
By Byron V. Acohido
The modern SOC is getting better at closing alerts. It is still bad at remembering them.
Alerts are multiplying. Innovation has been focused on machines that can triage, correlate, and recommend a response at a much elevated scale. The queue indeed is moving faster than ever. Alert in, verdict out, case closed.
Attackers do not work case by case. A scan on Tuesday, an exploit attempt on Thursday and an unfamiliar login the following week may, in fact, be pieces of the same campaign. But once the SOC closes a case, what it learned does not carry forward to the next investigation.
That gap is becoming more consequential as attackers blend into legitimate activity. CrowdStrike found that 82 percent of detections in 2025 were malware-free, with adversaries relying on valid credentials, trusted identity flows and approved SaaS integrations. In that environment, history is not background. It is evidence.
What is absent is not more detection or faster triage. It is a way to keep an investigation alive—to carry its subjects, evidence and reasoning forward so that what arrives tomorrow can change what yesterday meant.
That is the argument Command Zero brought to Black Hat USA 2026. I sat down in Las Vegas with CEO Dov Yoran and CTO Dean De Beer to talk about Throughline, the capability the Austin company launched at the show. For a full drill-down, please give the accompanying podcast a listen. Here is what I took away from it.
Five alerts, one attack
It starts routinely enough. Five phishing emails arrive at one company over five days. Each targets a different employee. Each is tailored to the department where it lands.
Handled one at a time, each message opens its own investigation. No single case carries enough evidence to change the verdict, so the analyst closes it and moves on.
The SOC does its job five times and still misses what happened once.
Read together, … more


