{"id":6017,"date":"2026-10-08T11:13:59","date_gmt":"2026-10-08T16:13:59","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6017"},"modified":"2026-10-08T11:14:00","modified_gmt":"2026-10-08T16:14:00","slug":"security-operations-weekly-october-4-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6017","title":{"rendered":"Security Operations Weekly &mdash; October 4, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#0f2c4d;background:linear-gradient(135deg,#0f2c4d 0%,#1e5a8f 50%,#2b8fb3 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">October 4, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">Security Operations Weekly<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">Cribl moves from data pipelines into the SIEM with infrastructure-based pricing, Vega and Exabeam give their agents persistent memory and context, and a clearing house that sits at the centre of US options markets puts an investigation agent on its SIEM data. Kevin Mandia raises $255.5M to test defences with agent swarms, a Swimlane-sponsored survey says analysts mostly like the change, and two studies show the real drag is still speed: only 21% can deploy a new control within six months, and most open critical flaws are more than 90 days old.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>This week the SIEM market argued about who owns the data layer. Cribl, which built its business routing telemetry into other vendors&rsquo; SIEMs, launched Cribl Detect on IP from its CardinalOps and Radiant Security acquisitions. It is priced at roughly $18,000&ndash;$20,000 per TB per month on the infrastructure it runs on rather than on ingestion or queries, runs federated search against data where it lives, and translates existing Splunk and Sigma rules. It is cloud-only for now, and a Fortune 50 engineer quoted by TechTarget calls the migration &ldquo;a real project, not a switch.&rdquo; Vega II makes a similar pitch from the AI side: its gateway streams any source into low-cost object storage, a post-trained model runs the detection and triage loop, and a memory layer keeps what it learned about the environment. Raffael Marty&rsquo;s market column puts both alongside Microsoft&rsquo;s ISOC and argues the boundaries between SIEM, AI SOC, data pipeline and MDR are collapsing into &ldquo;the full loop.&rdquo;<\/p>\n<p>The second thread is agentic investigation leaving the demo stage. The Options Clearing Corporation built a SOC Agent on Amazon Bedrock that runs analyst-style investigative loops over its SIEM data; Leidos launched UpHold Effect for federal SOCs with configurable autonomy and an audit record of every recommendation; Exabeam turned Nova into a persistent investigator and added Claude-based skills; and Splunk set out its trusted agentic SOC model, where the analyst still validates the evidence and approves the action. Every one of them leans on the same phrase &mdash; humans in control &mdash; and none published outcome numbers. Swimlane&rsquo;s survey of 500 US and UK security workers gives the staff view: 62% say AI helped them build skills, while 47% expect SOC analyst jobs to get harder to land.<\/p>\n<p>The third thread is a reminder that the bottleneck is downstream of detection. Cisco&rsquo;s survey of 8,000 security professionals found just 21% can deploy a new security control within six months of approval, and 40% of teams spend more time collecting and matching data than hunting. Detectify&rsquo;s data on 1,293 customers found 86&ndash;97% of open critical and high findings had been exposed for 90 days or more, and a Dark Reading column argues that is an ownership problem a scanner purchase cannot fix. Meanwhile offensive validation is attracting the money: Kevin Mandia&rsquo;s Armadin raised $255.5M at a $2.5B valuation for agent swarms that chain vulnerabilities, and RemoteThreat raised $7M to test what happens after the first compromise. The foundational reading this week is practical hunting craft: falsifiable hunt hypotheses, SAML forgery detection, decoy accounts and an OAuth backdoor that survives token revocation.<\/p>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Cribl Detect&rsquo;s first production migrations.<\/strong> Cribl claims up to 50% savings against existing SIEMs, and analysts quoted by TechTarget say assisted Splunk and Sigma translation still needs validation and tuning. The proof point is a named customer that has moved its detections across and reports what broke. Also watch for the on-premises and self-managed options Cribl says it is considering.<\/li>\n<li><strong>Published accuracy for Cribl&rsquo;s SecIT Bench.<\/strong> Cribl&rsquo;s first run tested 20 models on 30 IT and security investigations and found a 17% accuracy spread against a 20-times cost range. Omdia&rsquo;s Torsten Volk says StreamAI&rsquo;s impact now depends on how accurate that benchmark is; independent replication would confirm or falsify it.<\/li>\n<li><strong>Outcome numbers from OCC and Leidos.<\/strong> Neither OCC&rsquo;s Bedrock SOC Agent nor Leidos&rsquo; UpHold Effect launch included a single metric. The first disclosure of investigation time, escalation rate or analyst override rate from a regulated operator would be the most useful agentic-SOC data point of the quarter.<\/li>\n<li><strong>Microsoft ISOC&rsquo;s 15 November date.<\/strong> Existing Sentinel customers can begin transitioning to the Integrated SOC from 2026-11-15. BlueVoyant&rsquo;s deployment service is the first partner offer built around that rollout; watch for others, and for what transition terms Microsoft gives customers with an active Sentinel workspace.<\/li>\n<li><strong>What Armadin ships for $445M.<\/strong> Armadin has now raised more than $445M across a $190M Series A in March and this $255.5M Series B, with In-Q-Tel among its backers. It has named no customers. Watch for the first customer references and for how it reports agent-found attack chains, against established breach and attack simulation tools.<\/li>\n<li><strong>Whether continuous attack testing shrinks the backlog or grows it.<\/strong> Armadin and RemoteThreat both promise to find more chained weaknesses. Detectify already shows public-sector organisations resolving only 8.3% of critical and high findings within 90 days. If more findings simply join the queue, the ownership argument in this week&rsquo;s Dark Reading column becomes the deciding factor.<\/li>\n<li><strong>Independent data on the SOC career ladder.<\/strong> Swimlane&rsquo;s respondents are positive about AI, but 47% expect analyst roles to get harder to obtain and leaders report taking on more work than practitioners (52% against 36%). A non-vendor survey of entry-level hiring would confirm or falsify the worry.<\/li>\n<li><strong>Cisco&rsquo;s six-month deployment gap.<\/strong> Only 21% of respondents can deploy a new control within six months, against 52% of the top tier. Watch whether agentic platforms are sold on closing this gap, and whether anyone measures it before and after.<\/li>\n<li><strong>Agent telemetry becoming standard SIEM content.<\/strong> LogRhythm added collectors for ChatGPT, Gemini and GitHub Copilot activity feeds; Splunk shipped an alpha NIST AI RMF control coverage dashboard; Exabeam correlates Claude Enterprise prompts, tool calls and actions. Watch for rival SIEMs shipping the same collectors out of the box.<\/li>\n<\/ul><\/div>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/10\/topic-map-security-operations-2026-10-04.png\" alt=\"Topic map of this week's Security Operations Weekly themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&rsquo;s topic map &mdash; SIEM economics and the data layer (Cribl Detect, Vega II, Microsoft ISOC and BlueVoyant), agentic investigation in production (Exabeam Nova, OCC on Amazon Bedrock, Leidos, Splunk) with humans kept in control, the SOC analyst career ladder (Swimlane), offensive validation (Armadin, RemoteThreat), the vulnerability backlog and remediation ownership (Cisco, Detectify), and hypothesis-driven hunting.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6016\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#0f172a;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h4>SIEM economics and the data layer<\/h4>\n<div class=\"cluster-intro\">Who owns the telemetry, and who charges for it. Cribl&rsquo;s launch is covered independently by TechTarget; the Vega II row is a vendor announcement published under Help Net Security&rsquo;s Industry News byline; the Security Boulevard row is Raffael Marty&rsquo;s syndicated market column; BlueVoyant&rsquo;s service is built around Microsoft&rsquo;s Integrated SOC rollout.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/www.techtarget.com\/it-infrastructure\/news\/366651477\/Cribl-targets-SIEM-data-costs-with-new-Detect-tool\">Cribl targets SIEM data costs with new Detect tool<\/a><\/td>\n<td class=\"src\">TechTarget<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/29\/vega-ii-agentic-cyber-defense-platform\/\">Vega II brings security-trained AI and lasting memory to the SOC<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/securityboulevard.com\/2026\/10\/the-security-operations-market-is-moving-from-narrative-to-execution\/\">The Security Operations Market Is Moving From Narrative To Execution<\/a><\/td>\n<td class=\"src\">Security Boulevard<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.channelinsider.com\/security\/managed-services\/bluevoyant-microsoft-isoc-deployment-service\/\">BlueVoyant Launches Microsoft ISOC Deployment Service<\/a><\/td>\n<td class=\"src\">Channel Insider<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Agentic investigation in production<\/h4>\n<div class=\"cluster-intro\">Agents doing investigative work on real SIEM data, each framed around keeping analysts in control. The OCC and Leidos rows are press releases with no published metrics; the Splunk row is a Splunk blog setting out its own model.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/press.aboutamazon.com\/aws\/2026\/9\/occ-strengthens-security-operations-with-an-agentic-ai-investigation-solution-built-on-aws\">OCC Strengthens Security Operations with an Agentic AI Investigation Solution Built on AWS<\/a><\/td>\n<td class=\"src\">Amazon (AWS press)<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.prnewswire.com\/news-releases\/leidos-launches-agentic-ai-platform-to-speed-response-to-cyber-threats-302891837.html\">Leidos launches agentic AI platform to speed response to cyber threats<\/a><\/td>\n<td class=\"src\">PR Newswire (Leidos)<\/td>\n<td class=\"dt\">Sep 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/siliconangle.com\/2026\/10\/01\/exabeams-nova-ai-agent-becomes-a-persistent-investigator-as-logrhythm-gets-ai-updates\/\">Exabeam&rsquo;s Nova AI agent becomes a persistent investigator as LogRhythm gets AI updates<\/a><\/td>\n<td class=\"src\">SiliconANGLE<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/ai-in-security-and-the-security-in-ai.html\">Trusted Agentic SOC: The AI in Security and the Security in AI<\/a><\/td>\n<td class=\"src\">Splunk<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>The analyst role<\/h4>\n<div class=\"cluster-intro\">How SOC staff feel about the change. The survey of 500 US and UK security workers was sponsored by Swimlane, an agentic AI vendor.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-security-operations-centers-careers-skills-swimlane\/831882\/\">SOC staffers generally pleased with AI&rsquo;s impact, but worries remain<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Offensive validation<\/h4>\n<div class=\"cluster-intro\">Two funding stories for AI-assisted attack testing: one of the year&rsquo;s largest security rounds, and a pre-seed bet on post-breach red teaming.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/techcrunch.com\/2026\/10\/01\/kevin-mandias-new-agent-swarm-security-startup-armadin-raises-255-5m-at-2-5b-valuation\/\">Kevin Mandia&rsquo;s new &rsquo;agent swarm&rsquo; security startup Armadin raises $255.5M at $2.5B valuation<\/a><\/td>\n<td class=\"src\">TechCrunch<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail\">RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Deployment speed and the vulnerability backlog<\/h4>\n<div class=\"cluster-intro\">The constraint downstream of detection. Both studies are vendor research: Cisco&rsquo;s survey of 8,000 security professionals across 30 markets, and Detectify&rsquo;s analysis of 1,293 of its own customers. The Dark Reading row is a contributed column by Nishant Sharma.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/30\/relentless-defense-cisco-cybersecurity-survey\/\">Most organizations need six months or longer to roll out new security controls<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/30\/research-unpatched-vulnerabilities-backlog\/\">Most open critical and high flaws are over 90 days old<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/vulnerability-backlogs-ownership-problem\">Vulnerability Backlogs Are an Ownership Problem<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Detection content and hunting craft<\/h4>\n<div class=\"cluster-intro\">Splunk&rsquo;s monthly detection release and four pieces of practitioner method: two SC Media hunting guides that make hunts falsifiable, and CISA&rsquo;s guidance on decoy accounts and files.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/splunk-security-content-for-threat-detection-response-september-2026-recap.html\">Splunk Security Content for Threat Detection &amp; Response: September Recap<\/a><\/td>\n<td class=\"src\">Splunk<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.scworld.com\/tech-explainer\/what-threat-hunting-actually-controls\">What threat hunting actually controls<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Sep 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.scworld.com\/practitioner-decision-guide\/hypothesis-driven-threat-hunting\">Hypothesis-driven threat hunting<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Oct 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/deception-by-design-cisa-s-guide-to-tricking-cybercriminals\">Deception by Design: CISA&rsquo;s Guide to Tricking Cybercriminals<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Sep 22, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Identity persistence and outsourced response<\/h4>\n<div class=\"cluster-intro\">Two identity attacks that outlast the obvious containment step, and a buyer&rsquo;s explainer on what managed detection and response should and should not cover. The CSO row is a contributed piece.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/www.csoonline.com\/article\/4223975\/revoking-the-token-didnt-kill-the-backdoor.html\">Revoking the token didn&rsquo;t kill the backdoor<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Sep 21, 2026<\/td>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/www.scworld.com\/tech-explainer\/saml-assertion-forgery-how-the-attack-works-and-how-to-stop-it\">SAML assertion forgery: how the attack works and how to stop it<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Sep 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/www.scworld.com\/tech-explainer\/mdr-explained-what-it-is-what-it-is-not-and-what-outcome-it-delivers\">MDR explained: what it is, what it is not and what outcome it delivers<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Sep 26, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Cribl moves into the SIEM, priced on infrastructure rather than ingestion<\/h4>\n<p class=\"meta\">TechTarget &middot; Security Boulevard &middot; September 29, 2026 &ndash; October 2, 2026<\/p>\n<p>Cribl Detect is Cribl&rsquo;s formal entry into the SIEM market, built on intellectual property from its acquisitions of CardinalOps in July and Radiant Security in August. The pricing is the pitch: roughly $18,000&ndash;$20,000 per TB per month, charged on the infrastructure the product runs on rather than on ingestion or queries, with Cribl claiming savings of up to 50% against existing SIEMs. &ldquo;Cribl Detect is priced on the infrastructure it runs on, not on how much you search,&rdquo; said Nicole Beckwith, Cribl&rsquo;s Senior Director of Security Engineering and Operations.<\/p>\n<p>Technically, Detect runs federated searches against data where it already sits, without rehydration delays on cold storage, and migrates existing Splunk and Sigma rules through assisted translation and mapping. It is not yet available on-premises or self-managed. Alongside it Cribl unveiled StreamAI, an AI gateway informed by its SecIT Bench: in the first run, 20 models across 30 IT and security investigations showed a 17% spread in accuracy against a 20-times range in cost.<\/p>\n<p>The analysts quoted are measured. Steve Koelpin, a principal AI observability engineer at a Fortune 50 company, says assisted translation makes migration &ldquo;a real project, not a switch,&rdquo; and that most large enterprises will not replace a SIEM immediately. Sean Sosnowski of Software Analyst Cyber Research warns that a conversational interface &ldquo;does not remove the need for complete data, dependable queries, or investigation results that hold up to scrutiny.&rdquo; Raffael Marty&rsquo;s column on Security Boulevard places the launch in a wider pattern &mdash; Microsoft&rsquo;s ISOC, Vega II, Scanner&rsquo;s federated indexing, Quorum Cyber&rsquo;s acquisition of Ontinue &mdash; and concludes that &ldquo;the new competitive surface is the full loop: data, context, detection, investigation, memory, policy, and action.&rdquo;<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.techtarget.com\/it-infrastructure\/news\/366651477\/Cribl-targets-SIEM-data-costs-with-new-Detect-tool\">TechTarget (Cribl targets SIEM data costs with new Detect tool)<\/a> &middot; <a href=\"https:\/\/securityboulevard.com\/2026\/10\/the-security-operations-market-is-moving-from-narrative-to-execution\/\">Security Boulevard (The Security Operations Market Is Moving From Narrative To Execution)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. Vega II: a security-trained model with a memory<\/h4>\n<p class=\"meta\">Help Net Security &middot; September 29, 2026<\/p>\n<p>Vega II is Vega&rsquo;s largest platform release since it emerged from stealth. It has three parts: a proprietary model post-trained for agentic cyber-defence work, which runs detection, triage and investigation loops; Vega Memory, which retains the ground truth of the environment and the actions taken so context carries from one investigation to the next; and Vega Gateway, which streams data from any source over OpenTelemetry, webhook or API into low-cost object storage, onboarding in minutes without legacy connectors.<\/p>\n<p>The argument is that analytics should reach sources that never fitted into a traditional SIEM. &ldquo;AI gave attackers a head start. It doesn&rsquo;t have to give them the future,&rdquo; said CEO Shay Sandler. This is a vendor announcement with no customer results or pricing; treat the persistent-memory claim as something to test on your own data, including what the memory retains and who can correct it when it is wrong.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/29\/vega-ii-agentic-cyber-defense-platform\/\">Help Net Security (Vega II brings security-trained AI and lasting memory to the SOC)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. Exabeam makes Nova a persistent investigator, and LogRhythm learns to watch AI tools<\/h4>\n<p class=\"meta\">SiliconANGLE &middot; October 1, 2026<\/p>\n<p>Exabeam&rsquo;s update moves its New-Scale platform toward agent-driven investigations. Nova now acts as a persistent investigator across the platform, collecting context and running follow-up searches as an incident develops. Related Cases, in early access since July, groups connected incidents automatically. A Guided Investigation Skills Pack brings Claude into command-line agents for natural-language triage, and Claude Enterprise customers get a single timeline of prompts, tool calls and actions with behaviour-based correlation.<\/p>\n<p>On the LogRhythm side, Exabeam added out-of-the-box collectors for ChatGPT, Gemini and GitHub Copilot activity feeds and moved the product from Elasticsearch to OpenSearch. It also open-sourced an Agentic SOC Skill Suite for Claude Code and OpenAI Codex through the Open Agent and AI Security Community. Steve Wilson, Exabeam&rsquo;s Chief AI and Product Officer, says the future SOC will be defined &ldquo;by how effectively people and AI agents work together.&rdquo; No performance figures were published.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/siliconangle.com\/2026\/10\/01\/exabeams-nova-ai-agent-becomes-a-persistent-investigator-as-logrhythm-gets-ai-updates\/\">SiliconANGLE (Exabeam&rsquo;s Nova AI agent becomes a persistent investigator as LogRhythm gets AI updates)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. A systemic market utility puts an investigation agent on its SIEM<\/h4>\n<p class=\"meta\">Amazon (AWS press) &middot; PR Newswire (Leidos) &middot; Splunk &middot; September 29, 2026 &ndash; October 2, 2026<\/p>\n<p>The Options Clearing Corporation &mdash; the world&rsquo;s largest equity derivatives clearing organisation, overseen by the SEC, CFTC and Federal Reserve as a Systemically Important Financial Market Utility &mdash; built a SOC Agent on Amazon Bedrock to automate alert investigation. The agent runs investigative loops over OCC&rsquo;s SIEM data, mirroring an analyst: form a question, retrieve evidence, evaluate it, repeat. &ldquo;The SOC Agent was designed to automate an investigative workflow while keeping OCC&rsquo;s security experts firmly in control of the process and its outcomes,&rdquo; said Ben Le, OCC&rsquo;s Deputy Chief Security Officer. The release gives no metrics or rollout timeline.<\/p>\n<p>Leidos made a similar launch for government SOCs. UpHold Effect Agentic SOC Automation runs agents around the clock to investigate alerts and assemble findings for human review, works alongside existing tools, lets each organisation set what the AI may investigate, recommend or execute on its own, and records every observation, conclusion and action. Leidos says it is FedRAMP-authorised, with a path toward DoD Impact Levels 4 and 5 with government sponsorship. &ldquo;Cyber teams need to keep pace with threats without giving up control,&rdquo; said Steve Hull, president of Leidos Digital.<\/p>\n<p>Splunk&rsquo;s Rod Soto describes the same design from the platform side: the analyst validates the evidence, understands the uncertainty and approves actions; agent-generated SPL keeps each recommendation inspectable; investigations feed back into detection engineering; and the SOC monitors its own agents for prompt injection, manipulated data, unsafe tool calls and compromised agent identities. All three are vendor-authored, so the useful question for your own pilot is what the audit trail shows when an analyst overrides the agent.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/press.aboutamazon.com\/aws\/2026\/9\/occ-strengthens-security-operations-with-an-agentic-ai-investigation-solution-built-on-aws\">Amazon (AWS press) (OCC Strengthens Security Operations with an Agentic AI Investigation Solution Built on AWS)<\/a> &middot; <a href=\"https:\/\/www.prnewswire.com\/news-releases\/leidos-launches-agentic-ai-platform-to-speed-response-to-cyber-threats-302891837.html\">PR Newswire (Leidos) (Leidos launches agentic AI platform to speed response to cyber threats)<\/a> &middot; <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/ai-in-security-and-the-security-in-ai.html\">Splunk (Trusted Agentic SOC: The AI in Security and the Security in AI)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. Analysts mostly like AI, but worry about the bottom rung<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; October 1, 2026<\/p>\n<p>Swimlane, an agentic AI vendor, surveyed 500 security workers in the US and UK in August and September 2026. 62% said AI had helped them develop their skills, and 92% of that group reported higher job satisfaction. Even among the 24% who said AI limited their ability to build skills, 91% still reported higher satisfaction. 41% said AI cut the time they spend investigating known threat patterns, and about a third said it sped up remediation recommendations.<\/p>\n<p>The worries are about the pipeline into the profession: 47% predicted that SOC analyst careers will become harder to obtain. Workload is shifting unevenly too &mdash; 52% of leaders said they now manage more security activities, against 36% of practitioners. Swimlane&rsquo;s own summary is that &ldquo;as AI assumes more investigative work, analysts are increasingly responsible for validating evidence, handling exceptions and making higher-impact decisions.&rdquo; Read it as vendor-sponsored, and as a prompt to look at how your own team trains people who no longer start on routine triage.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-security-operations-centers-careers-skills-swimlane\/831882\/\">Cybersecurity Dive (SOC staffers generally pleased with AI&rsquo;s impact, but worries remain)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. Agent swarms and post-breach testing draw the money<\/h4>\n<p class=\"meta\">TechCrunch &middot; Dark Reading &middot; October 1&ndash;2, 2026<\/p>\n<p>Armadin, founded by Mandiant founder Kevin Mandia, raised a $255.5M Series B at a $2.5B valuation, led by Andreessen Horowitz and Accel, with Bain Capital Ventures, Redpoint, 8VC, Ballistic Ventures, GV, In-Q-Tel, Kleiner Perkins and Menlo Ventures participating. That follows a $190M Series A in March and brings total funding past $445M. The product uses swarms of autonomous AI agents to test continuously, chaining vulnerabilities to simulate attacks on enterprise systems so weaknesses can be patched before attackers or rogue agents find them. No customers were named.<\/p>\n<p>At the other end of the funding scale, RemoteThreat, founded in 2025 by CEO Chris Thompson and CTO Shawn Jones, raised $7M in pre-seed funding for AI-assisted red teaming that starts after the initial compromise, building custom tools for each engagement rather than using static payloads. &ldquo;Pen testing is going to be a commodity market; it&rsquo;s going to be done at scale,&rdquo; Thompson told Dark Reading. For the SOC, both mean more validated attack paths arriving in the queue &mdash; which makes this week&rsquo;s backlog data the relevant counterweight.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/techcrunch.com\/2026\/10\/01\/kevin-mandias-new-agent-swarm-security-startup-armadin-raises-255-5m-at-2-5b-valuation\/\">TechCrunch (Kevin Mandia&rsquo;s new &rsquo;agent swarm&rsquo; security startup Armadin raises $255.5M at $2.5B valuation)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail\">Dark Reading (RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>7. The bottleneck is deployment and ownership, not detection<\/h4>\n<p class=\"meta\">Help Net Security &middot; Dark Reading &middot; September 30, 2026 &ndash; October 2, 2026<\/p>\n<p>Cisco&rsquo;s survey of 8,000 security professionals in 30 markets found only 8% of organisations reach its top tier of AI-era threat defence. Just 21% can deploy a new security control within six months of approval, against 52% of top performers, and 40% of teams spend more time collecting and matching data than pursuing threats. Internal friction makes up half of Cisco&rsquo;s 100-point scoring model; one CSO in India described &ldquo;confusion about who had the final authority to shut down the affected systems&rdquo; during an incident.<\/p>\n<p>Detectify&rsquo;s analysis of 1,293 customers in the US, UK and the Nordics, using payload-based testing to confirm findings, found open critical and high vulnerabilities exposed for 90 days or more in 97% of cases in the Nordics, 92% in the UK and 86% in the US. The public sector resolved only 8.3% of critical and high findings within 90 days; consumer packaged goods led at 46.2%. Organisations with exposed AI tooling fixed critical flaws at less than half the rate of the wider base. &ldquo;A security team may know exactly what needs to change, but the affected system could be owned by another department,&rdquo; said Detectify CEO Rickard Carlsson.<\/p>\n<p>Nishant Sharma&rsquo;s Dark Reading column draws the conclusion: &ldquo;Scanning capacity and remediation capacity are independent variables, and only one of them scales with a purchase order.&rdquo; He names four ownership failures &mdash; no owner, no authority, no capacity, no consequence &mdash; and argues for tracking time to remediate by team, SLA compliance and the share of assets with a verified owner rather than raw finding counts. One programme he describes cut remediation time from 45 to 10 days and lifted SLA compliance from 30% to 95% mainly by fixing ownership.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/30\/relentless-defense-cisco-cybersecurity-survey\/\">Help Net Security (Most organizations need six months or longer to roll out new security controls)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/30\/research-unpatched-vulnerabilities-backlog\/\">Help Net Security (Most open critical and high flaws are over 90 days old)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/vulnerability-backlogs-ownership-problem\">Dark Reading (Vulnerability Backlogs Are an Ownership Problem)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>8. BlueVoyant packages the move to Microsoft&rsquo;s Integrated SOC<\/h4>\n<p class=\"meta\">Channel Insider &middot; October 2, 2026<\/p>\n<p>BlueVoyant launched a Microsoft Defender XDR ISOC Deployment Service for Microsoft 365 E5 and E7 and Microsoft Defender Suite customers. It starts with a free ISOC Readiness Assessment of what is deployed and where it is fragmented, which does not need direct access to the environment: customers can export data snapshots instead. Deployment then covers Defender for Endpoint, Identity, Office 365 and Cloud Apps and Entra ID Protection, plus custom detection walkthroughs, workbooks, automation engineering and UEBA tuning.<\/p>\n<p>The pitch is that operational debt should be cleared before agents are layered on top. &ldquo;Agentic security turns yesterday&rsquo;s technical debt into tomorrow&rsquo;s decision debt,&rdquo; said Micah Heaton, BlueVoyant&rsquo;s Executive Director of Microsoft Product and Innovation Strategy. The service is available now, subject to customer eligibility, agreed scope and Microsoft&rsquo;s phased rollout; pricing beyond the free assessment was not disclosed.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.channelinsider.com\/security\/managed-services\/bluevoyant-microsoft-isoc-deployment-service\/\">Channel Insider (BlueVoyant Launches Microsoft ISOC Deployment Service)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>9. Make every threat hunt end in a decision<\/h4>\n<p class=\"meta\">SC Media &middot; September 30, 2026 &ndash; October 1, 2026<\/p>\n<p>Two SC Media guides set a standard that answers the measurement problem in last week&rsquo;s SANS survey. A hunt should end in one of four outcomes: adversary presence confirmed, a negative confirmation with adequate telemetry, a coverage gap identified, or a detection improved. The hypothesis must be written before any query and name the behaviour, scope, time window and expected evidence, so the hunt can be falsified. Before running anything, check that each required log source has recent data with the needed fields populated for the period hunted.<\/p>\n<p>Execution tests four pivots &mdash; the primary signature, precursor signals, artifact trails and correlation pivots &mdash; rather than a single query. Outcomes then route to different owners: presence to incident response, negative confirmations and detection ideas to detection engineering, evidence gaps to exposure management or logging, and revised hypotheses back to the backlog. Measure the outcome mix rather than hunt volume; the guide suggests a mature programme lands around 40% negative confirmations, 30% coverage gaps, 20% detection improvements and 10% presence confirmations.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.scworld.com\/tech-explainer\/what-threat-hunting-actually-controls\">SC Media (What threat hunting actually controls)<\/a> &middot; <a href=\"https:\/\/www.scworld.com\/practitioner-decision-guide\/hypothesis-driven-threat-hunting\">SC Media (Hypothesis-driven threat hunting)<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action --><\/p>\n<h2>Calls to action<\/h2>\n<ul style=\"font-size:14.5px;line-height:1.6;color:#1f2937;padding-left:20px;margin:0 0 14px 0;\">\n<li><strong>Run a cost model before any SIEM migration pitch lands.<\/strong> Total your current SIEM cost per TB actually searched and stored, then compare it with Cribl&rsquo;s roughly $18,000&ndash;$20,000 per TB per month infrastructure pricing and with a Microsoft ISOC estimate for your third-party data. Include the engineering time to translate and validate your existing Splunk or Sigma rules.<\/li>\n<li><strong>Pick your ten highest-value detections as a migration test set.<\/strong> Whatever platform you evaluate, port those ten first and test them with known-good events. Assisted translation still needs validation, and this is the cheapest way to see what breaks.<\/li>\n<li><strong>Write down agent permissions before a pilot starts.<\/strong> For each action an investigation agent could take &mdash; query, recommend, enrich, contain &mdash; decide whether it may run on its own, needs approval or is forbidden, and require an audit record of every recommendation and analyst override, as Leidos and OCC both describe.<\/li>\n<li><strong>Add your AI tools to the log sources.<\/strong> Ingest activity feeds from ChatGPT, Gemini, GitHub Copilot or Claude Enterprise where your SIEM supports them, and start with alerts on prompts and tool calls that touch sensitive data or production systems.<\/li>\n<li><strong>Name an owner for every internet-facing asset.<\/strong> Following the Dark Reading column, assign each asset to a person or standing team rather than a department, then report time to remediate and SLA compliance by owner instead of total open findings.<\/li>\n<li><strong>Measure your own control deployment time.<\/strong> Take the last three security controls you approved and record how long each took to reach production. If it is over six months, find which approval or ownership step held it up before buying anything new.<\/li>\n<li><strong>Make your next hunt falsifiable.<\/strong> Write the hypothesis with behaviour, scope, time window and expected evidence; check each required log source for recent, populated data; and record which of the four outcomes it ended in.<\/li>\n<li><strong>Deploy a honey account this week.<\/strong> Following CISA&rsquo;s decoy guidance, create a decoy Active Directory account with a 60-character random password, block it from authenticating, keep it out of routine deprovisioning, and alert on any attempt to use it with the EDR and IAM tooling you already own.<\/li>\n<li><strong>Hunt for forged SAML sessions and rogue app registrations.<\/strong> Correlate service-provider sign-ins with ADFS issuance events (Event 1200) and alert on reads of the DKM container (Event 4662). For OAuth backdoors, block the application registration itself, not just its tokens, while isolating the affected host.<\/li>\n<li><strong>Check your MDR contract against five questions.<\/strong> Which telemetry sources are monitored and which are not; which containment actions the provider may take without approval; how each SLA clock is defined; who owns connector and coverage health; and whether containment preserves forensic evidence.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">Security Operations Weekly<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>October 4, 2026 &middot; Weekly Edition Security Operations Weekly Cribl moves from data pipelines into the SIEM with infrastructure-based pricing, Vega and Exabeam give their agents persistent memory and context, and a clearing house that sits at the centre of US options markets puts an investigation agent on its SIEM&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38],"tags":[],"class_list":["post-6017","post","type-post","status-publish","format-standard","hentry","category-security-operations"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6017"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6017\/revisions"}],"predecessor-version":[{"id":6020,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6017\/revisions\/6020"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}