The ITSPmagazine Podcast

The Last Mile of Security Operations Runs on a Local Model | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Karthik Kannan, Founder and CEO at Anvilogic | Hosted by Sean Martin

Episode Summary

Seven years after setting out to build a full security operations platform, Anvilogic says the vision is complete, with agents handling data, detection, triage, investigation, and case management under human control. Karthik Kannan explains why the last mile of AI in the SOC runs on a model that lives inside your own environment.

Episode Notes

Recorded on location at Black Hat USA 2026 in Las Vegas at the end of day two, Karthik Kannan, Founder and CEO at Anvilogic, walks through a seven year build that reached its original shape this year. The plan from the start was a full security operations platform covering data, the detection engineering process, triage and investigation, and case management. In the shorthand of the category, SIEM and SOAR combined.

It arrived in phases. Detection engineering came first, implemented on top of Splunk for most customers, then the data platform expanded into data lakes including Snowflake, Databricks, and Microsoft Azure. Triage and investigation followed over the last two years. In the last year Anvilogic rolled out agents that carry out the work of specific personas, and this year the company launched Blueprints, an orchestrator agent that brings the discrete agents together to run a whole workflow with humans in the loop.

What separates a security graph from a frontier model? It knows the environment. Karthik Kannan describes the enterprise security graph as Anvilogic's own model running inside the network, learning the micro environment, with frontier LLMs called on to fill gaps in the macro environment. His argument is that platforms operating as LLM wrappers miss the last mile, because AI on its own reaches 60, 70, or 80 percent of the way if you are lucky.

How does a team keep control when agents run the workflow? Through gates, permissions, and a record of what happened. Workflows can be described in plain English, with human gates inserted as often as the team wants. Access controls sit at the persona, organization, and object levels, and activity is audited and logged, which matters to the GRC teams Anvilogic works with.

Screens dedicated to what the company calls a maturity score show which feeds are coming in, what kinds of detections exist, and what coverage looks like against the MITRE ATT&CK framework, in a form available to executives and CISOs. Karthik Kannan also points to version 8.0, introduced the week before the event, which includes an Anvilogic MCP Server for connecting to third party tools.

Customers are already building their own Blueprint workflows during proofs of concept, including a large life sciences customer Anvilogic expects to feature in a public case study. Karthik Kannan is careful about the claim being made here. This is not a proclamation of an autonomous SOC. It is automation that makes life in a SOC easier and more efficient, adopted at a crawl, walk, run pace, with every step visible along the way.

This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

GUEST

Karthik Kannan, Founder and CEO at Anvilogic
On LinkedIn: https://www.linkedin.com/in/karthikkannan001/

RESOURCES

Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

Learn more about Anvilogic: https://www.anvilogic.com

Anvilogic 8.0, from onboarding to investigation: https://www.anvilogic.com/learn/anvilogic-8-0-automate-the-soc

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

karthik kannan, anvilogic, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic secops, ai soc platform, enterprise security graph, detection engineering, triage and investigation, blueprints orchestrator agent, mcp server, mitre att&ck coverage, human in the loop automation, siem and soar, security operations, grc audit logs

Episode Transcription

The Last Mile of Security Operations Runs on a Local Model | A Brand Briefing at Black Hat USA 2026 with Karthik Kannan, Founder and CEO at Anvilogic | Hosted by Sean Martin


 

[00:00:00] Sean Martin: All right, hi.


 

[00:00:11] Karthik Kannan: Hey Sean,


 

[00:00:11] Sean Martin: how are you?


 

[00:00:12] Karthik Kannan: I'm doing well, thank you. And you


 

[00:00:13] Sean Martin: still standing?


 

[00:00:14] Karthik Kannan: Still standing at the end of a day two.


 

[00:00:17] Sean Martin: End of day two. We're at Black Hat USA 2026 in Vegas. Somewhat cool in here. There's a lot of people in here though, so it's kind of hot still.


 

[00:00:25] Karthik Kannan: Yeah, it's


 

[00:00:25] Sean Martin: not like outside.


 

[00:00:26] Karthik Kannan: Not like outside. It's a good 20 degrees cooler in here.


 

[00:00:30] Sean Martin: You have any good conversations here?


 

[00:00:32] Karthik Kannan: We are having a lot of wonderful conversations. We have customers standing right here with my, uh, team. Lots of good conversations these past few days.


 

[00:00:40] Sean Martin: Great. Glad to hear that. So we're gonna talk about Anvilogic. Obviously all the things that you're working on. Uh, fast forward about your role and leading up to founding Anvilogic?


 

[00:00:54] Karthik Kannan: Sure. We started the company same time, around same time, seven years ago. We've been at it for [00:01:00] that long and gen AI has helped propel this even further than we had imagined. Our vision was always to build out a full security operations platform. What that means is having control over data, the detection, engineering process, triage investigation, and all the way up to case management and that. If you think about adding technical jargon, SIEM and SOAR combined,


 

[00:01:24] Sean Martin: Okay. Right.


 

[00:01:24] Karthik Kannan: That's what we had set out to do seven years ago. Obviously, you don't do it all on day one. So we took our time, we built out the detection engineering piece, which was our first beachhead. We implemented that on top of Splunk for most customers. And then once we did that, right, we moved into our next phase, which was expanding the data platform from just being Splunk to data lakes like Snowflake and Databricks and Microsoft Azure, and you name it. But Snowflake became a big, integral piece of it. And then after that, we said it's not just about [00:02:00] data and detection engineering, we have to really move into triage and investigations too, because we have to close the loop. So over the last two years, we've been building out our triage and investigation capabilities, but about two and a half years ago, or whenever it was, gen AI popped up. Obviously we didn't know it was gonna happen, but it was a brilliant thing we thought to happen. Because now what we've done in the last year is we've rolled out a series of agents, and those agents do the function of specific personas. Essentially taking a persona, like a data engineer and automating their workflow, which is taking raw data, normalizing it, conforming to a certain kind of schema. Fitting it into a detection model. Those are all human workflows that we've now automated with agents. And this year we launched Blueprints, which is our orchestrator agent, which takes all of our discrete agents and brings them all together to run a whole [00:03:00] workflow. Now we are truly a SecOps platform, from data to detection, to triage, to investigation, to case management, all done by discrete agents. With humans in the loop, but with an orchestrator agent called Blueprints that can automate all of these functions or specific functions one at a time. So we've come seven years to complete the vision we had laid out.


 

[00:03:24] Sean Martin: Right.


 

[00:03:24] Karthik Kannan: And now we are really happy with where the product is.


 

[00:03:27] Sean Martin: Sounds so cool. I mean, as an engineer, I'm like, I want to get in there and play with this stuff,


 

[00:03:32] Karthik Kannan: customers. So we have a booth set up right here. Yeah. Customers have, we know exactly that. We have a bit of a. Capture the flag like experience here. They're playing around with the platform, it's running in the background, and they're coming here and doing their own detections and hunting and triage on the platform.


 

[00:03:49] Sean Martin: So many questions in my head. 'cause there's obviously you said agents for personas that do certain things, so they're trained and skilled for those things. Yep. Um, [00:04:00] how does that map to things like MITRE or playbooks? Or things that an organization might already have in place. Yep. Uh, that they then gain value, additional value for having a. Exactly.


 

[00:04:12] Karthik Kannan: And those are a few important pieces that you mentioned, like having the playbooks or working with the existing playbooks, uh, MITRE ATT&CK framework. Those are all basics on the platform. There's a variety of other institutional best practices and institutional knowledge that we work with. So the key is our founding philosophy was we should have what we now call an enterprise security graph. Think of it like our own model that exists internally inside the network. Okay. That is learning the micro, uh, uh, environment. When we have to go fill the gap, we go to the, uh, frontier LLMs, OpenAI and other models to fill the gaps where, which we call the macro environment.


 

[00:04:56] Sean Martin: Okay.


 

[00:04:57] Karthik Kannan: One without the other, doesn't work. And most companies [00:05:00] don't seem to realize that they're all LLM wrappers. They just go out and query the frontier models. That doesn't work because you have to know what the last mile inside the environment is. So what we built is what we call an enterprise security graph that has the ontologies of the security domain built in. It has the workflows built in, it has the rationale behind the workflows. That is not only built in, but also being continuously learns from the smartest analysts operating. Now we can produce playbooks out of all of this that continuously learn, and that's what is important in this day and age, is just AI is only going to take you 60, 70, 80% of the way if you're lucky.


 

[00:05:42] Sean Martin: Right.


 

[00:05:42] Karthik Kannan: But really to. Across the last mile. You need to have a local model. That's what we've been building for years now. And now we are able to surface that up through our agents. Right.


 

[00:05:53] Sean Martin: Supplemented augmented with the uh,


 

[00:05:56] Karthik Kannan: Exactly. Frontier


 

[00:05:56] Sean Martin: models.


 

[00:05:56] Karthik Kannan: Exactly. That's the secret.


 

[00:05:58] Sean Martin: Very cool. So [00:06:00] they, um, talk to me about how this changes. Security operations program from, I dunno, the SOC manager to SOC analyst, and maybe even broader beyond those two to a broader security program.


 

[00:06:19] Karthik Kannan: Yeah. So all of these roles, all of these personas have a part to play.


 

[00:06:23] Sean Martin: Okay?


 

[00:06:24] Karthik Kannan: And they have a piece of our platform that they can work with. There are agents constructed specifically for these personas and their workflows. And if you find yourself caught between two, you are fine to use both, okay? Or many. Or you can carve out your own. So you can come to our Blueprints, build your own workflow. You don't have to be told this is your discrete path. You can build your own and you speak to it in English language and it builds a workflow for you right in front of your eyes. And you can insert a human gate as often and in as many places as you want. So you control your destiny as [00:07:00] any persona that you are. And at the end of the day, they all come together. We have access controls at the, uh, you know, persona level, and we have access controls at the, uh, organization level. We have access controls and privileges at the object level. Okay. So we really can control how the agents work so they don't run amuck. And then everything is logged as well. Audited and logged and whatnot.


 

[00:07:24] Sean Martin: I was gonna ask you about the auditing because. Depending on what sector company works in, they might have to release materials for an audit.


 

[00:07:33] Karthik Kannan: Of course, it's important. We work very closely with GRC teams.


 

[00:07:37] Sean Martin: Okay.


 

[00:07:38] Karthik Kannan: So we produce the audit logs. Uh, we have all of these access controls built in. And you can define, uh, at the data feed level, uh, we have a, a whole set of screens that are dedicated to what we call maturity score, which tells you in, uh, in a multidimensional way, what kind of feeds are being, uh, introduced into the system. What kinds of detections, what's the coverage [00:08:00] on the MITRE ATT&CK framework. All of that is readily available. To the executives, to the CISOs, right? And by, by the way, you don't have to know the platform in and out. You can tell the agent what you want and it knows where to go. Produce your natural language and produce natural language, speak in English. It'll respond to you with the right answers. And now last week we introduced a version 8.0. Which includes our own MCP Server. Okay. So now we can talk to third party tools and connect up with them and exchange information without literally having to be told or instructed by someone to go to another tool or to another product. The, you know, the MCP to MCP agent, to agent communications are kind of making bigger value come out of this, right?


 

[00:08:47] Sean Martin: So. The, the platform, the agents, the orchestration, the end-to-end logging and the auditing and, and reporting. Great view overall, how [00:09:00] does somebody look at internally what's happening so that they can actually say that, that's how I would do it, or this is doing it better, or I need to tweak it because of the environment I'm in or the risk I really care about. How do, how do they get in and see what you're doing?


 

[00:09:15] Karthik Kannan: Yep.


 

[00:09:16] Sean Martin: With transparency,


 

[00:09:17] Karthik Kannan: everything, that's the word I was gonna use. Everything in the product is transparent and explainable. So when an agent does a job or completes a workflow on the right side, you will see a preview screen of what's happening and exactly what it is doing at every step. And when you insert those human gates. You can stop it right there, you know, make sure you're comfortable with what's happening, and then let it proceed. And everything is explainable and all of the enrichment is visible to you. If you can spend as much time on platform as you want, getting comfortable with the transparency, and then once you get comfort, then you can automate more and more and more. Our customers are doing exactly that. They're doing a crawl, walk, run. So they get comfortable, [00:10:00] they know what it is doing. They insert those human gates and at some point say, start to semi-automate things. We are not proclaiming some sort of an autonomous SOC. What we are saying is we are using automation in a way to make life in a SOC much, much easier and more efficient.


 

[00:10:17] Sean Martin: And so you mentioned this, that, that they can build their own agents. With their own skills and personas. Do you have customers doing that already?


 

[00:10:25] Karthik Kannan: Yeah, they are already.


 

[00:10:25] Sean Martin: Any examples?


 

[00:10:25] Karthik Kannan: In fact, we had a POC. I can't name the customer yet, but hopefully we'll publish a case study out of it. Just during the POC, the customer created their own Blueprint workflows. They were so proud of it. They were showing us in the POC what they had done the previous day, and we had another customer, a very large life sciences customer that we will have a public case study about very soon, did a POC in just a few days. We released version 8.0. They were playing till midnight every day last week. And at the end of the week they said this is way beyond what they had [00:11:00] imagined or had seen before. Hopefully we'll publish all of this pretty soon. But we are seeing really interesting use cases when people start to see the possibilities with successful AI based automation. Their eyes light up and they are gonna tell us more and more use cases that we never imagined, and that's all gonna go back into our playbooks. We are gonna have an armory of playbooks and customers are gonna be building those for us.


 

[00:11:27] Sean Martin: All goes back to playbooks.


 

[00:11:29] Karthik Kannan: Exactly.


 

[00:11:30] Sean Martin: The threats come. They run.


 

[00:11:32] Karthik Kannan: Yep.


 

[00:11:33] Sean Martin: Gotta be prepared to respond. Any, uh, any final word on, I don't know, some results where teams close things faster, reduced overhead and, and angst with the team? Any, anything you wanna share? Yep.


 

[00:11:46] Karthik Kannan: All of the above. In fact, we might have had a couple of graphics here, uh, that showed exactly that. How much, uh, time savings, what sort of efficiency, how many dollars saved, uh, you know, how little dwell time exists in [00:12:00] the system. So we call it fighting AI with AI. Uh, AI is producing, you know, faster attacks from vectors that we don't anticipate as as much, but AI is also helping defend. So that's what we are doing. Hopefully some of the metrics here you caught on video. But yeah, we are seeing real world results. We are focused on very, very large Fortune 1000 type companies, and they are very smart SOCs, right? So when they adopt something like this, you know, that. This is validated.


 

[00:12:31] Sean Martin: Thanks for clarifying that as well. I was gonna ask what your target, uh, audience is. That's, that's, that's great.


 

[00:12:36] Karthik Kannan: Yep.


 

[00:12:36] Sean Martin: Karthik sounds really cool.


 

[00:12:38] Karthik Kannan: Yep.


 

[00:12:39] Sean Martin: I wanna get in there and build my own agents.


 

[00:12:40] Karthik Kannan: Please do.


 

[00:12:42] Sean Martin: Hopefully, hopefully, uh, your customers are having fun and, and achieving some great results. They are, they are.


 

[00:12:47] Karthik Kannan: They are.


 

[00:12:48] Sean Martin: So, I appreciate you. Uh, thank


 

[00:12:49] Karthik Kannan: you Sean,


 

[00:12:49] Sean Martin: sharing this story.


 

[00:12:50] Karthik Kannan: Pleasure doing this with you,


 

[00:12:51] Sean Martin: everybody. Uh, be sure to connect with Karthik and the Anvilogic team. Of your own agents.


 

[00:12:57] Karthik Kannan: Thank [00:13:00] you.