If you had asked in 2013 what made CrowdStrike dangerous, most people would have said the Falcon agent. The agent was excellent, and competitors raced to copy it. What turned out to be harder to replicate was the Threat Graph. Elite hunters and an intelligence team spent years pouring judgment into that record, and the graph got smart because they did. Threat Graph was running inference at a scale nobody else could touch.
Fast forward to today and AI has collapsed the cost of building security tooling. A competent team with enough tokens can ship comparable architecture inside eighteen months. What did not get cheaper is the judgment or time it takes to fill a context graph. Frontier and open-weight models keep getting better at reasoning, and that makes discernment more valuable, not less.
From innovation to infrastructure
Walk the floor at this year's Black Hat Conference and you can see that graphs have not only endured, they’ve become integral to security operations. Which raises three questions: Why use a graph in the first place? What are the inputs to that graph? And most importantly, how does a graph deliver better, faster, and enduring value to a security organization?
The three components that get bundled together when referring to "graph" are worth pulling apart. Expertise is the input. Architecture is what turns it into a durable record. Memory is the asset that compounds.
CrowdStrike's Threat Graph was built as the brains behind the Falcon agent. We built the TRACE Graph as the memory of your environment: everything it has done, and everything we have learned from watching it.
TRACE Graph: Your behavioral system of record, shaped by our hunters
The TRACE Graph is a record of behavior across endpoint, identity, cloud, network, and SaaS, specific to your environment and applied to every hunt run inside it. Alongside the ingestion inputs, it holds the outputs: hunts, hunt reports, findings, and the feedback from your team. It’s not a copy of your telemetry or a threat intelligence feed. TRACE Graph holds what we learn from observing your environment: scattered events and identities baselined, and behavior normalized in a way no amount of log reading produces.
Why TRACE? Threat Research and Context Engine doesn’t quite roll off the tongue. We named it TRACE to represent how we transparently navigate evidence to create correlations. Every conclusion can be traced back through the evidence that produced it: a throughline from raw event to enriched entity to conclusion, so an operator can always work backward from a decision to the reasoning behind it. It is a global system, shaped by more than a century of combined detection-engineering and threat-hunting experience, applied locally to your environment.
Every hunt that you or we run writes back to it. Vespyr, our autonomous hunting agent, doesn’t start from an alert. It runs like our threat hunters that shaped it. It starts with a behavioral hypothesis and journals its own work: the hypothesis, the telemetry examined, the pivots taken, the paths ruled out, the outcome. A hunt that finds nothing still records what normal looked like that day.
Behind the TRACE Graph is years of learned behavior across enterprise environments, 300+ million agentic investigations, and 2,000+ behavioral detections derived from real behavior rather than a generic content library. More than 4,000 high-confidence findings have surfaced so far, each with attribution and root cause attached.
Even inside a POV, the TRACE Graph surfaces new findings in environments already running EDR, IAM, and SIEM. We’ve caught an insider copying 748 source code files to a USB drive at a Fortune 1000, a remote actor operating undetected for months at a digital retailer, and credentials sitting exposed in CLI arguments at a healthcare technology company. Not one of them tripped a rule.
I started Nebulock on the conviction that the most dangerous thing inside an enterprise looks completely ordinary. The TRACE Graph is how we separate two kinds of ordinary: routine behavior that’s harmless, and malicious activity that imitates it.
Catch behavior that rules cannot
We call that ordinary-looking danger a green flag: an attacker with valid credentials behaves like any other user, or a sanctioned AI agent starts doing something nobody authorized. By every traditional measure the activity is routine, which is exactly why it trips no rules.
The agentic version is newer and harder. Behavioral analytics worked on people because human working hours, systems, and identities are largely predictable. Agents break all three assumptions. They hold tokens, service accounts, and hosts scattered across your estate, run at three in the morning as a cron job, and behave legitimately by design.
Gravitee's 2026 survey found 82% of executives were confident their policies covered unauthorized agent actions, 88% already had an incident, and only 21% could see what their agents were doing. We baseline human and non-human actors on the same footing.
The same blind spot shows up in coverage reporting. CardinalOps found that enterprise SIEMs miss roughly 79% of the ATT&CK techniques adversaries actually use, and that 13% of deployed rules are broken and will never fire. This gap is widening at an accelerating rate.
Here is what a broken rule looks like. In Splunk, a logon failure event can carry both a raw field and its normalized counterpart, Status=0xc000006d alongside status=failure. Write the rule against the wrong spelling and you get valid syntax that returns nothing, forever, silently. A missing rule shows up as a gap in your coverage report. A broken rule shows up as coverage.
That limit applies to sophisticated tooling that models the environment up front from authoritative systems and applies that model at detection time. It confuses the org chart with the organization. Your systems of record tell you what is provisioned: who holds which role, which asset is critical, what the identity graph is meant to look like. Useful, and not behavior. No CMDB has ever told anyone that a service account never touches that data store outside business hours.
Configuration is a snapshot of intent, behavior is a record of conduct, and green flags only ever appear in the latter.
Better inputs make for better findings
The TRACE Graph is a more effective context graph because it uses three methods to fill it with data: hypothesis-driven hunting, internal validation, and adversary emulation.
Threat hunting is hypothesis-driven and needs zero evidence to begin. Investigation is evidence-driven, which means a lead already exists. If a product's hunt starts from an alert then it is an investigation wearing a hunting costume. A context graph fed by investigations becomes a record of what your alerts have already caught. TRACE is filled by hypothesis-driven hunting, so it becomes a record of what nothing flagged.
Your team is the second input. When a tenured defender closes a finding as expected behavior, that judgment is the highest-quality signal available for every hunt that follows.
Adversary emulation is the third: labeled ground truth from real attack sequences, so the record learns the shape of an intrusion before a real adversary runs one.
Together these methods feed a virtuous cycle: the detections run in-pipeline and re-baseline themselves as the environment moves, so detections don’t quietly rot a week after it’s written, and each one improves the priors for the next hunt.
Time is the input you cannot buy
If behavioral baselines settle quickly, why would tenure matter?
Because a single behavior class settles quickly and an enterprise does not. Baseline what normal MCP usage looks like across a fleet and it stabilizes fast: the same clients, the same packages, the same command lines.
What needs tenure and tribal knowledge is the activity that happens rarely, like the post-acquisition integration work that reads as lateral movement by design. The first time it happens it looks anomalous, and it gets tuned out as noise.
Technical parity among context graphs can only take you so far. Even with an excellent team of hunters, the memory and knowledge of what happened before cannot be retroactively acquired before it arrived. Even with synthetic data, you cannot baseline a year you were not present for.
What drives the TRACE Graph for better security outcomes
A behavioral record without measurement is just an opinion. Four practices keep the TRACE Graph accountable:
- We examine the agents, not only their answers, by instrumenting how a hunt executes rather than grading what it returns.
- Ground truth is generated, not assumed. Adversary emulation produces labeled cases with known outcomes, which is how hunting efficacy gets measured instead of asserted.
- Our operators are the reinforcement signal. Our Detection Engineering and Threat Hunting team works directly inside the product to evaluate and improve the agents that reason over the TRACE Graph.
- Detections are tested, not just written. Every detection is validated against your environment, checked for logic drift, and rewritten as the environment moves.
One thing we will be exact about. In our open-source framework, the command that graduates a hunt into a formal detection with its journal lineage ships today as a design preview, and the connector is not finished. That loop runs inside Nebulock. Our commitment to publishing the open-source version still stands as we continue to build it.
Making the bet
In a crowded ocean of security tools with many claims, we’re making a bet: a behavioral record of a specific environment appreciates faster than any corpus of known-bad indicators can be maintained, and that the gap widens every quarter adversarial tooling gets cheaper to generate.
One principle holds over all of it, and it came from our team rather than from me. Agents propose, humans approve. The TRACE Graph exists to uplevel the defender, not to replace the judgment that makes a defender worth upleveling.
I’ll close on a question rather than a claim: If your program started from what your environment actually does, instead of from the alerts it happened to generate, what would you hunt first? That answer is different at every company I talk to, and it's the most interesting conversation in security right now.
Threat Graph took years of the best hunters in the world to fill. The TRACE Graph has taken two years of ours, and it's available to all Nebulock customers out of the box..
Reach out to see a demo of how it would work in your environment.
Damien