<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Threat Detection</title><description>Cybersecurity articles tagged #Threat Detection on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Augmenting SOCs with Wazuh AI Analyst and LLM Integrations</title><link>https://runtimerebel.com/blog/augmenting-socs-with-wazuh-ai-analyst-and-llm-integrations</link><guid isPermaLink="true">https://runtimerebel.com/blog/augmenting-socs-with-wazuh-ai-analyst-and-llm-integrations</guid><description>Wazuh integrates AI, including its AI Analyst and LLM options, to augment SOC workflows, reduce analyst fatigue, and accelerate threat detection and response.</description><pubDate>Fri, 21 Aug 2026 16:20:52 GMT</pubDate><category>AI</category><category>Threat Detection</category><category>Incident Response</category><category>Wazuh</category><category>Security Operations Center</category></item><item><title>Entra Log Analysis: Detecting Password Spray Attacks with PowerShell</title><link>https://runtimerebel.com/blog/entra-log-analysis-detecting-password-spray-attacks-with-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/entra-log-analysis-detecting-password-spray-attacks-with-powershell</guid><description>Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.</description><pubDate>Fri, 21 Aug 2026 08:33:19 GMT</pubDate><category>Entra ID</category><category>Azure AD</category><category>PowerShell</category><category>Threat Detection</category><category>Identity Access</category></item><item><title>Detecting AI-Driven Polymorphic Phishing Attacks</title><link>https://runtimerebel.com/blog/detecting-ai-driven-polymorphic-phishing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-ai-driven-polymorphic-phishing-attacks</guid><description>AI-powered phishing attacks leverage personalization and polymorphic evasion, challenging traditional filters. MSPs must focus on post-compromise detection.</description><pubDate>Fri, 21 Aug 2026 08:29:38 GMT</pubDate><category>Spear Phishing</category><category>Email Security</category><category>Threat Detection</category><category>AI Powered Phishing</category><category>Polymorphic Phishing</category></item><item><title>MSI Malware Detection: Statistical Analysis for Base64 Payloads</title><link>https://runtimerebel.com/blog/msi-malware-detection-statistical-analysis-for-base64-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/msi-malware-detection-statistical-analysis-for-base64-payloads</guid><description>Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.</description><pubDate>Mon, 15 Jun 2026 10:19:14 GMT</pubDate><category>MSI Malware</category><category>Base64 Obfuscation</category><category>Threat Detection</category><category>Malware Analysis</category><category>SANS ISC</category></item><item><title>Claude Fable 5: Anthropic Unveils New High-Performance AI Model</title><link>https://runtimerebel.com/blog/claude-fable-5-anthropic-unveils-new-high-performance-ai-model</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-fable-5-anthropic-unveils-new-high-performance-ai-model</guid><description>Anthropic releases Claude Fable 5, a limited-time high-performance AI model based on the Mythos architecture, targeting advanced reasoning and efficiency.</description><pubDate>Wed, 10 Jun 2026 05:38:24 GMT</pubDate><category>Anthropic</category><category>Claude Fable 5</category><category>Mythos Architecture</category><category>AI Security</category><category>Threat Detection</category></item><item><title>AI as Security Enabler: CISO Strategies for Modern Defense</title><link>https://runtimerebel.com/blog/ai-as-security-enabler-ciso-strategies-for-modern-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-as-security-enabler-ciso-strategies-for-modern-defense</guid><description>Zoom&apos;s CISO details AI&apos;s role in augmenting security teams, addressing challenges like talent gaps and alert fatigue, and strategic CISO insights.</description><pubDate>Wed, 03 Jun 2026 01:10:54 GMT</pubDate><category>AI</category><category>Cybersecurity</category><category>CISO</category><category>Security Operations</category><category>Threat Detection</category><category>Zoom</category></item><item><title>Optimizing EDR for Operational Resilience and Threat Detection</title><link>https://runtimerebel.com/blog/optimizing-edr-for-operational-resilience-and-threat-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/optimizing-edr-for-operational-resilience-and-threat-detection</guid><description>Explore how leading organizations optimize EDR deployment to achieve operational resilience against advanced threats and move beyond legacy prevention models.</description><pubDate>Tue, 02 Jun 2026 13:26:38 GMT</pubDate><category>EDR</category><category>Endpoint Security</category><category>Operational Resilience</category><category>Threat Detection</category><category>SOC Optimization</category></item><item><title>Leveraging SIEM for MSPs: Strategies to Reduce SOC Alert Fatigue</title><link>https://runtimerebel.com/blog/leveraging-siem-for-msps-strategies-to-reduce-soc-alert-fatigue</link><guid isPermaLink="true">https://runtimerebel.com/blog/leveraging-siem-for-msps-strategies-to-reduce-soc-alert-fatigue</guid><description>Explore how Managed Service Providers use SIEM to consolidate security logs, reduce alert noise, and improve incident response times in modern SOC environments.</description><pubDate>Thu, 28 May 2026 17:23:29 GMT</pubDate><category>SIEM</category><category>Msp</category><category>SOC Operations</category><category>Threat Detection</category><category>Log Management</category></item><item><title>Next-Gen NDR: Reducing Alert Fatigue with Agentic AI Capabilities</title><link>https://runtimerebel.com/blog/next-gen-ndr-reducing-alert-fatigue-with-agentic-ai-capabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/next-gen-ndr-reducing-alert-fatigue-with-agentic-ai-capabilities</guid><description>Examine how agentic AI is transforming Network Detection and Response to mitigate alert fatigue and improve threat triage efficiency for SOC teams.</description><pubDate>Mon, 25 May 2026 13:17:18 GMT</pubDate><category>NDR</category><category>Agentic AI</category><category>SOC Operations</category><category>Network Detection and Response</category><category>Threat Detection</category></item><item><title>Agentic SOC Platforms: AI-Driven Security Operations Evolve</title><link>https://runtimerebel.com/blog/agentic-soc-platforms-ai-driven-security-operations-evolve</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentic-soc-platforms-ai-driven-security-operations-evolve</guid><description>Exaforce&apos;s $125M funding highlights growth in agentic SOC platforms. Learn how AI and automation are redefining threat detection and response for security teams.</description><pubDate>Tue, 12 May 2026 20:39:41 GMT</pubDate><category>Exaforce</category><category>Agentic SOC Platform</category><category>AI in Cybersecurity</category><category>Security Operations</category><category>Threat Detection</category><category>Automation</category></item><item><title>One Missed Threat Per Week: The Risk of Ignoring Low-Severity Alerts</title><link>https://runtimerebel.com/blog/one-missed-threat-per-week-the-risk-of-ignoring-low-severity-alerts</link><guid isPermaLink="true">https://runtimerebel.com/blog/one-missed-threat-per-week-the-risk-of-ignoring-low-severity-alerts</guid><description>Analysis of 25 million security alerts reveals that ignoring low-severity telemetry causes enterprise SOC teams to miss one significant threat every week.</description><pubDate>Fri, 08 May 2026 12:37:22 GMT</pubDate><category>Alert Fatigue</category><category>SOC Operations</category><category>Threat Detection</category><category>Telemetry Analysis</category></item><item><title>Spectrum Security Emerges from Stealth with $19M for Threat Detection</title><link>https://runtimerebel.com/blog/spectrum-security-emerges-from-stealth-with-19m-for-threat-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/spectrum-security-emerges-from-stealth-with-19m-for-threat-detection</guid><description>Spectrum Security exits stealth with $19M in funding to address the scaling challenges of modern security data infrastructure and threat detection platforms.</description><pubDate>Tue, 28 Apr 2026 08:57:36 GMT</pubDate><category>Spectrum Security</category><category>Threat Detection</category><category>Security Data Lake</category><category>Funding</category><category>SIEM Modernization</category></item><item><title>OpenAI GPT-5.4-Cyber: Defensive AI for Security Teams</title><link>https://runtimerebel.com/blog/openai-gpt-5-4-cyber-defensive-ai-for-security-teams</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-gpt-5-4-cyber-defensive-ai-for-security-teams</guid><description>OpenAI unveils GPT-5.4-Cyber, a model optimized for defensive security. Learn how it assists SOC teams in threat detection and vulnerability remediation.</description><pubDate>Wed, 15 Apr 2026 08:40:12 GMT</pubDate><category>OpenAI</category><category>GPT 5 4 Cyber</category><category>Defensive AI</category><category>Vulnerability Management</category><category>Threat Detection</category></item><item><title>Depthfirst&apos;s $80M Funding: Advancing AI in Threat Detection</title><link>https://runtimerebel.com/blog/depthfirst-s-80m-funding-advancing-ai-in-threat-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/depthfirst-s-80m-funding-advancing-ai-in-threat-detection</guid><description>Depthfirst secured $80M in Series B funding to advance AI research, develop security models, and scale enterprise adoption.</description><pubDate>Wed, 01 Apr 2026 20:20:04 GMT</pubDate><category>AI</category><category>Machine Learning</category><category>Cybersecurity Funding</category><category>Threat Detection</category><category>Security Innovation</category></item><item><title>AI in Cybersecurity: Shifting Focus Beyond Historical Threats</title><link>https://runtimerebel.com/blog/ai-in-cybersecurity-shifting-focus-beyond-historical-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-in-cybersecurity-shifting-focus-beyond-historical-threats</guid><description>Cybersecurity teams must broaden their threat intelligence scope, moving beyond historical threat actors to anticipate novel AI-driven attack vectors and future threats.</description><pubDate>Wed, 01 Apr 2026 12:29:20 GMT</pubDate><category>AI</category><category>Machine Learning</category><category>Threat Intelligence</category><category>Cybersecurity Strategy</category><category>Threat Detection</category><category>AI Training</category></item><item><title>Google Drive Ransomware Protection Enabled by Default for Workspace</title><link>https://runtimerebel.com/blog/google-drive-ransomware-protection-enabled-by-default-for-workspace</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-drive-ransomware-protection-enabled-by-default-for-workspace</guid><description>Google Workspace now enables AI-powered ransomware detection by default for paying users to identify and mitigate cloud-based encryption threats automatically.</description><pubDate>Wed, 01 Apr 2026 08:37:40 GMT</pubDate><category>Google Workspace</category><category>Ransomware Protection</category><category>Cloud Security</category><category>Threat Detection</category><category>Google Drive</category></item><item><title>Evaluating AI SOC Agents: Gartner&apos;s Key Questions</title><link>https://runtimerebel.com/blog/evaluating-ai-soc-agents-gartner-s-key-questions</link><guid isPermaLink="true">https://runtimerebel.com/blog/evaluating-ai-soc-agents-gartner-s-key-questions</guid><description>Evaluate AI agents in your SOC effectively. Based on Gartner&apos;s insights, discover key questions to assess real impact, reduce alert fatigue, and enhance security…</description><pubDate>Mon, 30 Mar 2026 16:28:35 GMT</pubDate><category>AI</category><category>SOC</category><category>Gartner</category><category>Security Operations</category><category>Alert Fatigue</category><category>Threat Detection</category><category>Evaluation</category><category>Cybersecurity Tools</category></item><item><title>Tracebit Raises $20M to Scale Cloud-Native Deception Technology</title><link>https://runtimerebel.com/blog/tracebit-raises-20m-to-scale-cloud-native-deception-technology</link><guid isPermaLink="true">https://runtimerebel.com/blog/tracebit-raises-20m-to-scale-cloud-native-deception-technology</guid><description>Tracebit secures $20M in Series A funding to expand its cloud-native deception platform, helping SOC teams detect lateral movement and credential theft.</description><pubDate>Tue, 17 Mar 2026 12:31:54 GMT</pubDate><category>Tracebit</category><category>Deception Technology</category><category>Cloud Security</category><category>Honeypots</category><category>Threat Detection</category></item><item><title>Optimizing Tier 1 SOC Performance: CISO Strategic Imperatives</title><link>https://runtimerebel.com/blog/optimizing-tier-1-soc-performance-ciso-strategic-imperatives</link><guid isPermaLink="true">https://runtimerebel.com/blog/optimizing-tier-1-soc-performance-ciso-strategic-imperatives</guid><description>CISOs face a paradox: critical Tier 1 SOC analysts are often least experienced. Learn strategies to mitigate cognitive load and enhance threat detection capabilities.</description><pubDate>Tue, 03 Mar 2026 16:22:05 GMT</pubDate><category>SOC Operations</category><category>Tier 1 Analysts</category><category>CISO Strategy</category><category>Security Operations Center Performance</category><category>Threat Detection</category><category>Cognitive Load</category></item></channel></rss>