Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Episode 16 - Beyond the Black Box: Solving Data Overload with Agentic Triage

In this episode, host Richard Bejtlich sits down with Dave Getman to discuss the evolution of Corelight Investigator and the paradigm shift from delivering raw sensor data to providing agentic triage. They explore how AI can synthesize millions of log lines into concise, actionable determinations—categorizing activity as malicious or benign—while maintaining transparency by "bringing the receipts" of raw evidence. Dave explains why the security pendulum is swinging back toward network detection to counter sophisticated EDR evasion and shares a roadmap for the future of auto-containment.

Identity in the SOC: Why network visibility still matters in the age of the identity perimeter

Long gone are the days where usernames were all you needed to secure a network. The same is true for your Security Operations Center (SOC) analysts trying to investigate a threat. "Who is jdoe05 and why are they logging into this server?" is a critical question to answer during an investigation, one that neither NDR (Network Detection and Response) nor EDR (Endpoint Detection and Response) can answer directly. Enter the Identity Provider (IdP).

Why Speed is Changing the Game in Cybersecurity

This YouTube Short dives into how cybersecurity is evolving in today’s digital age. While the threat from attackers is nothing new, what's changed is the speed at which they can act, thanks to advancements like Frontier AI. This acceleration is reshaping how we manage vulnerabilities, challenging traditional security methods that depend on human involvement. Learn why grasping this shift is essential and how the Control Gap White Paper offers insights into the future of cybersecurity.

What Santa Clarita Businesses Should Look for in a Managed IT Services Provider

Technology has become a core part of how modern businesses operate. From cloud apps and remote work tools to cybersecurity, data backup, and helpdesk support, companies rely on their IT systems every day. For businesses in Santa Clarita, the right managed services provider can make a major difference. A strong provider does more than fix computers when something breaks. They help protect your network, support your employees, improve uptime, and plan for future growth.

5 Mindset Shifts for Security Teams with Gal Yosef

In this episode, Gal Yosef, Head of Product Management at AlgoSec, explores the five critical mindset shifts security teams must make to successfully secure today’s hybrid and multi-cloud environments. As organizations expand across AWS, Azure, GCP, and on-premises infrastructure, traditional security approaches often create silos, visibility gaps, and operational complexity.

Shifting CEO Focus: From Detection to Containment in Cybersecurity

Discover why CEOs need to rethink their cybersecurity strategies for 2023. Instead of merely asking, "Are we patched?" they should focus on "Are we exposed?" Emphasizing the importance of containment over detection, this short highlights the critical role of AI in defense strategies and the necessity for swift action to prevent widespread business disruptions. Learn how CEOs can effectively prioritize their efforts on critical systems and empower their teams to act with authority, ensuring business continuity in the face of evolving cyber threats.

Provably better data

Every security vendor says their data is better. Corelight decided to test that claim directly. Using real nation-state attack scenarios, including Salt Typhoon-related activity, the same AI model was evaluated against multiple security data sources to measure investigation accuracy, threat visibility, and incident response coverage. The only variable was the data.