The 7 sins killing your SOC efficacy (and why NDR is the cure)
Avoid the 7 deadly sins of Network Detection and Response (NDR). Learn why firewall logs, black-box AI, and alert fatigue are killing SOC efficiency.
I know, I know. AI-SOC, modernization, Mythos all in one headline, coming from the person that said they can't stand marketing buzzwords and hype? Hear me out. I still see a lot of initiatives around SOC Modernization floating around (hello, 2015 called and wants its trend back). What SOC leaders are really talking about is innovating across their infrastructure to incorporate AI's benefits, which makes sense. And Mythos-class models that are accelerating vulnerability exploitation at machine speed are increasing the urgency for this change. I get that.
When I think about incorporating AI across the SOC, particularly in response to urgent challenges like Mythos, I immediately worry about trust and transparency. Modern defense requires absolute certainty, not mystery verdicts. If I can't see the data, explain the detection, or evaluate the workflow steps, how can I defend the outcome?
I really like the notion of a "defensible" AI-SOC. If you want to build one that withstands compliance audits, real-world scrutiny, and can take on AI-adversaries, you need to think holistically about four things: the data that feeds your agents and models, transparent machine-speed detection, trusted agents, and explainable AI-assisted workflows. That is a lot to take on, but the path is actually pretty straightforward.
If you want to modernize your SOC, start by modernizing the data you use. Feeding generic firewall logs or noisy NetFlow aggregates into an LLM or multi-agent setup yields incomplete context and inaccurate verdicts. We tested this. In Capture the Flag benchmarks built around real Salt and Volt Typhoon scenarios, AI agents powered by frontier models like Claude 4.6 scored 95% accuracy on complex forensic questions when backed by Corelight network telemetry. Give those exact same agents firewall logs, and their performance drops below 50%. Give them NetFlow, and they stall out under 20%. The choice of model barely mattered. The data did.
You cannot patch your way out of modern attack speeds. Static signatures and IOC matching still have a role, but relying on them to detect zero-day exploits or algorithmic attacks won't cut it. When the next exploit lands faster than a patch cycle, you need to be ready to detect the intruder, and that requires AI/ML-powered detection. Corelight uses AI/ML to surface threats that signatures miss, and every verdict is backed by actual Zeek® log entries rather than confidence scores or behavioral summaries. The result is a complete evidence chain that analysts can inspect, detection engineers can write against, and regulators can audit. Because we all know: a detection you cannot explain is a detection you cannot defend. Corelight's latest detection package release doubles down on two of the most pressing challenges for SOCs:
Today’s frontier LLMs are very cyber–capable, but capable is not deterministic. Feed an LLM open-ended prompts and raw logs, and there is no guarantee the same query will produce the same conclusion twice. That is not a foundation you can build auditable security operations on. To build agents you can trust, you need to make the AI output deterministic, grounding it with domain-specific skills and investigative logic that runs securely across cloud and hybrid environments, without sacrificing context or relying on external cloud APIs. To give AI agents actual investigative discipline, we built the Corelight Agent Builder Library. We packaged years of elite Zeek and forensic methodology into structured, machine-readable blueprints. Instead of loose LLM reasoning, these blueprints enforce strict, step-by-step logic pathways for triage, protocol pivoting, and behavioral analysis. These use the same investigation methodology that powers Corelight's own Agentic Triage, broken into modular building blocks that benefit L1 analysts, DIY agent builders, and even air-gapped environments:
Speed without trust is, well, just increased risk. Automated triage is supposed to eliminate manual burden, not create more work for analysts stuck double-checking opaque alerts. As Agent Lux, Corelight's multi-utility AI agent, I can tell you that when I execute an investigation, I operate on a few core principles:
SOC modernization today is not about upgrading old technology to the latest version or putting in more tools. And certainly it is not about replacing human defenders with "AI everywhere". Machine-speed attacks and skill shortages have changed what SOC modernization actually means. Today's analysts need to combine speed with trust. When regulators demand an audit trail under NIS2 or SEC disclosure rules, "the AI flagged it" isn't a defense. Don't settle for mystery verdicts. Build your AI-SOC on open data, transparent detections, and explainable workflows. That's how you stay defensible.
Avoid the 7 deadly sins of Network Detection and Response (NDR). Learn why firewall logs, black-box AI, and alert fatigue are killing SOC efficiency.
Read how to identify C2 activities and agent downloads associated with MITRE Caldera agents using this Zeek Caldera detector via GitHub.
Signatures catch known threats and anomaly detection flags deviations. TTP-based detection closes the gap by detecting behaviors mapped to MITRE...