Three months ago, a Fortune 500 company wired $47 million to an account it shouldn't have.
No zero-day was involved. No nation-state. No insider gone rogue.
The attacker was a large language model. It cost roughly $200 to operate.
Over 48 hours, the model scraped the company's public GitHub repositories, parsed LinkedIn profiles, dissected quarterly earnings calls, and cross-referenced job postings to reverse-engineer internal approval workflows. It identified the financial controller by name, studied her writing cadence from social posts, mapped her reporting chain, and then generated 300 individually tailored spear-phishing emails, each one linguistically distinct, each one surgically targeted.
One landed.
From there, the model studied the compromised inbox, learned the company's invoice formatting conventions, identified an upcoming vendor payment cycle, and submitted a wire transfer request so flawless it sailed through two layers of human review.
Seventy-two hours. Reconnaissance to exfiltration. The money vanished across six jurisdictions before anyone flagged the anomaly.
Meanwhile, the company's threat hunting team was still writing queries to investigate a suspicious login from the previous week.
This is not a thought experiment. This is the threat landscape as it exists today, and the overwhelming majority of security operations centres are not equipped to survive it.
The Asymmetry Nobody Wants to Name
There is a particular kind of institutional denial that takes hold when the rules of a game change faster than the players can adapt. You see it in militaries clinging to cavalry doctrine after the invention of the machine gun. You see it in newsrooms insisting print advertising will recover. And you see it, right now, in cybersecurity, an industry that has spent two decades building defences calibrated for human-speed adversaries and is only beginning to reckon with what happens when the adversary thinks in milliseconds.
The math has shifted beneath everyone's feet.
60 days
Average dwell time in 2019. Embarrassing, but survivable. Defenders had a window.
16 days
Average dwell time by 2023, after attacker automation matured.
< 24 hrs
Full kill chain execution by dark LLMs in 2025. Reconnaissance to exfiltration at machine speed.
Your threat hunters still compose queries by hand. That is not a gap. That is a species-level mismatch.
Inside the Modern SOC: A Quiet Crisis
Walk into any security operations centre in any major enterprise today. You will find talented, overworked analysts drowning in a flood they were never designed to manage.
The numbers tell a story that no vendor slide deck wants to confront honestly. The average SOC analyst faces north of 1,000 alerts per day, with false positive rates hovering above 95 percent. Threat intelligence arrives as dense PDF reports that sit unread in shared drives. SIEM queries, the primary investigative instrument, take hours to write and minutes to crash. Coverage gaps exist everywhere, but no one can map them. Dwell time is still measured in weeks.
And yet, by some unspoken collective agreement, everyone pretends the machinery is functioning. It isn't. The adversary just acquired artificial general reasoning as an offensive weapon. The defence is still running grep on log files. That disparity doesn't close on its own. It widens exponentially.
Five Comfortable Fictions the Industry Refuses to Abandon
Every discipline under existential pressure develops its own mythology, reassuring stories that delay the painful work of adaptation. Cybersecurity has at least five.
Fiction One: Indicators of Compromise Will Save Us
When malware rewrites its own signature every 30 seconds, a file hash blacklist is not a detection strategy. It is a historical exhibit. When phishing infrastructure spins up and burns down faster than any feed can catalogue, your IOC database is documenting the past, not illuminating the present.
The uncomfortable conclusion: if your hunting programme is still anchored to indicators of compromise, you are systematically looking where the threat no longer is.
Fiction Two: We Have Good Threat Intelligence
Most organisations don't have threat intelligence. They have threat inventory: 47 feeds, in 12 formats, scattered across six platforms, with no correlation layer, no contextual enrichment, and no operational integration.
Intelligence answers a single question: Is this happening in my environment, right now? If your threat intel cannot answer that in under 60 seconds, it is not intelligence. It is overhead.
Fiction Three: Behavioural Detection Is Too Complex
You know what is genuinely complex? Explaining to a board of directors why a threat actor lived inside your network for six weeks while your team manually correlated alerts across 15 security products.
Behavioural detection is not inherently complex. The platforms most organisations use to attempt it are. On the right infrastructure, a behavioural hunt is as straightforward as: Show me Office processes that spawned PowerShell and accessed files outside their historical pattern. One sentence. No query language. No data science degree.
Fiction Four: AI Is Just Hype
Ransomware operators are using LLMs to craft personalised extortion communications referencing victims' org charts and regulatory exposure. Nation-state actors are generating polymorphic implants that rewrite themselves on every execution. Script kiddies with no formal training are automating multi-stage attack chains that would have required a skilled operator and weeks of effort 18 months ago. AI in adversaries' hands is a force multiplier already deployed in the field.
Fiction Five: We Just Need Better Analysts
No. You need to stop wasting the analysts you have.
The typical threat hunter's time breaks down roughly as follows: 40 percent writing and tuning queries, 30 percent correlating data across siloed platforms, 20 percent triaging false positives, and 10 percent, one-tenth of their professional capacity, actually hunting threats. That is not a talent deficit. It is a tools failure of staggering proportion.
Toward a Doctrine for the Age of AI Adversaries
What does threat hunting look like when you stop optimising for a threat landscape that no longer exists? Five principles emerge, not as theory, but as operational necessity.
Hunt Behaviours, Not Artifacts. A file hash changes. A domain rotates. An IP shifts. But the behaviour underneath, the credential abuse pattern, the lateral movement sequence, the exfiltration cadence, persists across campaigns and toolsets. Hunt behaviours and you detect threats you have never seen before. Hunt IOCs and you detect threats someone else already catalogued.
Match the Machine's Clock Speed. If your threat hunting workflow is not automated, it is not threat hunting. It is a demonstration project. Automated baseline learning, real-time anomaly detection, instant cross-source correlation, and behavioural models that update without human intervention are the minimum viable response to the current threat velocity.
Demand Context With Every Signal. An alert without context is noise with a timestamp. Every hunt finding must answer four questions: What happened? Is this normal for this user, this asset, this hour? What does threat intelligence say? What is the business impact? Speed without context is just fast noise.
Map Your Blind Spots Or the Adversary Will. What percentage of MITRE ATT&CK techniques can your environment currently detect? If the answer is uncertain, that uncertainty is itself the vulnerability. You are hunting in selective darkness, leaving everything else unmonitored, which is precisely where a sophisticated adversary will operate.
Make Every Hunt Compound. Every hunt should validate or invalidate a hypothesis, update behavioural baselines, feed the detection engineering pipeline, improve subsequent hunts, and expand measurable coverage. If a hunt does not make the organisation demonstrably stronger, it consumed resources without producing value.
The Platform That Took This Seriously
Spharaka Sphere™ was built on the premise that the entire threat hunting model requires reconstruction, not incremental improvement, but architectural reimagination for an era of AI-speed adversaries.
Threat Intelligence at Operational Speed
Consider the typical CVE response cycle. Day one: advisory published. Day two: an analyst reads the PDF. Day three: IOCs manually extracted. Day four: SIEM queries written. Days five through seven: investigation buried in false positives. Day eight, maybe an answer. Eight days. The vulnerability was exploited in the wild on day one.
Spharaka Sphere™ collapses that timeline to minutes. Within 30 seconds, a CVE is auto-ingested, parsed, and enriched. Within two minutes, it is correlated against the entire customer environment. Within five minutes, behavioural hunt models are generated. Within ten minutes, findings are delivered to analysts contextualised, prioritised, and actionable.
Natural Language Hunting
The current state of threat hunting requires analysts to learn proprietary query languages, SPL, KQL, whatever dialect their SIEM speaks, map data sources manually, write complex cross-table joins, wait 20 minutes for execution, receive 10,000 unfiltered results, and then manually separate signal from noise. The bottleneck is not analytical skill. It is query infrastructure.
An analyst types: "Show me PowerShell executions spawned from Office applications that made outbound connections to previously unseen external IPs in the last 24 hours." Results return in seconds, enriched with user and asset baselines, historical pattern analysis, threat intelligence correlation, MITRE technique mapping, and recommended next steps. The hunters hunt. They do not wrestle with syntax.
Behavioural Analytics Without the PhD
A traditional tool alerts: "Unknown process detected."
Spharaka Sphere™ alerts: "Process chain is statistically anomalous for this user, accessing resources outside their defined role, at an unusual hour, matching MITRE T1078 (Valid Accounts), correlated with active threat intelligence on credential abuse campaigns." That is the difference between a fire alarm and a fire investigator.
Visible Coverage
Most SOCs hunt what they know how to hunt. Everything else is invisible, and adversaries live in the invisible. Spharaka Sphere™ provides real-time MITRE ATT&CK coverage mapping: green for techniques you can detect, yellow for partial coverage, red for blind spots. Then it generates hunt hypotheses specifically targeting your gaps.
Compounding Returns
Every hunt feeds a flywheel. A successful hunt automatically becomes a scheduled detection. A false positive updates the behavioural model. A newly discovered TTP enters the hunt library. A closed coverage gap updates the MITRE mapping in real time. Six months on the platform means six months of accumulated intelligence, refined models, eliminated blind spots, and automated detections, each iteration making the next sharper.
The Numbers
| Metric | Before | After | Change |
|---|---|---|---|
| CVE response time | 7+ days | < 1 hour | 99% reduction |
| Hunt creation time | 2-4 hours | 3-5 minutes | 95% reduction |
| False positive rate | 95%+ | < 15% | 80-point drop |
| Coverage visibility | Guesswork | Real-time MITRE | Quantified |
| Time spent hunting | ~20% | ~75% | 3.75x increase |
The Maturity Question
Where does your organisation sit?
Level 0: Reactive. Wait for alerts. Investigate after damage. Hope. Roughly 30% of organisations. You are almost certainly already compromised and do not yet know it.
Level 1: Basic Hunting. Manual, hypothesis-driven searches. IOC lookups. About 45% of organisations. You are hunting last month's threats.
Level 2: Structured. Documented playbooks. Regular cadence. Some automation. Around 20%. You are systematically hunting yesterday's threats.
Level 3: Continuous. Automated behavioural analysis. Integrated threat intelligence. Real-time coverage visibility. Approximately 4%. You are keeping pace.
Level 4: Autonomous. AI-generated hypotheses. Machine-speed execution. Self-improving detection. Proactive prevention. Less than 1% of organisations. AI adversaries operate at Level 4.
The Closing Window
The average data breach now costs $4.45 million. But the deeper cost is institutional trust, and trust, once broken, does not recover on a quarterly earnings cycle.
In 2019, defenders had roughly 60 days to find an intruder. By 2023, that window had narrowed to 16 days. For AI-powered attacks in 2026, the window is measured in hours. Every year, the adversary gets faster. Every year, the detection window shrinks. The tools, largely, stay the same. At some point, the arithmetic becomes unforgiving. The evidence suggests that point has arrived.
The knife was fine when the other side had knives. They have drones now.
About the Author
Ravikumar Nalluri is the Co-founder and CTO of Spharaka Networks™. With nearly two decades of experience in cybersecurity, he is focused on redefining how organisations defend against AI-driven, automated attacks. Connect on LinkedIn.
Hunt at Machine Speed
See how Spharaka Sphere™ replaces query-driven hunting with autonomous, behaviour-led detection that compounds with every incident.



