Enhanced Detection Engineering at Scale in the Agentic Era

Imported from official source

Cybersecurity Classified by Officially

Resolving detection coverage gaps is a universal problem across the security industry. Before joining GreyNoise, I led Elastic’s Endpoint Protections security research team which was tasked with building visibility and detection capabilities in their Endpoint Detection and Response (EDR) solution. Researchers, red teamers, and attackers alike would constantly poke, prod, and reverse engineer our EDR’s detection capabilities then broadcast their evasions and bypasses to the masses. However, I always saw this as a unique challenge; iron sharpens iron, after all, and resolving these issues led to an improved product with expanded coverage. I believe this experience suits me well as I transition into my new role as the Head of Adversary Engagement at GreyNoise and lead our detection and deception engineering efforts.

When GreyNoise was founded in 2018, 16,510 entries were added to the Common Vulnerabilities and Exposures (CVE) system. The number of entries (48,162) added in 2025 shot up to almost triple the number from 2018. Part of this astounding increase in CVEs can be attributed to the sharp rise in the number of CVE Numbering Authorities over the last decade from 23 in 2016 to over 500 by 2026. However, generative AI has had an undeniable impact on the annual number of reported CVEs over the past few years (130% growth from 2022 through 2025) which speaks to an existential crisis currently facing the security industry.

Large language models (LLMs) have lowered the barrier of entry for aspiring vulnerability researchers and exploit developers while significantly enhancing the capabilities of more experienced researchers and attackers. The mean time to exploit CVEs has sharply dropped to the point where it is now slightly negative, meaning that the average vulnerability was likely exploited in the wild before it was reported and assigned a CVE number.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.greynoise.io/blog/enhanced-detection-engineering-at-scale-in-the-agentic-era

Officially imported this from GreyNoise’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
GreyNoise — imported from official source
Official source
https://www.greynoise.io/blog/rss.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.greynoise.io/blog/enhanced-detection-engineering-at-scale-in-the-agentic-era

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.