Cloud Security Podcast Cloud Security Podcast

Why AI Won't Replace Your SOC: Federated Data & APEX Framework

Sep 1, 2026 · 37m

Summary

Nicole Beckwith, Senior Director at Cribl, discusses the APEX framework for high-fidelity, behavior-based detection engineering. She critiques AI-driven SOC automation that relies on low-value IOCs, advocating instead for chaining TTPs and clustering activities to catch rapid attacks like GTG-1002. Beckwith emphasizes using AI to augment analysts rather than replace them, while addressing challenges in federated search, log retention, and agent identity management.

Topics discussed

Intro: AI in SOC, detection challenges, and guest introduction Nicole Beckwith's background in security engineering and operations Shift from IOC-based to behavior-based detections due to AI Federated search, single lens, and deterministic data querying Log source triage: deciding what to keep vs. pipe to data lake Data lakes, AI agents, and the importance of auditing hunts Securing AI agents: Identity management vs. service accounts Blind spots in AI detection: Tuning and environmental context The Apex Framework: Using raw telemetry to avoid schema breaks Pyramid of Pain: Moving up to TTPs and behavioral chaining Clustering, time-boxing, and detecting rapid threat actors Applying Apex to existing SIEMs and data lakes Empowering SOC teams with AI and episode wrap-up
Listen ad-free on Castria