Press Release DATANET

Quad Miners CTO Outlines AI-Driven Security Operations Strategy at Security MegaVision 2026

2026. 03. 10. Strategic Planning Division

Summary

Quad Miners Felix CTO presented the company's approach to automating security operations for the AI transformation (AX) era at Security MegaVision 2026 (Korean: 시큐리티 메가비전 2026 - 사이버 시큐리티 패러다임 대전환), an event hosted by Jeonja Sinmun. The presentation introduced context-aware AI detection technology and LLM multi-agent based analysis capabilities designed to help security teams manage increasingly complex threat environments. Quad Miners also described early-stage plans to unify data across NDR, EDR, cloud, and SaaS environments to reconstruct end-to-end attack timelines and streamline response.        

Presentation at Security MegaVision 2026

Quad Miners Felix CTO presented on "Security Operations Automation in the AI Transformation Era" at Security MegaVision 2026 (Korean: 시큐리티 메가비전 2026 - 사이버 시큐리티 패러다임 대전환), an event hosted by Jeonja Sinmun. The session addressed how the growing adoption of AI agents, along with the expansion of multi-cloud and SaaS environments, is reshaping the demands placed on security operations.

Challenges Facing Security Operations

The presentation outlined two operational challenges currently facing security organizations:

  • Security teams typically operate more than 60 individual security products, with limited data integration across tools making it difficult to gain a unified view of organization-wide threats.
  • Security Operations Centers (SOCs) process more than 100,000 security events and 150 tickets per day, creating a significant operational burden.

To address these challenges, Quad Miners introduced the concept of "context-based AI observability" — an approach that moves beyond basic event monitoring toward integrated analysis of security data to understand the full context and flow of an attack.

Context-Aware AI Detection Technology

Quad Miners identified context-based AI detection as a core technology for security operations in the AX era. Key elements include:

  • Analyzing changes in endpoint and network traffic using multiple AI and machine learning models to detect anomalous behavior
  • Learning communication patterns and behavioral data for internal assets to identify deviations from normal activity
  • Scoring the risk level of detected anomalies so analysts can prioritize high-risk threats
  • Combining large-scale data processing with full packet-based forensic capabilities to perform network behavior analysis and incident reconstruction simultaneously

Quad Miners also indicated that a generative AI-based user behavior analysis capability is expected to be added. This feature would analyze content activity data — including email, message boards, and search activity — to learn normal work patterns and automatically detect data leakage or malicious behavior.

LLM Multi-Agent Based Integrated Context Analysis

Quad Miners is also developing technology that uses LLM-based multi-agent systems to perform integrated analysis of security events.

Under this approach, multiple AI agents work in parallel to summarize logs, analyze events, and assess threats, integrating distributed security data to analyze the full scope of an attack. This allows security analysts to query security data and review threat analysis results using natural language.

This technology is being implemented on top of Network Blackbox, Quad Miners' flagship Network Detection and Response (NDR) product.

Early-Stage Plans for End-to-End Attack Reconstruction

Quad Miners described plans to integrate data from NDR, EDR, cloud, and SaaS environments to automatically reconstruct the complete timeline of an attack.

For example, the full sequence of an attack — from a phishing email, to a user click, account compromise, internal lateral movement, and command-and-control (C2) communication — would be reconstructed as a single narrative for security analysts. At the same time, the system would automatically generate forensic evidence such as PCAP data, reconstructed sessions, and downloaded files, with the goal of significantly reducing response time.

Quad Miners also referenced Model Context Protocol (MCP)-based agent orchestration as a direction under consideration for automating threat analysis and response workflows, including automated security actions such as endpoint isolation.

The technologies described above are part of Quad Miners' ongoing technology roadmap. No release timeline has been set.

This content was developed based on facts confirmed in an article published by Jeonja Sinmun (Korea) on March 10, 2026, at 13:20 KST.
#Network Blackbox #NDR #AI Observability #Context-Based Security
Source · DATANET
View Original Article
← Back to News