NoLimitSecu #536 - Automatisation des investigations du SOC

NoLimitSecu #536 - Automatisation des investigations du SOC

🎙 NoLimitSecu 👥 2K 📅 March 24, 2026 ⏱ 38 min 👁 359 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

SOCAIautomationinvestigationQevlar AI

Summary

In this episode of NoLimitSecu, host Johann interviews Ahmed Achchak, co-founder and CTO of Qevlar AI, about automating SOC investigations. Ahmed begins by outlining the major challenges faced by SOCs, including alert fatigue, high alert volumes, and the limitations of static automation tools. He explains that these issues lead to overwhelmed analysts and increased risk of missing critical alerts. Qevlar AI aims to address these problems by providing an autonomous investigation platform that ingests alerts from various sources (EDR, SIEM, email) and conducts thorough investigations in about 2.5 minutes. The system uses a graph-based AI orchestrator to plan and execute investigation steps, complemented by LLM agents for semantic analysis and computer vision models for inspecting suspicious content. Key features include transparency, explainability, and reproducibility, as the orchestrator is deterministic. The platform is deployed as a SaaS, with client control over data sources and the ability to add contextual information via structured data or free-text comments. Ahmed emphasizes that Qevlar does not learn from client data, ensuring data privacy. The conversation also touches on the impact on junior analysts, who benefit from the detailed reports as a learning tool. The episode concludes with a discussion on the company’s growth, with 47 employees and ongoing development efforts.

205 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its detailed explanation of a novel AI-driven approach to SOC automation, contrasting with traditional SOAR solutions. The argumentation is solid, as Ahmed provides concrete examples of how the system works, such as the graph-based investigation process and the use of multiple AI models. He also addresses potential concerns, such as data privacy and the impact on junior analysts, with reasoned responses. The discussion is technical yet accessible, offering insights into the practical implementation of AI in cybersecurity operations.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the interview is based on the founder’s expertise and company claims, without external citations or peer-reviewed evidence. The sources cited are limited to the company’s website and LinkedIn profile, which are not independent. The title accurately reflects the content, focusing on SOC investigation automation. No comments were provided for analysis.

155 words

Title / Content Match

The title accurately reflects the content, focusing on the automation of SOC investigations through AI.

Quality & Reliability

7/10

The interview features a co-founder of Qevlar AI, providing detailed insights into the technical architecture and operational aspects of their SOC automation solution. The discussion is coherent and grounded in practical experience, though it lacks external validation or peer-reviewed sources.

Key Moments

Cited Sources

  • Ahmed Achchak - LinkedIn — Guest's professional profile
  • Qevlar AI — Company website

Concurring Sources

  • Qevlar AI — Company website corroborates the product's capabilities.

Contribution & Novelties

The interview provides an original perspective on applying AI to SOC investigations, highlighting a graph-based approach for deterministic decision-making, which differs from typical LLM-centric solutions. It offers practical insights into deployment, customization, and data privacy considerations.

Pour aller plus loin :

79 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical depth, and reliability, indicating a well-rounded discussion with moderate technical detail and credible claims, though lacking external validation.

Reliability 7/10