Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 1 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.

A double-edged bleeding edge: Classifying AI threats

Sophos X-Ops presents a working taxonomy for attacks using, and targeting, AI Conversations about ‘AI threats’ typically collapse into one of two extremes. On the one hand, hype: unverified claims that don’t hold up to scrutiny and invite significant criticism. On the other, dismissal: it’s just old tradecraft with new branding.

AI Powered Threat Detection: CISO's Guide

The market is giving CISOs a blunt signal. AI-powered threat detection and response was valued at USD 5.59 billion in 2024 and is projected to reach USD 23.52 billion by 2032, at a 20.00% CAGR according to Kings Research on the AI-powered threat detection and response market. That kind of growth doesn't happen because security teams like new tooling. It happens because modern environments generate more telemetry than analysts can realistically review, and attackers move faster than rule updates.

Strengthening modern detection with Open NDR and integrated threat intelligence

Adversaries are evolving faster than defenders can respond, and they're weaponizing AI to accelerate their attacks. We’ve seen “living-off-the-land”, lateral movement, and the abuse of legitimate administrator tools enable hackers to hide in plain sight, diluting the effectiveness of traditional detection methods. Meanwhile, defenders are nervously trying to keep up with the accelerating pace of AI-empowered threats hitting them at machine speed.

The Cybersecurity Poverty Line: Why it exists and why Sophos exists to erase it

The Cybersecurity Poverty Line: Why it exists and why Sophos exists to erase it Erase is an ambitious word. We chose it because the agentic era of AI creates a genuine opportunity to change the equation. There are roughly 359 million businesses in the world. Fewer than 35,000 of them employ a CISO. Every framework, product taxonomy, analyst report, compliance regime, and piece of cybersecurity marketing in circulation assumes a senior security leader on the other end.

Episode 17 - Home Labs and Tinted Windows: Why Network Visibility Starts at Your Front Door

In this episode, host Richard Bejtlich and guest Ricky Lin explore the practical—and often personal—side of network defense: monitoring the home network. Ricky shares how he uses Corelight and Zeek to track everything from his children's YouTube habits to the constant chatter of IoT devices like Tesla vehicles and smart appliances. They delve into the "tinted windows" analogy to explain why visibility into encrypted traffic is still possible through network metadata, even when the contents are hidden.

Threat Detection and Response Solutions: A Complete Guide

For those evaluating threat detection and response solutions, the underlying issues are often a persistent reality: The firewall says one thing, the endpoint tool says another, cloud alerts pile up in a separate console, and the compliance team still asks for evidence that no one can assemble quickly. Analysts waste time pivoting between tools when they should be deciding whether an incident is real and what to contain first.

Corelight Sensor v29.1 release highlights: Network evidence powers network operations

Corelight Sensor v29.1 and Fleet Manager v29.1.1 fundamentally expand what a Corelight Sensor delivers. The release turns existing network evidence into a shared source of truth for SecOps, NetOps, triage, and forensic investigation. Network performance monitoring and asset classification unlock new value from traffic you're already collecting.

Extending the value of network evidence: Introducing Performance and Asset Visibility

Every packet flowing through a Corelight sensor contains both security-relevant data and performance-relevant data. Until now, Corelight has focused exclusively on extracting security value from network traffic: connection logs, protocol analysis, and threat detections. But the same traffic that reveals lateral movement also reveals TCP latency. The same DNS queries that surface potential C2 channels also reveal resolution timing.

Performance and Asset Visibility Walkthrough

Network security depends on clear visibility across every digital asset. This detailed walkthrough covers Corelight's new Network Performance and Asset Classification logs. You will learn about these two logs, how to configure them, and how to use them during cyber investigations. Network Performance and Asset Visibility logs are available as part of the Sensor v29.1 general availability release to customers with Sensor and Investigator Bundle licenses.

Performance and Asset Visibility Demo

Network security depends on clear visibility across every digital asset. In this brief demo, we will see how Corelight's new Network Performance and Asset Classification logs can be referenced when doing a threat hunt. You will learn about the logs and what information they contain. Network Performance and Asset Visibility logs are available as part of the Sensor v29.1 general availability release to customers with Sensor and Investigator Bundle licenses.

Real Time Threat Detection

Weekly cyberattacks now average 1,968 per week, up 18% year over year and 70% since 2023, while security teams still take an average of 277 days to identify and contain a breach, according to SentinelOne's cybersecurity statistics roundup. That combination changes the meaning of “real time” in security. It no longer means a dashboard that updates quickly. It means building detection and response so attackers don't get months of freedom between first access and containment.

What is Application Threat Detection and How Does it Work?

Security threats don’t announce themselves. They can slip in through vulnerabilities in your code, hide in third-party libraries, and exploit gaps that your team hasn’t had time to patch yet. That’s why application threat detection isn’t just a nice-to-have; it’s the foundation of a modern security program.

Ransomware Detection: Master Modern Strategies 2026

In 2024, ransomware was publicly disclosed in more than 5,600 attacks worldwide, with over 2,600 victims in the United States alone. The same reporting says the FBI's 2024 IC3 report logged 3,156 ransomware complaints, an 11.7% increase from the prior year, which is a useful reminder that this isn't a niche malware problem. It's a persistent operational risk that keeps showing up across sectors and environments (Fortinet's ransomware statistics summary).

Why Security Tools Alone Can't Eliminate Operational Risk

The company had done what most security consultants recommend. They invested in endpoint protection. Employees completed cybersecurity training. Multi-factor authentication was enabled across critical systems. Network monitoring tools generated alerts around the clock. Regular software updates were enforced through company policy. On paper, the organization appeared well protected.

We Gave OpenClaw Red Team Tools (It Found Domain Admin)

Our Red Team handed OpenClaw a penetration testing toolkit and pointed it at one of our own legacy Active Directory networks. 23 findings across 11 attack paths... But the findings aren't the interesting part. What's interesting is how it got there. Work that takes our human team three days took the agent three hours. Mid assessment it hit a wall, reasoned about its own limitations and proposed spinning up an EC2 GPU instance to crack a password hash. Nobody told it to.

Sophos recognized for endpoint leadership in SE Labs Awards 2026

Sophos recognized for endpoint leadership in SE Labs Awards 2026 Independent testing confirms what our customers already know: Sophos Endpoint delivers consistent, real-world protection at every tier of the market, from the largest enterprises to small businesses. We’re proud to announce that Sophos has won three awards at the SE Labs Awards 2026: Enterprise Endpoint (Windows), Small Business Endpoint (Windows), and Small Business Security Development.

Black Hat Asia 2026: Everything from cat feeders to solar farms

There is a saying you will hear from veterans in the Black Hat Network Operations Center (NOC): “Threat hunting on the Black Hat network is like trying to find a needle in a stack of needles." With dozens of training classes running live exploit chains, capture-the-flag traffic, and researchers probing every corner of the internet, our Corelight sensors generate a rich set of Zeek logs, many of which can look suspicious in varying degrees.

The North Korean IT worker scam: Defending against the modern insider threat

The threat is coming from inside the organization. It is coming from a laptop farm three states over, routed through a proxy, and operated by a threat actor sitting on the other side of the globe. We are witnessing a massive shift in how adversaries breach organizations. They no longer need to spend weeks probing your external firewalls or crafting the perfect zero-day exploit. Instead, they simply update their resumes, pass your interview process, and your IT department ships them a corporate device.

Episode 16 - Beyond the Black Box: Solving Data Overload with Agentic Triage

In this episode, host Richard Bejtlich sits down with Dave Getman to discuss the evolution of Corelight Investigator and the paradigm shift from delivering raw sensor data to providing agentic triage. They explore how AI can synthesize millions of log lines into concise, actionable determinations—categorizing activity as malicious or benign—while maintaining transparency by "bringing the receipts" of raw evidence. Dave explains why the security pendulum is swinging back toward network detection to counter sophisticated EDR evasion and shares a roadmap for the future of auto-containment.

Identity in the SOC: Why network visibility still matters in the age of the identity perimeter

Long gone are the days where usernames were all you needed to secure a network. The same is true for your Security Operations Center (SOC) analysts trying to investigate a threat. "Who is jdoe05 and why are they logging into this server?" is a critical question to answer during an investigation, one that neither NDR (Network Detection and Response) nor EDR (Endpoint Detection and Response) can answer directly. Enter the Identity Provider (IdP).

Aurora Mobile Threat Defense - Addressing Your HighestTrusted, Least Protected Endpoints

Mobile devices are becoming the highest‑trusted endpoints that are the least protected. They approve logins. They hold authentication apps. They carry email, collaboration, and business applications. And they travel everywhere your workforce travels: across corporate networks, home Wi‑Fi, airports, hotels, and cafés. That combination (high trust plus constant movement) is why mobile has become such a reliable entry point for credential theft and account takeover.

Provably better data

Every security vendor says their data is better. Corelight decided to test that claim directly. Using real nation-state attack scenarios, including Salt Typhoon-related activity, the same AI model was evaluated against multiple security data sources to measure investigation accuracy, threat visibility, and incident response coverage. The only variable was the data.

Bridging the gap: How Corelight and Crowdstrike Charlotte AI are redefining SOC investigations

For years, SOC analysts have lived in a world of swivel-chair analysis. When an alert fires in an endpoint tool, the next step is almost always a manual pivot to a network console to see if the network reality matches the host behavior. This manual back-and-forth isn't just tiring; it’s a window of opportunity for attackers. Corelight is excited to highlight a new integration with CrowdStrike Charlotte AI.

Corelight Brings Network Data to Cisco Cloud Control | Corelight

Corelight, a leader in fueling the AI SOC, today announced that it is providing industry-leading data to power AI investigations of emerging threats through an integration of Corelight Open NDR into Cloud Control Studio. Cloud Control Studio is the design space within Cisco Cloud Control, Cisco’s unified platform for agentic IT operations, where customers can build AI agents and connect them to non-Cisco tools.

How BlueVoyant's ASIM-First Strategy Simplifies Threat Detection in Microsoft Sentinel

Earlier this year, BlueVoyant adopted a new detection strategy built on the Advanced Security Information Model (ASIM). For those unfamiliar, ASIM is Microsoft's normalisation layer that standardises log data across products into consistent schemas. Our approach is simple: The result? Dramatically faster use case development and cleaner, more maintainable detection logic.

Why Your Detection Latency Budget Determines Blast Radius

Most teams buy detection on a single number. The datasheet says “millisecond detection,” the proof-of-concept fires the instant a test payload lands, and the box gets checked. Then a real AI agent incident runs in production, and the postmortem shows the attack completed its objective well before anyone contained it, even though the alert, technically, fired in milliseconds. The number was real. It just measured the wrong thing.