate when analysts drive the workflow and agents execute specific tasks on command. L2 works when you want the agent to propose containment plans while the analyst retains takeover capability.</p><p>The paper describes L2 control mechanisms as requiring "control transfer from agent to user, and vice versa" plus "shared representation of progress." That maps well to incident response dashboards where analysts can see what the agent is doing and intervene.</p><h3>In-Depth Investigation: L3</h3><p>Deep investigation is judgment-heavy work. Context matters. The analyst brings domain knowledge, institutional memory, and threat intelligence the agent doesn't have.</p><p>L3 fits this workflow. The agent leads the investigation, gathering data, correlating events, building timelines. But it consults the analyst for direction. What's the hypothesis? Which threads are worth pulling? Does this pattern match something we've seen before?</p><p>The paper notes that L3 agents require "productive and timely consultation." The agent needs to know what expertise the user brings and when to ask for it. For security investigations, this means the agent should surface findings and ask about relevance rather than drawing conclusions autonomously.</p><h3>Threat Hunting: L2-L3</h3><p>Hunting is exploratory by nature. You're looking for things you don't know exist yet. Hypotheses matter. Intuition matters.</p><p>Collaboration beats full automation here. L2-L3 is the range. The agent surfaces anomalies, suggests investigation paths, runs queries. The human drives the hunt itself.</p><p>The paper describes L2 as the level where "back-and-forth communication between the user and the agent is the most frequent and rich." Threat hunting benefits from this dynamic. The hunter's domain expertise combined with the agent's ability to process large datasets creates a feedback loop that pure automation can't replicate.</p><h3>Detection Engineering: L2-L3</h3><p>Detection engineering is systematic but consequential. Bad detections create alert fatigue. Missed detections create gaps.</p><p>L2 is the baseline. The agent assists with query building, suggests detection patterns, helps test against historical data. The engineer retains control over what gets deployed.</p><p>L3 is appropriate for mature teams with well-governed detection lifecycles. The agent drafts detections, runs validation, and consults the engineer before deployment. The key is having proper testing and review controls already in place.</p><p>The paper warns about L4 agents and "meaningless rubber stamping" from user disengagement. This risk is real for detection engineering. If engineers just approve whatever the agent proposes, detection quality will degrade.</p><h2>The Double-Edged Sword</h2><p>The paper repeatedly emphasizes that autonomy amplifies both benefits and risks. Higher autonomy means more scale and efficiency. It also means errors compound over multiple steps without intervention.</p><p>This maps directly to security operations. An agent that autonomously closes false positive alerts at L5 saves analyst time. An agent that autonomously closes true positive alerts at L5 creates security incidents.</p><p>The paper also raises concerns about deskilling and loss of critical thinking when automation takes over judgment tasks. Security teams should consider this. If agents handle all investigation, what happens to analyst skill development? L2 and L3 autonomy levels preserve opportunities for human engagement while still providing automation benefits.</p><h2>Autonomy Certificates</h2><p>The paper proposes "autonomy certificates" as a governance mechanism. A third-party body evaluates an agent's behavior and certifies the maximum autonomy level at which it can operate.</p><p>This concept has implications for security vendors. Right now, every AI SOC vendor claims some version of autonomous operation. There's no standard way to compare what that actually means.</p><p>An autonomy certificate framework would force clarity. Does your agent operate at L3 or L4? What approval mechanisms exist? Under what conditions does it escalate?</p><p>For security buyers, this creates better evaluation criteria than vague claims about AI capabilities.</p><h2>Double-Layer Governance: Reasoning and Abilities</h2><p>The agency vs. autonomy distinction from the paper points to a practical governance model. You need to control both what the agent can think about doing and what it can actually do.</p><p>At BlinkOps, we implement this as double-layer governance:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5-7q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5-7q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5-7q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5-7q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5-7q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5-7q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg" width="1920" height="3440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3440,&quot;width&quot;:1920,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1617185,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5-7q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5-7q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5-7q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5-7q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ef7d86c-a5f7-49b8-85a4-f6130e5ab758_1920x3440.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Layer 1: Reasoning Constraints</strong></p><p>This layer limits what the agent can decide to do. It's autonomy governance. You define the scope of problems the agent is allowed to reason about and the types of conclusions it can reach.</p><p>For example, an agent handling alert triage might be constrained to reason only about severity classification and enrichment. It can't decide to initiate response actions, even if it has the technical capability. The reasoning boundary is set before the agent ever considers what actions to take.</p><p>This maps to the paper's definition of autonomy as "the extent to which an AI agent is designed to operate without user involvement." By constraining reasoning scope, you limit how far the agent goes before involving a human.</p><p><strong>Layer 2: Ability Constraints</strong></p><p>This layer limits what the agent can execute. It's agency governance. Even if the agent reasons its way to a valid conclusion, it can only act through explicitly permitted capabilities.</p><p>This is your tool allowlist. The agent might determine that isolating a host is the right response, but if host isolation isn't in its permitted action set, it can't execute. It has to escalate.</p><p>This maps to the paper's definition of agency as "the capacity to carry out intentional actions." By constraining the toolset, you bound the blast radius of any autonomous decision.</p><p><strong>Why Both Layers Matter</strong></p><p>Single-layer governance creates gaps.</p><p>If you only constrain abilities (Layer 2), the agent can still reason about actions outside its scope and make recommendations that push humans toward decisions the agent shouldn't influence. An agent without response permissions might still conclude "this host should be isolated immediately" and create pressure for hasty action.</p><p>If you only constrain reasoning (Layer 1), the agent might find edge cases where its reasoning scope overlaps with dangerous capabilities. A triage agent reasoning about "enrichment" might decide that querying a production database for context falls within scope.</p><p>Double-layer governance closes both gaps. The reasoning layer defines intent boundaries. The ability layer enforces execution boundaries. An action only happens if it passes both checks.</p><p><strong>Practical Implementation</strong></p><p>For each workflow, define:</p><ol><li><p><strong>Reasoning scope:</strong> What questions can the agent answer? What conclusions can it reach? What types of decisions are out of bounds?</p></li><li><p><strong>Action permissions:</strong> What tools and integrations can the agent invoke? What parameters can it set? What requires human approval?</p></li><li><p><strong>Escalation triggers:</strong> When reasoning hits scope boundaries, where does it go? When actions require approval, who approves?</p></li></ol><p>This gives you granular control without blocking automation entirely. An L4 agent can still operate autonomously within its defined scope. But that scope is explicitly bounded at both the reasoning and execution layers.</p><p>The paper's framework helps here. L4 requires "customizable conditions for seeking approval." Double-layer governance operationalizes this. The conditions are defined by reasoning scope violations (Layer 1) and action permission requirements (Layer 2).</p><h2>What This Means for AI SOC Design</h2><p>If you're building or buying AI-powered security tooling, ask different questions:</p><p><strong>What autonomy level does this workflow need?</strong> Not "how autonomous is this agent?" Match the autonomy to the task risk profile.</p><p><strong>What are the must-have controls?</strong> Each autonomy level has required control mechanisms. L4 requires approval elicitation for consequential actions and customizable conditions. L2 requires control transfer mechanisms and shared progress visibility. Verify these exist.</p><p><strong>Where are the approval gates?</strong> Every workflow should have defined checkpoints. Know what triggers human involvement.</p><p><strong>What's the fallback?</strong> When the agent hits a failure state, what happens? The paper notes that L4 and L5 agents should iterate on solutions or modify approaches when blocked. How does your agent handle this?</p><p><strong>Who's accountable?</strong> Higher autonomy means harder accountability tracing. The paper cites research showing it's simultaneously more important and more difficult to anticipate harms from autonomous AI. Design governance around this reality.</p><h2>Closing Thoughts</h2><p>Chasing L5 everywhere is a design mistake, not a strategy.</p><p>The vendors pushing "fully autonomous SOC" are selling a destination most teams shouldn't want to reach. The right autonomy level varies by task, by maturity, by risk tolerance.</p><p>The paper's framework gives us a shared vocabulary for these discussions. Use it.</p><div><hr></div><p><strong>Reference:</strong> Feng, K.J.K., McDonald, D.W., &amp; Zhang, A.X. (2025). <em>Levels of Autonomy for AI Agents</em>. University of Washington. <a href="https://arxiv.org/abs/2506.12469">arXiv:2506.12469</a></p><div><hr></div><p><strong><a href="https://secops-unpacked.ai/research/ai-soc-vendors">Check out our SecOps Market Landscape tracker and evaluation frameworks</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://secops-unpacked.ai/research/ai-soc-vendors&quot;,&quot;text&quot;:&quot;SecOps Market Landscape&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://secops-unpacked.ai/research/ai-soc-vendors"><span>SecOps Market Landscape</span></a></p>]]></content:encoded></item></channel></rss>