Podcast: Play in new window | Download
Subscribe: Apple Podcasts | RSS
Nicole Beckwith joins me on this episode of the TechSpective Podcast to talk about a problem most of the security industry still hasn’t fully reckoned with. Beckwith runs security engineering and operations at Cribl, and before that she spent years in law enforcement and digital forensics, which is the lens she uses to explain why the way we’ve built detection for the last couple of decades is running out of road.
Matching Isn’t the Same as Understanding
For as long as I’ve covered this industry, detection has mostly come down to matching something you already know is bad against something showing up on your network: a hash tied to known malware, an IP address tied to known bad infrastructure. It’s a yes or no answer, and for a long time that was good enough, because attackers weren’t changing their tooling anywhere near as fast as they’re changing it now.
That model is breaking down. Polymorphic malware changes its own hash per victim. Phishing infrastructure gets built fresh, one URL at a time, sometimes one top-level domain at a time. By the time a hash or a bad domain makes it into your threat feed, the attacker who used it has often already moved on to the next one. Beckwith put it plainly: the bottom layers of the pyramid of pain, the framework the industry has used for years to rank how much damage a given detection actually does to an attacker, are “essentially just on fire right now.”
An Indicator Only Proves Someone Was There
Beckwith’s law enforcement background gives her a useful way to explain what’s actually missing. An indicator, she says, is a single piece of evidence, the equivalent of a fingerprint on a glass or a license plate written down at the scene. It puts someone there. It doesn’t tell you what they did once they arrived, who they were working with, or why. “It’s a fast, cheap triage of known bad,” is how she describes it, and that’s the right job for it. The mistake is treating a triage tool like it’s the whole case.
Behavior is a different kind of evidence. An attacker can swap a hash in seconds, but if they want credentials, they still have to do the things credential theft requires, and those actions leave a pattern an indicator alone was never built to catch.
Why This Is Harder to Fake, and Harder to Buy
This is also where a lot of vendor marketing falls apart. Walk any security conference floor this year and nearly every booth claims some version of AI-powered, behavior-based detection. Beckwith has spent enough time doing exactly that to know most of it is still a rules engine underneath, with a model bolted on for the pitch. Real behavioral detection takes the unglamorous work of engineering telemetry, mapping it to actual attacker tactics, and tuning it against your own environment instead of shipping something generic and calling it AI. That work doesn’t show up on a slide, which is exactly why most vendors skip it.
Beckwith gets into a lot more of this on the episode, including what this shift means for who gets hired into a SOC and how she personally judges whether a vendor’s AI claims hold up.
Watch or listen to the full conversation on the TechSpective Podcast.
- Moving Past Indicators Toward Behavior - September 9, 2026
- When the AI Breaks Its Own Rules - September 2, 2026
- What It Took to Film a Real-Life Lion King - August 28, 2026




