<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ReliaQuest Blog - Threat Hunting, Security Operations, and More</title><description>Stay up-to-date on the latest cybersecurity topics and security operations thought leadership from ReliaQuest experts.</description><link>https://reliaquest.com/</link><item><title>Sorting the Agentic AI Hype From Black Hat 2026: 4 Things to Look For</title><link>https://reliaquest.com/blog/sorting-the-agentic-ai-hype-from-black-hat-2026-4-things-to-look-for/</link><guid isPermaLink="true">https://reliaquest.com/blog/sorting-the-agentic-ai-hype-from-black-hat-2026-4-things-to-look-for/</guid><description>Every booth at Black Hat 2026 read &quot;Agentic AI.&quot; So how do you filter the hype and figure out which tools will actually strengthen your defense?</description><pubDate>Thu, 06 Aug 2026 09:00:00 GMT</pubDate><content:encoded>&lt;p&gt;At the Mandalay Bay Convention Center, you could measure how fast the market is moving by counting the signs that read &amp;quot;Agentic AI&amp;quot; over the booth. The label was everywhere. What it actually meant changed booth to booth—and that is the problem you carry home.&lt;/p&gt;&lt;p&gt;The stakes behind the noise are real. The fastest data exfiltration ReliaQuest tracked in 2025 took 6 minutes, and any actor with the right model can now run advanced, targeted attacks at enterprise scale. A human watching an alert queue cannot match that pace.&lt;/p&gt;&lt;p&gt;Now the badges are in a drawer and the follow-up emails are rolling in, every one of them promising agentic AI. The useful question to ask yourself as you filter through your inbox on the flight home is not &amp;quot;who said agentic?&amp;quot; All of them did. It&amp;#39;s &amp;quot;how does this actually work, and will this strengthen my defense?&amp;quot; &lt;/p&gt;&lt;p&gt;Agentic defense is an approach to security operations where autonomous AI continuously understands the environment, reasons over risk, configures proactive measures, and coordinates defensive action across the tools and data already in place. Done well, it gives defenders more speed and scale, and the ability to operate effectively without being an expert in every tool or discipline. Identifying a comprehensive agentic AI solution from a repackaged claim comes down to a short list of criteria. Each one maps to a question you can tie directly to a vendor before agreeing to a second meeting.&lt;/p&gt;&lt;h2&gt;1. Autonomous Execution, End to End&lt;/h2&gt;&lt;p&gt;A complete solution runs the full range of SOC work autonomously—not just incident response, but detection engineering, threat hunting, threat intel research, and IT and OT coverage—across your tools and approved workflows, while defenders keep control of the decisions that matter. The tell on the floor was scope: many demos automated one scripted step in one discipline and handed the rest back to an analyst. The ones worth a second meeting ran continuously, and collaboratively, across every discipline and closed the loop without a human stepping in to finish the job.&lt;/p&gt;&lt;p&gt;Ask the vendor:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;i&gt;Does your AI run end to end across disciplines—investigating every alert, building and deploying detections, hunting proactively, and covering OT—or does it automate one step and hand the rest back to an analyst?&lt;/i&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;2. Knowledge of the Opponent&lt;/h2&gt;&lt;p&gt;Autonomy without context is fast guessing. Real defense is shaped by threat intelligence, attacker behavior, known exposures, and the attack paths most likely to be used against a specific environment. On the floor, this showed up as a clean split: tools that score generic risk versus systems that reason over what an attacker would plausibly do next. The deeper question is where that intelligence originates—whether a vendor generates its own or resells someone else&amp;#39;s.&lt;/p&gt;&lt;p&gt;Ask the vendor: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;i&gt;Where does your threat intelligence come from?&lt;/i&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;i&gt;Do you run your own researchers—boots on the ground producing native intel and threat research—or are you repackaging third-party feeds?&lt;/i&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;i&gt;Does your AI apply that intel to my environment continuously, or reason only over data inside your own platform?&lt;/i&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;3. Coverage Across Your Existing Architecture&lt;/h2&gt;&lt;p&gt;A comprehensive solution works across your existing tools, clouds, SIEMs, and data stores without forcing everything into one platform. This is where the show floor divided. Many pitches quietly assumed you would centralize your data in their lake first, which resets your architecture on their terms and creates blind spots for data too expensive or too sensitive to move. The stronger model normalizes telemetry from any vendor at the field level without centralizing it, and runs detection at the source, at storage, or in motion as data moves—without requiring a SIEM.&lt;/p&gt;&lt;p&gt;Ask the vendor: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;i&gt;Does this require my data to land in your platform before detection can run, or can it normalize across my existing tools and detect at the source, at storage, and in motion without requiring a SIEM?&lt;/i&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;4. Plain-Language Operation for Anyone on the Team&lt;/h2&gt;&lt;p&gt;Most security tools gate their power behind syntax: to run a hunt, you first have to know how to write one. A comprehensive solution understands a defender&amp;#39;s intent in plain language and coordinates each request across the environment—build detections, run hunts, investigate alerts, and execute response without knowing SPL, KQL, or any vendor-specific syntax. This week reinforced how much of the &amp;quot;skills shortage&amp;quot; is really a syntax and tooling problem. When the interface is intent instead of query language, the pool of people who can do the work expands immediately.&lt;/p&gt;&lt;p&gt;Ask the vendor: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;i&gt;Can an operator who doesn&amp;#39;t know query syntax build a detection, run a hunt, and execute a response entirely in plain language, or does your demo still require an expert to phrase the request?&lt;/i&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Raise the Bar on the Follow-Up&lt;/h2&gt;&lt;p&gt;The market adopted agentic language faster than agentic operation. That gap is normal for any inflection point, and it&amp;#39;s the opening for security leaders to raise the bar as the follow-ups begin. Any vendor can demo one of these four in isolation. A comprehensive agentic AI solution answers all four at once—executing autonomously across every discipline, reasoning over intelligence it generates itself, covering your existing architecture without moving your data, and operating in plain language for anyone on the team. This combination set the bar. Take the four questions into every follow-up conversation, and look out to see them answered live, before a POC ever gets signed. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded></item><item><title>The Best Defense Is Proactive: GreyMatter Recognized by Forrester Among Proactive Security Platforms</title><link>https://reliaquest.com/blog/forrester-recognizes-greymatter-ai-soc-platform-in-proactive-landscape/</link><guid isPermaLink="true">https://reliaquest.com/blog/forrester-recognizes-greymatter-ai-soc-platform-in-proactive-landscape/</guid><description>GreyMatter enables security teams to move from reactive processes into proactive security—and beyond to predictive operations. See the Forrester report.</description><pubDate>Mon, 23 Mar 2026 07:00:00 GMT</pubDate><content:encoded>&lt;p&gt;For years, security operations has been defined by how fast a security team can identify and respond to threats. But AI changed the equation for both the adversary and the SOC. Responding faster is no longer enough.&lt;/p&gt;&lt;p&gt;At ReliaQuest, we’ve long viewed security operations as a journey that security leaders can follow to mature their operations:&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;p&gt;Proactive operations is the new standard for getting ahead of modern threats. Predictive operations is the goal for staying ahead of threats as they evolve. We built our agentic AI security operations platform, GreyMatter, around this conviction.&lt;/p&gt;&lt;p&gt;In the &lt;i&gt;Proactive Security Platforms Landscape, Q1 2026&lt;/i&gt;, Forrester formalized the industry shift—establishing the “proactive security platform” as a defined market category and recognizing ReliaQuest GreyMatter among notable platforms. &lt;/p&gt;&lt;h2&gt;Security Operations Has a Response Problem&lt;/h2&gt;&lt;p&gt;Most security teams are trapped in a reactive cycle. As alert volume grows, analysts are forced to spend more time triaging and responding, leaving less time for the work that actually reduces risk. The result is a constant state of firefighting that makes it harder to anticipate future incidents.&lt;/p&gt;&lt;p&gt;Meanwhile, attackers are moving faster. In 2025, attackers achieved &lt;a href=&quot;https://reliaquest.com/campaigns/annual-threat-report-2026/executive-summary-2025-vs-2024-at-a-glance&quot;&gt;lateral movement in as little as four minutes—85% faster than the year prior&lt;/a&gt;. At that pace, faster response is not enough to reduce risk.&lt;/p&gt;&lt;p&gt;Even mature teams that invest in proactive capabilities struggle to apply them continuously or at scale. According to Forrester, the primary challenge facing the proactive security market is that “fragmented security solutions and siloed data leave teams missing the right context.”&lt;/p&gt;&lt;p&gt;Proactive security operations solves this challenge by unifying fragmented data and tooling into a single operational model, giving teams the context they need to act on risk before it becomes an incident. &lt;/p&gt;&lt;h2&gt;What Is Proactive Security Operations?&lt;/h2&gt;&lt;p&gt;Proactive security operations is the practice of continuously reducing risk before an incident occurs. Reaching that state requires operational alignment across three pillars: visibility, prioritization, and remediation. &lt;/p&gt;&lt;p&gt;&lt;b&gt;1. Visibility&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Know what&amp;#39;s in your environment and where risk lives across endpoints, cloud workloads, identities, applications, OT/IoT, and third-party systems. Forrester says a proactive security platform “must provide a depth of asset context, such as its business relevance, data stored or transmitted by the asset, and whether security controls are appropriate and effective.” &lt;/p&gt;&lt;p&gt;&lt;b&gt;2. Prioritization&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Visibility without prioritization is noise. But just because an exposure can be exploited doesn’t mean it should be prioritized. According to Forrester, “proactive security vendors must also incorporate business context, IT operations team capacity, and the impacts of risk event modeling to show why one exposure should be remediated over another.” &lt;/p&gt;&lt;p&gt;&lt;b&gt;3. Remediation&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Forrester is direct: “a prioritized list of problems doesn’t improve security posture.” Proactive security is only possible when teams act on that knowledge—fast, consistently, and at enterprise scale. That requires a platform that goes beyond opening tickets, integrating directly with patching, configuration management, and security controls to close exposures before adversaries reach them.&lt;/p&gt;&lt;p&gt;Each pillar is essential, but they’re only effective in achieving proactive security operations when all three work together. &lt;/p&gt;&lt;h2&gt;The Journey from Reactive to Proactive—and Toward Predictive&lt;/h2&gt;&lt;p&gt;We built GreyMatter on the conviction that the only way to outpace advanced adversaries is to proactively reduce risk.&lt;/p&gt;&lt;h3&gt;Break Free from Reactive Work&lt;/h3&gt;&lt;p&gt;GreyMatter ingests and correlates telemetry across your entire security stack, then applies agentic AI to autonomously investigate and respond to 100% of alerts across 300+ technologies with 99.4% accuracy. Threats are contained in under five minutes—closing the window before attackers achieve lateral movement. &lt;/p&gt;&lt;p&gt;By eliminating Tier 1 and Tier 2 manual work, GreyMatter frees analysts to focus on higher-value, proactive initiatives.&lt;/p&gt;&lt;h3&gt;Scale Proactive Operations Across the Enterprise&lt;/h3&gt;&lt;p&gt;Getting out of reactive mode creates capacity that GreyMatter enables with native proactive capabilities most SOCs struggle to build and sustain on their own:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Dark web monitoring and digital risk protection&lt;/b&gt; to identify external threats before they reach your perimeter.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Continuous asset discovery &lt;/b&gt;to maintain a live inventory of every asset, entity, and exposure across your environment.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Threat hunting&lt;/b&gt; to proactively search for adversary activity across 300+ technologies.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Threat intelligence research&lt;/b&gt; that connects external risk from the open, deep, and dark web with your internal environment. &lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Agentic Teammates Make Proactive Capabilities Predictive&lt;/h3&gt;&lt;p&gt;Forrester calls agentic AI the leading disruptive force in proactive security — but observes that for most vendors, AI &amp;quot;isn&amp;#39;t yet changing how proactive security teams work.&amp;quot; For GreyMatter customers, it already has.&lt;/p&gt;&lt;p&gt;GreyMatter&amp;#39;s Agentic Teammates use over 200 agents and 400 AI tools to operationalize proactive capabilities at machine speed — autonomously executing threat hunts, generating and deploying detection logic, producing tailored intelligence reports, managing infrastructure health, and bridging OT/IT environments. Work that used to require dedicated teams running manual processes now runs continuously and without human intervention.&lt;/p&gt;&lt;p&gt;Together, these Teammates transform proactive capabilities into autonomous predictive operations.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/campaigns/greymatter-network-effect-collective-intelligence/greymatter-network-effect-guide/&quot;&gt;GreyMatter&amp;#39;s network effect&lt;/a&gt; amplifies this further. Threat intelligence and detection logic are shared across the full ReliaQuest customer base. When adversary behavior is observed in one environment, protections are applied across all.&lt;/p&gt;&lt;h2&gt;Proactive Security Is the New Standard&lt;/h2&gt;&lt;p&gt;For years, proactive security was treated as aspirational—a maturity milestone teams would reach once they cleared their alert queue. But AI has made that operational model obsolete.&lt;/p&gt;&lt;p&gt;To us, Forrester&amp;#39;s &lt;i&gt;Proactive Security Platforms Landscape&lt;/i&gt; reflects what we’ve seen across thousands of enterprise environments: breaches are rarely the result of a single missed vulnerability. They are the result of chained exposures, missed signals, and delayed response. Breaking that chain requires consolidated visibility, intelligent prioritization, and automated remediation working continuously and at scale.&lt;/p&gt;&lt;p&gt;Proactive security is no longer a theoretical future state. It is the required standard.&lt;/p&gt;&lt;p&gt;We believe ReliaQuest was recognized by Forrester as a proactive security platform because GreyMatter was built to enable exactly this shift—giving security teams the speed to move away from reactive operations, the capabilities to scale proactive programs, and the foresight to become predictive.&lt;/p&gt;&lt;p&gt;&lt;i&gt;Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, &lt;/i&gt;&lt;a href=&quot;https://www.forrester.com/about-us/objectivity/&quot;&gt;&lt;i&gt;read about Forrester’s objectivity here&lt;/i&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded></item><item><title>Threat Intelligence Works Best When It’s Operationalized</title><link>https://reliaquest.com/blog/threat-intelligence-works-best-when-its-operationalized/</link><guid isPermaLink="true">https://reliaquest.com/blog/threat-intelligence-works-best-when-its-operationalized/</guid><description>Forrester External Threat Intelligence Service Providers Landscape, Q1 2026, describes an external threat intelligence market —and recognized ReliaQuest among notable providers in this space.</description><pubDate>Fri, 24 Apr 2026 09:00:00 GMT</pubDate><content:encoded>&lt;h3&gt;GreyMatter Recognized by Forrester Among Notable External Threat Intelligence Providers&lt;/h3&gt;&lt;p&gt;Threats are accelerating, and AI is making it easier for adversaries to launch more sophisticated attacks at scale. At the same time, security teams are challenged to cover more ground—fraud intelligence, brand impersonation, exposed credentials, and supply-chain risk—with the same headcount and tooling. Raw IOC feeds and standalone intelligence platforms were never intended to power defense for that reality.&lt;/p&gt;&lt;p&gt;At ReliaQuest, we’ve long believed that threat intelligence only delivers value when it’s embedded into how your SOC operates—powering detections, driving hunts, and triggering threat response. We built GreyMatter around that conviction.&lt;/p&gt;&lt;p&gt;In &lt;i&gt;The External Threat Intelligence Service Providers Landscape, Q1 2026&lt;/i&gt;, Forrester describes an external threat intelligence market evolving toward an operationalized, AI-enabled approach—and recognized ReliaQuest among notable providers in this space.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;External Threat Intelligence Can&amp;#39;t Stay Idle&lt;/h2&gt;&lt;p&gt;Most security teams aren’t short on threat intelligence, but they often lack ways to operationalize it. The problem is where the intelligence lives and how it’s used. When it’s consumed in a standalone platform separate from the tools and workflows where detection, hunting, and response happen, it’s harder to act on. &lt;/p&gt;&lt;p&gt;According to Forrester, &amp;quot;gaps in operationalizing intelligence and aligning it to business context are the primary challenge&amp;quot; in the external threat intelligence market. That challenge plays out in SOCs every day. Analysts end up manually translating intelligence into detection rules, cross-referencing IOCs across alerts and tools, and contextualizing findings for their specific environment. Every handoff adds delay. That manual translation layer kills speed.&lt;/p&gt;&lt;p&gt;In 2025, the fastest data exfiltration ReliaQuest tracked took just six minutes. Average SIEM detection time remained at 51 minutes. At that pace, intelligence that isn&amp;#39;t operationalized is already too late.&lt;/p&gt;&lt;p&gt;Consider this scenario—a dark web forum is discussing new ransomware TTPs targeting the manufacturing industry. In a siloed model, that intel might sit in a report until it’s pulled for a quarterly analysis. Meanwhile, threat actors move forward with plans shared in the forum, and a manufacturing company on the receiving end of the attack doesn’t find out about it until the incident unfolds in real time. As attackers increasingly use AI to find and exploit vulnerabilities across the open, deep, and dark web, security leaders need to drastically reduce the time between collecting intelligence and acting on it. &lt;/p&gt;&lt;p&gt;Threat intelligence has to be embedded into the operational core of the SOC so it can continuously inform detections, hunts, and response.&lt;/p&gt;&lt;h2&gt;How GreyMatter Operationalizes Integrated Threat Intelligence &lt;/h2&gt;&lt;p&gt;Within GreyMatter, threat intelligence is continuously collected from deep, dark, and open web sources through proprietary collection systems and human-led research. That intelligence is correlated against assets, identities, vulnerabilities, and IOCs in a unified model—the foundation GreyMatter&amp;#39;s Agentic Teammates use to take action.&lt;/p&gt;&lt;p&gt;Forrester notes that &amp;quot;usable intel data is rich in context and delivered in machine-consumable formats that map directly to detections, response playbooks, and threat-hunting workflows.&amp;quot; That&amp;#39;s how GreyMatter delivers intelligence to the SOC.&lt;/p&gt;&lt;p&gt;Because threat intelligence is embedded at the platform level, the Agentic Teammates can autonomously:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Build and tune detections&lt;/b&gt; as new IOCs and TTPs emerge, updating rules across your SIEM and EDR tools without waiting for manual engineering cycles.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Kick off targeted threat hunts&lt;/b&gt; based on emerging threat actor activity, campaign patterns, or newly exposed infrastructure relevant to your environment.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Execute automated response playbooks&lt;/b&gt; that scope impacted identities, contain compromised assets, and initiate remediation within minutes of a signal surfacing.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;GreyMatter also natively converges threat intelligence with digital risk protection and attack surface discovery. When executive credentials appear in a stealer log or a fraudulent domain impersonating the brand is identified, those signals feed directly into the same operational model—triggering detection, investigation, and response through integrated workflows. That kind of convergence is where the threat intelligence market is headed—GreyMatter was built to operate this way from the start.&lt;/p&gt;&lt;h2&gt;What Forrester’s Market Perspective Highlights&lt;/h2&gt;&lt;p&gt;Forrester&amp;#39;s report highlights three dynamics shaping the external threat intelligence market. &lt;/p&gt;&lt;p&gt;&lt;b&gt;1. Main trend: Agentic AI being embedded into threat intelligence workflows to improve effectiveness and efficiency.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;How we believe GreyMatter fits in: &lt;/b&gt;GreyMatter&amp;#39;s&lt;a href=&quot;https://reliaquest.com/security-operations-platform/greymatter-agentic-teammates/&quot;&gt; Agentic Teammates&lt;/a&gt; leverage over 200 agent skills and 400+ AI tools to operate across threat intelligence workflows autonomously. The Threat Intel Teammate conducts research across the open, deep, and dark web and 57+ threat intelligence feeds to generate real-time threat reports tailored to a customer&amp;#39;s specific environment. Together, the Agentic Teammates autonomously investigate and respond to 100% of alerts across 300+ technologies with 99.4% accuracy—more than 74 million times a year.&lt;/p&gt;&lt;p&gt;&lt;b&gt;2. Primary challenge: Gaps in operationalizing intelligence and aligning it to business context.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;How we believe GreyMatter fits in: &lt;/b&gt;GreyMatter closes the operationalization gap by correlating external intelligence against a customer&amp;#39;s assets, identities, vulnerabilities, and IOCs in a unified model—then acting on it. The Detection Engineering Teammate reduces time spent on manual detection engineering by 70%, building, tuning, and deploying rules from natural language prompts. &lt;/p&gt;&lt;p&gt;&lt;b&gt;3. Top disruptor: AI systems and applications that meaningfully enhance threat intelligence capabilities.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;How we believe GreyMatter fits in: &lt;/b&gt;AI enhances every stage of the intelligence lifecycle within GreyMatter, from collection through response. GreyMatter customers contain threats in less than 5 minutes, and in a commissioned &lt;a href=&quot;https://reliaquest.com/campaigns/industry-recognition-reports/the-total-economic-impact-of-reliaquest-greymatter-june-2025/&quot;&gt;Total Economic Impact™ study of ReliaQuest GreyMatter&lt;/a&gt;, Forrester Consulting found that GreyMatter reduces Mean Time to Resolve by 75% for a composite organization based on interviewed ReliaQuest customers. &lt;/p&gt;&lt;p&gt;In one case, when Scattered Spider TTPs emerged, &lt;a href=&quot;https://reliaquest.com/campaigns/greymatter-network-effect-collective-intelligence/greymatter-network-effect-guide/&quot;&gt;GreyMatter deployed seven detection rules across all customers in a matter of days&lt;/a&gt;—turning isolated threat research into network-wide protection.&lt;/p&gt;&lt;p&gt;To us, Forrester&amp;#39;s market perspective confirms what we&amp;#39;ve seen operating across enterprise SOCs: the future of threat intelligence is operationalized, AI-driven, and embedded into the security operations lifecycle from collection through response.&lt;/p&gt;&lt;p&gt;GreyMatter makes that operational reality possible—giving security teams the foundation to detect, investigate, and respond before adversaries can execute.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/campaigns/shared-intelligence-shared-defense-swap-in-forrester/forrester-the-external-threat-intelligence-service-providers-landscape/&quot;&gt;&lt;b&gt;Read the full Forrester report&lt;/b&gt;&lt;/a&gt; to see how the external threat intelligence market is evolving. &lt;/p&gt;&lt;p&gt;&lt;i&gt;Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here .&lt;/i&gt;&lt;/p&gt;</content:encoded></item><item><title>ReliaQuest Named a Visionary in the Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies</title><link>https://reliaquest.com/blog/reliaquest-named-a-visionary-gartner-magic-quadrant-for-cyberthreat-intelligence-technologies/</link><guid isPermaLink="true">https://reliaquest.com/blog/reliaquest-named-a-visionary-gartner-magic-quadrant-for-cyberthreat-intelligence-technologies/</guid><description>Gartner recognized ReliaQuest as a Visionary for turning threat intelligence into autonomous detection and response—advanced threat detection at machine speed. </description><pubDate>Mon, 04 May 2026 11:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;b&gt;ReliaQuest Recognized as a Visionary in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies&lt;/b&gt;&lt;/p&gt;&lt;p&gt;At ReliaQuest, we&amp;#39;ve built GreyMatter on a clear belief: threat intelligence delivers the most value when it&amp;#39;s operationalized across security operations for stronger, faster defense. That belief shapes how we approach every part of the platform.&lt;/p&gt;&lt;p&gt;We’re seeing how AI is accelerating attackers. In 2025, the fastest data exfiltration we observed was six minutes—down from over four hours the year before. Simply collecting intelligence for periodic review is no longer enough. Security teams need to go beyond collecting intel. They need to use it to power action. &lt;/p&gt;&lt;p&gt;Our approach starts with collecting and unifying threat intelligence into a single operational view within GreyMatter. In the &lt;i&gt;2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies&lt;/i&gt;, Gartner recognized ReliaQuest as a Visionary for this approach.&lt;/p&gt;&lt;p&gt;For security teams, that recognition signals a shift: the future of threat intelligence is not simply in gathering more data, but in operationalizing it to help teams detect, investigate, and respond before adversaries can execute.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3&gt;Threat Intelligence Is Too Valuable Not to Operationalize&lt;/h3&gt;&lt;p&gt;Most organizations treat threat intelligence as a research function. Intelligence reports are skimmed during quarterly briefings as valuable intelligence that could have been used to autonomously update detection rules or trigger containment actions is instead filed away. &lt;/p&gt;&lt;p&gt;The reality is that &lt;a href=&quot;https://reliaquest.com/campaigns/greymatter-network-effect-collective-intelligence/greymatter-network-effect-guide/&quot;&gt;threat intelligence is the foundation of proactive security operations.&lt;/a&gt; Without it, detection rules stagnate, investigations lack context, and response actions are generic rather than environment specific. The missed opportunities to leverage threat intel are often the difference between staying ahead of threats and falling victim to them. &lt;/p&gt;&lt;p&gt;When exfiltration happens in minutes and detection takes nearly an hour, intelligence that isn’t operationalized is just documentation. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3&gt;How GreyMatter Operationalizes Threat Intelligence&lt;/h3&gt;&lt;p&gt;Within GreyMatter, threat intelligence is continuously collected from over 50 feeds spanning deep, dark, and open web sources, combined with proprietary collection systems and human-led research. By correlating intelligence with assets, identities, vulnerabilities, and IOCs in a unified model, GreyMatter turns intelligence into direct operational context for detection, investigation, and response.&lt;/p&gt;&lt;p&gt;For example, when GreyMatter identifies a customer’s executive credentials in a stealer log, that signal doesn’t sit in a queue waiting for manual review. GreyMatter immediately triggers a detection update across your SIEM and EDR tools, scopes the impacted identities, and initiates containment actions. From there, teams can investigate and respond directly within GreyMatter, rather than switching between fragmented tools and workflows. &lt;/p&gt;&lt;p&gt;This is what it means to operationalize threat intelligence. &lt;/p&gt;&lt;p&gt;That shift from intelligence as reference material to intelligence as an operational driver is what moves a SOC out of reactive, into proactive—and ultimately predictive operations.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3&gt;What Gartner Recognized In GreyMatter&lt;/h3&gt;&lt;p&gt;Gartner&amp;#39;s evaluation identified four core strengths in GreyMatter:&lt;/p&gt;&lt;p&gt;&lt;b&gt;1. AI-orchestrated decisioning.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;GreyMatter embeds agentic AI and automated workflows directly into the platform, enabling analysts to move from intelligence discovery to investigation to response in a single operational environment. &lt;/p&gt;&lt;p&gt;2&lt;b&gt;. Integrated data fabric.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;Rather than requiring centralized data ingestion, GreyMatter executes detection logic, enrichment, and response actions natively across your existing security tools. &lt;/p&gt;&lt;p&gt;3&lt;b&gt;. Automated detection engineering.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;GreyMatter supports automated rule creation, tuning, back-testing, and false positive reduction— streamlining workloads that traditionally consume significant analyst cycles. &lt;/p&gt;&lt;p&gt;4&lt;b&gt;. Proprietary dark web intelligence.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;Intelligence is aggregated through proprietary systems designed to surface malicious indicators, infrastructure, and threat behaviors, including exposed credentials, stealer-log data, ransomware signals, and activity across criminal forums. &lt;/p&gt;&lt;hr/&gt;&lt;p&gt;In the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies, Gartner recognized ReliaQuest as a Visionary. This placement validates what we&amp;#39;ve built in GreyMatter: a platform where threat intelligence functions as the connective tissue between detection engineering, alert triage, and response orchestration. And the impact is measurable. GreyMatter Agentic Teammates autonomously investigate and respond to 100% of alerts across 300+ technologies with 99.4% accuracy—more than 74 million times a year—while GreyMatter customers contain threats in under 5 minutes.&lt;/p&gt;&lt;p&gt;Our placement as a Visionary reflects more than strength in threat intelligence alone. It signals that the future of security operations lies in operationalizing intelligence across the entire lifecycle—from detection engineering to investigation and response. &lt;/p&gt;&lt;p&gt;That’s what GreyMatter customers already see in production: a platform where threat intelligence powers every detection, every investigation, and every response action autonomously, and at scale. That operational reality is what we&amp;#39;ll continue to build on.&lt;/p&gt;&lt;p&gt;&lt;i&gt;Gartner does not endorse any vendor, product, or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner&amp;#39;s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, Magic Quadrant is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.&lt;/i&gt;&lt;/p&gt;</content:encoded></item><item><title>Attackers Have Gone Agentic. Defense Must Do the Same.</title><link>https://reliaquest.com/blog/defense-must-go-agentic/</link><guid isPermaLink="true">https://reliaquest.com/blog/defense-must-go-agentic/</guid><description>GreyMatter is the agentic defense layer for the enterprise—giving defenders the same speed, scale, and skills advantages AI gives attackers, plus cost control. </description><pubDate>Mon, 15 Jun 2026 05:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Cyber defenders are fighting a new kind of offense. Attackers have gone agentic. AI has given them speed, scale, and sophistication that removes the skills needed to execute advanced, widespread attacks that was impossible just a few years ago. What once required deep expertise and significant resources can now be done by anyone with access to the right AI tools.&lt;/p&gt;&lt;p&gt;Anthropic&amp;#39;s Mythos model autonomously discovered thousands of zero-day vulnerabilities across every major operating system and browser—flaws that survived decades of human review and millions of automated security tests. Work that once took a specialist team weeks now happens in hours. AI is compressing the window between vulnerability discovery and weaponization to near zero. Multiple frontier AI models—including OpenAI&amp;#39;s GPT-5.4-Cyber and Google&amp;#39;s Big Sleep—already possess comparable capabilities and more will follow. The era of AI-accelerated attacks at scale is here. AI has given attackers three structural advantages:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Speed&lt;/b&gt;: AI-powered tools automate full attack cycles in minutes. The fastest exfiltration time recorded in 2025 was 6 minutes, based on ReliaQuest threat research.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Scale&lt;/b&gt;: AI allows simultaneous targeting of thousands of organizations. What once required an army now runs on a single prompt.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Skills Barriers Removed&lt;/b&gt;: Any actor with access to the right AI model can launch advanced, adaptive, targeted attacks at enterprise scale. AI tools like Mythos are clear demonstrations of this being a reality.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Meanwhile, the attack surface keeps expanding, and enterprise data is scattered across EDR, email, network, cloud, and SIEM. It exists in the hands of VIP employees traveling across the globe, partners, contractors, and customers. It lives on the open, deep, and dark web. It grows with every new acquisition, new business unit, new geography, and every new software the enterprise adopts—especially AI software.&lt;/p&gt;&lt;p&gt;Defenders must secure everything, everywhere, all the time. Yet most businesses still treat their security as something a team does in a room by watching the alert queue. A SOC team, a set of tools, an MSSP on call—that sufficed when threats were slow, data lived in one place, and human analysts could be stationary and keep up. That world doesn’t exist anymore. Security teams are more mobile and spread out than ever, just like the businesses they defend. Organizations must understand that security operations is not a cost-center, it’s the defense layer of the business, defending them from constant attacks.&lt;/p&gt;&lt;h2&gt;&lt;b&gt;The Market&amp;#39;s Failed Response&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;The security market hasn’t helped. Instead of giving defenders a real solution, it keeps offering options that add complexity without fixing the architecture underneath:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Option 1: Centralize in a SIEM&lt;/b&gt;: Too expensive, too slow, requires per-tool query language and syntax knowledge that prevents acquiring headcount and talent, and leads to coverage gaps because you cannot store everything. This model once worked when threats moved slowly and a handful of tools covered the perimeter. That is not the case today.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Option 2: Outsource to MDR / MSSP&lt;/b&gt;: You lose control, speed, and the ability to tailor defense to your business. They are single-threaded and only look at a single tool in your environment. It is a black box that only specializes in one specific type or brand of tool management, eliminating the network effect across a wide span of customers.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Option 3: Increase Headcount&lt;/b&gt;: More humans doing human-speed work against machine-speed attacks slows response time down. Analysts drown in mundane work, always feel behind, and burn out because their talent is being wasted.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Option 4: AI Tools&lt;/b&gt;: Siloed AI capabilities across DCIR, startups without the operational depth to accurately work in production, and AI within the more established platforms cannot act beyond their own data. Most are not truly autonomous, and none have a consistent pricing model. They charge per token, per query, per investigation—passing unpredictable and uncontrolled AI costs directly to their customers. As usage scales, costs spike. As new models emerge, defenders cannot take advantage without re-procurement or heavy integration management.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Option 5: Build vs. Buy:&lt;/b&gt; Requires the specialized expertise, infrastructure, and time most organizations do not have. Accuracy is unproven at scale.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Attackers have gone agentic, gaining speed, scale, and the removal of skills barriers. But the same benefits attackers gain from AI can be given to defenders. Agentic AI can make them defend faster across any environment with a lowered skills barrier. You must defend AI with AI.&lt;/p&gt;&lt;h2&gt;&lt;b&gt;Agentic Defense: Defending AI with AI&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;Security operations is the defense layer of every organization—the team, the processes, the technologies working together to protect the business. When facing AI-accelerated attacks, that defense layer must become agentic.&lt;/p&gt;&lt;p&gt;Agentic defense is the application of agentic AI to existing security operations people, processes, and technology to make the defense faster, more accurate, and more fortified against the AI-accelerated attacks coming at it. The same foundation, now powered by agentic AI, defends AI-accelerated attacks at machine speed with near-perfect accuracy across the entire environment.&lt;/p&gt;&lt;p&gt;This means making the work defenders already do—detection, investigation, hunting, response, intelligence research—operate autonomously at scale. Detections are built and deployed by AI as new threats emerge. Threat hunts are executed across the entire environment autonomously before an analyst has to ask. Every alert is investigated immediately, with no queue. Gaps in coverage are identified and closed before an attacker finds them. When the entire security operation becomes agentic, threat discovery and response initiates in seconds.&lt;/p&gt;&lt;h2&gt;&lt;b&gt;ReliaQuest GreyMatter: Agentic Defense for the Enterprise&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;ReliaQuest GreyMatter, the agentic AI security operations platform, is the agentic defense layer for the enterprise. It levels the playing field and gives defenders the same three structural advantages agentic AI gives attackers, plus an added cost benefit:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Speed: Lightning Fast with Near-Perfect Accuracy &lt;/b&gt;
GreyMatter agentic AI detects threats in seconds and contains them in under 5 minutes at 99.4% accuracy—the highest in the industry, proven across 1,300+ enterprises. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Scale: Defend Across Any Environment&lt;/b&gt;
GreyMatter operates across 300+ technologies—SIEM, EDR, cloud, network, email, OT, and AI applications—across multi-cloud, hybrid, and M&amp;amp;A environments simultaneously. The attack surface keeps expanding. GreyMatter scales with it without requiring data centralization or additional headcount.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Skills Barriers Removed: Any Defender Can Operate at the Highest Level
&lt;/b&gt;GreyMatter removes the skill barrier that has always limited who can participate in security operations. Any defender can defend any threat in plain language. It has six autonomous agentic systems, called GreyMatter Agentic Teammates, that deliver 3X the output of the existing security team without adding headcount—working continuously across every discipline, 24/7, without burnout or shift gaps.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Cost Efficiency: $2 to $4 Back for Every $1 Spent
&lt;/b&gt;GreyMatter’s AI Model Broker controls AI cost at the infrastructure level—selecting the most cost-effective model for each task. The result is flat, predictable, unlimited pricing. No tokens, no queries, no per-investigation charges. Customers consistently re-architect their security environment for efficiency and see $2 to $4 in return for every $1 they spend.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;GreyMatter gives any defender the ability to harness AI to detect threats, run investigations, and execute response faster across their entire tech stack in plain language, without needing to be an expert in every tool they own. The result is an AI defense prepared for any AI accelerated attack.&lt;/p&gt;&lt;h2&gt;&lt;b&gt;The Time to Level the Playing Field&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;Attackers have gone agentic and the threat is not slowing down. AI has fundamentally changed the rules. The window between vulnerability discovery and exploitation has collapsed. The volume of attacks is increasing. The sophistication is accelerating.&lt;/p&gt;&lt;p&gt;Organizations that transform their defense layer now—while attackers are still learning how to use these same AI capabilities offensively—will have a structural advantage.&lt;/p&gt;&lt;p&gt;ReliaQuest is an agentic AI cybersecurity company whose platform, GreyMatter, serves as the agentic defense for the enterprise—defending organizations against AI-accelerated attacks.&lt;/p&gt;</content:encoded></item><item><title>Agentic Attacks Have Already Hit Finance. The Defense Architecture Hasn&apos;t Caught Up.</title><link>https://reliaquest.com/blog/agentic-defense-finance-fraud-attacks/</link><guid isPermaLink="true">https://reliaquest.com/blog/agentic-defense-finance-fraud-attacks/</guid><description>Financial services faces agentic offense across credential harvesting, ATO, and ransomware. Why the defense architecture must match—and what that looks like in production.</description><pubDate>Wed, 27 May 2026 04:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Phishing infrastructure targeting financial services has tripled in a single quarter—now accounting for half of all observed threat activity against the sector. Brand-impersonating domains have overtaken credential exposure as the dominant digital risk signal, feeding account-takeover pipelines at scale.&lt;/p&gt;&lt;p&gt;Nearly 150 financial organizations hit by ransomware in 90 days, with Clop and DragonForce demonstrating deliberate sector specialization above all-industry baselines.&lt;/p&gt;&lt;p&gt;These campaigns share a structural characteristic: they&amp;#39;re multi-vector, machine-speed, and low-skill to execute. &lt;/p&gt;&lt;h2&gt;What AI Offense Looks Like in Practice&lt;/h2&gt;&lt;table&gt;&lt;tr&gt;&lt;th&gt;&lt;p&gt;Actor&lt;/p&gt;&lt;/th&gt;&lt;th&gt;&lt;p&gt;Technique&lt;/p&gt;&lt;/th&gt;&lt;th&gt;&lt;p&gt;Fraud Vector&lt;/p&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/blog/threat-spotlight-identifying-north-korean-insider-threats/&quot;&gt;&lt;u&gt;Lazarus Group&lt;/u&gt;&lt;/a&gt; &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Fake developer recruitment pipelines, fabricated repositories &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Credential theft at scale &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;APT42 &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Spearphishing via .lnk files with Dropbox C2 &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Executive account takeover &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;UNC1069 &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Deepfake Zoom calls + ClickFix lures &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;Authorized push payment fraud &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Each operates with an automation layer that removes the skills barrier—what required specialized teams three years ago now scales with commodity AI tooling.&lt;/p&gt;&lt;p&gt;For a sector where minutes of service disruption carry regulatory exposure, fraud loss, and brand damage, the math is stark: mean time to contain rose 49% last quarter to 2 hours and 34 minutes per incident.&lt;/p&gt;&lt;p&gt;Every one of those minutes is active exposure—funds moving, credentials being monetized, lateral movement progressing.&lt;/p&gt;&lt;h2&gt;Why the Current Architecture Can’t Match AI Offense&lt;/h2&gt;&lt;p&gt;Current defense models share a structural failure—they leave the underlying architecture intact:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Centralize in a SIEM—too expensive, too slow, creates coverage gaps the moment ingestion costs force tradeoffs&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Outsource to MDR—single-threaded visibility into one tool, no network effect across the environment, no tailoring to your business logic&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Add headcount—human-speed work against machine-speed attacks, burnout for the people you can least afford to lose&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Siloed AI tools—can&amp;#39;t act beyond their own data boundaries, no unified picture to operate on&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;That world is gone. Enterprise data now lives across EDR, email, network, cloud, SIEM, and in the hands of executives traveling globally. It grows with every acquisition, every new geography, every AI tool the business adopts. Defenders must secure everything, everywhere, continuously—and they&amp;#39;re doing it with architectures that force analysts to pivot between six disconnected tools per investigation, manually re-querying across incompatible schemas.&lt;/p&gt;&lt;p&gt;Centralizing everything in a SIEM is too expensive, too slow, and creates coverage gaps the moment ingestion costs force tradeoffs. Outsourcing to MDR providers means single-threaded visibility into one tool—no network effect across the environment, no tailoring to your business logic. Adding headcount puts human-speed work against machine-speed attacks and burns out the people you can least afford to lose. And siloed AI tools can&amp;#39;t act beyond their own data boundaries—they have no unified picture to operate on.&lt;/p&gt;&lt;p&gt;The consistent failure across all of these: they leave the underlying architecture intact. Detection still happens after centralization. Correlation still requires manual field mapping. Response still waits for a human to connect signals across tools.&lt;/p&gt;&lt;h2&gt;What Agentic Defense Actually Requires&lt;/h2&gt;&lt;p&gt;If offense is automated, multi-vector, and operating at machine speed across distributed infrastructure—defense must match it structurally. That means:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Detection before centralization.&lt;/b&gt; Applying correlation logic in-transit closes the gap between telemetry generation and threat identification to seconds.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Schema-native correlation from day one.&lt;/b&gt; Automatic field-level normalization at ingest eliminates the manual translation bottleneck across every connected technology.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Autonomous, multi-disciplinary response.&lt;/b&gt; Parallel investigation across identity, endpoint, network, and email simultaneously—matching the multi-vector structure of agentic attacks.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Cost architecture decoupled from usage.&lt;/b&gt; Defenders should never face a choice between investigation thoroughness and budget.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;GreyMatter: Agentic Defense in Production&lt;/h2&gt;&lt;p&gt;ReliaQuest built GreyMatter&amp;#39;s architecture around these requirements. The &lt;a href=&quot;https://reliaquest.com/security-operations-platform/universal-translator/&quot;&gt;Universal Translator&lt;/a&gt; maps every field from 300+ connected technologies to OCSF at the moment of integration—schema-native correlation from day one.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/security-operations-platform/transit/&quot;&gt;GreyMatter Transit&lt;/a&gt; applies multi-event detection logic to data in motion, firing correlation rules before anything is parsed or stored—5 seconds from telemetry event to validated alert.&lt;/p&gt;&lt;p&gt;Six autonomous agentic systems decompose security disciplines into hundreds of single-task agents. The IR Analyst teammate breaks every investigation into parallel component tasks—email metadata, identity anomalies, endpoint telemetry, domain reputation—each routed through an AI model broker that selects the optimal model per task.&lt;/p&gt;&lt;p&gt;Across ReliaQuest&amp;#39;s finance customer base, Automated Response Playbooks execute containment in 4 minutes 46 seconds. The sector average: 2 hours and 34 minutes.&lt;/p&gt;</content:encoded></item><item><title>The 5 Stages to Common Finance Fraud Attacks—and How to Stop Them</title><link>https://reliaquest.com/blog/5-stages-of-common-finance-fraud-attacks/</link><guid isPermaLink="true">https://reliaquest.com/blog/5-stages-of-common-finance-fraud-attacks/</guid><description>Finance fraud moves through 5 connected stages, from credential theft to wire transfer. See the attack types at each stage and how to break the chain before the payout.</description><pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Attackers targeting financial institutions have moved up the stack. Instead of attacking infrastructure head-on, they go straight for identity, trust, and human behavior—the layer where a stolen credential becomes a wire transfer. What looks like five separate fraud types is usually one operation moving through stages, each setting up the next. Under each stage are the named attack types it covers—the fraud your team likely already tracks, shown in the order a full operation tends to move through. Follow it from the outside in, and the places to break the chain come into focus. &lt;/p&gt;&lt;h2&gt;Stage One: Harvesting Credentials Outside the Perimeter&lt;/h2&gt;&lt;p&gt;&lt;i&gt;&lt;b&gt;Credential theft · brand and domain impersonation · dark-web credential exposure&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;The operation starts where internal tools have no visibility. Adversaries register lookalike domains, clone login pages, and harvest customer and employee credentials at scale before validating them against real authentication surfaces. In Q1 2026, &lt;a href=&quot;https://reliaquest.com/campaigns/finance/finance-sectoral-threat-report&quot;&gt;impersonating domains overtook credential exposure&lt;/a&gt; as the dominant external risk signal against finance.&lt;/p&gt;&lt;p&gt;This is the cheapest point to interrupt the chain, because no valid session exists yet—and interrupting it means looking outward, not just inward. Monitor domain registrations for lookalikes of your brand, watch dark-web and paste sites for leaked credentials, and pursue takedowns on spoofing infrastructure before it goes live. Phishing-resistant MFA such as FIDO2 or passkeys does the rest: even harvested credentials don&amp;#39;t yield a usable session.&lt;/p&gt;&lt;h2&gt;Stage Two: The AI-Generated Lure&lt;/h2&gt;&lt;p&gt;&lt;i&gt;&lt;b&gt;AI-generated phishing · spearphishing · business email compromise (BEC)&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;Phishing-for-information was the single top MITRE technique against finance last quarter. Commodity AI tooling stripped out the skill and time these campaigns used to demand, so volume and quality climb together—and they move faster than most pipelines can keep up. If detection logic only runs after data lands and indexes in a SIEM, you&amp;#39;re measuring response in hours while the attacker measures it in minutes. Closing that gap is mostly about proximity and automation: run detection as close to the event as possible, automate phishing triage so analysts aren&amp;#39;t hand-reviewing every reported email, and enforce DMARC, DKIM, and SPF so spoofed senders fail authentication before they reach an inbox.&lt;/p&gt;&lt;h2&gt;Stage Three: Impersonation That Turns Access into Approval&lt;/h2&gt;&lt;p&gt;&lt;i&gt;&lt;b&gt;Executive impersonation · deepfake fraud · authorized push payment (APP) fraud&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;A foothold isn&amp;#39;t a payout. To move money, the operation needs authority, so it escalates to the people who have it. The target is a finance leader who can approve a transfer, reached through a channel no perimeter tool watches.&lt;/p&gt;&lt;p&gt;Technical controls alone won&amp;#39;t stop a convincing deepfake; process will. Require out-of-band verification for payment approvals above a threshold, using a known callback number rather than contact details supplied in the request itself—the single most effective control against authorized push payment fraud. &lt;/p&gt;&lt;p&gt;Detection has a role too, but only when the signals combine: an anomalous executive login means little on its own and a great deal alongside a payment approval request arriving through an unusual channel or at an odd hour. Threat intelligence that maps these actors&amp;#39; known techniques to your environment is what turns &amp;quot;unusual&amp;quot; into &amp;quot;recognized.”&lt;/p&gt;&lt;h2&gt;Stage Four: Moving Like an Insider&lt;/h2&gt;&lt;p&gt;&lt;i&gt;&lt;b&gt;Account takeover · privilege abuse · insider threat&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;Once the operation holds legitimate credentials and executive cover, it stops looking like an attack. A permission change in identity, a data pull in SaaS, an access pattern in cloud—each event looks ordinary in its own tool, and surfaces as a threat only when all three are read as one sequence.&lt;/p&gt;&lt;p&gt;This is a correlation problem before it&amp;#39;s a detection problem, and teams lose here when their signals sit in incompatible schemas that force manual stitching. Normalize telemetry across identity, SaaS, endpoint, and cloud so behavior reads as a single sequence. Enforce least privilege and just-in-time access so one compromised account can&amp;#39;t roam. And baseline normal behavior per identity, so the abnormal data pull stands out against that user&amp;#39;s own pattern rather than a generic threshold everyone trips.&lt;/p&gt;&lt;h2&gt;Stage Five: The Payout&lt;/h2&gt;&lt;p&gt;&lt;i&gt;&lt;b&gt;Wire fraud · ransomware · data exfiltration&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;p&gt;The operation ends in a transfer, an exfiltration, or ransomware—and finance ransomware surged 44% quarter over quarter. Much of that pressure is opportunistic: Clop’s mass exploitation of managed file-transfer tools like MOVEitand Cleo hit the sector hard precisely because finance relies on them, while groups like DragonForce show more deliberate sector focus. Every minute here is active loss, which makes two things decisive: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Detect on behavior rather than payloads, because these operators live off the land with signed binaries that signature tools wave through; the tells are the actions, such as mass file access, unusual outbound transfer, and credential dumping. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Contain automatically. A human connecting signals across tools is too slow at this stage, so isolating a host, disabling an account, or blocking a destination has to happen without waiting on manual triage.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Where GreyMatter Fits&lt;/h2&gt;&lt;p&gt;Every stage above describes defense that should happen. The hard part is doing all of it, across every tool, fast enough to matter. That&amp;#39;s the agentic defense layer GreyMatter is built to be.&lt;/p&gt;&lt;p&gt;GreyMatter detects at source, at storage, or &lt;a href=&quot;https://reliaquest.com/campaigns/detect-earlier-spend-less/solution-brief-greymatter-transit-detection-in-motion/&quot;&gt;in transit&lt;/a&gt;, running multi-event correlation on data while it is still streaming, before it is parsed, indexed, or stored—which takes mean time to detect from hours to seconds. The &lt;a href=&quot;https://reliaquest.com/campaigns/operate-across-any-environment/greymatter-universal-translator-sb/&quot;&gt;Universal Translator&lt;/a&gt; maps every field from 300+ connected technologies into a unified OCSF schema the moment each tool connects, so identity, endpoint, SaaS, and cloud activity correlate as one sequence without centralizing the data first; that is the stage-four correlation problem, solved at ingest. &lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/campaigns/build-your-own-ai-driven-soc/multi-agentic-system-orchestration/&quot;&gt;Six agentic systems&lt;/a&gt; cover the disciplines a lean team can&amp;#39;t staff: the IR Analyst Teammate investigates every alert autonomously at 99.4% accuracy, while threat intel continuously maps finance-sector actor behavior to your environment. For financial services, that adds up to containing identity-based attacks at machine speed and producing a full audit trail for DORA and SEC compliance.&lt;/p&gt;&lt;p&gt;ReliaQuest&amp;#39;s finance customers have reached average mean times to contain of under 5 minutes; Donnelley Financial Solutions cut its own from two hours to three minutes. Your existing tools stay where they are. GreyMatter reads them as one defense instead of six.&lt;/p&gt;</content:encoded></item><item><title>Infrastructure Health, Now Agentic: The IT Engineer Teammate Is Here</title><link>https://reliaquest.com/blog/infrastructure-health-now-agentic-the-it-engineer-teammate-is-here/</link><guid isPermaLink="true">https://reliaquest.com/blog/infrastructure-health-now-agentic-the-it-engineer-teammate-is-here/</guid><description>The IT Engineer Teammate brings agentic triage to infrastructure health—autonomous investigation, chat support, and firewall review. Read the breakdown.</description><pubDate>Wed, 29 Jul 2026 09:00:00 GMT</pubDate><content:encoded>&lt;h2&gt;Healthy Tools Are the Foundation of Every Investigation&lt;/h2&gt;&lt;p&gt;Technology and infrastructure health is the foundation of the SOC. Investigations, threat hunts, and detection engineering all assume the same thing: the tools underneath are up, generating telemetry, and functioning as intended. When that assumption breaks, the rest of the SOC breaks with it.&lt;/p&gt;&lt;p&gt;The failures are rarely loud. A log source stops sending data. A connector drops. A parser silently degrades. Each one generates a health alert, and each one opens a blind spot in detection—coverage the team believes it has but no longer does. A ransomware rule that stops firing looks identical to a quiet environment. A threat hunt that returns zero results looks like good news—until someone learns the endpoint sensors feeding it went offline 7 days ago.&lt;/p&gt;&lt;p&gt;Meanwhile, every new tool adds operational drag. Engineers spend hours manually triaging health alerts—pivoting between consoles to answer basic questions about cause, urgency, and recovery—time that gets pulled directly out of real security work.&lt;/p&gt;&lt;h2&gt;Meet the IT Engineer Teammate&lt;/h2&gt;&lt;p&gt;GreyMatter&amp;#39;s IT Engineer Teammate is a persona-based agentic system built into the platform, purpose-built to monitor, triage, and investigate the health of your security stack. It autonomously investigates every health alert, answers questions in chat, runs connection and credential tests, surfaces chronic issues, and learns your environment over time through Agentic Memory. It also adds firewall configuration analysis in chat and coordinates directly with the Detection Engineer, Threat Intel Analyst, and Threat Hunter.&lt;/p&gt;&lt;p&gt;It is one teammate in the multi-agentic system GreyMatter orchestrates—alongside the IR Analyst, Threat Hunter, Threat Intel Analyst, Detection Engineer, and OT Engineer—each decomposed into hundreds of single-task agents so accuracy holds as work spans disciplines. Each system owns its discipline end-to-end but collaborate across disciplines without being asked, delivering agentic defense-in-depth.&lt;/p&gt;&lt;h2&gt;Core Capabilities&lt;/h2&gt;&lt;h6&gt;&lt;i&gt;Autonomous Investigation and Enrichment. &lt;/i&gt;&lt;/h6&gt;&lt;p&gt;Every health alert is investigated end-to-end before it reaches you—historical baseline drawn from the past 8 weeks, real-time state from GreyMatter, cross-alert correlation, and severity assessment. The alert arrives with an answer attached, not a data point to chase.&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h6&gt;&lt;i&gt;Conversational Triage and Support.&lt;/i&gt;&lt;/h6&gt;&lt;p&gt;Ask follow-up questions in plain language without re-explaining context. Get step-by-step troubleshooting, field definitions, and integration setup guidance directly in chat.&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;h6&gt;&lt;i&gt;Proactive Validation and Diagnostics. &lt;/i&gt;&lt;/h6&gt;&lt;p&gt;On a failure, the Teammate executes connection tests against direct source connections and log sources, validates authentication, and returns tailored remediation guidance.&lt;/p&gt;&lt;h6&gt;&lt;i&gt;Predictive Monitoring and Pattern Recognition.&lt;/i&gt;&lt;/h6&gt;&lt;p&gt;Instead of surfacing 20 identical alerts across weeks, the Teammate distinguishes one-off failures from systemic problems and flags degradation trajectories—&amp;quot;EDR sensor failures recurring on the same host group&amp;quot;—so the team can act at the root.&lt;/p&gt;&lt;h6&gt;&lt;i&gt;Agentic Memory. &lt;/i&gt;&lt;/h6&gt;&lt;p&gt;The Teammate learns maintenance windows, baseline log volumes, and escalation preferences, then applies them automatically. Tell it &amp;quot;expected during Sunday 2 AM maintenance—don&amp;#39;t alert,&amp;quot; and it recognizes future Sunday failures as expected, confirms connections restore afterward, and only alerts if something fails outside the window.&lt;/p&gt;&lt;h6&gt;&lt;i&gt;Firewall Configuration Support. &lt;/i&gt;&lt;/h6&gt;&lt;p&gt;Upload a configuration in chat and receive prioritized, line-referenced recommendations, a complete updated configuration file, and—on request—a side-by-side comparison explaining the security and performance impact of each change.&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;h2&gt;How It Works&lt;/h2&gt;&lt;p&gt;The IT Engineer Teammate builds on the connections GreyMatter already has to the technologies in your stack. There is no separate install. It leverages those existing API connections to the sources it monitors, watching their health and triaging the alerts they generate—the same way the IR Analyst Teammate triages a security detection.&lt;/p&gt;&lt;p&gt;When a health alert fires, the Teammate investigates and enriches it autonomously, then shows its work. Agentic Steps Transparency exposes every step on the alert—which tools ran, what was queried, and why the Teammate reached its conclusion.&lt;/p&gt;&lt;p&gt;Health also stops being a separate silo. As one of the teammates in GreyMatter&amp;#39;s multi-agentic system, the IT Engineer Teammate collaborates with the Detection Engineer, Threat Intel Analyst, and Threat Hunter across disciplines without being asked—so an infrastructure problem surfaces as a coverage problem the moment it matters.&lt;/p&gt;&lt;h2&gt;Ask in Plain Language, Get an Answer Grounded in Your Environment&lt;/h2&gt;&lt;p&gt;You can also work with the Teammate directly in natural language—no dashboards, no query syntax. Ask the IT Engineer Teammate:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;&amp;quot;What caused this connector failure and how do I fix it?&amp;quot;&lt;/b&gt; The IT Engineer identifies the root cause, runs a connection and credential test against the source, and returns step-by-step remediation guidance you can execute immediately.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;&amp;quot;Is this log source outage urgent?&amp;quot;&lt;/b&gt; The IT Engineer scores severity against the source&amp;#39;s expected volume and the detection coverage that depends on it, so urgency reflects operational impact rather than alert volume.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;&amp;quot;Has this alert fired before, and how often?&amp;quot;&lt;/b&gt; The IT Engineer pulls the historical baseline from the past 8 weeks and reports recurrence, frequency, and whether the pattern is trending toward failure.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;&amp;quot;Show me chronic issues that need strategic attention.&amp;quot;&lt;/b&gt; The IT Engineer surfaces recurring problems and degradation trajectories that warrant infrastructure-level action instead of another one-off ticket.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;&amp;quot;How is this SIEM parsing failure impacting my detection coverage?&amp;quot;&lt;/b&gt; The IT Engineer coordinates with the Detection Engineer to map the failure to the specific rules and coverage at risk.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;&amp;quot;Review this firewall configuration and recommend improvements.&amp;quot;&lt;/b&gt; It returns prioritized, line-referenced changes and a complete updated config, with a side-by-side impact comparison on request.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Answers that once took 30 minutes of console-hopping arrive in about 2 minutes, grounded in your environment.&lt;/p&gt;&lt;h2&gt;Use Cases&lt;/h2&gt;&lt;h3&gt;Collapsing Chronic Noise Into One Root Cause. &lt;/h3&gt;&lt;p&gt;An EDR sensor fails on the same host group every few days. Handled as isolated alerts, it produces 20 near-identical tickets across a month and never gets prioritized. The IT Engineer Teammate recognizes the pattern, collapses the noise into a single finding—&amp;quot;EDR sensor failures recurring on the same host group, recommend infrastructure capacity review&amp;quot;—and points the team at the cause instead of the symptom.&lt;/p&gt;&lt;h3&gt;Closing a Silent Detection Gap. &lt;/h3&gt;&lt;p&gt;A ransomware detection rule stops firing. On its own, that looks identical to a quiet environment. The Detection Engineer Teammate asks the IT Engineer Teammate whether a data problem is behind it. The IT Engineer traces a configuration error that broke processing 36 hours earlier, monitors restoration, and notifies the Detection Engineer to replay the affected detections. The customer receives one clear notification and closed coverage rather than a silent gap.&lt;/p&gt;&lt;h3&gt;Hardening a Firewall Configuration on Demand. &lt;/h3&gt;&lt;p&gt;A network engineer uploads a firewall configuration directly into chat. The IT Engineer Teammate returns prioritized, line-referenced recommendations, a ready-to-paste updated configuration, and a side-by-side comparison that explains the security and performance impact of each change. Config review moves from a periodic manual chore to an on-demand check.&lt;/p&gt;&lt;h2&gt;Availability&lt;/h2&gt;&lt;p&gt;GreyMatter Health is delivered to all GreyMatter customers automatically, with no customer action required—core visibility and triage of health alerts. The IT Engineer Teammate and cross-Teammate coordination is live with an active Teammates package.&lt;/p&gt;</content:encoded></item><item><title>Shadow AI Is a Non-Human Identity Problem Wearing a Different Name Badge</title><link>https://reliaquest.com/blog/shadow-ai-non-human-identity-problem/</link><guid isPermaLink="true">https://reliaquest.com/blog/shadow-ai-non-human-identity-problem/</guid><description>Shadow AI hides in engineering pipelines and credentials, not just ChatGPT. Learn why it is a non-human identity problem and how to detect it with behavioral context.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Shadow AI hunting does not start with employees pasting data into ChatGPT.&lt;/p&gt;&lt;p&gt;That is where most security teams start, which is not a bad instinct, just an easy one. Consumer chatbot use is visible, the services are known, and blocking unauthorized traffic is easily solved. &lt;/p&gt;&lt;p&gt;Spend more time thinking about the AI tooling used by engineering and data teams.&lt;/p&gt;&lt;p&gt;These teams connect tools to source code, CI/CD pipelines, cloud environments, databases, APIs, and production systems. Some tools have no separate account in the corporate identity provider. Others operate through credentials assigned to a human user.&lt;/p&gt;&lt;p&gt;A security team can monitor every visit to ChatGPT and still miss the activity that creates the greatest Shadow AI security risk: AI tooling with access to production.&lt;/p&gt;&lt;p&gt;For more on agentic architecture and non-human identity, our guide on &lt;a href=&quot;https://reliaquest.com/campaigns/build-your-own-ai-driven-soc/ai-agent-vs-agentic-systems-in-security-operations/&quot;&gt;AI Agents vs. Agentic Systems in Security Operations&lt;/a&gt; covers the underlying concepts.&lt;/p&gt;&lt;h2&gt;Why the Shadow AI Conversation Starts in the Wrong Place&lt;/h2&gt;&lt;p&gt;Ask security teams about &lt;a href=&quot;https://reliaquest.com/blog/ai-is-showing-up-in-real-attack-report/&quot;&gt;Shadow AI,&lt;/a&gt; and most will talk about user input. They want to know whether employees are pasting customer records into ChatGPT or uploading confidential documents to public models.&lt;/p&gt;&lt;p&gt;This fear is common. &lt;a href=&quot;https://www.gartner.com/en/newsroom/press-releases/2025-11-19-gartner-identifies-critical-genai-blind-spots-that-cios-must-urgently-address0?&quot;&gt;According to a study by Gartner&lt;/a&gt;, 69% of companies suspect that their employees are using unauthorized public GenAI technology. However, focusing on public tools can pull attention toward the activity that is easiest to spot.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/campaigns/the-ultimate-checklist-for-efficient-threat-detection/detection-engineering-that-scales/&quot;&gt;Detection from the engineering team’s side &lt;/a&gt;is harder. A developer integrates a coding tool with a repository, or a data scientist calls an external model within an analytics flow. A development team might integrate an AI service into an application via an API without creating a new SaaS account that can be easily detected by security.&lt;/p&gt;&lt;p&gt;Look there before assuming browser activity says much about your &lt;a href=&quot;https://reliaquest.com/cyber-knowledge/&quot;&gt;organization’s real exposure&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Most people adopt these tools with good intent. The &lt;a href=&quot;https://reliaquest.com/blog/defense-must-go-agentic/&quot;&gt;risk depends heavily&lt;/a&gt; on the access surrounding the tool. An AI service that helps rewrite an email presents one set of concerns. A tool connected to systems that build and deploy software presents another.&lt;/p&gt;&lt;h2&gt;Where Shadow AI Actually Surfaces First&lt;/h2&gt;&lt;p&gt;Engineering teams work with repositories, build systems, deployment pipelines, cloud infrastructure, secrets, and production applications. Data teams may work with customer records, proprietary business data, analytics environments, and production data stores.&lt;/p&gt;&lt;p&gt;When either team adds AI to an existing workflow, the tool can gain access to sensitive systems, expanding the AI attack surface.&lt;/p&gt;&lt;p&gt;Analysts need to establish what it can read, what it can change, which credentials support it, and what other systems trust those credentials. A low-privilege experiment against synthetic data deserves a different response from an unsanctioned service connected to production code.&lt;/p&gt;&lt;p&gt;We would prioritize according to blast radius. Understanding that blast radius is what allows real risk-based decisions.&lt;/p&gt;&lt;h2&gt;Why It Spreads Faster and Hides Better Than Traditional Shadow IT&lt;/h2&gt;&lt;p&gt;There is a distinction between Shadow IT and Shadow AI. Traditional Shadow IT often leaves something concrete behind: an application, cloud service, account, network connection, or expense.&lt;/p&gt;&lt;p&gt;Sometimes, Shadow AI is already embedded in your workflows. A developer connects a third-party model to an approved application through an API, or adds AI capabilities to engineering tools already in use. The tool may then operate with an employee token or existing service credential.&lt;/p&gt;&lt;p&gt;Nothing has to appear as a new AI account in Okta or Google Workspace.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/campaigns/build-your-own-ai-driven-soc/build-an-ai-driven-soc-6-entry-points-for-safe-ai-adoption/&quot;&gt;Security operations centers&lt;/a&gt; (SOCs) may see legitimate credentials interacting with legitimate systems and have no obvious indication that an unsanctioned AI tool sits between the person and the action.&lt;/p&gt;&lt;p&gt;Experiments can also become permanent before governance catches up. By the time security finds the tool, colleagues may already depend on it.&lt;/p&gt;&lt;h2&gt;The Visibility Gap: Why “We Monitor ChatGPT” Isn’t an Answer&lt;/h2&gt;&lt;p&gt;Browser monitoring shows which AI services users access through channels that are monitored. It does not show every model called through an API, all AI components inside an engineering pipeline, or each tool operating through an existing credential.&lt;/p&gt;&lt;p&gt;Often, telemetry is the first limitation.&lt;/p&gt;&lt;p&gt;If you do not gather relevant identity events, API activity, repository changes, credential use, pipeline behavior, and cloud actions, you will be unable to piece this activity together later. There is no detection solution that can recover data that was never collected.&lt;/p&gt;&lt;p&gt;It becomes even more difficult when this activity is carried out under a legitimate identity. A known user, valid token, and expected permissions can still give an analyst the wrong impression about who, or what, performed an action.&lt;/p&gt;&lt;h2&gt;What’s Actually at Risk: Source Code, Pipelines, and Credentials&lt;/h2&gt;&lt;p&gt;Within engineering environments, pay particular attention to source code, credentials, and CI/CD pipeline security.&lt;/p&gt;&lt;p&gt;Source repositories hold the company&amp;#39;s intellectual property and operational knowledge. Pipelines link development and deployment. The credentials used for these processes could grant access beyond the system where the investigation starts.  &lt;/p&gt;&lt;p&gt;The time available to investigate that access is also shrinking. Recent threat research recorded the fastest lateral movement at four minutes, the fastest data exfiltration at six minutes, and an average breakout time of 34 minutes.&lt;/p&gt;&lt;p&gt;An AI tool connected anywhere in that chain may influence more than its immediate task.&lt;/p&gt;&lt;p&gt;Data teams face a similar issue. A third-party AI service connected to an analytics environment or production data store may gain sensitive access without creating the visible footprint security teams expect from Shadow IT.&lt;/p&gt;&lt;p&gt;The practical question is how far an action can travel if the tool, credential, or workflow behaves unexpectedly.&lt;/p&gt;&lt;h2&gt;The Identity Problem Underneath It All&lt;/h2&gt;&lt;p&gt;Consider a user called Bob.&lt;/p&gt;&lt;p&gt;Your logs show Bob modifying code, calling an API, or interacting with a production system. Bob may have performed the action himself. An unsanctioned AI tool may also have performed it using Bob’s credentials or through a workflow he initiated.&lt;/p&gt;&lt;p&gt;The identity record cannot settle that question, which is one of the trickiest problems in AI identity management.&lt;/p&gt;&lt;p&gt;The AI tool may never receive its own account. Bob is still the authenticated identity even when software makes decisions and takes actions on his behalf. &lt;/p&gt;&lt;p&gt;This is becoming an increasingly important identity issue as AI systems become more autonomous. The National Institute of Standards and Technology (NIST) has advocated for &lt;a href=&quot;https://www.nccoe.nist.gov/news-insights/new-concept-paper-identity-and-authority-software-agents&quot;&gt;adaptive identity&lt;/a&gt; and access controls that account for the growing role of non-human identities.&lt;/p&gt;&lt;p&gt;Security teams cannot work without behavioral context. Sudden changes in repository activity, API sequences, credential use, access timing, or velocity may warrant investigation. &lt;/p&gt;&lt;p&gt;With GreyMatter, we correlate activity from current security solutions and environments, enabling analysts to view identity activity alongside other telemetry and potentially gain insight into permissions, behavioral context, and blast radius without having to reconstruct activity across disconnected console environments.&lt;/p&gt;&lt;p&gt;Security teams also need to know who has the means to influence, push, or chain together internal systems built on top of AI.&lt;/p&gt;&lt;p&gt;Inside GreyMatter, &lt;a href=&quot;https://reliaquest.com/security-operations-platform/agentic-ai/&quot;&gt;Agentic Teammates&lt;/a&gt; inherit the permissions of the user who initiated the request. In other words, if the user cannot access a resource or perform an action, neither can the agent.&lt;/p&gt;&lt;h2&gt;Building Detection from Scratch: The First Three Signals&lt;/h2&gt;&lt;p&gt;We recommend starting with:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Behavioral baselines. Monitor significant shifts in velocity, time, access patterns, and behaviors of identities who have the ability to change code, pipelines, production systems, or sensitive data.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Credential vaults and approved tooling. Monitor the credentials used by approved tools to connect to important systems, which may indicate compromise of the visibility layer itself.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Error-handling and retry behavior. Look out for processes that interpret errors, tweak inputs, select a different tool, or try an alternate path to achieve the same goal.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The third signal deserves attention. Scripted automation tends to fail according to predefined logic. AI-driven activity can adjust after failure.&lt;/p&gt;&lt;p&gt;Do not treat that pattern as proof of AI; use it to identify activity that warrants closer investigation.&lt;/p&gt;&lt;h2&gt;Response Without Becoming the Department of No&lt;/h2&gt;&lt;p&gt;We do not believe security teams can prohibit their way out of Shadow AI.&lt;/p&gt;&lt;p&gt;Most employees who introduce these tools are just trying to get their work done. If every new AI use case meets an automatic block, engineering and data teams will continue experimenting without involving security. The organization loses the cooperation it needs to understand access and risk.&lt;/p&gt;&lt;p&gt;The RACI needs to be explicit about who can authorize an AI application, who evaluates access to the application, who takes responsibility for the risks produced by the application, who observes behavior, and who intervenes in case of an anomaly.&lt;/p&gt;&lt;p&gt;Shadow AI does not fall under any particular function; security, engineering, IT, compliance, and data management functions may all play some role. The problem is when each thinks the other will handle the issue.&lt;/p&gt;&lt;h2&gt;Closing perspective: Shared Ownership is a Challenge&lt;/h2&gt;&lt;p&gt;Shadow AI reveals that several teams may own parts of the problem without clear boundaries between them.&lt;/p&gt;&lt;p&gt;Consumer chatbot monitoring still has value, but it does not tell you which AI tools can modify source code, use trusted credentials, influence deployment pipelines, or connect to production data.&lt;/p&gt;&lt;p&gt;The CISO must understand who has approval authority to introduce an AI application into production, who changes the AI application&amp;#39;s guardrails, and who is responsible for investigating activity performed by a legitimate identity that does not fit the user.&lt;/p&gt;&lt;p&gt;If these questions hinge on assumptions, risk decisions become a guessing game. CISOs need evidence of who can influence these systems and how far that influence can travel, rather than relying on what they have been told.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/resources/videos/reliaquest-greymatter-demo-home-page/&quot;&gt;Request a GreyMatter demo&lt;/a&gt; to see how identity and behavioral context can support security investigations across your environment.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded></item><item><title>Data Poisoning: What Threat Hunters See That Governance Frameworks Miss</title><link>https://reliaquest.com/blog/data-poisoning-threat-hunters-governance/</link><guid isPermaLink="true">https://reliaquest.com/blog/data-poisoning-threat-hunters-governance/</guid><description>AI data poisoning starts in the supply chain, not the training set. Learn what threat hunters watch for and why identity and provenance matter more than governance checklists.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;AI data poisoning rarely starts in a training set. For most organizations, it starts in the vendor, package, or pipeline that delivers the model.&lt;/p&gt;&lt;p&gt;In practice, we spend more time looking upstream, at the vendors, packages, datasets, software components, and CI/CD pipelines that deliver AI capability. An attacker who compromises one of those dependencies may influence what an AI system trusts before the organization using it realizes anything has changed.&lt;/p&gt;&lt;p&gt;For many organizations, the immediate exposure sits in the supply chain and in the identities that can influence it.&lt;/p&gt;&lt;p&gt;For readers who want the foundations of agentic architecture first, our guide on &lt;a href=&quot;https://reliaquest.com/campaigns/build-your-own-ai-driven-soc/ai-agent-vs-agentic-systems-in-security-operations/&quot;&gt;AI Agents vs. Agentic Systems in Security Operations&lt;/a&gt; discusses the underlying concepts.&lt;/p&gt;&lt;h2&gt;Why Data Poisoning Discussions Start in the Wrong Place&lt;/h2&gt;&lt;p&gt;The textbook explanation of data poisoning attacks talks about bad data entering a training set. An attacker manipulates examples, the model learns from them, and its behavior changes as a result.&lt;/p&gt;&lt;p&gt;The conversation tends to focus on “AI slop” ending up in training data. But the real exposure for most organizations is in the systems and pipelines delivering these components, not the training data itself. Most organizations use frontier or open-source models rather than training their own, then build scaffolding on top of them.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/&quot;&gt;MITRE ATLAS&lt;/a&gt; is indicative of the wider AI attack surface. The knowledge base includes the use of poisoning training data, the publication of poisoned data sets and models, and the publication of poisoned AI agent tools.&lt;/p&gt;&lt;p&gt;We also draw a clear line between poisoning and tampering. Poisoning actively manipulates the data used to shape a system. AI model tampering changes how data or model output gets interpreted without necessarily altering the training data itself.&lt;/p&gt;&lt;p&gt;The distinction affects the investigation. Label every unexpected change in AI behavior as poisoning, and threat hunters may start from the wrong evidence.&lt;/p&gt;&lt;h2&gt;The Highest-Value Targets Right Now&lt;/h2&gt;&lt;p&gt;We start with anything pulled from public libraries, third-party packages, off-the-shelf software, and quickly assembled or vibe-coded applications.&lt;/p&gt;&lt;p&gt;Every dependency introduces another trust decision. Packages change. Vendors get compromised. Components can arrive with behavior the organization never reviewed.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://airc.nist.gov/airmf-resources/playbook/&quot;&gt;NIST’s AI Risk Management Framework&lt;/a&gt; asks for policies and monitoring of third-party software and data. This approach seems appropriate. It’s also where things end. Policies and monitoring confirm that the vendor was checked at the point of onboarding. However, they don’t provide much insight into whether the model or component behaves differently now compared to a few months ago.&lt;/p&gt;&lt;p&gt;That’s what the threat hunter focuses on: confirming that the policy exists or catching the exact moment when the system deviates from its normal baseline behavior.&lt;/p&gt;&lt;p&gt;We also pay particular attention to LLM-as-a-judge systems.&lt;/p&gt;&lt;p&gt;Organizations increasingly use one AI system to grade, check, or validate another AI system’s output. This can improve quality and support autonomous AI guardrails, but it also creates an authoritative decision point.&lt;/p&gt;&lt;p&gt;If an attacker compromises the system trusted to evaluate AI output, downstream controls may continue accepting decisions from a judge that can no longer be trusted. That makes LLM-as-a-judge poisoning a particularly useful target for an attacker.&lt;/p&gt;&lt;h2&gt;Supply Chain or Insider Threat? A False Distinction&lt;/h2&gt;&lt;p&gt;Many governance frameworks view insider risk as &lt;a href=&quot;https://reliaquest.com/blog/threat-spotlight-no-safe-distance-the-business-impact-of-recent-global-developments/&quot;&gt;separate from external compromise&lt;/a&gt;. In an investigation, the route into the environment may be less important than what the attacker or insider gained access to.&lt;/p&gt;&lt;p&gt;External attackers often compromise vendors or packages, while insiders use their sanctioned access to influence datasets, components, or pipelines. Both actors can reach systems that build, approve, and deliver AI capabilities.&lt;/p&gt;&lt;p&gt;Knowing who can influence the pipeline is the starting point for assessing blast radius.&lt;/p&gt;&lt;p&gt;AI supply chain security depends heavily on identity, including non-human identity security. Teams need to know who can approve training data, modify evaluations, introduce models or components, and connect systems.&lt;/p&gt;&lt;p&gt;Without that information, any assessment of blast radius relies on assumptions alone. &lt;/p&gt;&lt;h2&gt;What Poisoning Looks Like to a Hunter Who Isn’t Looking for It&lt;/h2&gt;&lt;p&gt;A poisoned system does not have to look broken.&lt;/p&gt;&lt;p&gt;A hunter may first see a change in behavior. An evaluation starts passing output it previously rejected. A model responds differently under a familiar condition. A guardrail continues to run but stops producing the expected result.&lt;/p&gt;&lt;p&gt;Detection isn’t possible without a reliable picture of normal behavior.&lt;/p&gt;&lt;p&gt;Since most organizations use frontier models rather than training their own, the real place to hunt is the scaffolding and wrappers built around those models, wherever guardrails live (code repositories, evaluations). &lt;/p&gt;&lt;p&gt;Any deviation from a known-good evaluation result is the signal to chase.&lt;/p&gt;&lt;h2&gt;The Months-Long Blind Spot, and Why There’s No Clean Playbook Yet&lt;/h2&gt;&lt;p&gt;A poisoning event may not produce an obvious incident when it happens. The affected component can remain inside a workflow until a particular condition causes the altered behavior to surface.&lt;/p&gt;&lt;p&gt;Organizations need the ability to investigate by extracting away the model layer and focusing on intended outcomes, but a true &lt;a href=&quot;https://reliaquest.com/cyber-knowledge/understanding-automated-incident-response/&quot;&gt;incident response playbook&lt;/a&gt; for this specific scenario doesn&amp;#39;t really exist yet. &lt;/p&gt;&lt;p&gt;It comes down to observability: the telemetry built around a system, and understanding where and how an intended outcome would manifest in production or client-facing infrastructure if something went wrong.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai&quot;&gt;IBM’s 2025 breach research&lt;/a&gt; gives some context for the wider supply chain problem. Third-party vendor and supply chain compromise carried an average breach cost of $4.91 million in its study.&lt;/p&gt;&lt;h2&gt;Agentic AI Turns One Compromised Node into a Compounding Problem&lt;/h2&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/security-operations-platform/agentic-ai/&quot;&gt;Agentic systems create a compounding effect&lt;/a&gt;, and that is where agentic AI security risk looks different from risk in a standalone model. They are a mix of disparate systems chained together, whether through hard-coded paths or the agentic layer calling the right things at the right times. If one node in that chain is compromised, the input or behavior passes from node to node to node, and the problem compounds.&lt;/p&gt;&lt;p&gt;That can make &lt;a href=&quot;https://reliaquest.com/blog/defense-must-go-agentic/&quot;&gt;agentic systems more lucrative targets&lt;/a&gt; than a standalone large language model because the blast radius through dependencies is wider. &lt;/p&gt;&lt;p&gt;The dynamic has flipped. Historically, security teams pushed the business toward better practices and investment. Now the business is pushing security teams to adopt AI faster, with pressure from the board level to avoid “falling behind.” Security is on the other side of the table, trying not to block innovation while still figuring out how to enable it safely. It has created what amounts to a reverse fire drill.&lt;/p&gt;&lt;p&gt;Security teams need to address approved components, permission boundaries, evaluation baselines, and limits on autonomous action before deployment.&lt;/p&gt;&lt;h2&gt;Building Detection from Scratch: The First Three Signals&lt;/h2&gt;&lt;p&gt;Three things come first. Provenance verification maps where every dataset, model, and component came from, tracing the dependency chain step by step. Behavioral monitoring catches a downloaded model doing something unexpected at load time. And identity controls log who can touch or influence the model, who approves training data and samples, and who can build agentic systems on top of it, with least privilege applied throughout.&lt;/p&gt;&lt;p&gt;As complexity grows and more people become involved, there are more opportunities for things to fall through the cracks.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/&quot;&gt;GreyMatter&lt;/a&gt;&amp;#39;s Universal Translator normalizes telemetry from disparate tools into a common schema at ingest, mapping identity and behavioral signals from every connected environment into one investigative view. An analyst can then trace whether a change in model or evaluation behavior lines up with activity from a specific identity, component, or dependency.&lt;/p&gt;&lt;p&gt;That context does not prove poisoning happened, but it arms investigators with evidence to test whether changed behavior connects to something in the surrounding system.&lt;/p&gt;&lt;h2&gt;Closing Perspective: Don’t Let This Eclipse the Real Question&lt;/h2&gt;&lt;p&gt;We think AI data poisoning gets more attention than its current risk warrants for many organizations.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://reliaquest.com/blog/ai-is-showing-up-in-real-attack-report/&quot;&gt;The current risk varies sharply by environment&lt;/a&gt;. Organizations building agentic systems have more reason to prioritize it because dependencies widen the potential blast radius. Most companies, at a macro level, are still consumers of models rather than builders of complex agentic systems.&lt;/p&gt;&lt;p&gt;For the average organization, the bigger concern is whether the partners and providers they rely on are asking the right questions and taking poisoning risk into account on their behalf. That may matter more than whether the organization itself is a direct target.&lt;/p&gt;&lt;p&gt;Internally, CISOs should be able to answer quickly and continuously who has the means to influence, push, or chain together systems built on top of AI. That is the starting point because it defines the blast radius. Without that understanding, risk decisions become a guessing game, with CISOs relying on what they have been told rather than demanding evidence.&lt;/p&gt;&lt;p&gt;If you’d like to see how identity and behavioral context can support security investigations across your environment, &lt;a href=&quot;https://reliaquest.com/resources/videos/reliaquest-greymatter-demo-home-page/&quot;&gt;request a GreyMatter demo&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content:encoded></item></channel></rss>