0x727 - Teknik - Le COCD/SOC moderne

0x727 - Teknik - Le COCD/SOC moderne

🎙 PolySécure Podcast 👥 540 📅 March 19, 2026 ⏱ 41 min 👁 98 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

SOCThreat IntelligenceSigmaMDRAI

Summary

In this episode, Nicolas interviews David Bizeul, co-creator of Sekoia, about the evolution of modern Security Operations Centers (SOCs). David outlines the key components of a modern SOC in 2026: the fusion of internal knowledge (assets, identities, vulnerabilities) and external knowledge (threat intelligence) with security events. He describes three detection engines: a threat intelligence engine based on a graph database, a correlation engine using Sigma rules, and an anomaly detection engine. He contrasts this with SOCs from a decade ago, which were heavy, lacked useful threat intelligence, and generated low-value alerts. The discussion covers the shift from alert generation to automated response, including AI-driven triage and playbooks. David also explains the MDR model and the importance of interoperability via OXA and MCP. He concludes with a warning that AI is only as good as its data sources, emphasizing the need for high-quality data before applying AI.

146 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into modern SOC architecture, drawing on David Bizeul’s extensive experience. The argumentation is coherent and well-structured, explaining the evolution from traditional SOCs to modern ones. The discussion is practical, focusing on real-world challenges and solutions. However, it lacks external evidence or case studies to support some claims, such as the 0.001% false positive rate.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The content is based on expert opinion and practical experience, but no specific sources are cited. The title accurately reflects the content. No comments were provided for analysis.

107 words

Title / Content Match

The title accurately reflects the content, which focuses on modern SOC (Security Operations Center) techniques and evolution.

Quality & Reliability

8/10

The discussion is led by David Bizeul, co-creator of Sekoia, providing expert insights into modern SOC architecture. The content is based on practical experience and technical details, but lacks external citations or verifiable references.

Key Moments

Cited Sources

  • Sekoia — Mentioned as the company co-created by David Bizeul, providing the SOC platform discussed.
  • Sigma — Referenced as the language used for correlation rules.
  • MCP (Model Context Protocol) — Mentioned as a protocol for interoperability between tools.

Concurring Sources

  • Sekoia — The company's platform aligns with the described modern SOC features.

Contribution & Novelties

The video offers a comprehensive overview of modern SOC components, emphasizing the integration of threat intelligence and automated response. It provides practical insights from an industry expert, highlighting the shift from manual analysis to AI-assisted triage. The discussion on data quality as a prerequisite for effective AI is particularly relevant.

Pour aller plus loin :

  • Sigma — The open standard for writing detection rules.
  • MITRE ATT&CK — A knowledge base of adversary tactics and techniques.
  • MDR (Managed Detection and Response) — Gartner’s definition of MDR services.

86 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a content-rich discussion with practical insights, but with limited external validation.

Reliability 7/10