Investigate every security event with an AI agent, without the frontier bill
Blog post from Datadog
Nicolas Grislain and his team have developed a two-stage detection pipeline to enhance AI-driven security detection at scale, addressing the challenge of applying expensive AI reasoning to every security event in large data streams. The first stage employs Mambark, a small state-space model pre-trained on sequences of audit logs to score every event, forwarding only the most suspicious ones for further investigation by an AI agent. Mambark's design choices include using a Mamba selective state-space model architecture and a uniform representation for diverse security telemetry data, allowing it to efficiently handle vast amounts of data while maintaining high performance across public benchmarks. In production, Mambark operates as a retriever, enabling the AI agent to focus on a prescreened shortlist of events, thus significantly reducing costs while enhancing detection precision. This system is currently being tested with Datadog Cloud SIEM design partners and represents a potential next generation of AI-powered security detection, integrating efficient anomaly detection with in-depth reasoning capabilities.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 6 | 6,829 | 1,441 | 261 | +10% |
| LLM | 6 | 7,655 | 1,347 | 245 | +22% |
| AI Model Fine-tuning | 1 | 975 | 221 | 80 | +28% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.