# Soap Box: Using threat hunting to drive detection Page: https://stenobird.com/podcast/risky-business-548735/soap-box-using-threat-hunting-to-drive-detection Text version: https://stenobird.com/podcast/risky-business-548735/soap-box-using-threat-hunting-to-drive-detection.md Podcast: [Risky Business](https://stenobird.com/podcast/risky-business-548735) Published: 2026-07-08T04:51:09+00:00 Episode link: https://risky.biz/SOAPBOX109/ Audio file: https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SOAPBOX109.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/risky-business-548735/episodes/soap-box-using-threat-hunting-to-drive-detection Duration seconds: 2116 ## Resource In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections. This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you’re going to build a good graph, do you want to build it for a person to use, or an agent to use? This is truly a conversation for the security nerd’s nerd. Enjoy! This episode is also available on YouTube ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/risky-business-548735/episodes/soap-box-using-threat-hunting-to-drive-detection/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/risky-business-548735/soap-box-using-threat-hunting-to-drive-detection.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.