Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now
aisecurity.llc
Linux Foundation / Cloud Native SecurityCon research on enterprise cloud detections, cloud SOC maturity, ATT&CK-aligned motives, and the growing importance of cloud-native telemetry in SIEM programs.
Devo
Security Research Engineer - Architecture Innovation / Conference Speaker
Presented Cloud Native SecurityCon North America 2023 research with Joshua Smith at Devo, analyzing 2,000 enterprise cloud detections to explain how cloud detections, controls, motives, ATT&CK mapping, and SIEM maturity patterns reveal the changing role of cloud infrastructure and workspaces in modern SOC programs.
Enterprise SOCs were rapidly expanding from traditional endpoint, network, and identity monitoring into cloud-native infrastructure, SaaS workspaces, multi-cloud environments, Kubernetes, and platform telemetry. Security teams needed a better way to understand which cloud detections mattered, how attacker motives appeared across detection content, and what mature cloud SIEM coverage looked like across real enterprise deployments.
This case study uses public conference, podcast, resume, and LinkedIn/Profile sources for report-level facts and conservative language for the author's contribution. Exact Devo datasets, customer names, proprietary detection logic, internal dashboards, non-public research notes, and unpublished artifacts are omitted unless later confirmed and approved for public use.