The 2-Minute Dwell Time: Why Agentic AI is Redefining Threat Hunting

The 2-Minute Dwell Time: Why Agentic AI is Redefining Threat Hunting

🎙 Cloud Security Podcast 👥 39K 📅 April 15, 2026 ⏱ 44 min 👁 15K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

dwell timeagentic AIautonomous systemsthreat huntingcloud security

Summary

In this episode of the Cloud Security Podcast, host Ashish Rajan interviews Damien Lewke, CEO of Nebulock and former threat hunting leader at CrowdStrike and Arctic Wolf. They discuss the evolution of threat hunting from 2015 to today, highlighting how adversaries have shifted from human-driven attacks to AI-orchestrated machine-speed operations. Lewke cites a recent example where a single threat actor used Anthropic and OpenAI to exfiltrate 150GB of data from the Mexican government. They explore the shrinking dwell time, now down to 2.5 minutes for lateral movement, and the limitations of traditional EDR and SIEM tools. The conversation clarifies the distinction between agentic systems (copilots with human-in-the-loop) and autonomous systems (agents that run end-to-end hunts). They discuss how to differentiate human from agent behavior using telemetry like command line patterns and NHIs, and the blind spots of AI agents, such as detecting malicious insiders and low-and-slow attacks. The episode also covers the future of detection engineering, the lifecycle of security detections, and the common pitfall of threat hunts dying in SharePoint folders. Lewke emphasizes the importance of organizational context and combining it with conviction at speed and scale.

188 words

Critical Evaluation

Value of the Information & Strength of the Argument

The episode provides valuable insights into the practical application of AI agents in threat hunting, drawing on the guest’s extensive experience. The argumentation is coherent and well-structured, moving from the evolution of threats to the technical distinctions between agentic and autonomous systems. The discussion is grounded in real-world examples, such as the Mexican government breach, which adds credibility. However, the value is somewhat diminished by the promotional nature of the conversation, as Lewke frequently references his company’s solutions. The argumentation would benefit from more independent evidence and less reliance on anecdotal claims.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The guest’s background lends authority, but specific claims about dwell times and attack examples are not backed by cited sources. The description provides links to the podcast’s website and social media, but no direct references to the mentioned research or incidents. The title accurately reflects the content, focusing on the reduction in dwell time and the role of agentic AI. The discussion is largely based on expert opinion rather than peer-reviewed research, which limits its scientific rigor. The lack of verifiable sources for key claims is a notable weakness.

201 words

Title / Content Match

The title accurately reflects the core theme: the dramatic reduction in dwell time and the role of agentic AI in threat hunting.

Quality & Reliability

7/10

The episode features a practitioner with extensive experience in threat hunting and AI, providing credible insights. However, claims about specific attacks and dwell times are not independently verified, and the discussion is largely anecdotal and promotional for the guest's company.

Chapters

Cited Sources

Concurring Sources

  • Anthropic's research on AI-driven attacks — The guest mentions Anthropic's published research on adversaries using their infrastructure, but no specific URL is provided.

Contribution & Novelties

The episode offers a practitioner’s perspective on the integration of AI agents into threat hunting, clarifying the distinction between agentic and autonomous systems and discussing practical detection methods. It highlights the shrinking dwell time and the need for speed and scale in security operations.

Pour aller plus loin :

  • Agentic AI — Provides background on the concept of agentic AI.
  • Non-human identities — Discusses the security implications of NHIs.
  • Dwell time — Explains the concept of dwell time in cybersecurity.

80 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, reflecting the in-depth discussion. Quality of information and global reliability are slightly lower due to the lack of verifiable sources and promotional elements.

Reliability 6/10

💬 No comments were provided for analysis.