Intel Node
The Hunter's Paradox: Is it time to embrace automated threat hunting?
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.
Should we let AI run our threat hunts? The debate usually splits into two camps. One says, "Yes, obviously! The sheer scale of our security telemetry is impossible for humans to deal with." The other says, "Absolutely not !   You can't trust an AI with something this important."    The thing is, I think both are wrong, or at least incomplete.    I've spent a long time as one of the louder voices saying that hunting is specifically a human-driven process.
I created the first widely recognized definition of threat hunting back in 2015, and the version I'd have given you until very recently put a human firmly at the center of it.    But lately I've been reconsidering the role of AI in threat hunting.