The Context Gap: Why Your SOC Misses Attacks It Already Logged

Every SOC has the same secret: the breach was in the logs the whole time. The login fired, the badge swipe was recorded, the query ran. The data was there. Nobody could read the story it was telling. That's not a visibility problem, it's a context problem. A 2 AM login means nothing until you know the account owner resigned yesterday, the box it hit is a domain controller, and the user has wire-transfer authority. Same event, three answers, and only one of them is "escalate now." This talk is about the layer most SOCs never build: identity, asset, business, and operational context wired into the alert before an analyst opens it. Through real investigations, we'll show how the same alert goes from a 45-minute tab-hunting chase to a 5-minute escalation, why this context gap is an attacker's window and not just an inefficiency, and how to get the data out of departments such as HR, IT, and Finance, who don't report to you. And we'll cover why this same context layer is what every AI agent in your SOC will live or die on as the SOC gets agentic. Key takeaways: Why more data and more tools quietly made triage worse, not better. The four kinds of context that change what an alert means (identity, asset, business, operational) and how that transforms detections and investigations. Practical ways to build a more decision-driven SOC.

    Speaker

    FURTHER SESSIONS

  • 1979 called. They already figured it out.

  • A Few Dollars to Disappear: Breaking C2 Beaconing Detection

  • Ants, Bricks and Spiders: Threat Emulation on the VMware Stack

  • Capture The Flag

  • Join us in Amsterdam!

    November 19, 2026

    Hang out, learn something awesome and make new friends.

    Get Tickets