Soap Box: Using threat hunting to drive detection
Jul 8, 2026 · 35m
Summary
Nebulock co-founder Damien Lukey discusses evolving from AI threat hunting to a contextual security analytics platform built on a proprietary graph. He explains how this structure enables agents to detect low-signal threats, shadow AI, and insider risks by normalizing data across silos. The conversation highlights replacing legacy UEBA tools and complementing SIEMs with continuous, behavior-based detections that inform future security operations.
Topics discussed
Introduction and guest background
Nebulok's threat hunting platform pitch
Shift from AI hype to context graphs
Complementing vs replacing detection stacks
The data normalization problem in security
Agents interacting with security graphs
Building per-customer context graphs
Shadow AI and non-security use cases
Example: Password manager compromise detection
Replacing UEBA and improving detection efficacy
Future of centralized intelligence and agents
Listen ad-free on Castria