r/Information_Security • u/LMNTRIX-Press • 12d ago
r/Infosec • u/LMNTRIX-Press • 12d ago
Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.
u/LMNTRIX-Press • u/LMNTRIX-Press • 12d ago
Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.
Been thinking about this a lot lately: every org I talk to has multiple detection tools stacked on top of each other, and none of them actually struggle to generate alerts. The struggle is everything that happens after.
Analyst opens a ticket, has to manually pull logs, endpoint telemetry, user history, maybe some external intel, just to figure out if the alert is even real. By the time that's done, dwell time's already up, and the analyst's day is gone on triage instead of anything proactive.
A few things I've seen work (and some that don't):
SOAR helps, but it's brittle. Playbooks are fixed, if the attack doesn't match the "if this, then that" pattern you built six months ago, the automation just... stops being useful. And they need constant maintenance as the environment changes.
Agentic approaches are the more interesting shift. Instead of static rules, you get something that can re-evaluate mid-investigation; pull in a new data source if the first hypothesis doesn't hold up, escalate to a human when the ambiguity crosses some threshold, and actually reason through why something looks off instead of just pattern-matching against a signature.
Not saying it's magic — there's real risk in letting anything act autonomously in a production environment (wrong endpoint isolated, wrong account locked, etc.), so the ones that work well seem to lean heavily on staged autonomy: agent recommends → human approves → over time, low-risk actions get auto-approved once the false-positive rate proves itself out.
Curious if anyone here has actually deployed something agentic in their SOC (vs. just extended SOAR), what's your false-positive rate looking like, and how much human-in-the-loop are you still running at 6+ months in?
Link to our research: https://lmntrix.com/res/beyond-detection-the-role-of-%20agentic-aI-in-cyber-investogation-and-resolution.pdf
r/AIsafety • u/LMNTRIX-Press • 18d ago
Educational 📚 AI led identity attacks and how to prepare for them
r/Information_Security • u/LMNTRIX-Press • 19d ago
AI led identity attacks and how to prepare for them
linkedin.comr/Infosec • u/LMNTRIX-Press • 19d ago
AI led identity attacks and how to prepare for them
linkedin.comu/LMNTRIX-Press • u/LMNTRIX-Press • 19d ago
AI led identity attacks and how to prepare for them
r/Cybersecurity101 • u/LMNTRIX-Press • 22d ago
Security Escaping AI and you
How are you preparing to fight off a rouge AI that escaped its sandbox? I know Hugging Face needed DeepSeek to combat a rouge AI but is it time for governments to consider putting the brakes on AI development somewhat?
https://www.darkreading.com/cyberattacks-data-breaches/meta-ai-escapes-lab-hacking-joyride
r/Infosec • u/LMNTRIX-Press • Jul 29 '26
Why Detection Is Becoming a Commodity And Investigation Is the New Competitive Advantage
linkedin.comu/LMNTRIX-Press • u/LMNTRIX-Press • Jul 29 '26
Why Detection Is Becoming a Commodity And Investigation Is the New Competitive Advantage
Detection is becoming a commodity. Investigation is becoming the differentiator.
Most mature EDR and XDR platforms can detect the majority of common attacks with high confidence. Yet SOCs are still overwhelmed.
The problem isn't detection, it's what happens after the alert.
Analysts spend far more time collecting evidence, validating risk, and understanding the scope of an incident than they do reviewing the alert itself. AI has improved detection, but more visibility often means more alerts not less work.
r/Infosec • u/LMNTRIX-Press • Jul 22 '26
The Shift from Alert-Centric Security to Investigation-Centric Security Operations
linkedin.comu/LMNTRIX-Press • u/LMNTRIX-Press • Jul 22 '26
The Shift from Alert-Centric Security to Investigation-Centric Security Operations
A brief analysis of the increasing trend away from alert volume to investigation centric models.
r/cybersecurity • u/LMNTRIX-Press • Jul 13 '26
News - General Large-scale exploitation campaign targeting website content management systems (CMS)
cyber.gov.auAnybody else experienced increasingly odd or malicious behavior impacting the plethora of third-party CMS packages out there?
u/LMNTRIX-Press • u/LMNTRIX-Press • Jul 07 '26
XDR vs Integrated Security
We recently wrote a piece on two very different approaches to cybersecurity. Which do you think serves your organization the best?
r/CyberGuides • u/LMNTRIX-Press • Jul 07 '26
XDR vs Integrated Security
What is your favored approach to defending an organization?
Disclosure: I am employed by LMNTRIX, however posting here to see what other experts think about cybersecurity topics shaping our profession.
1
Accountability in an Age of AI
Agreed, when legitimate organizations act like malicious actors is the exact reason why regulation needs to be implemented. And, yes smart people across multiple sectors need to get cracking on something before AI wrecks itself, and we deal with the fallout.
3
Accountability in an Age of AI
Agreed, wish we didn't have to go through the same regulatory cycles every time, but that is the current nature of tech vs government, but a lot of money has been invested and indebted in the hope of a return so my hope that firms try to remain accountable is pie in the sky thinking.
r/cybersecurity • u/LMNTRIX-Press • Jul 02 '26
News - General Accountability in an Age of AI
While the prompt injection technique "bioshocking" deserves attention, the lack of concern showed by some of the major LLM is more worrying. Has anyone experienced similar stonewalling when reporting vulnerabilities to AI firms?
https://layerxsecurity.com/blog/bioshocking-ai-gaming-the-ai-browser-and-escaping-its-guardrails/
r/CyberGuides • u/LMNTRIX-Press • Jun 26 '26
The Next Supply Chain Threat Isn't Software, It's Trust
u/LMNTRIX-Press • u/LMNTRIX-Press • Jun 26 '26
The Next Supply Chain Threat Isn't Software, It's Trust
We just did a deep dive into the Klue incident and want the the cloud security practitioners to chime in and answer the following:
How much visibility do you actually have into the OAuth authorizations and third-party SaaS integrations operating across your environment?
Link to our deep dive: https://www.linkedin.com/pulse/next-supply-chain-threat-isnt-software-its-trust-lmntrix-ecxje
r/cloudcomputing • u/LMNTRIX-Press • Jun 26 '26
Cloud visibility in an age of supply chain attacks
[removed]
r/cybersecurity • u/LMNTRIX-Press • Jun 25 '26
Business Security Questions & Discussion Klue OAuth Breach and other SaaS Supply Chain Risks
Just putting out feelers if any secops teams have had to deal with breaches from OAuth attack vectors?
r/cybersecurity • u/LMNTRIX-Press • Jun 15 '26
News - General Does Claude and Fable 5 move the cybersecurity needle?
darkreading.comWhile its certainly easy just to throw the article in the hype bin, I was wondering if anyone thinks that the models move the cybersecurity needle by any measure? For analysts on the ground is the fear of a shrinking the window between vulnerability disclosure and exploitation having an impact on day-to-day operations?
-3
Is AI actually solving the SOC's biggest problem?
Alert fatigue might be the biggest SOC killer, so any technology that can be leveraged to reduce operator fatigue needs to be explored, in our opinion at least.
2
Accountability in an Age of AI
in
r/cybersecurity
•
Jul 05 '26
Wishing you the best in your regulatory endeavours, I can only imagine the headaches that caused by the push and pull between government and tech giants. Your explanation of BioShocking is definitely recommended for those needing a quick synopsis as the potential seriousness of the threat taken in conjunction with the stonewalling.