Why AI Won't Replace Your SOC: Federated Data & APEX Framework
Sep 1, 2026 · 37m
Summary
Nicole Beckwith, Senior Director at Cribl, discusses the APEX framework for high-fidelity, behavior-based detection engineering. She critiques AI-driven SOC automation that relies on low-value IOCs, advocating instead for chaining TTPs and clustering activities to catch rapid attacks like GTG-1002. Beckwith emphasizes using AI to augment analysts rather than replace them, while addressing challenges in federated search, log retention, and agent identity management.
Topics discussed
Intro: AI in SOC, detection challenges, and guest introduction
Nicole Beckwith's background in security engineering and operations
Shift from IOC-based to behavior-based detections due to AI
Federated search, single lens, and deterministic data querying
Log source triage: deciding what to keep vs. pipe to data lake
Data lakes, AI agents, and the importance of auditing hunts
Securing AI agents: Identity management vs. service accounts
Blind spots in AI detection: Tuning and environmental context
The Apex Framework: Using raw telemetry to avoid schema breaks
Pyramid of Pain: Moving up to TTPs and behavioral chaining
Clustering, time-boxing, and detecting rapid threat actors
Applying Apex to existing SIEMs and data lakes
Empowering SOC teams with AI and episode wrap-up
Listen ad-free on Castria