Corelight in the Black Hat USA NOC: A playlist of attendee mistakes
Inside the Black Hat USA NOC, we found cleartext Splunk and BigFix traffic, leaky apps, and an exposed MCP server with read and write access.
Inside the Black Hat USA NOC, we found cleartext Splunk and BigFix traffic, leaky apps, and an exposed MCP server with read and write access.
See what a SOC agent does when it has real network forensics expertise behind it, from hypothesis to IDS alerts, timeline, and next steps.
Corelight Sensor v29.2 adds behavioral anomaly detection for multi-stage intrusions, AI governance dashboards, and low-touch sensor provisioning.
Learn how to build a defensible AI-SOC for the Mythos era with network evidence, auditable detection, grounded agents, and explainable workflows.
Signatures catch known threats and anomaly detection flags deviations. TTP-based detection closes the gap by detecting behaviors mapped to MITRE...
Discover what defending the Black Hat NOC taught me about using Model Context Protocol (MCP) to build an agentic SOC and accelerate threat hunting.
Discover what defending the Black Hat NOC taught me about using Model Context Protocol (MCP) to build an agentic SOC and accelerate threat hunting.
See how a Black Hat Asia 2026 threat hunt traced rare cleartext HTTP/2 traffic to exposed cookies after repeated QUIC and TLS failures.
At Black Hat Asia 2026, online games exposed cleartext inside TLS streams. See how Corelight uses network visibility to verify encryption.