Everyone complains about their SIEM. People would drop it if they could.
We built Nebulock on a simple bet: security outcomes result from hunting first, not from waiting for an alert. That's where we started, and it's still the core of the platform. Hunting was always just the first of three jobs that organizations have historically routed through a SIEM. Investigation and detection engineering are the other two, and we've been modernizing all three, in each case moving the work off a system built to wait for an alert and onto agents built to go find the answer. Endpoint, cloud, and identity telemetry are the data sources we centralize and reason over continuously. Everything else, we believe, should be pulled in only when a hunt, an investigation, or a detection actually needs it.
Put plainly: the SIEM model is just in case . Ingest everything now, index it, pay to store it, on the chance someone asks a question later. We think the right model is just in time . Reach the authoritative source at the exact moment a hunt, investigation, or detection needs it, and use what comes back to sharpen the finding. The SIEM isn't going away, and we're not suggesting that you rip it out. But it doesn't need to be the center of gravity for detection, investigation, and hunting either.
Today we're introducing Nebulock Helix , the part of the platform that opens the aperture to comprehensive coverage across hunting, investigating, and detections engineering. Helix connects Nebulock's agents to the security tools you already run, so they can query and reason over that data on demand, at the exact moment an investigation, detection, or hunt needs it. That includes Vespyr running an autonomous hunt, and it includes you, mid-investigation, asking a question yourself. Nothing gets pre-ingested. There's no pipeline to babysit, and no bill for data sitting in storage on the off chance you need it later.
If we think of security data as siloed, like separate strands that never touch, Helix winds them together like a cable, building strength over time without ever losing the connection between them.
Helix launches with support for vulnerability management, and it will expand from here.
The problem with ingesting first Most platforms solve context the same way: pull everything into a central store so it's there when someone eventually asks a question. That's the SIEM model, and a growing list of AI-SOC tools have simply put a copilot or chatbot on top of it. Yes, your queries might be faster, or appear more intelligent, but you’re still dealing with the same, huge pile of data.
It's also expensive. Security teams routinely pay premium, per-gigabyte ingestion fees on massive, redundant data streams just to let them sit unread, on top of the pipeline it takes to keep them flowing.
That trade-off is backwards.
A hunt-first platform doesn't need to hold everything up front. It needs to reach the right source at the right moment, when a hunt, investigation, or detection actually calls for it. That's what just in time means in practice, and it's what Helix does: query the authoritative system directly, when it's relevant, and use what comes back to sharpen the finding.
This is the direction we want security tooling to go: away from data stores that sit idle and become cost centers, and towards pulling targeted data that's actually relevant to an investigation. That means Nebulock's agents aren't just telling us something's suspicious anymore, they're telling us whether it's exploitable. That's the difference between an alert and an answer. - Mark Sutton, CISO, Bain Capital Reduce your reliance on SIEM Helix connects Nebulock's agents to your existing security tools for just-in-time enrichment, starting with vulnerability management and expanding over time to SIEM, network, and the other sources that add context to investigations, detections, and hunts.
That shows up in two ways:
The Q&A experience you'd expect through Investigate. Ask "are any of my assets vulnerable to CVE-x" or "what devices have nginx installed" in plain English, and Helix translates that into the right query for your VM tool and returns the answer. No manual lookup, and no need to learn Qualys QQL, Tenable's syntax, or whatever your VM platform calls its own language.Helix answers your natural language questions and starts asking its own. This is the one we're most excited about. When Nebulock's agents have that same access on demand, that changes the hunts, the findings they produce, and the recommendations Nebulock makes.Here’s why this matters:
Better prioritization. Vulnerable hosts get flagged the moment a hunt touches them, instead of waiting on someone to cross-reference a scan report by hand.Fewer false positives. Agents that know patched from unpatched stop treating every suspicious signal on a hardened host like one on an exposed host.Less manual work. The lookups that used to interrupt an investigation – tabbing into a scanner, learning its query syntax, finding a host, reading a report – now happen automatically inside a hunt, or in a single plain-English question if you're running the investigation yourself.This is also a step toward something bigger: reducing how much your team leans on a legacy SIEM for day-to-day work. Less data has to be ingested and stored just in case, which means less SIEM storage and compute to pay for and maintain, in service of a system that mostly sat idle waiting for an alert anyway.
Just-in-time vulnerability management enrichment, three ways Hunt-led: A hunt is built from an actively exploited CVE’s known TTPs and flags a host showing that behavior. Before it ever reaches you, the agent queries your vulnerability scanner to check whether the host is actually vulnerable to that CVE. If it is: "Host has the CVE this hunt is scoped to and shows the matching behavior. Escalate as likely active exploitation." If it isn't: "Host isn't vulnerable to this CVE. The behavior still needs investigating, but route it as standard triage, not a confirmed exploit."Operator-led: You're investigating a host for an unrelated reason: say a user reported a phishing email, and you want to check its patch status as part of your workup. Instead of pivoting to the scanner console and writing a query, you ask Nebulock in plain English and get the answer inline.Intel-led: A threat intel brief drops describing a CVE under active exploitation. You paste the URL into Nebulock, and Helix queries your VM tool, translating the CVE and asset details into whatever syntax that scanner speaks, to figure out which hosts are actually vulnerable, before a single hunt query runs. That shortlist becomes the hunt. Instead of hunting broadly and hoping something surfaces, the hunt is scoped to exactly the hosts the CVE could apply to, and the result confirms or rules out compromise on each one.In every case, it's just-in-time data, folded into the finding at the exact moment you need it.
What Helix supports today Nebulock Helix ships with just-in-time enrichment across the following vulnerability management platforms:
Qualys VMDR Rapid7 InsightVM Tenable Axonius CrowdStrike Spotlight / Exposure Management Microsoft Defender Vulnerability Management In this first release, VM was the obvious place to start: nearly every security team runs one and exploitability context turns a "suspicious" finding into a prioritized one almost immediately. From here, Helix expands to cloud, network, and the other systems that hold context worth pulling into a hunt.
Where Helix is headed: sidestepping the SIEM for better security outcomes Helix is how we reduce the reliance on SIEM in practice: whether it's Vespyr running an autonomous hunt or you running an investigation, Nebulock's agents reach into the tools you already have, in plain language rather than each one's query syntax, pull exactly what's relevant, and hand you a sharper answer, without asking you to ingest, index, or maintain anything new.
If you're already a Nebulock customer, Helix's vulnerability management enrichment is available to you now. If you're not yet a customer and want to see how just-in-time context changes what Nebulock can tell you, book a demo , or come find us in person at Black Hat USA, booth #5312 .