Cloud Security Podcast Cloud Security Podcast

The "Hunt First" AI Security Strategy

Aug 25, 2026 · 46m

Summary

Host Ashish joins Damien Lukey, CEO of Nebulok, to discuss the "Hunt First" methodology, advocating for proactive threat hunting over reactive alert management. They explore how AI democratizes security by analyzing telemetry to detect silent breaches and shadow AI, such as unauthorized MCP agents. The conversation addresses AI's role as a force multiplier for analysts, emphasizing transparency in reasoning to build trust and counter the misconception that AI replaces skilled threat hunters.

Topics discussed

Intro: AI attacks, missed intrusions, and Hunt First methodology Damien Lukey's background in DoD and SOC detection engineering Using AI to solve for breaches rather than just closing alerts Democratizing threat hunting: No special skills or maturity needed Defining Hunt First: A proactive mindset and continuous hunting Moving beyond alerts to focus on underlying data and signals Contextualizing risks and overcoming talent gaps with AI AI transparency: Exposing reasoning to empower junior analysts Balancing AI with heuristics: When traditional detection is better Hunting for Shadow AI and MCP agents in user space Detecting AI vs AI: Combining heuristics with AI agents Identifying AI behavior through tempo, breadth, and attribution Emergent risks of AI agents and the importance of visibility The future of SIEM: Data gravity vs. purpose-built security AI as a force multiplier: Addressing fears of job displacement Evolving skill sets: From signature writing to reasoning Digital transformation parallels and the rise of malware-free threats Continuous learning, vibe coding, and closing jokes Outro: Sponsor credits and podcast platform links
Listen ad-free on Castria