AI-powered attacks have collapsed the window defenders have to detect and respond to threats. Existing SIEMs and security operations tooling were built to centralize and correlate events under the assumption that teams would have mostly on-prem server and network logs and hours to work an alert. At the same time, the volume of telemetry has grown enormously, by some estimates nearly 100% in the last year alone. This has broken existing architectures and pricing models, forcing teams to choose between security value and what they can afford to ingest.
New architectures and approaches have been proposed to solve these issues such as bolting AI onto existing SIEMs or running federated analytics where data sits to avoid costly ingestion. However, neither of these approaches solves the underlying problems. In order to detect and respond at machine speed, security operations must be built AI-native from the start. This requires a hybrid approach with detection streaming in real time, and the ability to federate searches when useful for context and forensics. Security teams today have unprecedented flexibility in how they architect their environments, but must be strategic to prepare for AI-powered attacks.
The hybrid approach offered by Artemis Security enables teams to fully utilize their security telemetry, detect on ingest, federate when necessary, and respond at machine speed, all without the ingest tax of existing SIEMs.
The Telemetry Most Orgs Are Dropping Has Become More Valuable
AI workloads drove a 93 percent rise in log and telemetry volume last year, and one in five organizations saw growth above 150 percent. Those figures appear in a piece “SIEM: Centralize Like You Mean It, Federate Like You Have To” by Anton Chuvakin. The same research puts the average share of logs that organizations exclude at 86 percent.
Most enterprises are discarding the majority of their telemetry “not by security design, but by budget necessity.” Volume keeps climbing, and with ingest-priced platforms every source added increases cost, so the share organizations can afford to keep declines.
What typically gets cut is the high volume to detection value telemetry such as DHCP leases, VPC flow records, and load balancer logs. Very rarely does any of it fire a detection on its own. These sources become valuable once teams need to reconstruct what happened.
With the rise of security agents, this telemetry becomes more valuable. AI systems can look at more sources per case and read far more of it, so the data being dropped is worth more today than it was six months ago. The architecture question that follows is how to keep more telemetry usefully, rather than how to keep less of it cheaply.
Security Telemetry Should Be An Engineering Decision Instead Of A Budget One
Chuvakin closes on a standard for centralizing vs federating log types. Each source should earn its place in the core for continuous detection and correlation while additional context can be federated. This choice should be made on engineering requirements, and not vendor pricing pressure.
Whether a source should be centralized depends on a few questions:
- Whether real-time detection depends on the source, in which case it belongs in the core regardless of cost
- Whether it is looked up against a specific indicator
- Whether its retention and tamper resistance sit with someone you are willing to depend on
Rather than cutting whatever is expensive, teams should place each source against what depends on it.
Most Of An Investigation’s Cost Is Set Before The Alert Arrives
By the time an alert reaches an analyst, most of the cost of working it is already set by the location and shape the data arrived in, and by the quality of the detection that fired it.
An attack that runs its course in minutes leaves no time to work out which field in which source means what. Detection has to read identity, endpoint, cloud, network, and core telemetry as one stream, which means normalizing on the way in. That layer often fails quietly. A vendor changes a format, the parser mapping breaks with it, and detection rules go blind while nothing alerts on the data issues.
Detection content decays the same way. Environments shift and vendors change what they emit, causing a rule that was accurate at deployment to silently stop firing. To solve that, you need:
- Every detector to be versioned and tested
- New detectors to run in shadow against live data before they go live
- Tuning to be proposed against the noise actually seen in that environment, and validated before it is applied
- A detector that stops earning its place to be retired
Artemis’s detectors are built against a model of the environment they run in. When the estate changes, the model changes with it, and tuning runs continuously against what that model shows.
Detection Built On A Model Of Your Environment
Security teams know their environment better than attackers do, which is their greatest advantage. The harder part is turning that asymmetry into detection logic that evolves.
Artemis models each customer’s environment continuously: users, AI agents, machines, cloud workloads, applications, and how each of them normally behaves. Detections are written against that model. Some of those detections cover known techniques. They map to MITRE ATT&CK, so a security team can see which techniques are covered, and which they cannot see at all.
A second layer of adaptive detectors is autonomously built and tuned to each customer’s estate, based on the context and coverage gaps learned from the environmental model.
The third layer, and the one that matters most against a fast attacker, is behavior-based anomaly detection. An attacker working with frontier AI can take thousands of actions across clusters, clouds, and applications, and each one looks unremarkable in isolation. Against a model of how those users, agents, and workloads normally behave, the pattern becomes visible in real time.
What This Buys You When The Attack Is Already Running
Coverage and cost come out of the same set of initial architectural decisions. Detection only works if the data is there, so choosing what data to stream centrally and knowing detection coverage are interdependent decisions. This ensures teams do not discover their blind spots during an incident.
Detection is only half of the clock. If the alert waits in a queue, the attack finishes first. Customers running Artemis have reduced mean time to detect and respond to security events by 94 percent with automatic AI investigations triggered on every alert.
It is also why our customers range from Fortune 500 security teams to AI-native companies like Cursor, environments with little in common except the need to defend at machine speed. If you or your team are interested in a deeper architectural dive, or would like to meet Shachar, please reach out at artemissecurity.com.