The "Hunt First" AI Security Strategy
Aug 25, 2026 · 46m
Summary
Host Ashish joins Damien Lukey, CEO of Nebulok, to discuss the "Hunt First" methodology, advocating for proactive threat hunting over reactive alert management. They explore how AI democratizes security by analyzing telemetry to detect silent breaches and shadow AI, such as unauthorized MCP agents. The conversation addresses AI's role as a force multiplier for analysts, emphasizing transparency in reasoning to build trust and counter the misconception that AI replaces skilled threat hunters.
Topics discussed
Intro: AI attacks, missed intrusions, and Hunt First methodology
Damien Lukey's background in DoD and SOC detection engineering
Using AI to solve for breaches rather than just closing alerts
Democratizing threat hunting: No special skills or maturity needed
Defining Hunt First: A proactive mindset and continuous hunting
Moving beyond alerts to focus on underlying data and signals
Contextualizing risks and overcoming talent gaps with AI
AI transparency: Exposing reasoning to empower junior analysts
Balancing AI with heuristics: When traditional detection is better
Hunting for Shadow AI and MCP agents in user space
Detecting AI vs AI: Combining heuristics with AI agents
Identifying AI behavior through tempo, breadth, and attribution
Emergent risks of AI agents and the importance of visibility
The future of SIEM: Data gravity vs. purpose-built security
AI as a force multiplier: Addressing fears of job displacement
Evolving skill sets: From signature writing to reasoning
Digital transformation parallels and the rise of malware-free threats
Continuous learning, vibe coding, and closing jokes
Outro: Sponsor credits and podcast platform links
Listen ad-free on Castria