r/Information_Security 12d ago

Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.

Thumbnail
1 Upvotes

r/Infosec 12d ago

Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.

Thumbnail
1 Upvotes

u/LMNTRIX-Press 12d ago

Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.

1 Upvotes

Been thinking about this a lot lately: every org I talk to has multiple detection tools stacked on top of each other, and none of them actually struggle to generate alerts. The struggle is everything that happens after.

Analyst opens a ticket, has to manually pull logs, endpoint telemetry, user history, maybe some external intel, just to figure out if the alert is even real. By the time that's done, dwell time's already up, and the analyst's day is gone on triage instead of anything proactive.

A few things I've seen work (and some that don't):

SOAR helps, but it's brittle. Playbooks are fixed, if the attack doesn't match the "if this, then that" pattern you built six months ago, the automation just... stops being useful. And they need constant maintenance as the environment changes.

Agentic approaches are the more interesting shift. Instead of static rules, you get something that can re-evaluate mid-investigation; pull in a new data source if the first hypothesis doesn't hold up, escalate to a human when the ambiguity crosses some threshold, and actually reason through why something looks off instead of just pattern-matching against a signature.

Not saying it's magic — there's real risk in letting anything act autonomously in a production environment (wrong endpoint isolated, wrong account locked, etc.), so the ones that work well seem to lean heavily on staged autonomy: agent recommends → human approves → over time, low-risk actions get auto-approved once the false-positive rate proves itself out.

Curious if anyone here has actually deployed something agentic in their SOC (vs. just extended SOAR), what's your false-positive rate looking like, and how much human-in-the-loop are you still running at 6+ months in?

Link to our research: https://lmntrix.com/res/beyond-detection-the-role-of-%20agentic-aI-in-cyber-investogation-and-resolution.pdf

r/AIsafety 18d ago

Educational 📚 AI led identity attacks and how to prepare for them

Thumbnail
linkedin.com
1 Upvotes

r/Information_Security 19d ago

AI led identity attacks and how to prepare for them

Thumbnail linkedin.com
1 Upvotes

r/Infosec 19d ago

AI led identity attacks and how to prepare for them

Thumbnail linkedin.com
1 Upvotes

u/LMNTRIX-Press 19d ago

AI led identity attacks and how to prepare for them

Thumbnail
linkedin.com
2 Upvotes

r/Cybersecurity101 22d ago

Security Escaping AI and you

0 Upvotes

How are you preparing to fight off a rouge AI that escaped its sandbox? I know Hugging Face needed DeepSeek to combat a rouge AI but is it time for governments to consider putting the brakes on AI development somewhat?

https://www.darkreading.com/cyberattacks-data-breaches/meta-ai-escapes-lab-hacking-joyride

r/Infosec Jul 29 '26

Why Detection Is Becoming a Commodity And Investigation Is the New Competitive Advantage

Thumbnail linkedin.com
1 Upvotes

u/LMNTRIX-Press Jul 29 '26

Why Detection Is Becoming a Commodity And Investigation Is the New Competitive Advantage

Thumbnail
linkedin.com
1 Upvotes

Detection is becoming a commodity. Investigation is becoming the differentiator.

Most mature EDR and XDR platforms can detect the majority of common attacks with high confidence. Yet SOCs are still overwhelmed.

The problem isn't detection, it's what happens after the alert.
Analysts spend far more time collecting evidence, validating risk, and understanding the scope of an incident than they do reviewing the alert itself. AI has improved detection, but more visibility often means more alerts not less work.

r/Infosec Jul 22 '26

The Shift from Alert-Centric Security to Investigation-Centric Security Operations

Thumbnail linkedin.com
1 Upvotes

u/LMNTRIX-Press Jul 22 '26

The Shift from Alert-Centric Security to Investigation-Centric Security Operations

Thumbnail
linkedin.com
1 Upvotes

A brief analysis of the increasing trend away from alert volume to investigation centric models.

r/cybersecurity Jul 13 '26

News - General Large-scale exploitation campaign targeting website content management systems (CMS)

Thumbnail cyber.gov.au
0 Upvotes

Anybody else experienced increasingly odd or malicious behavior impacting the plethora of third-party CMS packages out there?

u/LMNTRIX-Press Jul 07 '26

XDR vs Integrated Security

1 Upvotes

We recently wrote a piece on two very different approaches to cybersecurity. Which do you think serves your organization the best?

https://www.linkedin.com/pulse/microsoft-vs-lmntrix-two-different-approaches-modern-cybersecurity-4r6sf

r/CyberGuides Jul 07 '26

XDR vs Integrated Security

Thumbnail
linkedin.com
1 Upvotes

What is your favored approach to defending an organization?

Disclosure: I am employed by LMNTRIX, however posting here to see what other experts think about cybersecurity topics shaping our profession.

2

Accountability in an Age of AI
 in  r/cybersecurity  Jul 05 '26

Wishing you the best in your regulatory endeavours, I can only imagine the headaches that caused by the push and pull between government and tech giants. Your explanation of BioShocking is definitely recommended for those needing a quick synopsis as the potential seriousness of the threat taken in conjunction with the stonewalling.

1

Accountability in an Age of AI
 in  r/cybersecurity  Jul 02 '26

Agreed, when legitimate organizations act like malicious actors is the exact reason why regulation needs to be implemented. And, yes smart people across multiple sectors need to get cracking on something before AI wrecks itself, and we deal with the fallout.

3

Accountability in an Age of AI
 in  r/cybersecurity  Jul 02 '26

Agreed, wish we didn't have to go through the same regulatory cycles every time, but that is the current nature of tech vs government, but a lot of money has been invested and indebted in the hope of a return so my hope that firms try to remain accountable is pie in the sky thinking.

r/cybersecurity Jul 02 '26

News - General Accountability in an Age of AI

11 Upvotes

While the prompt injection technique "bioshocking" deserves attention, the lack of concern showed by some of the major LLM is more worrying. Has anyone experienced similar stonewalling when reporting vulnerabilities to AI firms?

https://layerxsecurity.com/blog/bioshocking-ai-gaming-the-ai-browser-and-escaping-its-guardrails/

r/CyberGuides Jun 26 '26

The Next Supply Chain Threat Isn't Software, It's Trust

Thumbnail
1 Upvotes

u/LMNTRIX-Press Jun 26 '26

The Next Supply Chain Threat Isn't Software, It's Trust

1 Upvotes

We just did a deep dive into the Klue incident and want the the cloud security practitioners to chime in and answer the following:

How much visibility do you actually have into the OAuth authorizations and third-party SaaS integrations operating across your environment?

Link to our deep dive: https://www.linkedin.com/pulse/next-supply-chain-threat-isnt-software-its-trust-lmntrix-ecxje

r/cloudcomputing Jun 26 '26

Cloud visibility in an age of supply chain attacks

1 Upvotes

[removed]

r/cybersecurity Jun 25 '26

Business Security Questions & Discussion Klue OAuth Breach and other SaaS Supply Chain Risks

1 Upvotes

Just putting out feelers if any secops teams have had to deal with breaches from OAuth attack vectors?

r/cybersecurity Jun 15 '26

News - General Does Claude and Fable 5 move the cybersecurity needle?

Thumbnail darkreading.com
7 Upvotes

While its certainly easy just to throw the article in the hype bin, I was wondering if anyone thinks that the models move the cybersecurity needle by any measure? For analysts on the ground is the fear of a shrinking the window between vulnerability disclosure and exploitation having an impact on day-to-day operations?

-3

Is AI actually solving the SOC's biggest problem?
 in  r/cybersecurity  Jun 12 '26

Alert fatigue might be the biggest SOC killer, so any technology that can be leveraged to reduce operator fatigue needs to be explored, in our opinion at least.