The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Hacker Valley Studio
Hacker Valley Studio artwork

What's Really Stopping AI From Running Your SOC with Aqsa Taylor

Hacker Valley Studio · 2026-06-23 · 32 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber9 / 20
Specificity & Evidence11 / 20
Conversational Craft8 / 20

Aqsa Taylor, Chief Security Evangelist at Exaforce, discusses how AI-driven SOC platforms are fundamentally reshaping security operations beyond alert triage. Rather than treating AI SOC as a tool for noise reduction, Taylor argues for an end-to-end lifecycle approach spanning detection, investigation, and response using agentic systems. The conversation covers Exaforce's real-time semantic knowledge graph technology - which enriches alerts with identity, configuration, and code context - and explains why legacy SIEMs and bolt-on AI tools fall short against modern attack speed. Taylor uses concrete examples like the HackerBot Claw campaign (detected in GitHub pull requests, not traditional CloudTrail logs) to illustrate why SOCs need unified platforms bridging SaaS logs, cloud activity, and internal events. The discussion also addresses the shift in 2026 security operations: as AI agents generate code at scale and attackers automate at enterprise speed, defenders must move beyond level-one automation to augment analyst capabilities rather than replace jobs. Exaforce's MDR service, vibe hunting (threat hunting via agent-driven feeds and context), and peer-based behavioral baselining for insider threat detection are explored as practical applications. For security leaders, CTOs, and SOC operators evaluating AI SOC investments, this episode challenges common misconceptions about outsourcing security decision-making to agents and establishes a confidence-building framework for progressive automation.

Key takeaways

  • →True AI SOC platforms should provide end-to-end lifecycle support across detection, triage, investigation, and response - not just alert triage and noise reduction.
  • →A semantic knowledge graph that enriches events with identity, configuration, code, and behavioral context is critical for AI systems to accurately distinguish true threats from false positives.
  • →Organizations should build confidence incrementally, starting with triage accuracy before moving to detection validation, investigation quality, and finally automated response actions.
  • →Threat hunting is the most accessible starting use case for teams beginning to evaluate agentic AI in their SOC without the risk of full autonomous response.
  • →AI agents enable SOC analysts to act as force multipliers by automating manual work like correlation, detection rule writing, and investigation - not by replacing human judgment.

In this episode

  1. 1The Evolution of AI in SOC: From Skepticism to Agency
  2. 2Recent Major Security Incidents and Vulnerabilities
  3. 3What Is AI SOC and the Full Lifecycle Strategy
  4. 4Exaforce's Knowledge Graph and MDR Service Model
  5. 5AI SOC Platform Integration with Existing Security Tools
  6. 6Threat Hunting, Vibe Hunting, and SaaS Application Security
  7. 7Building Confidence in Agentic Platforms: From Triage to Response
  8. 8Practical First Steps for Implementing AI-Driven SOC Operations

Mentioned

ExaforceAqsa TaylorHacker Valley StudioCharter CommunicationsShiny HuntersMicrosoft EntraSalesforceOracle PeopleSoftGitHubSlackGoogle WorkspaceMicrosoft Teams

Guests

Aqsa Taylor

Topics in this episode

ExaforceAgentic SOC platformSemantic knowledge graphMDR (Managed Detection and Response)HackerBot Claw attack campaignGitHub security threatsVibe huntingBehavioral anomaly detectionSaaS security (Slack, Google Workspace, Microsoft Teams)SOAR platforms

Questions this episode answers

What is the difference between traditional AI SOC tools and Exaforce's agentic SOC platform?

Traditional AI SOC platforms focus narrowly on alert triage and noise reduction sitting atop existing SIEMs, lacking business context and detection coverage gaps. Exaforce builds a real-time semantic knowledge graph integrating identity, configuration, code, and event data, enabling end-to-end detection, investigation, and response automation without manual playbook maintenance or upstream dependency on SIM data.

How does Exaforce detect attacks that legacy SIEMs miss, like the HackerBot Claw campaign?

HackerBot Claw wasn't detected in traditional CloudTrail or SIEM logs - the malicious code was injected via GitHub pull requests. Exaforce's platform connects SaaS platforms (GitHub, Slack, Google Workspace) and cloud activity into one unified graph, allowing it to detect threats across environments SIEMs don't monitor.

What is vibe hunting and how does it work in Exaforce?

Vibe hunting automatically monitors threat intelligence feeds for attack news, matches indicators of compromise, and runs agent-driven investigations that pull together identity, configuration, code, and event context to show whether your organization is impacted and what response actions are needed.

How should security teams decide what to automate vs. keep manual in an agentic SOC?

Build confidence progressively: start by validating platform accuracy on triage and false positives, then move to detection quality, investigation analysis depth, and finally response automation - never jump from zero to full automation without establishing trust in each layer.

How does Exaforce's peer-based behavioral baselining detect insider threats on day one?

Instead of comparing a user only to their own historical behavior (which is blank on day one), Exaforce compares new employees to the normal activity patterns of their peer team members, flagging malicious behavior immediately if they deviate - catching insider threats before they establish a baseline.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

There are a handful of genuine operational insights - particularly around peer-group behavioral baselining for insider threat detection and the 'data foundation before agents' argument - but large portions of the episode are promotional language, platitudes about AI being a 'superpower,' and high-level restatements of obvious SOC challenges. The news segment adds factual context but not analytical depth.

it should be an entire lifecycle strategy, not just triaging, but also in detection
if the data is missing the context that is required by these models, then the agentic models, you can't really rely on them

Originality

7 / 20

The peer-group baselining for day-one insider threat detection and the 'full-lifecycle vs. bolt-on' framing show some fresh thinking, but the dominant narrative - AI augments rather than replaces, build trust incrementally, garbage in garbage out - is thoroughly recycled territory. The internet/teacher analogy for AI not killing jobs is a well-worn take.

Internet kind of did not take away teachers or, you know, we still have teachers and schools and all of that. It just made us much more efficient
What's different now with wipe coding is that it's just happening at a much faster scale

Guest Caliber

9 / 20

Aqsa Taylor carries the title 'Chief Security Evangelist,' which is an advocacy and marketing function rather than an operator who has run a SOC at scale; she is also the guest of her own company's sponsored episode, which limits the independence of her perspectives. She demonstrates genuine domain knowledge but speaks primarily as a vendor representative rather than a practitioner with direct operational accountability.

I wrote a report on AI SOC for MD and typically the pitch I would get for AI SOC is we help you triage alerts
I'm not in sales, but I will just say how I like to understand things

Specificity & Evidence

11 / 20

The news segment delivers real specificity - named threat actors, a 9.8 CVSS rating, 40 million records, 206 patches, three actively exploited zero-days - and the interview surfaces the HackerBot Claw/GitHub PR attack vector and a concrete North Korean insider-threat scenario. However, the headline performance metrics (90% fewer false positives, 95% faster investigations, sub-30-minute ATIR) appear only in the sponsor read, not from the guest, and customer references remain anonymous.

Charter Communications...had 40 million customer records leaked this month after refusing to pay Shiny Hunters ransom. The entry point to, uh, all of this was a vishing call
Oracle rated this vulnerability a, uh, 9.8 out of 10. It didn't require login. It only required network access

Conversational Craft

8 / 20

The host shows genuine practitioner experience - the SOAR/playbook-maintenance question and the 'when not to outsource' question are well-grounded and produced useful answers - but there is zero pushback on any vendor claim, no probing of how the 90%+ metrics were measured, and the sponsored nature of the episode is a structural ceiling on critical engagement throughout.

maintaining your playbooks became a full time job. Is it different with aisoc?
What is it in your world? Like in what situations is it very wise for security analysts, engineers to not outsource quite yet?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B54%
  • Speaker A46%

Most-used words

platform30security13team13detection12exaforce11knowledge11response11data10help10context10force9graph9triaging8access8different8agents8

Episode notes

In 2025, out of all 70+ guests we had on our show, not one of them said they’d trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief Security Evangelist at Exaforce, to find out what changed, and what's still standing in the way of security teams being able to trust AI agents with response. The conversation covers what's really behind the agentic SOC hype, why "vibe hunting" might be the most fun phrase in cybersecurity right now, and how teams can build enough confidence to hand over the keys to detection, investigation, and response. Aqsa also gets into the one thing she believes has to come before any of it works: the data. Without the right context feeding your AI you’re just getting confident guesses dressed up as answers. Listen to find out if your team is ready to take the leap into an agentic SOC.

Full transcript

32 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: What is AI SoC? In today's world, we can do more

Speaker B: with AI, and it should be an entire lifecycle strategy, not just triaging, but also in detection.

Speaker A: When you look at something like AI, especially from a security operations perspective, you want those team members to have the best access to tools.

Speaker B: You're giving them a leverage.

Speaker A: You're giving someone a superpower.

Speaker B: What's different now with wipe coding is that it's just happening at a much faster scale. This is an example of why we need to rethink our strategy and why SoC in 2026 looks different from SoC in 2020.

Speaker A: What's going on? Hacker Valley Fam welcome back to the show. I gotta say, we are living in a moment right now where the conversation around AI and cybersecurity has completely changed. It's changed so much. And if you look back at the Hacker Valley studio catalog from 2025, all the guests that I had on, I had over 70 guests on, and every single one of them said, there's not a chance that I would trust my AI to do the things that I do. Only for things like summarization, but not for agency. Well, I'm here to tell you that everything has changed over the past year. It's 2026, and now people are giving agents full control. We had no idea that we were going to see the adversary use AI the way that they did. We, we had no idea that AI, uh, agents were going to outpace and outclass software engineers. So we're going to be talking all about the layers of agentic, especially from the cybersecurity and the SOC perspective. So without further ado, roll the intro.

Speaker B: Who says tech can't be.

Speaker A: Before we jump in, here are three things that I've been watching from this past month that sets the table for today's conversation. It's time to hack the headlines. Number one, Shiny Hunters is having a month, and I don't mean that lightly. Charter Communications, a very big company, the company behind spectrum, had 40 million customer records leaked this month after refusing to pay Shiny Hunters ransom. The entry point to, uh, all of this was a vishing call, which if you don't know what vishing is, it's a voice phishing. One employee got social engineered over the phone and their Microsoft Entra account got compromised. And Shiny Hunters walked right into Charter Salesforce. And since they took literally everything, they took names, addresses, phones, plan details, support, ticket data, and they took 40 million records, all from a vishing phone call. Number two is also shiny Hunters. They've had a Very busy month. They've been at it and they're back at it as well. They went after an unpatched Oracle PeopleSoft vulnerability. This unpatched vulnerability was out for some time, and it took them a little bit of time to patch it. June 10, to be specific, uh, Oracle rated this vulnerability a, uh, 9.8 out of 10. It didn't require login. It only required network access. And if you think about environments that don't require you to log in per se, to be on the network, but have a big network, universities, universities were hit really hard by this specific vulnerability. And I think that the lesson is very clear here. You got a patch on the timeline when it comes out, and you also have to put compensating controls when there is no patch. So lessons have been Learned. And number three, Microsoft June Patch Tuesday dropped and there was 206 vulnerabilities that were ultimately patched. There was 3,0 days that were actively being exploited in the wild, which is absolutely insane that in one patch alone, three, zero days were patched. That means the window between vulnerability discovered and vulnerability weaponized is collapsed. There's no time. We used to have hours, we used to have minutes, and now we don't even have our seconds. It's just that fast. When every piece of your technology stack is a potential gap, you need a second system, a solution that can reason across everything in real time. So without further ado, let's head into the interview with Axa Taylor, chief security evangelist at Exaforce. My guests today, they've been in the trenches. They've been in the trenches helping cyber security teams, security teams, technology teams at large, learn how to use technology to be a little bit better at their job and their program. My special guest for this episode, they've been part of successful startups and also part of exits. And they're coming at this one from a new perspective. What everybody's talking about right now, agentic sock or AI sock, you name it. And the company that we're going to be really focusing and shining a light on today is exaforce. And I have the pleasure of welcoming Axa Taylor, who is the chief security evangelist exa force aa. Welcome to the show.

Speaker B: Hey, Ron. Thank you, thank you. I am so excited and honored to be speaking here with you.

Speaker A: I am honored to have you on. It's a pleasure. It's been great getting to know you, just number one. And I know that you've been super busy with Gartner and many other speaking engagements, so thank you. For taking the time.

Speaker B: Thank you for having me. I'm, I've been a fan of your show and I love the authenticity and the conversations that you bring to security industry. So being here is like a dream come true. Super excited. Thank you.

Speaker A: I love what y' all are doing at Exa Force, and I love the space of, you know, AI and SOC. Y' all have 125 million reasons to be celebrating right now and gaining customers. Um, big congratulations on the, the recent funding. You know, where's all that money going from your perspective?

Speaker B: So definitely product growth. Right? So we already have a solid product. Now we want to make sure that more SOC teams around the world are equipped with the same defense and are equipped with the same capabilities. And so that means, uh, expanding also our MDR team. We provide a SOC platform and MDR service, expanding our GTM team and all over, just making sure that more and more defenders out there are equipped with an Agentix SOC platform that is their partner and not just a tool.

Speaker A: When we spoke, you mentioned there's a knowledge graph. There's going to be global expansion, which I think is a given for, you know, that sheer amount of funding. And then there's also, uh, the MDR as well. So tell me a little bit about the knowledge graph and the MDR component. Like, how do those relate to what you all doing at exiforce?

Speaker B: Yes, we believe the winning model for SOC is Agentix SOC platform that exiforce provides. And I'll talk a little bit about the technology in a bit, but also the NDR service, the human accountability, to help equip you with that trust and with the same with that human assurance of people looking at your, uh, environment, actively providing you reports and actively taking care of those issues for you. So that is a winning model in our opinion, which is why EXA Force provides both an Agentix SOC platform and an MDR team that uses the same SOC platform that we provide to you as a platform. Now, the knowledge graph is how we really differentiate. So before people jump into using AI for whatever, let's say triaging your false positives or helping you reduce noise or enriching your signals, signal and all of that, the data needs to be there for those models to, um, to be more accurate and to have more assured results on. But if the data is missing the context that is required by these models, then the agentic models, you can't really rely on them with that same assurance and confidence. So what we really focused on is how we build that semantic knowledge graph. The signals that we take go beyond events. So the knowledge graph takes into account identity, configuration code, all these additional things into account and then layers and enriches your events on top of them. So you have the assurance and confidence that when the platform says something is critical, it's truly critical and not a false positive.

Speaker A: I wanted to hear from you, you know, one of the leaders in this space. What is AI SOC in today's world?

Speaker B: So I'll tell you what the usual messaging sounds like and then I'll tell you what I think should it should really be. I wrote a report on AI SOC for MD and typically the pitch I would get for AI SOC is we help you triage alerts, we help you reduce noise, we sit on top of your existing SIM and we can help you make it more efficient, which is great. I'm not taking away the importance of that because the alert fatigue is real on that side of the house. But I think we can do more with AI and it should be an entire lifecycle strategy, not just uh, triaging but also in detections. Like how can we leverage a Gentex platform to show you gaps that maybe your sims cannot catch and how can we use that to further enhance uh, and predict have better behavioral models like your anomaly behavior. Like comparing a person not just to their normal activity but to their peers normal activity. And so having that context and then spreading it across detection, triage, investigation and response is what true agentix SOC platform should provide. Not just stop in one side of that cycle but end to end, um, help you give that assurance and guarantee that it can really help you with respond as well.

Speaker A: I worked at companies that tried to build their own phishing solution and then that blew up and then I had a great idea, I was like okay, great, I will work for the SOAR companies and uh, then that will give them the ability to manage all their workflows. And I think it gave them a little bit more control but it didn't give them the ability to execute end to end while also managing it. Because maintaining your playbooks became a full time job. Is it different with aisoc? Like is it a full time job to maintain what goes in there, the decisions or is that automatically figured out from uh, the AI?

Speaker B: This is where the quality of the AI SoC platform will come into play and also via the context and the real time graph comes into play. Because if you look at an AI SoC platform that's more focused on reprioritization or false positive reduction or triaging, uh, it's probably Dependent on the events that are coming from the upstream providers like SIM platforms, XDRs and all. So that means it doesn't have that additional business context identity relationships, it doesn't have configuration and it doesn't have its own detection support for coverage gaps like maybe SaaS applications, GitHub, et cetera. So that means all of that is somebody's responsibility manually to provide to that platform versus why we built EXA force this way is to remove that responsibility and take it in house on the platform. So now the exabot in front of you will go through all of these different aspects of a threat. So not just like hey it's an IOC match but like okay, this user, how long they've been, who's their manager, what is the identity relationships, what Google files they have access to, what they have access what they've shared externally and then, and then build the entire analysis for you.

Speaker A: I have to jump in for a second to share some details about our sponsor for this episode. Exaforce. One attacker with AI now operates like 100 attackers. Most SOCs, they still operate at the scale of their headcount. That's the asymmetry that every security team has been fighting for the beginning of time. Legacy sims and bolt on AI tools. They weren't built for this life, they weren't built for this challenge. They constructed context. After the alert fires they perform hundreds of queries and many minutes of investigation. And by then it's already too late. The attack's already within motion. Exaforce takes a different approach. They build a real time security knowledge graph the moment that data lands in your environment they connect identities, permissions, code and cloud activity as they happen. What they have is a multimodal AI system. They have four exabots across detection, triage, investigation and response. That means 90% fewer false positives, 95% faster investigations and your average time to alert to response is now sub 30 minutes. Run the platform with your team or let their analysts run it as your mdr. Exforce is the agentix SOC built to give defenders the advantage. To learn more you could visit exaforce.com thank you Exaforce for sponsoring this episode. Now let's get back to the interview. Being in the security solution space, I know that everyone has a lot of tools, especially in the enterprise you all are probably working with, especially the enterprise. For people that have XDR or whatever the case is for detection and uh, response, they already have a SIM and they have all these other tools for tax service management and Exposure management. And they ask you, where does exaforce and AI SOC fit in? Can I replace something? Do I keep everything and then spend more? What's the thought process and uh, what's typically communication communicated there?

Speaker B: So my personal style and I'm not in sales, but I will just say how I like to understand things is what's the use case? Right. So let's look at some of the recent attacks. Let's look at, let's say the hackerbot Claw attack campaign. That one was not a typical, uh, detection on AWS or CloudTrail. It was on GitHub, okay, a SaaS platform. And it was in a PR like a pull request. The way malicious code was injected was through pull requests. And so those kinds of attacks are not typically, uh, detected in the legacy SIM platform. Well, maybe if you, you may have your cloud security platforms that are different and then you have your sock platforms that are looking at events and audit trails. But then where do you bridge these things together? Because you, as a sock defender, uh, or sock analyst, I like calling defenders, you are responsible for um, now managing this, right? You're responsible for bringing, bridging that story. You're responsible for acting upon it, like, hey, what is the radius of impact and how do I respond to this? So exa force brings that to you in one place and adds additional layer on top of it. All these attacks are happening fast and happening at scale and you need a platform that also responds to the same speed and scale in near real time.

Speaker A: Do you feel more comfortable, confident or less comfortable and confident with the fact that, uh, there's software generating software through AI agents? Like, is it more secure, the technology that the agents are building?

Speaker B: If there is a senior software engineer, he knows what he's doing and he's using AI for wipe coding parts of his tasks, I would have more confidence because of his skillset. And someone who is just doing like a college project, doesn't have any clue and has given AI the complete reins to do whatever it wants and just wipe code. Something without any quality gates. I would say a risk still with vulnerabilities. But the question is how fast now we have to respond to it, right? What's different now with wipe coding is that it's just happening at a much faster scale and it's done so much more faster. And this is an example and a real example of why we need to rethink our strategy and why SOC in 2026 looks different from SOC in 2020.

Speaker A: You know, it's, it reminds me of giving people automation. When you look at something like AI, especially from a security operations perspective, you want those team members to have the best access to tools. Like if the best access to tool is uh, uh, autonomous platform that could dynamically bring you in information and give you a better understanding that I think it's hard to say that you were replacing the job. You're, you're giving someone a superpower, you're

Speaker B: giving them a leverage. Yes. And I love how you said it. It's not just level one. Can we move beyond it? It's 2026, uh, like we need to move beyond. We are automating level one or cut down jobs from the SOC analyst. No, it's, it's more like if you think about Internet, a weird analogy, but Internet kind of did not take away teachers or, you know, we still have teachers and schools and all of that. It just made us much more efficient and people learned to uh, get the results faster, learn faster, and use it as a platform that helps you, helps you scale your knowledge and your expertise much faster. And that's what we're doing to soc. We are bolstering your SOC team so that they're not wasting time and trying to do all this manual work, stitching your correlations, trying to write detection rules, but making it easier with like natural level language. You have an hypothesis, you ask in natural language, and then you watch the bots create the hunt.

Speaker A: Speaking of hunt, I know that you all have pioneered and kind of imagined a new phrase and a new concept which I think is sexy. It's called vibe. Vibe hunting. And uh, I'm like, okay, I want to do a little vibe hunting. What goes into that?

Speaker B: Essentially the idea is that the teams could use agents or X4's platform that automatically first of all has this threat center feed. So every time there is a news article, we have inbuilt feeds that we look at and all the customers are informed like, okay, there is this attack that happened, but now let's look at the IOC matches. So everything happens automatically. And then when there is a match, you can easily investigate and the bots can threat hunt for you. So that the context that it takes from the identity configuration code and your events, it bridges all of that and then shows you if you are impacted, then what should have happened, uh, what may have happened, what happened, and then who, what, where all those details. And this happens so quickly because you're not tapping on your team members for that cloud context that is missing on your event.

Speaker A: We are dominated by the SaaS world, right? Like everybody's using SaaS, Slack, Google Workspace, Microsoft Teams, all these are SaaS platforms and all these have file sharing capabilities and sensitive data that you can expose and leak through these platforms. So when you're looking at something like just the sheer amount of apps that the enterprise has within exaforce, are you able to say like, pull all the Slack logs, pull all the Google Workspace logs and then tell me if you see anything interesting.

Speaker B: Yes. So let me give you like, ah, an example. Right? Um, let's say a traditional platform will tell you a file was shared or like open to the public or whatever. It won't tell you the historical context, who created that file, where was it living, who had access to it, who is managing it, and then is there any pii, whatever, all of that, that kind of information, you would go to a DLP or something else to really learn about it. With Xaphores you get the entire mapping. So looking back into the history, like, okay, this file, this person, usually their team interacts within this folder and they share files and this is what the, the normal behavior looks like. So now let's switch it to. What would happen if a North Korean actor posed to be an employee and joined a company? Well, on day one, if you're looking at just the user behavioral um, baselining, you would look at their activity and you would then form m the baseline. But maybe they are malicious from day one. Like maybe on day one they're trying to do lateral movement. They're trying to see what, how they can exploit their access to gain privileged information. Maybe some of that information, depending on their work role, is available to them, but they shouldn't really be sharing or constantly downloading from that particular file. So we form the baseline not just for the user, but also for the peers. So when someone joins, if they start acting out of the normal baseline on day one or two or three, and we compare that to the peers in the same team and how they don't do the things this person's doing, then we start looking deeper into it and start flagging things. So that way if there is an insider threat that happens in the very early stage of their joining the company, you can still detect it. So that level of detail, um, and visibility is what helps, helps our users to understand if something is truly critical or something is a normal behavior for the team.

Speaker A: What is it in your world? Like in what situations is it very wise for security analysts, engineers to not outsource quite yet?

Speaker B: It comes down to if you've Built that confidence even if it's in a platform or a person. So if it's someone, whether you're MDR service, your own in house SOC analyst or an agentic platform, you can't go from like zero to respond to all tickets for me, you know, so you kind of build that strategy from the beginning of like okay, are you confident on the triaging? Are you confident with the things that it says are false positives versus critical? So let's say you are confident with the accuracy of that triaging. Then you move on to the quality of the detections. Like are you confident on what types of detections are coming in from the platform? Then you go into the investigation like in the end to end analysis of a threat hunt, how much assurance do you have on the analysis part of it, on the layers that it's looking at? Then you move to respond because then you can have automation agents. In our case in exa force you have export response or automation agents that help you respond to these as well. But that's, that comes with building that confidence and thankful for us. We have had customers who are in response like actually using response and not just using us for detection or triage or analysis. And one of these customers has even publicly mentioned this in um, in our RSA conference that they have uh, we did a panel at, during RSA conference that they, they actively use it for response, uh, for some of the response actions as well. So that is where we are now. I don't think that it's impossible to use an agentic platform for that level of semi, uh autonomy. Not full autonomy but it is possible but with the right confidence level. So I wouldn't suggest you use your Claude created platform.

Speaker A: I think that's generally the gateway into stuff like this. Right. Um, you first start by looking at all the tools and solutions that you have and then you take the same step that we were hearing about last year and you put a LLM wrapper around all your data and then you start to discover things like oh wow, okay, I didn't know that I didn't know about these things or I didn't know that I didn't know about my process. I didn't know we didn't have a uh, incident response process. Even though I am the incident responder. Things start to click. What is the first thing? If you know everyone generally does this. They try to go about it themselves and then they cry for help. If you were to even try it by yourself, what is one use case that you think would be worth like kind uh, of showing the value in something like this.

Speaker B: Look at threat hunting. I think that's, that's a good example. I mean the triaging, the filtering, enriching normalization. Yes, you can, you can also go there but I find threat hunting quite like fun and, and I mean not, not if you're actually in a, impacted by a thread but see how you can use, go to our sub stack. Actually there's some good examples if you want to know how to start. There are some like um, detection quick uh playbooks there that you can use as well that we worked with uh, that I work with other com, um you know, practitioners to create. So that's a good place too. If you're just trying to see how, how do I use something like Claude, uh, non exoforce, just in general trying to learn how AI can be used in your day to day SOC operations. I think that's a great place to understand these attack campaigns and use AI in some ways. And I would say beyond that you will still hit a limitation because maybe you can do um, something like IOC collection, um, and scrape blogs or articles but if you're looking for like a continuous loop and it being a part of your feed and it being something more proactive than reactive, that's when you want to use something like exoforce because then you're moving away from having to do that automation yourself again and again and kind of trusting a kind of like a live agent that will now do it for you.

Speaker A: I love that sentiment. Like just get a partner that could help you be proactive rather than only reactive. I've been there so many times in my career and it, it's, it's absolutely dreadful. We got to talk about, you know, in simple terms what it is that you all do better than anybody else and I feel like we've already been kind of talking about that and what is the best way for someone to get started to learn more about X Force?

Speaker B: Sure. Exiforce is an agentix SOC platform. We help you become ten times more efficient in your entire SOC strategy. That means not just triaging, not just detection, but detection, triage, investigation, response, all the way, end to end, not just depending on events from your upstream providers, but also having inbuilt house detections and having um, a live real time security graph that is correlating all these pieces together in near real time. And we also take configuration, identity code and all the other factors into account. On top of events we also provide an MDR service so you get that assurance and human accountability on top of the platform. You can learn more about us at our website, exaforce.com make sure you follow our LinkedIn, Exaforce and maybe also connect and follow with me. I would love to connect with you and continue this discussion. Even beyond this, if you're looking for a community, we have a practitioner's community on substack called the Force Multiplier substack. And the idea here is that we don't talk about vendors, we don't talk about platform names, uh, we just talk about sharing knowledge. So if you have playbooks, if you have experience in detection engineering or threat hunting campaigns, you just share knowledge with the other community and we invite you to participate and write, uh, and collaborate on reports and articles there. So check out our reports there. There's some on open claw, hackerbot claw, GitHub governance, and also on how to use Claude and some open tools out there too. But share knowledge because this is a team sport and we're all defenders.

Speaker A: We are all defenders. And if you are looking for a partner in the AI SoC, you got to hear from Axa Best. I mean, wow, you all are building something really cool. I mean, it sounds like it's going to transcend, uh, just outside of focusing on the SoC, you know, looking at all those things and use cases that you just described. So I'm wishing y' all nothing but the best. So you definitely better check out, uh, exaforce and axa, thank you so much for taking some time out of your busy day. I know that you're super busy, I know you got some more speaking engagements coming up, but, uh, big thank you to you. All right, let's sit with something that AXA said and really give it all the airtime, all the airtime it deserves. She said the data has to be there first, before the agents, before the automation, before any of it. Think about what that actually means. If your knowledge graph is missing context, then the model starts to fill in those blanks with what it knows. And that is often what we consider to be hallucination. It's taking a guess as something that isn't actually correct. That's where false confidence gets baked directly into your platform. And then your analysts start to read and react to this and ultimately act on it. I've spent years watching the industry chase the next tool. And every generation is the same promise. Reduce the noise, cut the alert. Alerts make analysts lives easier. And every generation, honestly, the noise just gets louder. We end up with more alerts, more information and ultimately more burnout. What Axa said described this fundamental difference. She said, this isn't the layer that you just bolt on top of your existing stack and you call it a day. We wish that's how it worked, but that's not how really anything works in life. This system, it starts correlating identity configuration and code the moment the data comes in. So again, you need the data. If you're not organizing and collecting data and making sure that it's all accurate, then you're going to ultimately be getting garbage out, garbage in, garbage out. So here's my final take. The analysts who are going to thrive, especially in this era, are the ones who stop thinking that AI is a tool. And it's a tool that just works for me. It's magical. It thinks for me. I don't have to think anymore. They look at it as a partner, a partner that requires trust to be built. And the way that you build trust is providing context information and building a relationship over time. Not expecting a day one. Axa said it herself, you don't just hand the keys over to anybody. Day one, that was just delusional. You earn the confidence and then you get better over time. Better with evidence. So a big shout outs to Axa for joining us today. A big shout outs to Exa Force for sponsoring this episode. Make sure you check out the links in the show notes or description wherever you're listening or watching. And if you're not already subscribed to Hacker Valley Media, be sure to click on that subscribe button now. What are you waiting for? And with that, we will see everyone next time. Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy MerzaSecure & Simple · on SOAR platforms85 / 100
  • Navigating the Cybersecurity Maze, with Geoff MooreIT Matters · on MDR (Managed Detection and Response)67 / 100
  • How AI Is Rewriting the CISO Playbook with Michael MyintSOC Unlocked: Tales from the Cybersecurity Frontline · on MDR (Managed Detection and Response)64 / 100
  • S6:E3 - Tom Dejong - Inside the BHIS SOC: Triage, Curiosity, and Career GrowthSimply Defensive · on SOAR platforms51 / 100

More from Hacker Valley Studio

All episodes →
  • Feed Your Brain: What Cybersecurity Veterans Are Getting Wrong with Johnny Xmas
  • Fighting Smarter: What Combat Sports Teaches Us About Cyber Defense with Robin Black
  • Is Vibe Coding Breaking the Internet? with Tanya Janca
  • Why Smart People Fall for Deepfakes with Perry Carpenter
  • Who Owns Your AI Security Policy? with Chris Cochran
Explore the best B2B Engineering & DevTools podcasts →
All Hacker Valley Studio episodes →