Episode 16 - Beyond the Black Box: Solving Data Overload with Agentic Triage
0:00 / 0:00
About the episode
In this episode, host Richard Bejtlich sits down with Dave Getman to discuss the evolution of Corelight Investigator and the paradigm shift from delivering raw sensor data to providing agentic triage. They explore how AI can synthesize millions of log lines into concise, actionable determinations—categorizing activity as malicious or benign—while maintaining transparency by "bringing the receipts" of raw evidence. Dave explains why the security pendulum is swinging back toward network detection to counter sophisticated EDR evasion and shares a roadmap for the future of auto-containment. By moving beyond the "black box" approach, this conversation reveals how AI serves as both a defender and a teacher, accelerating time-to-value for analysts and drastically reducing median dwell times on the network.
Episode transcript
Transcript coming soon...