The "Hunt First" AI Security Strategy

View Show Notes and Transcript

Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-bad SIEM alerts, you may be missing the silent breaches.  In this episode, Ashish is joined by Damien Lewke, Founder and CEO of Nebulock, to discuss the critical shift toward a "Hunt First" mindset. Damien explains why moving away from alert fatigue and focusing on raw, normalized telemetry (across endpoint, identity, and cloud) is the only way to proactively surface unknown threats. We also dive into how AI is finally democratizing the elite skill of threat hunting, allowing even single-person security teams to investigate and attribute complex behaviors.From hunting down shadow AI (like unapproved MCPs) to challenging the notion that AI will replace threat hunters, this episode is a masterclass in modern security operations.

Questions asked:
00:00 Introduction: The Problem with Reactive Security Alerts
02:00 Damien Lewke’s Background (DoD, CrowdStrike, Arctic Wolf, Nebulock)
04:00 Why Breaches Happen in Silence: The Value of Telemetry Over Alerts
05:30 How AI Democratizes Elite Threat Hunting for Small Teams
07:30 Defining the "Hunt First" Mindset and Methodology
11:00 Surfacing Active Intrusions Using Cross-Domain Context
13:30 The Importance of Transparency in AI Decision Making
16:30 When NOT to Use AI for Detections (The Power of Heuristics)
18:30 The Best First AI Security Use Case: Hunting Shadow AI & MCPs
23:00 Detecting Rogue AI Agents via Tempo, Breadth, and Automation Signatures
28:30 The Future of SIEM: Data Gravity vs. Purpose-Built Security Analytics
34:30 Disagreeing with Gartner: Why Threat Hunters Are More Vital Than Ever
40:00 The 89% Rise in AI-Augmented Attacks and Taking Action
41:30 The "You Laugh, You Lose" Cybersecurity Joke Challenge

Damien Lewke: [00:00:00] 82% of all intrusions don't involve any sort of malware. AI-augmented or AI-generated attacks are up 89% year over year. Breaches happen in silence. Breaches happen because we miss something.

Ashish Rajan: I only have six people, each one of them doing at least fifty, sixty tickets a day. Yeah. By the time you multiply that, there's not enough time for threat hunting at this point.

Damien Lewke: We have surfaced over four thousand active incidents. So active intrusions that otherwise would have been missed by just focusing on alerts. Open-weights models are actively being distilled, and two dudes in a GPU can point their rig at an environment and go to town. No one's writing signatures or detections for this.

Damien Lewke: And after a couple weeks, unbeknownst to anybody, it goes out and it touches a production DB. That's no one's fault. You were allowed to do it. Does everybody know something I don't? The answer is no. The cool thing about AI is we are all learning this at the same time. The time to exploit is shrinking from months to weeks to minutes.

Ashish Rajan: Yeah. Most people don't start with threat hunting as the first [00:01:00] thing they build in security organizations, especially when you build a security program. I had a great conversation with Damian Lukey, who is trying to change that conversation. In this Hunt First conversation, we spoke about what does it take to start building Hunt First as a methodology, no matter what the size of your organization.

Ashish Rajan: You don't have to wait till a certain level of maturity before you start doing threat hunting. We spoke about the challenges of building a threat hunting, why, if you are a purist of threat hunting, you may enjoy the fact that AI is actually making your job better. We also spoke about some other things like, hey, it is possible today than ever before, thanks to AI, to enable your organization to be threat hunting for looking for patterns, anomalies, uh, through telemetry instead of just trying to focus on what your SIEM gives you.

Ashish Rajan: So if hunting first and threat hunting is important for you, I'll definitely check out this episode with Damian Lukey. And as always, if you have been listening or watching an episode of the podcast for a while and have been finding it valuable, I would really appreciate if you drop the follow or subscribe button, whichever podcast platform you follow us on, whether it's [00:02:00] YouTube, LinkedIn, Spotify, or Apple.

Ashish Rajan: I hope you enjoyed this episode with Damian. I'll talk to you soon. Hello, and welcome to another episode. I've got Damien with me. Hey, man. Thanks for coming on the show.

Damien Lewke: It's good to be here again, Ashish.

Ashish Rajan: I mean, dude, I'm, uh-- I enjoy my conversation so much. I, I think we didn't even recor- we didn't realize we were recording until we kinda just kept going.

Ashish Rajan: But just for, uh, for people who may not have, uh, seen your previous episode, could you share a bit about yourself, your professional background?

Damien Lewke: Yeah, absolutely. So, uh, I'm Damien. I'm the founder and CEO of Nebulock. Nebulock is a hunt first agentic security operations platform. My background, uh, so I've only ever spent my career in security.

Damien Lewke: I began my career in the DoD, building out the threat hunting and cyber ops team for a large weapon system. I left that and joined CrowdStrike after the Series C, got a chance to, got a chance to build and run the, uh, engineering integrations team and tech partnership with Secureworks through our IPO. Uh, spent a couple years out in Australia doing major account sales engineering with, with Palo Alto Networks before going back to school at MIT, studying natural language processing [00:03:00] algorithms at our computer science AI lab.

Damien Lewke: And then I ran the AI detections, intelligence, and security research product teams at Arctic Wolf. So I was in charge of the team that built the detection systems for our 1,200-person SOC and 10,000 customers by proxy. Yeah. So always been in and around hunting, detections, and cyber ops. Uh, very, very grateful.

Damien Lewke: It's been a, uh, a great ride.

Ashish Rajan: And it's an interesting background as well because a lot of conversation for AI at the moment is focusing on, hey, security for AI and AI for security, and the AI for security component seems to land on SOC level one automation to- Mm-hmm ... to a large extent. And I think it's probably because it's maybe easier to count the ROI 'cause I can see how many full-time whatever.

Ashish Rajan: Yeah. You almost feel-- I, I'm, I, I don't know where you sit on this, where having done this, um, vast amount of experience across the detection space- Mm-hmm How has AI changed that for you, and w-where do you feel people are over-indexing versus how they should approach the AI for [00:04:00] security, uh, conversation?

Damien Lewke: Yeah. Starting with what's the problem we're trying to solve. Coming from an MDR's perspective, I get the ROI and the value of closing tickets. Um, when you have hundreds or thousands of alerts that you need to deal with, that's a really easy metric to quantify. So the ROI is quantifiable, but I think it's asking the wrong question.

Damien Lewke: Breaches happen in silence. Breaches happen because we missed something. We didn't have full visibility and context. We missed a series of completely benign signals that together are malicious. So when I think of AI for security, it's a great start, and we've automated, uh, what I would call the, the reactive component of security.

Damien Lewke: But if you really wanna use AI effectively for security, you wanna look at first principles and solve for the breach. So you wanna use AI to find those low and no-signal events that tell you how and where you missed something. Because no matter how many known bad things you solve for, it's the unknown bad, it's the signals that we miss, [00:05:00] that ultimately lead to those devastating breaches that we read about in The Wall Street Journal and other places.

Ashish Rajan: I'm with you on this because a lot of people have spent a lot of time and money on the reactive controls, right? I think in, in fact, it's easier to report on versus the threat hunting part, which I feel a lot, a lot of people feel, "I have to be a certain size and certain maturity before I can start doing that."

Ashish Rajan: Yeah. I see you smiling already. So is, is that, like, is that misplaced today with AI? That I have to be a certain size or have certain level of maturity? Like, I need special people in my team- Mm-hmm ... because without them, I can't do this.

Damien Lewke: Yeah, 10 years ago, security was very different, and this idea of threat hunting was reserved for a few very specialized people and skill sets, or people might outsource it as a, as a service.

Damien Lewke: What does AI do fundamentally, particularly in security operations? It, it democratizes things. On the attacker side, right, the time to exploit is shrinking from months to weeks to minutes. Yeah. On the defensive side, what it's allowed us to [00:06:00] do is democratize this very elite skill set of threat hunting, and by proxy detection engineering as well, to any organization.

Damien Lewke: So, you know, our smallest customer is an 85-person passwordless company with one full-time security operator. Oh. But our largest is a 130,000 for- person Fortune 500. Yeah. I, I, I think the key thing is when it comes to understanding what threat hunting is and how it applies to my environment, the, the questions I would ask myself are: Do I wanna shift from a wait for bad things to happen?

Damien Lewke: Do I wanna shift from a reactive to a proactive approach? And I think pretty much everybody does. Mm. Do I want to focus on not the threats that we understand, but rather what's gonna have a deep and meaningful impact to my business? And, you know, translating that to how that applies to threat hunting for any organization is, now that I have access to a capability in the form of AI and agents, can I apply that [00:07:00] to my environment?

Damien Lewke: And as long as you invest in General security hygiene, you do some sort of logging and aggregation, you're running an EDR, for example, you can already get threat hunting. Yeah. It's not something that is reserved for the few. And I'm so, so happy to see that because a lot has changed with AI, and this is definitely one of those positives for the network defender that you now can actually start threat hunting no matter how big you are.

Ashish Rajan: You have been talking about the hunt first- Yes ... analogy for some time. Mm-hmm. Could you describe that a bit more? So is that where it comes from? That to your point, everyone can... It actually doesn't have to be like a highly skilled, sophisticated hacker. Yeah. It's available generally for everyone to use as long as you have the right mindset towards.

Ashish Rajan: So how do you describe hunt first, uh, as, that you guys been promo- promoting?

Damien Lewke: Yeah. Hunt first, uh, as a definition. So hunt first is all about a mindset. You're proactive by default. What hunt first actually means is threat hunting is not asking a question. It's following a structured framework that's aligned to your [00:08:00] organization's risk, and using agents, in Nebulaq's case, to democratize and accelerate the threat-informed defense approach from, okay, I know what actors are targeting me, I have all of this telemetry and data, and providing a system that continuously hunts over it, continuously looks for, identifies, validates, and attributes anomalous behavior.

Damien Lewke: But importantly then has the context to say, "Hey, here's what I saw. Here's what it means to your organization, and here's what to do about it." So hunt first is a mindset. Yeah. And that's really what we've been able to do at scale. I mean, even since you and I last spoke- Yeah ... as a company, we've more than doubled in size in terms of employees and customers, and it's, it's been really exciting to see how this esoteric idea of threat hunting has really started to go mainstream.

Damien Lewke: Yeah. But when you apply that proactive by default approach and looking at telemetry, not alerts- The downstream benefits that so many organizations get. [00:09:00]

Ashish Rajan: Interesting. Just double-click on that for me, 'cause I think- Yeah ... uh, most people have SIEM and they get l- well, let's just say tons of alerts. Yes. That, and traditionally, we have just been building, uh, the, the, at least the SOC team that I built- Mm-hmm

Ashish Rajan: we were focused on a, okay, how many alerts do we get from our SIEM? Yep. How many people do we need realistically who can go through X number of tickets in a day? Yep. The, the thought process for building that team has usually been around, and th- one of the reasons why people never get to threa- threat hunting is because, well, I only have six people.

Ashish Rajan: Mm-hmm. Each one of them doing at least 50, 60 tickets a day. Yep. By the time you multiply that, there's not enough time for threat hunting at this point in time.

Damien Lewke: Exactly.

Ashish Rajan: Right. So how... Uh, e- explain to me in terms of why telemetry over alerts c- and doesn't that make it expensive then? 'Cause I think most people would have gone, "The reason I have alerts-" Yeah

Ashish Rajan: is because SIEM only, already gets, like, limited supply of logs." Yep. So how, what, how do you approach that?

Damien Lewke: Yeah. Um, I think let's start with the alerts versus telemetry discussion. Yeah. The [00:10:00] amazing thing about alerts is you know that they're bad. You know that there is something that has happened- Yeah

Damien Lewke: that some vendor has told you requires investigation. That's right. The amazing thing is automation, agents, there are so many capabilities out there today that allow you to take a sea of known bad alerts and streamline that whole process. Yeah. Telemetry is so much more valuable because we do all of this log aggregation and storage because we know that these alerts don't catch everything.

Damien Lewke: But if I operate under the assumption that if I focus on closing all of these tickets, and I understand why because of stocks and flows and we wanna measure output- Yeah, yeah ... and it allows us to justify investment, if we're just focusing on the alerts problem, then the whole reason we stored all of this data, the reason your Splunk bill is $5 million a year never gets realized.

Damien Lewke: You're not actually doing anything with that data. Yeah. So the hunt first approach really is if we remove the alerts and we focus on the [00:11:00] underlying data, if we understand what's been alerted and we know what hasn't- Mm. I continuously query and look at that dataset and surface other signals that otherwise have gone missing.

Damien Lewke: A great example of this, um, so, you know, uh, if you have identity, endpoint, and cloud telemetry all logged into your SIEM-

Ashish Rajan: Yeah ...

Damien Lewke: if an Okta API token gets used, not a bad thing. If it's used to authenticate into a MacBook, not a bad thing. If that MacBook opens up the AWS CLI and accesses infrastructure, not necessarily a bad thing.

Damien Lewke: But if you look at all of those in concert as a series of events and then go, "Well, hey, wait a minute. That API token looks to have been stolen," well, I have access... Yeah, I, I, I have direct evidence of an active, persistent intrusion in my environment. So hunt first is [00:12:00] separating the alerts, focusing on the data- Yeah looking at various signals, and then in a sequence, in the context of your organization's risk, going, "Actually, this is far more concerning than we otherwise might have thought." This is something I, I, I'd say just i- in that vein to, to back it up with, with evidence, we've had the opportunity to run over 300 million agentic investigations.

Damien Lewke: Right. So this whole hunt first approach. And to be fair, not every single one is gonna yield something bad, but we have surfaced over 4,000 active incidents- Mm ... including the one I just used. So active intrusions that otherwise would've been missed by just focusing on alerts.

Ashish Rajan: But maybe just to put some context there, 'cause you mentioned the example of that organization with 85 people- Yep

Ashish Rajan: uh, in there. You almost also, as, as a, as an experienced CISO or experienced security person, you probably... People who are listening or watching would go, "Well, the reason why I didn't do threat hunting is because I didn't have the right kind of skill set in the team."

Damien Lewke: Yeah.

Ashish Rajan: So now I'm, I get it. The technology has come in.

Ashish Rajan: I have the [00:13:00] metrics. I have the telemetry to prove- Mm ... that I can get a lot more information.

Damien Lewke: Yeah.

Ashish Rajan: But it's like saying- I would be con-- I would be nervous giving that to an intern or someone who's young going, "There are plenty of signals." Yep. Follow, follow them. You know what I mean? Like- Go for it. Yeah ... so, so how do you gain that confidence in what AI is producing?

Ashish Rajan: 'Cause a lot of people, obviously, there is that whole notion of there's hallucination and all that as well. But at the same time, you don't want to miss a hallucination. Even if it turns out to be a false positive, that's okay. At least you've gone down that path. So- Yeah ... how, how, how do, how do you see people balance that?

Ashish Rajan: With, uh, one side you have the talent capability where- Mm-hmm ... you can't have an expensive, super talented resource. On the other side, you have a lot of resources- Yeah ... but then the question of trust is still there. How do you, uh... At least how are you finding your customers finding building that trust with the output from the AI?

Damien Lewke: Yeah. And beyond Nebulock, of course, would love everybody to be a Nebulock customer. But I understand, uh, everybody's on their own journey. If I were to use an agentic system as a customer, [00:14:00] I would require transparency. Mm. So the way that we really focus on it is, yes, there's a lot that goes into the agents that we've built, but it's all about transparency.

Damien Lewke: It's exposing the logic and the reasoning behind what happens, uh, getting to the point where we expose the actual queries and the iterations that the agent does. Not only does that allow folks to understand what is this and why does it matter, but to your point about interns, I think one of the greatest challenges that we see when you use any sort of black box capability is people just accept it as rote truth.

Damien Lewke: Yeah. If you really want to democratize something, and you have a junior resource or limited resources, if you expose the decision-making behind it, you actually enable the person, and that's the whole point. So for us, it's always been about transparency of reasoning, showing the data that led to this, and that does...

Damien Lewke: We've seen this. Even if you're, you know, one year out of university with very limited SecOps experience, you're [00:15:00] able to go, "Okay, I understand why we are where we're at." Mm. "And that gives me the confidence to take an action."

Ashish Rajan: Right. Okay, and to your point, so you're almost allowing them to learn, but at the same time, giving the right information to...

Ashish Rajan: Giving the right context and transparency for, "Hey, this is why we believe this is a, an interesting anomaly that you should go down the path of."

Damien Lewke: Absolutely.

Ashish Rajan: Instead of just like, "Hey, looks like S3 bucket is open to the internet. Go figure it out."

Damien Lewke: 100%. Yeah, yeah. You know, um, another great example of something simple, I know this is more on the endpoint, but SSH port forwarding.

Damien Lewke: Yeah. SSH port forwarding, devs do it all the time. It's totally fine. Well, it's a little risky, but it's totally fine. Yeah. But the context is if Damien in accounting is SSH port forwarding- ... it's a different question entirely. And that's also the nuance, right? Is like the same signal, depending on context, may mean completely different things.

Damien Lewke: Mm. And that's why you expose that reasoning, 'cause it just makes things clear. And again, I, I, what, what I would expect and hope from other [00:16:00] agentic platforms in general is that that reasoning is made clear. Because at the end of the day, we're all dealing with an increasingly agentic adversary. Yeah. And we need to enable and empower teams to take effective action.

Ashish Rajan: I feel some of the audience members who probably have been doing non-AI- Mm ... threat detection for a while, may be purists, uh- Sure ... and, and may also go down the path of, "It's never going to give us the right result."

Ashish Rajan: Yeah. And I feel there is, there is a balance to be found in a lot of organizations have kind of started building AI capabilities themselves. Yeah. I'm sure this is one of them as well. Is AI right for all forms of protection, or is it like... You almost like, as, as a leader, someone's making a choice for, "Hey, that is a good way to go down path.

Ashish Rajan: This is not a good way to..." Like, how do you balance that? Yeah

Damien Lewke: First of all, to your first question, like, is AI good for all sorts of detections? No. Okay. Absolutely not. Um, it's a non-deterministic system. [00:17:00] There are plenty of great examples of traditional signals extraction mechanisms. Um, obviously you can run detection rules.

Damien Lewke: There are heuristics that you can build. There are ML models that you can use Agentic platforms in general, this is not something to say like all traditional signals, methods are dead, but rather the new format is you can now route all of these signal sources to an agent who can reason and use context and distill all of these signals into something a network defender can use.

Damien Lewke: And we wrote a, a blog about how we use CatBoost, for example. Yeah. Um, you know, there are plenty of non-deterministic use cases if you're looking at, say, command line classification or service account creation- Oh, yeah ... where a good old-fashioned heuristic is so much better and cheaper- Mm-hmm ... especially for those orgs that have token budgets and are going, "Ah, should I build this in-house, and what should I use it?"

Damien Lewke: Like, don't give up on data science and detections engineering, but think of building a pipeline where you can route those [00:18:00] signals to an agent that can reason across them and go, "Okay, I see how all of these are connected in something that is clear, human legible, and distinct."

Ashish Rajan: Maybe if we just extend that analogy- Please

Ashish Rajan: 'cause I feel to, to what you said, some of them are obviously non-AI use cases. Yep. 100% on that. Um, how does one... And maybe just to, uh, paint a more modern picture. I have AI agents, I have MCPs running in my organization- Oh my God ... which is the reality for a lot of people today. Yep. Some of them I know of, some of them I don't know of.

Ashish Rajan: So I, I feel confident that, oh, maybe I should use ThreatHunter to understand how, how, what kind of agents am I not really, uh, not seeing in the environment. Maybe that's a threat that I'm doing. What's an easy way to start approaching that problem? 'Cause obviously there's a traditional path that the purists, I'm sure, are listening in for.

Ashish Rajan: Yep. And then there is the path using AI. What's the, what-- How are you gonna approach that today? And if people are thinking of what their first AI use case should be in that kind of world, [00:19:00] what's an easy use case they can think of that they can validate to everyone that, hey, this is actually something gonna work?

Damien Lewke: Yeah. Uh, I've got a first use case, and we'll talk about that. Yeah. I'm also gonna shout out my purists as part of this answer. Sure. So first AI use case, looking for shadow AI. Like, if you wanted to do this today, go on a shadow AI hunt. I promise you, you're going to find something. And I actually think the MCP use case is a really good one.

Damien Lewke: Um, it runs in user space, clear text commands. Like, it's pretty easy to understand what MCP is running in your environment, provided you have access to that data. Yeah. The key is, if you've allowed MCP, there are probably a series of codified use cases that you have for that. So really, if you look at everything running in totality and you see any sort of deviation from that, well, there's your first finding.

Damien Lewke: Yeah. Like, that's the output of your threat hunt. Um, to my purists out there, I know this is a little scary. For non-purists or it might sound overwhelming, but baselining is a tremendous way to do this. Mm. If you [00:20:00] have access to data, if you've been able to normalize it, and you have some mechanism of interacting with it, you can build a baseline around MCP activity.

Damien Lewke: Yeah. So looking at MCP process executions, looking at child processes, and then, you know, on the deviation side, you can start going, "Well, hey, when, you know, node touches a credential or we see an abnormal tool call"- Mm ... that's when I start to understand the, the value. So easiest use case, look for MCP in your environment.

Damien Lewke: That'll flag any sort of shadow AI, kinda eighty-twenty rule, and then you can really drill down from there.

Ashish Rajan: Do you find that, um, one of the things that I remember from the cloud era was a lot of people, like incident response and threat detection w- did not get a lot of, like the limelight in the beginning because people just thought, "Oh, I don't have the right kind of talent for it."

Ashish Rajan: Yeah. But we've, we started the conversation by saying, "Hey, you don't have to be talented. You should be able to just go ahead and look at the [00:21:00] anomaly and get some more information for it as well." Mm-hmm. Um, and obviously, how good is AI against AI in that, in this context, right? Because technically it's like AI agent- Yeah

Ashish Rajan: and a lot of people look at this as like everything is new. Like I don't even know- Yeah, yeah ... if I know all use cases of MCP myself- Mm ... to build a plan. So, uh, do you find-- How are you finding in the customers you're helping with, with the, whether it's the shadow AI hunting or whether it's your MCP hunting, how are you finding the response to be in terms of is AI-- Does, does AI do a good job against its itself?

Ashish Rajan: Yeah. Like, I'm trying to think like, who else is it going against? Going against itself. OpenAI versus OpenAI, I guess. Yeah. Um, and if- Or Hugging Face ... or Hugging Face. There is that one, uh, when it goes out of the sandbox, apparently. Yeah. Um, but do you find that, uh, those kind of circumstances where now that I'm, I've put myself in a box- Mm-hmm

Ashish Rajan: AI, I'm using AI for detection-

Damien Lewke: Mm-hmm ...

Ashish Rajan: against AI, how good are... Is it [00:22:00] hallucinating in the sense that, "Oh, actually, that was, that was fine. That was, that was totally fine. That was nothing"- Yeah ... "nothing to see here. Please move on," or does it actually do a good job? And, or should people consider having, especially the ones who are motivated enough to have a different frontier model-

Damien Lewke: Mm-hmm

Ashish Rajan: because I don't wanna use OpenAI against OpenAI. Yeah. I wanna use Claude against OpenAI. Um, obviously, I've still, I've spoken about so many use cases. Mm-hmm. But I'm just thinking in terms of how b- have you seen AI respond from a detection perspective to other AI capable things, I guess?

Damien Lewke: It's not just AI responding to AI, it's heuristics classifiers plus AI. Because what you're able to do, and this is what I find to be extremely helpful, um- Instead of just doing like a, a regex lookup or a quick search looking for a particular process name, if you're able to do something around like I can use a detection rule or a scheduled detection query that I built and combine that with an AI, that's going to be far more accurate and [00:23:00] effective and dramatically reduces potential hallucination risk.

Damien Lewke: Because we know, and I get it, AI gets excited sometimes, and it sees what it thinks is there, and it can extrapolate out. But if you balance that with a bit of other context and some proven determinism, it's extremely effective. So e- examples of, uh, a couple things that we've done on the, um, on the OpenClaw and Hermes side.

Damien Lewke: Yeah. It's one thing to see an OpenClaw running in your en- in, in your environment. You know, five, six months ago, people were like, "Oh my God, this is the worst thing ever," and now everybody's doing it.

Ashish Rajan: Yeah.

Damien Lewke: The, the next step is to think about, okay, when I'm using AI to hunt for or, or detect AI, what are the classic hallmark signatures?

Damien Lewke: Uh, and not signatures as in DAT files, but signatures as in behavior that an AI will do, and it's all about tempo and breadth. So instead of just being like, "Hey, go look for Hermes"- Yeah ... instead I can [00:24:00] go Shadow AI agents are going to burst in terms of commands run and iterations. Look for that

Ashish Rajan: In a very short amount of time

Damien Lewke: In a very short amount of time.

Damien Lewke: Right. It's funny. Well, so back to the DoD. I think we, we spoke about this last time, but, uh, it's just interesting how things come full circle. So back in the day, there used to be this exercise where if you wanted to find an active intrusion, you would use time series to find it. Yeah. Because if a human was in your environment, it would take 20, 30 seconds to write a command.

Damien Lewke: Yep. There might be typos. It could take minutes, hours. Someone might step away and get a coffee. Yeah, yeah. But the whole point was to run a hunt in your environment based on time series, and if you found commands run outside of a certain time window- Yeah ... you either had a sysadmin- Yeah ... or an APT. Yep. And then if it was anything else, it was IT scripts, and it's totally benign.

Damien Lewke: Yeah. It's just funny how that's completely flipped now, where you're like, "Wait, wait, [00:25:00] wait, wait, wait. We gotta, like, shrink the time. We gotta look for, like, burst," and that's actually more concerning to us.

Ashish Rajan: Yeah, and I guess to your point, you're trying to, still trying to separate a human signature from an agent signature in that as well.

Ashish Rajan: Yes. 'Cause to your point, it could be a sysadmin running a script.

Damien Lewke: 100%.

Ashish Rajan: So, uh, do you find with hunting, hunt first especially- Mm-hmm ... uh, is the signature separation of human versus AI easier?

Damien Lewke: We found it easier. Okay. And this goes back to this idea of hunt first is telemetry first, identifying, validating, and attributing anomalous behavior.

Damien Lewke: Mm-hmm. It is really effective because of the A. It's, it's about the attribution. Right. So over time, if you start to look at sysadmin behavior and agents, there are a lot of things that you'll see agents do that humans don't do. My favorite example is service account creation. Typically, un- uh, I mean, I won't speak for every organization.

Damien Lewke: In general, sysadmins are not gonna spin up two or three new service accounts, [00:26:00] um- Mm-hmm ... under, in, in, in a minute- Yeah ... you know, uh, at 7:30 in the morning on a Wednesday.

Ashish Rajan: All with admin privileges as well. 100--

Damien Lewke: Oh, I mean, that's my favorite, right? Or you see, like, user privileges, PrivEsc- ... now admin, service account's created, and you go, "Hmm, that is either an extremely efficient sysadmin-

Ashish Rajan: Yeah

Damien Lewke: or it's probably an agent, and I'd be willing to bet it's an agent." And, and, and that really is where we've, where we've seen the unlock, right? Is it's all about the attribution. Yeah. Um, attribution sounds scary sometimes, and I think people think about, okay- It's a blame game ... it's, it's a blame game, and am I pointing figures, fingers?

Damien Lewke: A- and that's not the case at all. Attribution is simply uncovering the underlying reason as to why something happened.

Ashish Rajan: Yeah.

Damien Lewke: And oftentimes The best intentions can just have emergent consequences. W- w- we've seen examples of people who are able to [00:27:00] run a Hermes or OpenClaw, and it's run safely and things are great, and after a couple weeks, unbeknownst to anybody, it goes out and it touches a production DB.

Damien Lewke: Mm. And like, that's no one's fault. You were allowed to do it. This was an emergent behavior because somewhere along the line, in order to achieve its objective, it needed to get prod data. Yeah. Now, much more concerning if, you know, this person is Damien in accounting. He's my favorite guy to pick on. Yeah.

Damien Lewke: So I think that's also been a really important part is like it's not blame, but rather visibility and context allows us to understand why something happened.

Ashish Rajan: Yeah. And I guess your point goes back to shadow AI and AI agents should be a first thing people should look at-

Damien Lewke: Yes ...

Ashish Rajan: because at least that gives you an understanding of what is in the environment that I'm not aware of-

Damien Lewke: Yes

Ashish Rajan: to go on that and then maybe go on the hunt again.

Damien Lewke: Exactly. Well, you can go on so many hunts. But if you don't have visibility into something, it's very hard to make an informed decision about [00:28:00] what to do. Yeah. And that's why I think shadow AI is a great first principles, like, thing to go out and do today- Yeah

Damien Lewke: that you can do if you've got access to that data.

Ashish Rajan: Yeah. Yeah. Awesome. And do you find that... 'Cause I think it's something you, you said earlier, which is quite interesting for me. The AI agent capability and using AI against AI is an interesting use case, and I, and I'm glad you mentioned the fact that it's not about the individual's capability if you use the AI the right way.

Ashish Rajan: Yeah. Um, w- what happens when, like say, I'm, I'm almost thinking that to what you're saying, I'm hunting first. The reason why we were hunting later was because we were so, investing so much into SIEM and- Yep ... detection and all that. Now, to your point, if I can use an existing telemetry- Mm-hmm ... to hunt first, is there a need to have the SIEM and everything that we do from that alert automation in the...

Ashish Rajan: And it doesn't have to be today- Yeah ... but moving forward in the future, do you see that? I

Damien Lewke: think SIEM, it, it, it's, it's the right question. I think [00:29:00] SIEM is a question of data gravity. Yeah. So my favorite thing about the SIEM is when Splunk started in 2003, it was Google for logs. It was, it was an observability platform.

Damien Lewke: Datadog is another great example. Yeah. Fantastic company, started as, um, an, as, as an observability platform. Yeah. For compliance, data retention, if you have a, a center of data gravity that you need for those use cases, I think the SIEM as a data store definitely will, will still be around and doesn't need to be ripped out today.

Damien Lewke: If you think about the security use cases, what I would call the, the analytics, the detection engineering, the threat hunting, the investigation, you do need a window of hot data across, I would say at a minimum, you know, your endpoint identity and cloud data that needs to be normalized to some extent so you can actually query the thing.

Damien Lewke: That part needs to, needs to shift off the SIEM, because when it comes to data bloat, creep, cost storage, it's just gonna become untenable.

Ashish Rajan: Right. You don't need, and you don't, you don't need [00:30:00] two of those, 'cause I, I guess the engineering also has one as well.

Damien Lewke: Yeah. Or compliance and GRC. Yeah, I, I have a, I have a friend who works at a, a very large enterprise and He worked in, uh, surety and they had a SIEM, and he was doing, like, surety and insurance and had access to, to a SIEM, and it was one of those, like, "Well, hey, wait a minute," like, "How on earth are you acc- accessing the same platform that people are doing detections engineering and- Yeah

Damien Lewke: test and validation?" That, to me, is when, you know, what started as a shoebox has become a skyscraper.

Ashish Rajan: Okay.

Damien Lewke: So I think the data store use case for the SIEM is still there, but I think all security use cases will shift off, and selfishly, I think that's exactly what we've built and what we're very well situated to do.

Damien Lewke: Yeah. But that doesn't mean Splunk is a bad investment, it just means maybe you don't need to invest as much and focus your core security efforts somewhere else into something that's more purpose-built to solve your problem.

Ashish Rajan: Do you find the maturity of a security program for an AI security [00:31:00] could be a lot more different?

Ashish Rajan: Yeah. Like, if I'm thinking for all the SOC leaders who may be watching- Mm-hmm ... or listening to this, or even threat hunters for that matter as well. Yeah. What do you see as a shift that they should do? Because they already have a- all of this, right? They already- Yeah ... they have a SIEM. Some of them even ha- even have a detection team doing threat hunting.

Ashish Rajan: Mm-hmm. I'm sure people watching are, are threat hunters themselves going- Yep ... "Does this mean my job is gone?" No, not at all. So what does this mean for existing security programs that have been running, whether when they wanna uplift for an AI? 'Cause I think when I ask the question about uplift of AI for, hey, prompt injection and all that- Yeah

Ashish Rajan: suddenly it feels like people don't feel that their job is going, because they feel like, "Oh, it's not me, it's just that it's a new kind of threat." Yeah. But when we say, "Oh, my de- detection capability is like, oh, an intern with the right information can also do a good job at it"- Mm-hmm ... suddenly you start questioning whether, what, what, who is in my team anymore moving forward- Yep

Ashish Rajan: and what am I really investing in? And to your point, we've already put some doubts in people's mind with SIEM now. Yep. Moving forward, should we really pay that much? And we just probably need, like, some kind of telemetry collection rather-

Damien Lewke: [00:32:00] Correct ...

Ashish Rajan: a regex expression comparison site- Mm-hmm

Ashish Rajan: for lack of a better word. But how, what do you see the change to a existing security program who goes down that hunt first methodology and go, "Okay, we believe in hunt first. We'd rather be preventative," and all that?

Damien Lewke: Yep.

Ashish Rajan: What do you see the change there?

Damien Lewke: So I'll talk about the change in just a moment. I think Sam and Dario, though I don't know them personally, have both talked about how the whole prognostication that AI would re- would remove jobs from the workforce hasn't actually come true, and I actually think AI is very much a, I'll use the force multiplier word, is a force multiplier.

Damien Lewke: Yeah. It, it, it allows, it allows teams to do more. So much we could talk about on the hunt and detection and what you can do with more. Um, but to answer your question, what's the first thing that people should do in this world of decoupling data storage, SIEM, and threat hunting detection engineering? If you're able to have the three [00:33:00] core behavioral legs that I would view as vital for, for hunt first, if you're able to normalize your endpoint identity and cloud data, and you have some way of engaging with that data, you're in a great position.

Damien Lewke: You can do that with, um, of course, Nebula, but there are plenty of other capabilities that you could use as well. Yeah. Um, one of the things that's been so encouraging, 'cause I get this question a lot, "Okay, um, I'm using AI to threat hunt, do detection engineering. What's the difference?" Uh, you know, I think that is amazing because it shows enterprise adoption of agentic capabilities, which answers that question of what happens to my job.

Damien Lewke: It's great. The people that use AI are continuing to accelerate- That's right ... and do more, which is great Whatever that AI is engaging with, that should be that normalized database of telemetry that allows you to quickly understand and receive results based on the questions that you have, allow you to build and deploy detections, and it just so happens that yes, of course, we, we do that.

Damien Lewke: But there are a [00:34:00] lot of folks that are beginning down that journey. I think you do run into a couple limits there, which is if you DIY, you're not necessarily thinking about things like pipelines, real-time detections, additional engineering resources. If you have the ability to do all of that, that's great, but I think that's kind of where the trade-off happens, which is I have my team, AI has unlocked more.

Damien Lewke: How and where do I wanna spend my calories- Yeah ... around unlocking that potential to do hunting, detection engineering, and investigation.

Ashish Rajan: Interesting, 'cause, uh, the way I saw that, the whole maturity of a security program- Yeah ... the reason I came up with that question is because Gartner has been talking about how, as a, as a skill-

Damien Lewke: Oh, yes.

Ashish Rajan: Yes ... this, this is gonna erode, and there's-- And maybe this is where some of the fear is not just with Sam and Dario, and again, I don't know them personally, but- ... it's like, uh, I feel like I'm calling them by first name like, "Oh, like Sam and Dario," so How you doing? Yeah, yeah, yeah. Um, it's like, uh, to what you [00:35:00] said, it hasn't been proven, but what has been proven, at least for, for what I've seen, is that if I have had experience with insert whatever field, like threat hunting, marketing, sales, whatever, I'm a better judge of the output that I get for whether it's something I can use- Yep

Ashish Rajan: whether it's something I need to improve on, which I think is, is good on one side. But when Gartner and other authorities come in, just say ba-ba- hey, this is eroding the skill. What would that mean for threat hunters? Are we not hunting anymore if AI does everything?

Damien Lewke: Yeah.

Ashish Rajan: I obviously have an answer, but I'm curious to hear, when you hear things like that coming from the industry where...

Ashish Rajan: What, what does that... Like, and what do you tell to the people who feel they're gonna be impacted by this?

Damien Lewke: Yeah. I see a lot of blue ocean for these folks. I would challenge Gartner on a few things. Number one, I think a lot of what the, what the hunting that they view to be, and this is not to disparage Gartner, but rather I think the general impression of what most hunters and detection engineers do is [00:36:00] query optimization.

Damien Lewke: And like, that's very wrong. You know?

Ashish Rajan: We have a life.

Damien Lewke: Exactly. Well, they're like, you know, "What's a great example of a threat hunt? Show me after-hours login after 2:00 a.m." Like, that's not a threat hunt. Yeah, yeah, yeah. Um, so the... I, I would, I would challenge that expectation, and I also think it's a lot of black box automation, and that to me is such a shame because really what should be happening is, is that reasoning should, should be exposed.

Damien Lewke: Um, I also think we're forgetting first principles. So we've talked a lot about shadow AI, and we alluded to, uh, OpenAI and Hugging Face. We're in a world where Open Weights models are actively being distilled, and two dudes in a GPU can point their rig at an environment and go to town.

Ashish Rajan: Yeah.

Damien Lewke: So if you think about the skill sets, and let's be clear, no one's writing signatures or detections for this [00:37:00] So what, what needs to change?

Damien Lewke: I think that the blue ocean for, for threat hunters and detection engineers is actually what you do is gonna be so much more valuable, because the velocity and veracity of threats targeting you has just increased by some ridiculous number that I have no real estimate for. And that's not to fearmonger, that's to say your work is that much more important because your alerts are gonna take care of the commodity stuff.

Ashish Rajan: Yeah.

Damien Lewke: But because what is sophisticated has now become commoditized, your skill set's gonna be that much more important. It's a really long-winded way of saying, "Gartner, I completely disagree with you." I would argue that these two principles are really being supercharged with agentic capabilities because of the problem that almost every single organization has today.

Ashish Rajan: Yeah. And I guess I, I would also add to the argument saying that... And again, this is not a criticism against Gartner itself as a body- Yeah ... but more the thinking that it's just challenging, challenging the norm, especially when we have [00:38:00] seen that after, what, five years almost of AI being across the board, one year or two years of AI agents.

Ashish Rajan: Sounds, doesn't sound like a long time, but- Yeah ... no one, no one really has lost their jobs- No ... because of this. They've also already, they've only gotten better by things like Hermes, your OpenClaw. They've only made them better. Yes. I mean, if you look at the number of bug bounty hunters, which in a way is, is like an adjacent threat hunting kind of in my mind.

Damien Lewke: It's like a... Or, or I, I'd say like they're, they're causally related- Yeah,

Ashish Rajan: yeah, yeah ...

Damien Lewke: for sure.

Ashish Rajan: So, but they've been on the internet basically, uh, claiming the throne for, "Oh my God, AI is the most amazing thing that could have happened." Yep. "I'm getting so much more bounties than I could before." It's already been proven in the industry that it's not that it...

Ashish Rajan: The only fear that you, if you are an average- Yeah ... probably, you can be like an average plus plus maybe, but if you're really bad to begin with, I mean, maybe that's where you should be concerned- Mm-hmm ... in terms of the, "Hey, okay, maybe I should start learning AI," and, you know, not just be on the high horse that my field is too pure.

Damien Lewke: Yep. [00:39:00]

Ashish Rajan: Um, I, I just generally, I think, sort of sit on the side of maybe there are use cases for that little small niche of people who are fearing for their jobs- Mm-hmm ... because they don't want to adopt AI and use AI. But I'm pretty sure, um, and in the career that you've had between DoD and Octawulf and everything else, you had to learn a lot of tools.

Ashish Rajan: I did. Cloud came in in between as well. Every- And as much as people forget-

Damien Lewke: Yeah ...

Ashish Rajan: it was completely new.

Damien Lewke: It was.

Ashish Rajan: Yeah, yeah.

Damien Lewke: Oh my gosh. Six years ago, digital transformation. You know, every... Living in Australia, that was like the conversation everybody was having. Yeah,

Ashish Rajan: yeah, yeah. And now we have somehow forgotten all that, and now we're thinking, "Oh, actually AI's..."

Ashish Rajan: I mean, I get it. The faster, the change is faster- Yeah ... so it feels a lot more scarier. But in a way, we have gone through transformation, like the quote, "transformation."

Damien Lewke: Yeah. Well, it, it, it, it's funny too, and I would say this Fun anecdote. Actually, I'll let you choose if it's fun. So my, my parents are both, uh, retired lawyers.

Damien Lewke: Yeah. My dad is 71, [00:40:00] and we were chatting on the phone a couple weeks ago, and y- you know, he's, he's a bit tech-forward, but not the most, and he was like, "Hey, Damien, now that I have some time, I'm taking the Vibe coding class." He, the guy's never written a line of code in his life. Now, to be very clear, he's not shipping production apps and selling it.

Damien Lewke: Yeah. But it's one of those things that even him as a, as a skeptic is starting to understand the, the value of something like this. Yeah. You know, kinda to, to, to the broader question, we can't ignore the facts. CrowdStrike, um, called this out in their, their threat report. We've got not only a shift in malware-free threats, so from 2020 back with digital transformation where it was 51% to last year where it's, uh, 82% of all intrusions don't involve any sort of malware, but also, uh, the fact that AI-augmented or AI-generated attacks are up 89% year over year.

Damien Lewke: I think the question you have to ask yourself, even if you have a lot of trepidation, is [00:41:00] do I have the capabilities myself to deal with a dramatically increasing threat landscape? Question one. Question two, and this to me I find extremely reassuring: Does everybody know something I don't? The answer is no.

Damien Lewke: The cool thing about AI is we are all learning this at the same time. Yeah. You just gotta do it. Yeah. And it doesn't mean you have to block off y- four months and d- descend into a hole and do nothing but AI, but rather like Cracking open Claude Code, listening to podcasts, you know, asking questions, spending just a few minutes every day- Yeah

Damien Lewke: can accelerate your learning curve so, so much. Yeah. It's never too late. The key is you just have to take action.

Ashish Rajan: 100%, and that's a, that's a great closing because- Oh ... that's, that's, that's the last technical question I had. Excellent. Uh, so we are doing this thing called, uh, you laugh, you lose. Yeah. And, uh- Oh.

Ashish Rajan: I know, we went down a completely different direction. I'm [00:42:00] like, I for- kind of forgot about that for a second. Like, oh shit, oh, we have, we have that as well. So- Mm. Uh, so- Oh ... you laugh, you lose. The rules are I say a joke, you say a joke. Mm-hmm. Uh, but obviously w- whoever's jokes makes the other person laugh then they lose.

Damien Lewke: Okay.

Ashish Rajan: Initially, I mean, we can do a best of three. We can do a best of one if you like.

Damien Lewke: Yeah. I'm just feeling very smiley- Yeah. ... so this, uh, puts me at a disadvantage.

Ashish Rajan: I mean, no, I think because we've had the conversation, I feel like, oh, I'm already smiling quite a bit. Sure. I should probably just put my poker face on.

Ashish Rajan: Yeah. But-

Damien Lewke: Think about rain clouds.

Ashish Rajan: Yeah, rain cloud, or think about threat hunt, that really puts a serious mood. Yeah. Um, so, uh, I can go first or you can go first.

Damien Lewke: Hit me.

Ashish Rajan: All right. Okay. All right. I've got my first joke. I need to go make it a good one, otherwise, um... Oh. Well, we'll, we'll start with the b- We'll see how the first one goes.

Ashish Rajan: If it, if it, if it feels it's a tie, we'll, we'll add two more, all right? Mm. Uh, I had to make a long list for you, man, because I'm like going through all of them going, "Oh, okay."

Ashish Rajan: I'm [00:43:00] already laughing before I've... All right. Um, all right. Threat hunting is that neighbor who notices you have taken out your trash an hour earlier than usual and has questions.

Damien Lewke: That was really good.

Ashish Rajan: That's good . I mean, I laughed at it. Okay, fair. All right, you're- No, no, I mean, I just, if I laugh, I lose. All right. Oh, fair. Okay. All right, you're up

Damien Lewke: So I've done a lot of soul searching recently, recently. And, uh I decided to go to a philosopher first and, and ask them what the, the meaning of all this, of the universe was, and they aptly said 42. I thought that was interesting, so I, uh, went to the, the engineers in my team and, and I asked what the, the meaning of the, the, the answer to everything was.

Damien Lewke: You know what they said? What? DNS. It's always DNS

Damien Lewke: Good. Well played.

Ashish Rajan: This is actually harder than I thought. Yeah. Just not laughing on especially tech jokes, I think, but-

Damien Lewke: I know ...

Ashish Rajan: are we, are we doing another one? Yeah. Hit me. All right. Okay. All right. [00:44:00] Like, this is gonna be hard. So- This is, this is my... So I was trying to Google for pickup lines. Not that I-

Damien Lewke: Oh, no.

Ashish Rajan: There you go. Lost. Yeah. I mean, I don't have, I don't have to say my joke, but I'll still say my joke anyways. Uh, the jo- uh, the thing was uh, where is it? Uh-

Damien Lewke: I like as you explain your research, I'm like, "That's hilarious." Yeah. That was great.

Ashish Rajan: So the pickup line was, uh, "Are you an anomaly? Because everyone else ignored you, and now I can't stop thinking about you."

Damien Lewke: That's really good.

Ashish Rajan: And I'm like, that's a great pick up line.

Damien Lewke: That's great.

Ashish Rajan: Especially the other per- I mean, especially from a BlackHat perspective. Oh, yeah. But all right, you're, you're up, man.

Damien Lewke: Um, okay. Uh, this one's a little more personal. So I think I mentioned this, but I'm a middle child. Mm-hmm. So I'm extremely open.

Damien Lewke: You could say I've got zero trust issues.

Damien Lewke: Well played.

Ashish Rajan: Wow, that was ... That was like, I, I- A terrible laugh Yeah, yeah. And I was like, "Oh, that's good." But I was like, [00:45:00] "Five seconds. Five seconds." Yeah.

Damien Lewke: Five seconds. It's good. Yeah. That was great, uh-

Ashish Rajan: It-

Damien Lewke: Great composure.

Ashish Rajan: I, I think, I think I, it, I didn't realize how hard... W- when Shilpi and I came up with this, I was like, "Oh, it should be easy.

Ashish Rajan: All jokes are dry anyways." Yeah. And then like, oh no, some of them are good, actually. So I appreciate you laughing. But- Thank you ... I, as, as a prize for this, you've won my book, AI-Secured Engineering. But Yeah. Let's go. But- Thank you ... where can people, uh, find more about the work you guys are doing at Nebulock and connect with you as well?

Damien Lewke: Yeah. So find us at Nebulock, N-E-B-U-L-O-C-K.io. . And, uh, you can find me at Damien Lewke on LinkedIn.

Ashish Rajan: I will put those, uh, links in the show notes as well. But dude, thanks so much for coming on the show.

Damien Lewke: Ashish, thank you so much for having me.

Ashish Rajan: I mean, we need to continue this conversation.

Damien Lewke: We really do. The vibes are immaculate. Yeah. Thank you so much, my friend. We could talk

Ashish Rajan: for

Damien Lewke: hours, but

Ashish Rajan: thanks so much, man.

Damien Lewke: Thank you. That's a wrap.

Ashish Rajan: Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by TechRiot.io. If you are enjoying episodes on cloud security, you can find more episodes like [00:46:00] these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.

Ashish Rajan: In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter that just gives you top news and insight from all the experts we talk to at Cloud Security Podcast, you can check that out on cloudsecuritynewsletter.com.

Ashish Rajan: I'll see you next episode.

Peace.

No items found.
More Videos