Navigate Select ESC Close

A Conversation With Cliff Crosland

2026-06-09 Science & Technology
52
3
0
Unsupervised Learning
Unsupervised Learning
673.0k subscribers

Unlock all features

FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.

Description

Check out Scanner here! - https://ul.live/scanner_yt Sat down with Cliff to talk about how Scanner is changing the game for security log analysis by making massive object storage searches insanely fast. We dive into how their platform acts as a high-speed data substrate that pairs perfectly with AI agents to automate threat hunting, alert triage, and detection engineering. Honestly, this is one of the most exciting pieces of tech I've seen in years, and I'm already figuring out how to build my own skills on top of it! What We Talk About: Ditching the Clusters for S3: How legacy, cluster-based SIEMs break down under modern data volumes, and why Scanner leans entirely into cheap, scalable S3 object storage while eliminating the usual latency issues. The Magic of Serverless & Schema-less Data: How Scanner bypasses tedious data engineering by natively ingesting raw, messy data, relying on a completely ephemeral compute engine that spins up from nothing only when you ask a question. Petabyte-Scale Threat Hunting in Seconds: Moving beyond basic detection and response to search across years of historical data, completing deep-dive threat hunts in mere seconds instead of waiting hours. Teaming Up with AI Agents: How to use autonomous AI tools to headless-query the data, auto-triage false positives, find visibility gaps, and generate shareable HTML reports so you aren't doing the heavy lifting at 3 a.m.. A Foundational Data Substrate: Why Scanner is much bigger than just a search tool; it's a foundational data layer designed to feed massive, lightning-fast context to your entire security program and custom tools. 00:00 - Introductions. 00:15 - What is the main problem Scanner is solving. 01:05 - What is the "magic" that allows the platform to look at that much data so incredibly fast?. 05:51 - What does the onboarding process look like, and do users need to get their data into S3?. 07:46 - How the platform handles caching for queries that need to be run every minute. 09:20 - Discussing use cases beyond standard detection and response. 11:11 - Hitting the limits of physics: How much data can it actually cover, and how fast can it go?. 13:18 - How Scanner acts as a partner for AI, and what the actual product interface looks like. 18:13 - The "Aha!" moment: Realizing Scanner operates as a foundational data plane or substrate. 20:23 - What types of data and file formats the system can ingest for schema-less analysis. 22:34 - Using an AI layer to automatically write and expand your security detection program. 28:36 - Having AI analyze your company's context and crown jewels to completely automate your defenses. 35:28 - Upcoming conference announcements (BSides, Black Hat) and where listeners can try out Scanner. Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at: https://danielmiessler.com/upgrade Follow on X: https://x.com/danielmiessler Follow on LinkedIn: https://www.linkedin.com/in/danielmiessler/

Top Comments

No comments available

Unlock the Data Inside
Turn Videos into Knowledge

  • Get FREE 10/day: transcripts, summaries, chats
  • Chat with videos, export text & PDF
  • $1 free API credit for RAG, chatbots & research

Free forever plan • All features unlocked

App screenshot