Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Inside SECNAP: An Agentic MDR Platform Built on LimaCharlie

Joshua Strickland from SECNAP shows how his team built a full agentic MDR platform on top of LimaCharlie. SECNAP layers its own customer portal and SOC workflows directly on LimaCharlie's API, giving AI agents the same access to telemetry and response actions as a human analyst. Joshua will walk you through the customer portal, the SOC dashboard, and a live attack simulation on a sandboxed machine, including how AI agents handle tier one and tier two triage with Sonnet and Opus, and how a human analyst reviews and approves response actions before anything ships.

Ship a Working Detection Pipeline in One Workshop: Headless SOC with Grid by LimaCharlie

By the end of this hands-on workshop, you will have deployed a working detection pipeline, ingested a cloud log source, and shipped a bespoke dashboard app, all using Claude Code integrated with Grid by LimaCharlie. Along the way, you will see how Grid compresses the traditional SIEM/EDR/SOAR stack into a single automated workspace. We go well beyond standard EDR and SIEM use cases. What to expect.

Proving the value of security operations with Christopher Crowley [344]

Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.

Intel Chat: Shai-Hulud is back, model pinning & the token spend problem [343]

Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two. No prep doc, no script: just what Matt and Chris were actually hearing on the floor. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.

Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

The most helpful AI agent is the least secure one

The most pleasant agentic AI system is the least secure one. That's the trap Rob van der Veer, Chief AI Officer at Software Improvement Group, lays out clearly: the agent that never says "permission denied" is the agent everyone loves to use. It always works. So we open up all the privileges just to keep it that way. He says we should do the contrary.

Building trustworthy AI with Rob van der Veer [341]

Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.

LimaCharlie Cloud Security: CNAPP Walkthrough

A walkthrough of Cloud Security in LimaCharlie — CNAPP capability built into the SecOps Cloud Platform. Connect your cloud and SaaS providers (AWS, GCP, Azure, Okta, Google Workspace, GitHub, Cloudflare, Anthropic, and even other LimaCharlie orgs) and everything is normalized into a single security graph: identities, permissions, workloads, and data. The engine reasons over that graph to surface attack paths — evidence-backed chains an attacker could actually walk — instead of isolated checkbox findings.

LimaCharlie 101: EDR deployment, detection rules, and threat intelligence

This workshop will cover the basics of the LimaCharlie SecOps platform. You will learn how to deploy EDR agents, gather additional telemetry and write detection and response rules, and integrate threat intelligence and YARA rules to detect and mitigate threats. Key Learning Objectives: Endpoint Detection and Response (EDR) Agent Deployment and Management: Learn the best practices for deploying LimaCharlie EDR agents across diverse environments. Understand the various deployment methods, agent configurations, and how to effectively manage agent health and status at scale.

Is this the end of human-written code?

Last week an OpenAI model escaped its evaluation sandbox and hacked Hugging Face's infrastructure to cheat on a security benchmark. We recorded a special episode of AI Chat about it. Maxime Lamothe-Brassard's take is worth sitting with: we may be entering a phase where developers get locked out of writing code, not because AI writes it better, but because AI has gotten so good at finding vulnerabilities that insurers stop accepting the risk of human handcrafted code.