Investigate every security event with an AI agent, without the frontier bill
Blog post from Datadog
Nicolas Grislain and his team have developed a two-stage detection pipeline to enhance AI-driven security detection at scale, addressing the challenge of applying expensive AI reasoning to every security event in large data streams. The first stage employs Mambark, a small state-space model pre-trained on sequences of audit logs to score every event, forwarding only the most suspicious ones for further investigation by an AI agent. Mambark's design choices include using a Mamba selective state-space model architecture and a uniform representation for diverse security telemetry data, allowing it to efficiently handle vast amounts of data while maintaining high performance across public benchmarks. In production, Mambark operates as a retriever, enabling the AI agent to focus on a prescreened shortlist of events, thus significantly reducing costs while enhancing detection precision. This system is currently being tested with Datadog Cloud SIEM design partners and represents a potential next generation of AI-powered security detection, integrating efficient anomaly detection with in-depth reasoning capabilities.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.