Deutsch

Defensive Services

AI-Driven Threat Detection

Signatures catch what somebody has already seen. The attacker who is genuinely dangerous to you brings nothing that appears on any list: they sign in with a valid password and carry on using your own tools.

01

The starting point

The most dangerous attacker brings no malware

A signature describes a file that already existed. Against commodity malware that works and will keep working — against someone who tailors their tooling to your organization it does not. And against someone who brings no tooling at all, there is simply nothing to sign.

Everything after the initial breach can be done with what is already there: PowerShell to execute, WMI to distribute, RDP to move on, a service account to stay. Living off the Land is the name for this, and in MITRE ATT&CK signing in with stolen credentials carries a technique of its own under Valid Accounts. None of it is malware. Every one of these tools is used legitimately in your organization every day — which is why none of them is on a blocklist, and why nobody raises an alarm.

What remains is not the tool but how it is used. An administrator who signs a service account in interactively at three in the morning and then searches the invoice archive is not running suspicious software. They are simply not behaving like themselves.

A wide dark space crossed by many uniform trails of light running in the same direction. A single one breaks out of the pattern and glows brightly.

The approach

First the normal state, then the deviation

NeoI does not start from a list of threats but from your operations. Before anything can count as unusual, what counts as usual has to be established — and that differs in every organization.

Your operations define what normal means

Over the first weeks a baseline forms for every account, device and service: which sign-ins are usual, at what times, from where, which systems a machine talks to, how much data volume is ordinary. In a law firm, file access on a Sunday is routine; in a manufacturing plant it would not be. No shipped rule can know that difference.

The deviation is what stands out, not the tool

So the alert is not “PowerShell was executed” but the break with an established pattern: a service account working interactively for the first time. A sign-in outside every previous window, followed by access to shares this account has never touched. A workstation talking to a datacentre server for the first time in months — and then to four of them.

Correlation across system boundaries

Individually, these anomalies are usually harmless. Their value emerges only in combination: the same sign-in, the same device, the same window across network, endpoint and cloud service. What runs in separate tools — UEBA for account behaviour, NDR for network traffic, EDR for the endpoints — has to come together in one case. Establishing that connection is work no human does at the required speed, and the actual reason a model is doing the computing here.

  1. 01

    Behavioural baseline per account, device and service instead of fixed thresholds

  2. 02

    Correlation across network, endpoints and cloud services into a single case

  3. 03

    Prioritisation by business relevance — the domain controller outweighs the meeting-room machine

  4. 04

    Every alert mapped to a technique in MITRE ATT&CK, so triage does not start from zero

  5. 05

    Readable reasoning per alert

    which behaviour, measured against which baseline, since when

  6. 06

    Feedback — every confirmed false positive sharpens the model for your environment

An alert nobody reads is not protection.

02

The measure

Fewer alerts, not more

The most common and entirely fair objection to AI in security is that it produces additional alerts. We measure ourselves by the opposite. An alert should only exist when a human genuinely has something to decide — everything else is work you pay for without becoming safer.

In practice: related events are consolidated into one case rather than queuing up individually. Forty entries over one night become a single case with a timeline. The result is visible in Strider, the monitoring layer of our suite — with the chain that led to the alert, not only its conclusion.

2–4 weeks
until the baseline is dependable
1 case
instead of dozens of separate alerts
ATT&CK
every alert mapped to a technique
explainable
readable reasoning, not a black box
03

The boundary

The human decides

Assessing a case and deciding on a countermeasure stay with analysts. We use a model to remove noise — not to shift responsibility. Blurring that line means selling convenience as security.

Where an automatic first response is defensible, such as isolating a single endpoint at four in the morning, Talion takes over — under rules agreed in advance, within narrow limits, and with audit-proof documentation of every action. Anything that could take a datacentre offline is decided by a human, without exception.

Without logs there is nothing to detect.

04

The honest view

What detection does not deliver

It does not start on day one. Weeks pass before the baseline is dependable, and during that time detection is weaker, not stronger, than a signature-based product. If you need immediate effect, this is not where you will find it.

It also does not replace logs that do not exist. Without sign-in events from the directory service, without process data from endpoints, without logs from cloud applications, any model stays blind. So the first piece of work is regularly not detection but closing the gaps in data collection.

And it does not replace the fundamentals. Missing multi-factor authentication, a flat network without segmentation, updates that were never applied — no detection helps against those, only fixing them does. If we see that at your site, we say so before any engine is discussed.

A dark surface with a sharply bounded circle of light. Beyond its edge further shapes lie in darkness, unlit.
05

How it fits together

Where detection belongs

Detection is a building block, not an operation. It produces cases someone has to assess — around the clock, weekends included. If you cannot or would rather not carry that yourself, combine it with SOC as a Service; if you have your own team and want to relieve it, with SOC Co-Managed.

When a case turns into an emergency, Instant Response takes over. And if you want to see how mature your detection is next to the other domains, you will find it in Sightadel.

A dark spatial lattice of fine struts. At six of its junctions sits a brightly lit sensor; the rest are bare.
06

In closing

Start with what you already log

In almost every organization the decisive data is already there — it is simply never brought together. So the first sensible step is not a purchase but an inventory: which events are collected today, how long are they retained, and who looks at them?

We do that inventory with you in an initial conversation. It costs nothing and often ends with a smaller recommendation than the one you expected.

FAQ

Frequently asked questions

Does AI not produce even more false positives?

It can, and many products do. The difference lies in what you measure: we do not count the anomalies found but the alerts that genuinely require a decision. Related events are bundled into one case, and every confirmed false positive feeds back into the model. In the first weeks there are more alerts, after that considerably fewer.

How long until detection becomes effective?

Two to four weeks until the baseline is dependable. Before that there are alerts, but their assessment is weak — what counts as normal simply is not established yet. That time cannot be shortened, and anyone shortening it for you is selling you shipped rules under a different name.

Does this replace our SIEM?

No, as a rule it builds on it. A SIEM collects and retains, detection assesses. If you already run one, we keep using its data rather than building a second collection point. Where there is no SIEM, we first clarify which events are being collected at all.

Does our data have to go into a cloud for this?

Not necessarily. Where regulation or your own policy requires it, the analysis stays on your premises. That is a question of deployment, not a property of the method — and we settle it before the engagement, not after.

Can we trace why something was flagged?

Yes, and that is a condition rather than an extra. Every alert states which behaviour stood out, against which baseline it was measured, and which individual events led to it. An alert that cannot be justified is one an analyst cannot assess — and an auditor even less so.

Defensive Services

More in this area

Instant Response

24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…

View

Quantum Cryptography (QaaS)

Harvest now, decrypt later already affects data encrypted today. Cryptographic inventory, assessment by lifetime and hy…

View

Firewall & Intrusion Detection

Firewall, segmentation and intrusion detection as one architecture — planned, implemented, operated. With Valar as a ha…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.