
The "Hunt First" AI Security Strategy
Show notes
Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-bad SIEM alerts, you may be missing the silent breaches. In this episode, Ashish is joined by Damien Lewke, Founder and CEO of Nebulock, to discuss the critical shift toward a "Hunt First" mindset. Damien explains why moving away from alert fatigue and focusing on raw, normalized telemetry (across endpoint, identity, and cloud) is the only way to proactively surface unknown threats. We also dive into how AI is finally democratizing the elite skill of threat hunting, allowing even single-person security teams to investigate and attribute complex behaviors.From hunting down shadow AI (like unapproved MCPs) to challenging the notion that AI will replace threat hunters, this episode is a masterclass in modern security operations.
Guest Socials - Damien's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
If you are interested in AI Security, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00) Introduction: The Problem with Reactive Security Alerts(02:00) Damien Lewke’s Background (DoD, CrowdStrike, Arctic Wolf, Nebulock)(04:00) Why Breaches Happen in Silence: The Value of Telemetry Over Alerts(05:30) How AI Democratizes Elite Threat Hunting for Small Teams(07:30) Defining the "Hunt First" Mindset and Methodology(11:00) Surfacing Active Intrusions Using Cross-Domain Context(13:30) The Importance of Transparency in AI Decision Making(16:30) When NOT to Use AI for Detections (The Power of Heuristics)(18:30) The Best First AI Security Use Case: Hunting Shadow AI & MCPs(23:00) Detecting Rogue AI Agents via Tempo, Breadth, and Automation Signatures(28:30) The Future of SIEM: Data Gravity vs. Purpose-Built Security Analytics(34:30) Disagreeing with Gartner: Why Threat Hunters Are More Vital Than Ever(40:00) The 89% Rise in AI-Augmented Attacks and Taking Action(41:30) The "You Laugh, You Lose" Cybersecurity Joke Challenge
Resources spoken about during the episode:
- Hunting MCP Server Exploitations
- Using classical machine learning for threat hunting (and saving tokens in the process)