
Hash values, IP addresses, and domains are virtually useless as primary detection mechanisms in the era of AI-driven polymorphic malware and short-lived phishing kits. If your detection strategy is still stuck at the bottom of the Pyramid of Pain, your incident response team is doused in noise while true threats slip through undetected. In this episode, Ashish sits down with Nicole Beckwith, Senior Director of Security Engineering & Operations at Cribl (former Secret Service investigator and Kroger security ops lead), to break down Cribl's open APEX framework. Nicole explains how APEX focuses on behavioral chaining, time-boxing, and clustering over raw telemetry to build high-fidelity detections without needing a thousand individual rules for every MITRE ATT&CK box. We also explore the shift from a "single pane of glass" to a deterministic "single lens" over federated data, why AI agents must be provisioned as true identities rather than unmonitored service accounts, and how to analyze hyper-fast threat archetypes like Anthropic's GTG 1002. Guest Socials - Nicole's Linkedin Podcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Security, you can check out our sister podcast - AI Security PodcastQuestions asked:(00:00) Introduction & The Death of Hashes and IP Detections(02:20) Nicole Beckwith's Background (Secret Service, GE Aerospace, Kroger, Cribl)(04:30) Moving Up David Bianco’s Pyramid of Pain to TTPs(06:20) Replacing the "Single Pane of Glass" with a Single Lens on Federated Data(09:40) Deciding What Logs to Pipe to a Data Lake vs. Keep in a SIEM(13:30) The Cost and Context Risks of Pointing AI Agents Directly at Unstructured Data Lakes(16:30) IAM Mistakes: Why AI Agents Must Be Provisioned as Identities, Not Service Accounts(18:40) The Biggest Blind Spot in AI Detection Engineering (Rule Writing vs. Tuning)(20:40) Why AI SOCs Break on Normalized Schemas and Need Raw Telemetry(22:20) Deconstructing the APEX Framework: Chaining, Time-Boxing, and Clustering(27:00) Detecting Anthropic’s GTG 1002 Archetype and MCP Scaffolding Abuse(30:30) How to Apply the APEX Framework to Any Existing Security Stack(34:20) Empowering Analysts: Why AI Should Not Be Used to Cut SOC HeadcountResources spoken about during the interview APEX Framework
Podzilla Summary coming soon
Sign up to get notified when the full AI-powered summary is ready.
Free forever for up to 3 podcasts. No credit card required.

Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats

The "Hunt First" AI Security Strategy

Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

How Adobe Uses AI Agents for building a WAF Pipeline?
Free AI-powered recaps of Cloud Security Podcast and your other favorite podcasts, delivered to your inbox.
Free forever for up to 3 podcasts. No credit card required.