
Security operations centers have run on the same …
Loading summary
A
We've been talking a lot about AI in the SoC. One company wants to do more with it. We'll talk about it on this episode of Safe Mode. Welcome to Safe Mode. I'm Greg Otto, editor in chief at cyberscoop. Every week we break down the most pressing security issues in technology, providing you the knowledge and the tools to stay ahead of the latest threats, while also taking you behind the scenes of the biggest stories in cybersecurity.
B
An attack is coming. It's about keeping us safe.
C
He's just a disgruntled hacker. She's a super hacker.
D
Stay alert. Stay safe.
C
Stay safe.
A
This is Safe Mode. Welcome to this week's episode of Safe Mode. I am your host, Greg Otto. In our interview segment, we're going to be talking with Extra Hop CEO Greg Clark, who just launched the Agentix SOC Alliance. We've been spending a lot of time over the past few episodes talking about how AI is uprooting the SOC and the way that things have been done inside security operations centers for years. And Greg talks about how he's bringing the right minds in the room to talk about what the future looks like. Really interesting conversation coming up, but first, talking with cyberscoop reporter Matt Kapko. It's been a while since we've had you on the program, Matt, and we're definitely excited to have you on because it's been another banner week when it comes to open source security and the issues that have plagued open source security. There was another bad issue this week. Let's talk about what happened there.
D
Yeah. So it seems like every week there's something new. There's been a lot going on in open source, a lot of problems. This all happened in the span of about 4 hours. Early Tuesday morning, an attacker broke into a GitHub maintainer account. This account controlled a series of widely used open source software packages. We've seen this repeatedly throughout this year. They dropped malicious code into those packages, which quickly spread to other maintainers and unrelated packages. By the time the supply chain attack ended, less than four hours later, more than 440 distinct packages were compromised.
A
And what were these packages? Talk about what exactly the depth of these packages and how important these are. Because time and time again with these stories we go, I've never heard of that piece of software. And then we find out that it's extremely important to technology companies and development companies alike.
D
Yeah, certainly. So I think the first one was called Kev. Many of these are names that most of us will not know, but developers and those that are building all these tools and products that we use and rely on every day. Very familiar with these. To give you a sense of how widespread these are in use, researchers at Wiz told me that this was the most critical initial compromise of open source software packages to date, all due to its scale. The first package that was hit Kev. This is downloaded more than 155 million times a week and and about a handful of the compromised packages in total. Those are present in more than 46% of all cloud environments. It's unclear how many of those compromised packages were installed in production environments, but the Open Source community and npm, the online registry that holds these packages, they have made some changes to help thwart some of these automated installs. Sort of take a beat versus letting the machines just automatically update the software before checking that it's legitimate or hasn't been tampered with.
A
So I want to make the point too here in that this Kev or Key V or whatever is the correct pronunciation for this package. That's a staggering number of weekly downloads. I mean, think about most apps that we download on our phones and what gets popular on the iOS or Android stores. They don't cross that threshold of being downloaded that many times in a week. Not even close. But given that stat, I do believe that that package is maintained by one person. Like there is not a company behind Kiwi or Kev or this package. This is a good example of how important software gets managed just by one person sitting in their house or a hobbyist that is doing something on the side. They are not paid to do this. This is not run by a company. This is just one dude somewhere on the end of a keyboard maintaining this
B
very, very important software package.
D
That's right. And if someone gets a hold of that maintainer's credentials, it's, you know, anything is game at that point. We've seen this time and time again. It's just there's no protection in place. One of the key tenets of open source software is that you can constantly update and make little tweaks and changes. The that's why there's so many repeated installs throughout the week. These companies or tools that rely on these packages are constantly updating. It may be a new integration, just a slight change in the software, so they're allowed to make those updates quickly. They want to. But when that software is compromised or been tampered with, it creates real problems.
A
So given that window that you said, were there any further downstream repercussions? Like it seems like even though this was a pretty bad one at the beginning. This seems to have leveled off. Like we haven't seen any downstream effects. Correct?
D
Yeah, it's, it's unclear why it stopped so quickly. I think researchers are still kind of trying to go through the aftermath here. And as far as how far it went downstream, it did flow to different maintainers that were completely unrelated to this, this first breach. Ultimately it compromised this. 440 packages that I mentioned earlier, which are downloaded more than 2 million 2 billion times a month. I mean, it's just a massive amount of downloads there. Again, we're not sure how many times those were downloaded, those specifically compromised packages. Researchers are still trying to sort through that.
A
So pivoting now because there was some other interesting news that you reported on one of the other groups that we've seen responsible for these attacks, Team pcp. You had an interesting report due to some research that you got from our friends at Aligo Security for listeners. If you remind, we just had their founder on Gala Baz a few weeks ago talking about some AI security issues, but this was something else entirely. They looked into the history of Team PCP and found some interesting stuff.
B
What did they find?
D
Yeah, so this was a pretty wild one. Team PCP and threat actor or group that we've been covering and seeing a lot of activity from this year. They, they put out research this week that they have been around since 2020. Up until recently, most researchers thought that this group had formed or gotten on the scene in late last year. This group is behind the majority of these attacks on open source software this year. They compromised more than 1,000 software packages in less than four months earlier this year and it directly links to this attack spree that we saw this week. We don't have formal attribution yet, but this malware which self propagates, it's built on Mini shaihalud, the repository that Team PCP published as open source in May. This variant, it scoops up tons of sensitive data, including credentials for all sorts of cloud environments, AWS, GitHub, cloud development tools. It also steals AI related configuration files, cryptocurrency wallets, just about anything you can imagine. Researchers from multiple firms said that the same payload was observed across all of these affected packages, indicating that the same attacker or group was behind the supply chain attack this week too. So there's a lot of evidence pointing to Team PCP being behind the attack this week as well. We just don't have formal attribution on that yet.
A
Really, really fascinating times, I'm sure. We'll be talking about this again because Team PCP has been really running rampant as of late, and you've done a great job keeping our audience up to date on the latest. So, Matt, thanks for joining us.
D
Thanks so much, Greg.
A
Now to our interview with Extra Hop CEO Greg Clark. Greg came on to talk about the announcement of the Agentix SOC Alliance. And like I said, we've been talking a lot about how AI has upended the SOC model. We've talked with people from Elastic and Command Zero and just talking about the ways that AI has really just changed the dynamic in cybersecurity really overnight. Greg recognizes this too, and that's really why he put together this alliance to talk through how to change the SOC for the better and how AI can be integrated without really decimating the way that security teams get their jobs on. Really interesting conversation that talks about AI in the SoC and how companies are really wrestling with frontier AI models from the US and open source models from China. Check it out.
B
All right, and now to our interview segment for this week's episode of Safe Mode. And look, you've been listening to us for the past few months. We've been really diving into how AI is changing cybersecurity and particularly around the SoC. We've had on experts from Elastic, we've had Dove Iran on from Command Zero, really talking about how AI is changing the way that security practitioners work inside the SoC. And just this week announced was the Agentic SOC alliance, which is the industry coming together and talking about the same problems that we've been talking about on this podcast. So joining us right now is the CEO of Extra hop, Greg Clark, who is part of this announcement with the Agentix SOC Alliance. So, Greg, thanks for joining the program.
C
No, thanks, Greg. Great to be here. Really appreciate it.
B
So let's dive right in. You had a blog entry with the announcement for the Agentix SOC alliance where you said the SOC was built for a threat that no longer exists. And for years now, almost decades, the SOC has run on the same real steps. Collect, cue, triage, investigate, and escalate. And for listeners that have not really seen an Agentic SOC work in practice yet, what does a machine speed attack actually look like in minutes? And why is this not just a human problem where we can just throw more people at it and go about our days?
C
You know, I think that that's really the, the core of it right, right there.
B
Right.
C
You know, the, the enrichment pipeline that has been in the industry for a long time was all about get some detection or Something of interest. Enrich it through a pipeline that was pretty slow, but very, very good, you know, did good work. He would get a lot of information about that and it would come to a dispatch and often that's sometimes an hour later for a log collection, you know, good. A good one is 10 minutes later. And, you know, you don't have 10 minutes. If you think about some of the breaches we've been looking at in the last month, you know, really buttoned up places that, you know, have been attacked, lost, you know, 3,600 repos in one case. And that breach kind of got underway in about 87 seconds. And so the AI versus AI at machine speed, which we're reading about in all the headlines, really does require us to get kind of forward of that enrichment pipeline that we've been working on in cyber for a long time, you know, around the simulation and get right on the early detections to be able to have a chance at response in the timeframes with which, you know, things happen. I would, I would say that this maybe isn't new, right? If you go back to the time that zero days existed in the Snowden breach and things like NotPetya and WannaCry came along, you know, people were reporting, you know, seven minutes to complete destruction on 25,000 endpoints and things like that. So it is where you have the ability to manufacture a zero day with AI and that can work very quickly. You know, we crush the timeframe and so why can't we just do it with the tools we have? Even if you sped up a bunch of the steps in there, you still don't get to the time requirements needed in this, in this kind of new threat era.
B
So talking about some of those attacks, I know that they've actually happened, you know, and we've reported on them and we know that attackers are moving at that machine speed. But a lot of the real world reaches, you know, still are almost like old, I feel like. I mean, you just have that example with the Snowden vulnerabilities or some of the vulnerabilities that that Snowden talked about. But I mean, a lot of what we're seeing too, still relies on like tried and true methods from an attacker perspective. Phishing unpatched VPNs. I mean, that we recently wrote about a letter that Senator Wyden wrote to some federal agencies that was like, hey, can we get legacy VPNs off the federal systems? Like they're a problem. So, so with that in mind, I'm wondering how Much of this urgency is already happening at scale. Like what are you seeing versus where you expect the threat to be in 12 to 18 months?
C
You know, I, I, I think the entire premise of the tradecraft, you know, for many years, you know, you know, been running Blue Coat or Symantec. I used to tell people, you can't predict tradecraft. You know, you, every two years there's pretty a big tectonic plate shift in tradecraft. And what you're surprised when it happens. You go, oh my gosh, look at that. That's like bizarre. Like you know, the, the hugging face gets beat up by an AI that escapes a sandbox. I mean go back two years ago and sort of play that sci fi movie for somebody that got no, well, I don't even know what you're talking about. You know, so it's kind of like, so the tradecraft moves and I think there's a couple of low common denominators like you were mentioning, you know, identity compromise, you know, is the past, present and future of actually extracting data. But getting that beachhead inside of a company, being able to get your malware up, how that malware works or that exploit works, you know, the living off the land aspects of things, you can't detect them, that's a whole new sport right now. And you know, for example, we used to see malware that came with a command and control channel and we worked on CNC detection. And now the malware comes with its own brain and when its exploit doesn't work, it will actually change its exploit and to make it work just like a control person for advanced malware would do. I think also the ability to get nation state tactics consumerized using AI is absolutely here. So you see things like posts I posted on LinkedIn about someone who took apart endpoint agents and pulled out a few things inside the endpoint agents that were really helpful to adversaries. That information becomes available. You're not a really super powered nation state like system programmer, but you can get an AI to build you an exploit from that information. And so the world is substantially different now than it was, you know, even I would say in six months ago.
B
With that, I would love to unpack your thoughts on like the architecture of how this will look because the models just power everything and the technology around the models as well. Uh, you talked about it in the, in the blog a little bit and some others have been talking about it. So I would love for you to walk me through what the, you know, the three layers around large Language models and, and AI agents. There's the context, there's the harness, and there's the model. I'd love to hear what you're talking about in terms of like how those CISO CISO conversations are, are working in the context there. What are CISO saying about all three of those? The context, the harness, and the model? Why are these three so important to the future of their socks?
C
Yeah, you know, I think, you know, that that's a really good frame and I'll try to break it down into things that normal people can understand. Okay, so what do I mean by the context? The context is the information with which you feed an intelligence, whether it's a human or it's an artificial machine inference. You have to give it some context so that it can work on the problem. And that's really about data around the environment. Often it's got to be a mixture of historic data and real time data. That's kind of what's going on right now. What happened in something that you wanted to take a look at or you wanted to hunt. Could be, for example, an advanced threat that shows up that the advanced threat guys figure out and send in to agentic SOC and says, go take a look for that. Then you have to know about that threat. How do I find it? What does it look like, how would I see it? What kind of behaviors does it have? Then you would start looking around for it. And the context is the information that the agent needs to go after a potential problem or look for something, respond to something. And that's really important because just like everything, if you don't have very good data, you can't solve the problem. You need vast amounts of data. You need history. Data often said, no history, no security. And these things in that architecture are referred to as the context. They can be things like identity provider logs, network trace, endpoint information, data lake history about what's happened in the environment over time. Those things need to be made available with the ability for an agent to read it and understand what it is. So the context has to come with some kind of map that an agent can look at and say, what's in here? How do I understand that? You know, an extra hop, you know, we have a programmer's guide that's 460something pages long, tells you how to use our data. Agents can read that and they get, they get an understanding of it and then the data's there and that's a big piece of the context. Now the next piece is really important is if you're going to put an agent into production. You know, there's a lot of people running experimental agents where they get up their Claude or their, you know, ChatGPT or their Gemini and they say, hey, you know, here's my data set, here's how to log into it, or here's an MCP server that'll serve it up. Go take a look at this and see if you can find that or whatnot. And they're blown away by the power of the agent. But if you're trying to put something in production that is going to take over some very important things or help a analyst with some very important things, you need a model which with you can govern how that gets put into production, how it gets tested, what it's allowed to do, what it's not allowed to do, how it integrates with humans, which we'll come to later, that are still super important in this discussion. And that harness is really some of the plumbing with which you put your sock together or you put any kind of agentic workflow together. That is a very important thing. There are a bunch of companies that are in the business of making these harnesses. You know, in our announcement lane chain is one of them and Kendo's another one. And you know, you need to have those, those folks, they give you a control point in the life cycle of an agent, in the governance of that agent. You know what context it's allowed to hook up to and you know, what, what it's allowed to do, what it's not allowed to do. And also it gives you an audit trail of kind of what happened. And then you come to the really interesting part which is this agent model layer. So we've got context, we've got a harness that gets the agents moved around. Agents come along and they get deployed into, in by the harness and then they look, they get an event and they're looking at it in the context and they're backed by a model. And this is where it is, a very rapid innovation cycle right now.
B
Yep.
C
Okay. At extra hop we are running an arena with today 98 open weight models in it. And we throw in all kinds of different things to see you know, which ones are best. And then we score them just like an arena would score them or you know, a shock tank, you know, you know, and in there we're, we're finding the rate and pace of innovation at the model and the inference and the reasoning is very diverse. And that is why we're saying in our release that you really want to try to be as model independent in the agent layer as you can. Because we may find that somebody pops a model out next month. Like, you know, Microsoft just pushed one out yesterday that was very interesting. Had a very strong training corpus which matters. You know, what, what, what did the model learn from? Very important topic. There's all these poisoning risks and stuff of right models and you want to be able to maybe back your agent with different inference, different models. Okay, so you have an agent that's going to hunt identity compromise, for example. How does it do it? Well, you can test it with lots of different models once it that you know are built for that and you'll find it'll do a good job. And so we think that in the architecture of an agentixoc, the next generation of what we're doing in the soc, you really need to separate your harness and your context from your agent model layer. And you want to take advantage in that model agent layer of all the innovation that's going to come down from people that are actually building these kind of agents. You know, Command zero doves company that was on your, your podcast a while ago. Great one, 10x great one. You know, there are lots of different ones and then there's lots of ones that will be purpose built by socks that have the capability of making them. And that's why we think you're going to have lots of agents, potentially swarms of them doing different things. And you want to be able to, to avail yourself to innovation that might be an insider threat innovator that has a great approach or a identity compromise innovator that has a great approach or someone who is really looking for remote execution, lateral movement that has a great approach. And each of these things will evolve very quickly. And that's why we think that the right architecture is that there is the context layer that needs to hold all kinds of different elements of information for you, harnesses to get things pushed out. And then lots of different kinds of agents, some made by vendors that make them like MDR vendors like 10x or Command0 or Fig or plenty of others, you know, profit lots of good ones and then there'll be ones that you just make yourself because you've got a certain risk that you care about and your team builds things specific to that risk.
A
Right.
B
So you hit upon a lot there. I have some deeper questions, particularly around the models. You said 98 models that you were testing at Extra Hop. I did not know even that 98 models existed. So I'm wondering, you know, you got into it a little Bit. But I'm wondering as a CISO, and I think from my own conversations with CISOs and trying to alleviate risk, one of the ways that you alleviate risk almost from like, human behavior perspective is just, you know, relying on one or two things, and that way, you know, you're not casting a wide net and you don't have to put out a lot of fires and you can depend on something to keep something moving. I'm wondering if you've had the same conversations, particularly around the models, because it seems like if I'm switching out models interchangeably, that seems like a harder thing to manage from a CISO perspective, especially the larger the enterprise gets where you have all of these models and you're depending on all this for a wide, wide area to protect when you're at the level of like, say, a federal agency or a very large enterprise, like Fortune 500 company. So what are those conversations like? Or am I hitting upon something? Or am I missing some context here? Because you got it, you got it,
C
you got it, you got it. Really right? Like, like, you know, you. If you go to a normal organization and say, you know, do you know what these open wave models can do? And, you know, we just saw one protect a Chinese model, actually protect something because of the guardrails and how, you know, regulated US models were not able to do it. You want to basically understand all of these pieces of how these things work. And so what, what we like our arena for it at extra hop, and we're all learning now, right? It's actually not difficult to hook up a harness that will actually take, say, a prompt and feed it to many of them. In our case, we're almost at 100. We used to have 120 in there. We took some out because they're just totally useless in the security context of that. There's probably 20 of them that matter and five of them that are really good. But what we want to do is to say, look, here's a problem. We had a detection on an endpoint that was true malware behavioral detection. Something happened. Show us your reasoning to go after that. What would you do to go after that and write it down and then ask for permission to move forward, get some more information, and then come back. These things are not like, oh, I figured out, and I just run a little bunch of stuff. They're just like a human you, you investigate, you find different facts happen. You do something else, you do something else, you do something else. And so what we're, what we're trying to figure out is which ones of these things reason best for certain problems. They're really a product of their training data. What we find in those tests as we do it right now today is the Chinese models are always in the top few on complicated cyber breach reasoning. Quinn, Jimmy, these are standouts on the things that they want to do to investigate something. My personal opinion is that they were trained well on adversarial methods. And when you turn that coin around in a LLM, you actually get a very good defense reasoning as well. And my good friend Kevin Mandian over at Ahmedan will probably ratify that statement. So that doesn't mean that our North American models aren't good. It just means that there's a few good ones and they can do the job exceptionally well. And it's not just the reasoning then it's about, okay, if you said, okay, I want you to go find the identity that was involved in that, say, remote execution and show me if it's active anywhere else. Okay. Then you throw that in there and say, okay, who's going to basically break that down into the best method to go look for that based on the context information available? And you get some very, very good answers to that. And so we're, we're really working hard in the alliance concept to actually also deliver that kind of benchmark in that arena to people. Because you can't push something into production unless you know.
B
Right.
C
It actually works.
B
Right.
C
And you compare it to kind of how you do it now and see if it's better or worse. Right. And. And you get some interesting results doing that.
B
Okay, so back to the harness. You know, the harness seems like the less understood of the three things we talked about there for the context, harness and model. Why is governance with the permissions and the human approval and the audit trails as much a technical architecture problem as it is a policy one?
C
You know, just use an example of some of the problems that we've had in the last couple of weeks around sandbox escape.
B
Right.
C
You know, all of these agents and things, they need to use some tools in their execution environment and they run those in the sandbox. That is a wild west zone, as you can see from the kinds of things that are happening around sandbox problems in the world right now. As one example of what you get from a harness, you actually get the approval of the tool chain. So when the agent wants to do something, harnesses will actually govern whether it's allowed to happen or not. So you get some guardrails around the sort of degrees of freedom that energentic intelligence can, can do. That's exceptionally important. You also, you know, you develop these things, you test them and then you push them into production. Very similar to what we did when we were building cloud workloads and we use things like Terraform. We go from our desk through some staging, through some validation, and then we get a production ready candidate and then we could test that and we push it into production. Well, the same thing happens in this agent world and harnesses are the equivalent of sort of the pipeline from development through to production and then giving you some observability into what's happening inside of that agent that you pushed out. So they give you governance on things like what the agent's allowed to do. They give you an STLC like platform to be able to deploy your agent. And they then allow you to. All of these things kind of need a human, which we can come to later. And they allow you to then check things with humans and they drive a complete audit trail what happened, which you have to have. So the harness is actually a super important piece of any decision of how you're going to anchor your next generation soc.
B
So you brought the human part into it. That is something that I was going to ask you because like I said, we've been talking about this for a while on Safe Mode, particularly this year. We had on Mike Nichols from Elastic, we had on David Slater from Armadan, Kevin Mandia's friend and co founder. We had on Dove, who I know that you will work with, just talking about where the human fits into this loop. So I'll ask you from the conversations that you're having, and given that the industry does seem to be iterating on this sort of on the fly, where do you see the human fitting into this? Because I think that's always the big question that everybody's worried that we're just going to have a sock that is autonomous. And then the leaders that I talked to are like, well, not really. The human is still going to fit in. So I think, you know, $64,000 question is, okay, where does the human fit in?
C
Where what happens? Yeah, so, so I'll answer the question. Two parts. You know what, let me, let me come back to a point which is really important, which how do the roles change in a sock when you have an agentic intelligence? I think that's a super important topic. But what happens just on the ability to do something where we are right now is people actually want to run it in sort of a parallel investigate mode. So take One of these things, take all the information and see how far you get. I want to just. Now I'm a level 3 SoC analyst and I want to look at your enrichment. I want to look at what you would do when I start to realize, which happens pretty quickly, that you actually do a really good job, Mr. Agent, and you're getting a long way down range on this problem in a couple of seconds. That would take me hours and hours to do. And you're grinding over immense amount of information I could never do as a human. The SOC people get very interested in this approach quick, okay, so that's the state of play now. But would you actually let it do something to a critical endpoint, like perhaps isolate it, reinstall it, put it back a normal recovery process? Well, no, because not going to do that. Somebody's going to look at it, make sure they like it, understand what's going to happen to it, know what it is, what kind of impact that is, and then approve or adjust what it's going to do or take it over and do something. With a normal runbook, that piece where there is a human in the loop prior to a critical decision is still essential. And so, you know, in our architectures, we think there's a policy gate that decides whether you hand this over to a human to execute a piece of it. Now that you've figured it all out and you've got a high conviction of what needs to happen, or there's a bounded execution boundary that will allow you to do something to it. Okay, the agent could take over. So, you know, first you figure it all out and then you hit a policy gate and you decide human. Most of the time today that's a yes or there is a policy gate. Now, what my personal thought is is it will be quicker than we think, that there is bounded execution by agents on the full, you know, response side of the, you know, detection and response. That will come quicker than we think. You know, I motion that by the end of next year, we're going to see a lot of response. Why do I say that? I've seen a bunch of cases where when you pull the same event that was processed by a human run SOC through a SIM pipeline and you compare it to what the agents did, the agents got it more correct, better conviction, and they did it sub three seconds, you know, which was very compelling.
B
Right.
C
And so I think we're going to see that transition from human in the loop to human, watches it with training wheels and then promotes certain things into being able to do that now when that happens, the governance really matters. You're not going to change that agent without super proof that it still works. You're not going to change that model without super proof that it works. And you're not going to let somebody else change that model without proof that it still worked. Okay. And so there becomes a lot of governance as we improve from humans checking everything to letting it do some things to perhaps letting it do more things. And that's, that's there, right?
B
There's still going to have to be some judgment for sure.
C
For sure. You know, like if you've worked in a security operations before, which a bunch of folks in my business have never done that. Now when I was running Symantec, we had the world's largest one. It's currently over at Accenture.
B
Okay, okay.
C
Seven global socks. Thousands of people grinding on advanced threat around the clock 247 all day. And you go in there and see what's happening. There's a bunch of things in there that you're never going to let off the hook with that without somebody looking at it. You know, you're not going to touch something that's got financial system of record implications until you really know whether it's okay or not. You're not going to pop a computer out of a Kubernetes cluster workload that's running your trading floor because it got a piece of malware on it somehow you might shut the whole thing down. That needs a lot of, you know, risk management, human stuff involved. But would you isolate and restore a call center workstation that got compromised by something? Probably that's what you do anyway, right? So there's different, different examples.
B
So finally when you announced the, the alliance, you said that, you know, leaders, you would rather leaders adopt this deliberately. They get forced into it by incident. And I think in the incident, like a good incident is the OpenAI hugging face which we just saw recently. So I'm wondering where does the next 12 months take the alliance? Is it more members? Is it published standards? Is it real interoperability demos? Like how much are you sinking into this alliance and what do you see in the future and how will it grow?
C
Yeah, so. So I would say that at extra hop we really see ourselves as a convener of the initial energy there. Okay. We really want this to be an industry thing. Everyone's welcome, competitors, people in other parts of it. We think that, that there's a lot of folks working on security in the concept of AI around model integrity, lots of different topics. But in this particular case, the ability to get accurate data quickly into an agent to respond to machine attacks is a little different zip code of AI security. And we want people to think about that. And it has a, a ton of just technical marketing in it to say, hey, there is a way to do this where you can get the industry to adopt it, competitors can be involved and it works. We want to bring some, another level of sort of specificity the pieces of it and then we think we work with some standards bodies to bring it out as real standards on how to do things Again, you know, my career, I've done this a lot. You know, I've worked on a lot of standards. I got my name on a bunch of them from when I used to, when I used to work for a living on the, on the tech. And it is very important that we keep this very open, standards based and produce a set of, of concepts for how to think about it. Just like when app servers came around, you know, there's weblogic back, they had a great one, but then everybody had them and there were standards for how to do it. And you know, various. This, this is exactly the same kind of thing. We need to think about it in pieces because you can never upgrade that whole thing at once. You're going to have layers of IT that do certain things. And you know, I think the context in Harness layer is kind of like the operating system of it and the applications that run on an operating system is the agent model, things that run on top of it. And we, we would really like that to be something that everybody sort of says, okay, yep, that's a good idea. We need to start talking about that. We need to put something together that does that and then the various vendors can show up with their differentiation.
B
Great, Greg, really interesting conversation. Thanks for hopping aboard and giving us some behind the scenes on the Agentix SOC alliance.
C
No worries, Greg. I really appreciate you inviting us on and giving us some airtime and we are in a very interesting time in cyber. I've been doing it for 45 years, Craig, and I've never seen anything as interesting as what we're doing.
B
I have to agree. Haven't been doing it as long as you, but it's definitely the most interesting time that I've seen in, in my, my coverage area. So glad you could hop on to talk about it. Really appreciate it.
C
Same here. Thanks, Greg. See ya.
A
Thanks for listening to Safe Mode, a weekly podcast on cyber security and digital privacy, brought to you by Cyber Scoop. If you enjoyed this episode, please leave a rating and a review and share it with your friends, your co workers, your CISOs, your sysadmins, your mom, your dad, anybody that wants to know more about cyber security. To find out more information or to contact me, please look for all of our social media handles or visit cyberscoop.com thanks for listening. Check us out next week.
Safe Mode Podcast: "The SOC wasn't built for this"
Date: August 6, 2026
Host: Greg Otto (Editor-in-Chief, CyberScoop)
Guests: Matt Kapko (CyberScoop Reporter), Greg Clark (CEO, ExtraHop)
This episode explores how artificial intelligence (AI) is fundamentally transforming Security Operations Centers (SOC), making legacy approaches obsolete in the face of rapid, machine-speed threats. It features two core sections: a timely discussion with reporter Matt Kapko about recent open source software supply chain attacks and an in-depth interview with Greg Clark about the launch of the Agentix SOC Alliance—an initiative aiming to redefine SOC architecture for the AI era.
Major Incident Recap:
Attack Dynamics & Aftermath:
Open Source Dependency Weaknesses:
Recurring Attacker (Team PCP):
Greg Clark details a three-layered architecture vital for an “agentic” SOC. (16:04–20:04)
This episode is a must-listen for anyone interested in the rapid evolution of cybersecurity operations under the pressure of AI—highlighting challenges, conceptual architectures, and the necessity for collaboration and standards in the new era.