Security News

Cybersecurity news aggregator

INFO News Dark Reading

Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal

Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS CYBER RISK СLOUD SECURITY NEWS News, news analysis, and commentary on the latest trends in cybersecurity technology. Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal CardinalOps will give Cribl customers the ability to map detection rules and security controls to the MITRE ATT&CK framework. SecOps teams can identify coverage gaps and operationalize threat intelligence. Jeffrey Schwartz,Contributing Writer July 15, 2026 3 Min Read SOURCE: DMYTRO OLEGOVICH ZAKHARCHUK VIA ALAMY STOCK PHOTO Security telemetry platform provider Cribl added agentic, AI-based detection engineering to the control plane to its product portfolio through its acquisition of CardinalOps. Cribl's suite of offerings, which collect, transform, route, and store security telemetry across security information and event management (SIEM) systems, data lakes, and other tools, has gained traction among among large enterprises in recent years. The CardinalOps acquisition, announced Tuesday, will give Cribl a more complete stack by adding detection capability. A key attraction for Cribl is CardinalOps's ability to map detection rules and security controls to the MITRE ATT&CK framework, surfacing coverage gaps and operationalizing threat intelligence. Nicole Beckwith, Cribl's senior director of security engineering and operations, says CISOs are increasingly being asked about gaps in MITRE ATT&CK coverage. "With mapping to MITRE, you can really see where your gaps in coverage are in visibility," she says. "They find and fix those broken and noisy rules and then unlock the value of your entire security stack." Related:Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? CardinalOps will help Cribl customers shift from just collecting telemetry to acting on it, Beckwith adds. "Customers are going to be able to not only see all the telemetry they have but then validate that detection coverage." Alternative to "Legacy" SIEM Beckwith says CardinalOps will also enhance the Cribl platform, making it an alternative to legacy SIEM stacks. "Together, this acquisition is going to help strengthen our platform by adding those really deep detection capabilities to our product," she says. "It gives customers basically an alternative to the SIEM stack that they've outgrown." "This is a strategically logical acquisition because Cribl is moving from being primarily the enterprise security and observability data control layer toward becoming a more direct participant in detection engineering and SOC outcomes," says Sean Sosnowski, research director at Software Analyst Cyber Research. Sosnowski says the resulting connection between Cribl and CardinalOps will enhance Cribl's platform. "If Cribl can combine telemetry control with detection posture management, it can help customers move from 'we have too much data' to 'we know which data matters for the detections we need,'" he adds. That, he says, is a much stronger value proposition for security teams because it links data engineering decisions to SOC effectiveness rather than treating pipeline optimization and detection engineering as separate problems. Related:Apple Reverses Age-Old Patch Policy to Keep Up With AI However, Sosnowski warns that Cribl delivering on that promise is contingent on effectively integrating the technology so that workflows can identify detection gaps, determine the required telemetry, route or transform the right data, and help SOC teams improve coverage without adding another disconnected console. "If it becomes a loosely coupled product bundle, the impact will be more limited," he says. Cribl's Humble Beginnings San Francisco-based Cribl, founded in 2018 by a team of former Splunk architects intent on building a scalable telemetry-processing platform, has experienced rapid growth over the past three years. Cribl grew from $1 million in annual recurring revenue to $100 million in less than four years. Growth then accelerated sharply, reaching $200 million in ARR and later surpassing $300 million. The company has raised more than $600 million and was valued at $3.5 billion after a roughly $320 million Series E round led by GV in 2024. Last year, Cribl CEO and co-founder Clint Sharp said he envisions Cribl eventually becoming a public company. "Cribl is already widely adopted in large enterprises because it solved a very practical market problem. Security and IT teams produce too much telemetry, send it to too many tools, and pay too much to store and analyze it without sufficient control over data routing," Sosnowski says. Related:Segmentation Works for OT If Operators Are Paying Attention According to Cribl, more than half of the Fortune 100 and 35% of the Fortune 500 use its platform. Cribl employs more than 1,000 people, including one of its most recent hires, Beckwith, who was director of detection and response at Kroger, one of the largest grocery retailers in the United States that uses both Cribl and CardinalOps. Beckwith was brought on by CISO Myke Lyons. "I believe in everything that they're doing and their roadmap," Beckwith tells Dark Reading. "So, when the opportunity arose to come over here, I jumped at it." About the Author Jeffrey Schwartz Contributing Writer Jeffrey Schwartz is a journalist who has covered information security and all forms of business and enterprise IT, including client computing, data center and cloud infrastructure, and application development for more than 30 years. Jeff is a regular contributor to Channel Futures. Previously, he was editor-in-chief of Redmond magazine and contributed to its sister titles Redmond Channel Partner, Application Development Trends, and Virtualization Review. Earlier, he held editorial roles with CommunicationsWeek, InternetWeek, and VARBusiness. Jeff is based in the New York City suburb of Long Island. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program More Webinars You May Also Like CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi AUG 28, 2025 CYBERSECURITY OPERATIONS Critical Zero-Days Crack Open CyberArk Password Vaults by Nate Nelson AUG 06, 2025 CYBERSECURITY OPERATIONS Women Who 'Hacked the Status Quo' Aim to Inspire Security Careers by Elizabeth Montalbano JUL 16, 2025 Latest Articles in DR Technology CYBERSECURITY OPERATIONS Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? JUL 14, 2026 CYBERATTACKS & DATA BREACHES Turning the Tables on Email Scammers With 'ScamBuster' JUL 13, 2026 IDENTITY & ACCESS MANAGEMENT SECURITY AI Agents Are a New Kind of Identity — and Most Organizations Aren't Ready JUL 9, 2026 CYBERSECURITY OPERATIONS Apple Reverses Age-Old Patch Policy to Keep Up With AI JUL 2, 2026 Read More DR Technology Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article