Nebulock Blog

Insights, research, and more in threat hunting and proactive secops.

RSS Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
July 30, 2026

Bringing Detection into the Hunt-First Security Era

Alex Hurtado joins Nebulock as Head of Detection Strategy to shape how detection engineering evolves hunt-first security operations.

Read More
July 29, 2026

Introducing Nebulock Helix: SIEM without the ingestion tax

Nebulock Helix queries your VM tools on demand, no pre-ingestion needed. Ships with Qualys, Tenable, Rapid7, Axonius, CrowdStrike, and Microsoft Defender.

Read More
July 28, 2026

Agentic detection engineering framework: Durable memory for detections

The Agentic Detection Engineering Framework (ADEF) is Nebulock's open source framework that gives detection rules a durable, agent-readable journal of why they exist and how they were tuned.

Read More
July 21, 2026

Open Weights, Open Season

Kimi K3's open weights ship July 27 with thin guardrails, and agentic ransomware is already here. How to hunt autonomous attacks by behavior, not names.

Read More
July 16, 2026

Using classical machine learning for threat hunting (and saving tokens in the process)

Detecting shadow AI by behavior, not tool names. Why Nebulock's threat hunt agent runs a deterministic, low-cost classical ML model instead of an LLM.

Read More
July 6, 2026

Automating the manual toil of detection engineering

Most of a detection engineer's time goes to data prep and upkeep, not logic. See how Nebulock automates the toil while keeping analyst judgment in the loop.

Read More
June 25, 2026

Nebulock Raises $25M Series A for Hunt-First, Always-On Security Operations

Today we're announcing our $25 million Series A funding, led by FirstMark, to build a hunt-first contextual security platform.

Read More
June 24, 2026

Get oriented in 30 seconds: introducing the Command Center

Command Center surfaces your most critical finding, recommended hunt, and actionable intel in a single, defender-focused view.

Read More
June 11, 2026

Your newest insider has legitimate access

Insider threat used to mean intent. In the agentic era, your most dangerous insider risk is an AI agent you authorized that won't trip an alert. Here's what to hunt.

Read More
May 29, 2026

Nebulog: Insider Risk Visibility, a Navigation Update, and New API Endpoints

Embed threat hunts into your workflows, cut investigation time, and sharpen insider risk coverage with Nebulock's May 2026 platform releases.

Read More
May 14, 2026

AI Artifacts: A New Layer of Endpoint Activity to Hunt

AI assistants and coding tools introduce a new layer of endpoint activity. These tools operate with a high degree of access: they read local files, execute commands, persist prompts and context, and communicate with external APIs. In many environments, this creates a blind spot where AI-assisted activity can occur with little to no detection coverage.

Read More
April 29, 2026

Hunting MCP Server Exploitations

Shadow AI is not a future risk. It is already inside your environment. Developers are connecting MCP servers to AI clients without centralized approval, visibility, or governance. These servers inherit user-level access, persist across sessions, and execute locally with no additional authentication prompt. From a defender's perspective, the activity looks like the user did it — because the process tree says so. That is the problem. And it is exactly where you hunt.

Read More
April 3, 2026

Hunting Supply Chain Compromises LiteLLM & Axios

Supply chain attacks are not new. What is new is the pace and the precision. In the recent Axios and TeamPCP campaigns, we have different actors, different tooling, but the same fundamental constraint: both must install through package managers, execute outside the language runtime, access credentials, persist, and communicate externally. Each step leaves a behavioral trace that outlasts any IOC list.

Read More
March 18, 2026

Vespyr: Your Autonomous Hunter

Autonomous hunting means the agent doesn't wait for a user directive. It monitors global intelligence, determines what's relevant to your environment, scopes and executes the hunt, and delivers findings without anyone having to kick it off. The human reviews, validates, and acts. The agent does everything before that.

Read More
February 18, 2026

Hunting the Notepad++ Update Hijack

Software supply chain attacks have shifted from occasional, high-profile incidents into a repeatable and increasingly preferred intrusion technique and the Notepad++ incident is the latest evolution. This gives hunters a case for looking at deviations from behavioral baselines.

Read More
February 9, 2026

Nebulog: What's New in Nebulock

The latest Nebulock product updates: Insights, integrations, additional detection, SOC 2 Type 2, and more.

Read More
February 3, 2026

Hunting OpenClaw and Agentic AI Through Behavior

This Hunt Mode breaks down the behaviors that give away OpenClaw (formerly ClawdBot / MoltBot), regardless of how it is packaged, renamed, or delivered.

Read More
January 28, 2026

coreSigma: Developing an Endpoint Security Framework Pipeline

The need for standardized macOS detection capabilities is clear. Based on the response to introducing coreSigma, we wanted to make it even easier for the community to gain additional macOS observability and implement their own macOS detections in their environment. That’s why we’ve made coreSigma publicly available in the Nebulock GitHub repository.

Read More
January 15, 2026

Hunting DigitStealer: Behaviors That Give Away macOS Infostealers

DigitStealer is the next evolution of macOS malware evolution. This breakdown outlines the behaviors to observe to properly hunt for it in your environment.

Read More
December 17, 2025

CVE-2025-55182: Finding Behaviors That Give Away React Server Components RCE

Breakdown of the hunt for the malicious behaviors in CVE-2025-55182, a pre-authentication exploit that bypasses most traditional web app firewalls and signature-based controls.

Read More
December 10, 2025

The Agentic Threat Hunting Framework

Give your threat hunting program memory and agency.

Read More
November 10, 2025

Vibe Hunting: Outcome-Driven Threat Hunting

Vibe Hunting is the meeting of human intuition with machine reasoning. Agents built by hunters to democratize threat hunting. Not just another co-pilot or AI overlay, but an enabler for security teams to add threat hunting to their skillset whether there’s dedicated threat hunters or not.

Read More
November 6, 2025

coreSigma: Expanding Sigma Detection for macOS

coreSigma, a macOS endpoint telemetry collection, detection, and analysis app built with the primary goal of extending Sigma's capabilities for macOS ESF and UL logs. Learn how coreSigma expands visibility and ways take a more proactive approach to macOS threat detection and response.

Read More
August 13, 2025

Why I Joined Nebulock

A 15-year cybersecurity professional shares how joining Nebulock changed his perspective on AI in threat hunting and how the platform augments human hunters rather than replacing them.

Read More
July 29, 2025

Introducing Nebulock: Agentic Threat Hunting for Everyone

We've launched the first autonomous threat hunting platform to democratize threat hunting for all security teams.

Read More

Hunt-first security

For what your alerts can't see.

Get a Demo