Beyond the Alert

Dropzone AI

Beyond the Alert features security operations leaders and SOC professionals sharing battle-tested insights on scaling security capabilities, managing high-performing teams, and leveraging emerging technologies to transform their operations. Join us as we discuss investigation techniques, leadership strategies, and real-world approaches to delivering effective security outcomes in an increasingly complex environment.

  1. Jun 18

    Why initial access brokers are an intelligence advantage, not just a threat

    Alex Bovicelli runs cyber threat intelligence across 15,000+ insured organizations at Tokio Marine HCC, and his program sits on something most teams will never have: direct visibility into thousands of ransomware claims and full DFIR engagements. That means he's not theorizing about how breaches happen. He's watching them close out in real time. In this episode, Alex gets into why the threat feeds most SOC teams rely on are a lagging indicator at best, how his team decides what actually gets escalated to customers, and what ransomware groups are really targeting right now and it's not what the news is covering. Topics discussed: Why threat feeds are post-exploitation artifacts and what analysts should be doing instead Using TTPs and MITRE ATT&CK to move left of bang before IOCs ever get published How visibility into insurance claims builds a prioritization model that customers actually trust Why one access broker selling to five ransomware groups makes infrastructure tracking easier, not harder Building narratives that get leadership to act before an incident, not after Where AI genuinely accelerates threat intelligence work and where the intelligence-generation hype breaks down Why groups like Akira have profitably targeted SMBs for years through opportunistic SSL VPN brute forcing, not targeted recon The mission-driven quality that separates elite threat intelligence analysts from technically competent ones Listen to more episodes:  Apple  Spotify  YouTube

    Why initial access brokers are an intelligence advantage, not just a threat
  2. Jun 4

    40% of IT teams already hired a fraudulent candidate and still think they can spot a deepfake

    GetReal surveyed 700 IT professionals at mid-to-large businesses and found that roughly 40% said they had already hired a fraudulent candidate. Most of those same respondents also said they were confident they could spot a deepfake. Tom Cross has tested face swaps and voice clones against leading biometric models, and they pass. Not sometimes. Typically. In this episode, he maps out exactly how threat actors are moving through the credential lifecycle right now, from remote onboarding to help desk resets, and what a hardened process actually looks like when neither a face nor a voice can be trusted as proof of identity. Tom also walks through a working agentic social engineering setup his team built from scratch: a softphone routed through speech-to-text, into an LLM, out through a voice cloner, and back to the call. One operator, thousands of simultaneous calls, and an AI that adapts its emotional tone in real time based on how the target responds. Microsoft's 2025 Threat Report puts 80% of initial access at credential-based attacks, not software vulnerabilities. Tom's position is that number will stay high, because there is no patch for human susceptibility to social engineering. Topics discussed: GetReal's survey finding: 40% of IT professionals report having hired a fraudulent candidate  Real-time full body deepfake tools that defeat biometric detection, including hair and hands The credential lifecycle as a kill chain and the two moments most actively targeted: issuance and reset How North Korea's IT worker placement operation exploits remote onboarding, stolen identities, and laptop facilitator networks running IP KVMs Early behavioral indicators to catch fraudulent employees before they reach your network The agentic social engineering stack: softphone, speech-to-text, LLM, voice cloner, and how it scales to thousands of simultaneous calls Why the Caesars and MGM breaches started with a LinkedIn search and a help desk call, not a CVE Why callback verification failed Marks and Spencer after attackers pre-swapped employee SIMs Post-reset correlation signals: direct deposit changes, new privileged account creation, and address modifications on day one of employment Why software vulnerabilities are shrinking as an initial access vector while social engineering is not

    40% of IT teams already hired a fraudulent candidate and still think they can spot a deepfake
  3. May 21

    If it's predictable, it's preventable: Duaine Labno’s framework for staying ahead of incidents

    Duaine Labno came up through law enforcement before taking over a workplace violence and threat assessment program, and that transition shaped everything about how he runs his threat intel teams. His team processes millions of data points and handles life-safety events in real time. What he lays out in this conversation is less about theory and more about the operational habits that separate teams who stay ahead of incidents from the ones reacting to them. Topics discussed: Anticipating what comes next before it gets asked, and how Duaine trains analysts with no prior experience to think that way Why treating incoming threat data as reliable by default is the single biggest mistake analysts make, and the multi-source verification process his team runs before any alert becomes actionable The three-step decision process his team follows once an alert is verified: confirm it's real, assess impact on the client and public safety, then develop messaging and next steps simultaneously How a modified incident command structure assigns clear roles during a live event so no one is pulled away from where the focus needs to be Running scenario training with ambient sounds and real past incidents to close the gap between classroom readiness and performance under actual pressure How media sensationalism of physical attacks drives copycat behavior, and what that pattern means for how threat teams should read today's domestic threat landscape Reading his team's operational state by walking in and asking a few targeted questions, and why that beats any status update Why urgency alone never moves executives, and how Duaine builds data-justified arguments to get resources and process changes approved after an incident What he learned from interviewing a retired government threat analyst who couldn't carry a conversation, and why communication ability is a hard requirement for anyone on his team "If it's predictable, it's preventable": his one-line framework for how every SOC and threat intelligence leader should start their day Listen to more episodes:  Apple  Spotify  YouTube

    If it's predictable, it's preventable: Duaine Labno’s framework for staying ahead of incidents
  4. May 7

    What Happens When Your AI Agent Learns How to Escape Your Own Lab?

    Dhruv Majumdar has 15 years across red teams, incident response, EY and Deloitte consulting, and co-founding an MDR company before Gartner coined the term. That history gives him a vantage point most vendor-side voices don't have: he's been the person buying tools, building detection programs from scratch, and managing ransomware incidents in real time. In this episode, he makes a clear case that the alert problem is a culture problem first and a technology problem second, and explains exactly why adding more agents to an overwhelmed SOC is the wrong answer. Dhruv draws from 13 ransomware incidents across his career, a 2019 near-miss that came down to three minutes before a hypervisor was fully encrypted, and a personal red team lab where one of his own AI agents escaped its network boundaries through a jump server it had learned to traverse during a prior session. Topics discussed: Why scaling from 5,000 to 50,000 alerts won't be solved by more detection agents, and what the autonomous response risk actually costs Applying the nuclear two-key principle to any application with widespread kinetic impact, and why single-admin golden keys are a policy failure not a tech gap Graph-based risk modeling over list-based inventory: cross-referencing MITRE behavior, time span, and response criteria to reduce 50,000 alerts to three users worth investigating Shadow AI as an evolved shadow IT problem: prompt-injected MCP skills files, LiteLLM compromise, and why sandboxing means nothing if you don't burn session tokens after every AI interaction Detecting unauthorized AI in your environment the same way you'd detect malware: unexpected cron jobs, PowerShell calls, and launch control anomalies as behavioral signals Known known vs. known unknown vs. unknown unknown as a SOC maturity diagnostic, and why most teams are still operating in the first tier Who audits the auditor: EDR silencers, log corruption, and the gap between what you think you're seeing and what's actually bypassing your stack What prevented full encryption during a live 2019 ransomware event: a 24-hour audit log re-reviewed by an ML algorithm that flagged the miss seven hours later, plus a SOAR block with three minutes to spare Listen to more episodes:  Apple  Spotify  YouTube

    What Happens When Your AI Agent Learns How to Escape Your Own Lab?
  5. Mar 26

    Elastic's Darren LaCasse on Why SOC Teams Should Sort Alerts by Volume Before Severity

    Darren LaCasse, Director of Threat Intelligence, Detection, & Response at Elastic, makes a case that most SOC leaders are solving alert fatigue the wrong way. Starting with critical alerts keeps teams treading water. His approach of sorting by volume first, clearing the biggest bucket, then using that momentum to ask why those alerts existed at all separates short-term queue management from the actual tuning work. He also walks through how his team built an in-house AI agent that cross-references threat intelligence against their own vendor lists, software asset inventory, and vulnerability data before it ever reaches a detection engineer, filtering hundreds of daily articles down to what is actually relevant to their environment. Beyond tooling, Darren challenges how the industry frames the talent shortage. He does not think it is a skills problem. He thinks employers do not want to make the long-term investment in junior analysts, and that avoidance is where burnout compounds. He talks about how he leads that differently: sharing his own mistakes openly, encouraging his team to document every decision so he can back them up, and what he actually looks for when hiring (someone who has solved a real business problem creatively, not a polished resume).  Topics Discussed: Reframing alert prioritization by sorting queues on volume rather than severity to build analyst momentum and reduce backlog Using historical alert data to identify chronic tuning problems versus one-time spikes in SOC queue volume Building in-house AI agents that cross-reference threat intelligence against asset inventory and vulnerability data for environment-specific relevance Translating threat intelligence deliverables into detection rules by running source reports through AI agents and validating against internal data lakes Evolving detection engineering from static, hand-built rules toward dynamic, AI-assisted scoring systems that aggregate signals into actionable investigations Reframing the cybersecurity talent shortage as an employer investment problem rather than a pipeline or skills gap Building team cultures where analysts feel safe to document decisions, admit mistakes, and take time off without guilt Predicting the SOC analyst role shifting toward agent management, including tuning, output validation, and QA across AI-assisted workflows Listen to more episodes:  Apple  Spotify  YouTube

    Elastic's Darren LaCasse on Why SOC Teams Should Sort Alerts by Volume Before Severity

About

Beyond the Alert features security operations leaders and SOC professionals sharing battle-tested insights on scaling security capabilities, managing high-performing teams, and leveraging emerging technologies to transform their operations. Join us as we discuss investigation techniques, leadership strategies, and real-world approaches to delivering effective security outcomes in an increasingly complex environment.