Risky Business Risky Business

Soap Box: Using threat hunting to drive detection

Jul 8, 2026 · 35m

Summary

Nebulock co-founder Damien Lukey discusses evolving from AI threat hunting to a contextual security analytics platform built on a proprietary graph. He explains how this structure enables agents to detect low-signal threats, shadow AI, and insider risks by normalizing data across silos. The conversation highlights replacing legacy UEBA tools and complementing SIEMs with continuous, behavior-based detections that inform future security operations.

Topics discussed

Introduction and guest background Nebulok's threat hunting platform pitch Shift from AI hype to context graphs Complementing vs replacing detection stacks The data normalization problem in security Agents interacting with security graphs Building per-customer context graphs Shadow AI and non-security use cases Example: Password manager compromise detection Replacing UEBA and improving detection efficacy Future of centralized intelligence and agents
Listen ad-free on Castria