# abstract.security > AI-optimized mirror of abstract.security containing 50 pages totalling 59,841 words of clean markdown content, structured data, and semantic HTML. Original source: https://abstract.security. Last updated: 2026-08-04T09:11:40.226Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Abstract | Composable SIEM Platform](/content/site-root.html): Break free from vendor lock-in with composable SIEM. Flexible data collection, AI-powered detection, and intelligent storage for modern SecOps teams. (762 words) ## Articles & Blog Posts - [C2 Corner: How I Mentor | Abstract](/content/blog/c2-corner-how-i-mentor/index.html): Jim Routh shares mentoring principles he’s used for decades to help CISOs and security leaders grow through ambiguity, responsibility, and trust. (660 words) - [C2 Corner: State of Enterprise Detection Engineering for a Modern SOC | Abstract](/content/blog/c2-corner-state-of-enterprise-detection-engineering-for-a-modern-soc.html): Explore 2025’s enterprise SOC evolution—data pipelines reshape SIEM economics, CTI drives TTP-based detections, and fundamentals still win the day. (3,337 words) - [Contagious Interview: VS Code & Cursor Infection Chains (Pt 2) | Abstract](/content/blog/contagious-interview-evolution-of-vs-code-and-cursor-tasks-infection-chains-part-2.html): Analysis of the Contagious Interview WeaselStore chain: PylangGhost and GolangGhost techniques, VS Code task abuse, and detection guidance for defenders. (1,466 words) - [Claude Code & Cowork Monitoring for Threat Detection | Abstract](/content/blog/claude-code-cowork-monitoring-for-threat-detection/index.html): Ingest Claude Code and Cowork telemetry into a security pipeline to cut storage cost, detect data leakage, and catch AI agent threats like TrustFall. (1,512 words) - [Contagious Interview: VS Code & Cursor Infection Chains (Pt 1) | Abstract](/content/blog/contagious-interview-evolution-of-vscode-and-cursor-tasks-infection-chains.html): ASTRO tracks new Contagious Interview tactics: Vercel-masking URLs, NVIDIA-spoofing Gists, and Drive payload delivery. Detection queries and IOCs. (686 words) - [Company | Abstract](/content/company/index.html): Abstract is crafted by category creators and industry veterans known for redefining the cybersecurity landscape. Meet our team and learn our mission. (1,315 words) - [Critical Cisco Secure Firewall Flaws: CVE-2026-20079 & 20131 | Abstract](/content/blog/critical-cisco-vulnerabilities-cve-2026-20079-and-cve-2026-20131.html): Cisco disclosed two critical CVSS 10.0 flaws in Secure Firewall Management Center enabling unauthenticated RCE and root access. Systems and fixes. (1,047 words) - [Contagious Interview: Tracking the VS Code Tasks Vector | Abstract](/content/blog/contagious-interview-tracking-the-vs-code-tasks-infection-vector.html): An in-depth look at the DPRK-linked Contagious Interview campaign and how malicious VS Code tasks enable silent code execution and developer compromise. (1,536 words) - [Platform | Abstract](/content/platform/index.html): Composable SIEM platform that fits your architecture. Centralize security data with AI-enabled SecOps, detection fabric, and flexible integrations. (662 words) - [Abstract Raises $25M!](/content/raises-25m/index.html): Abstract is crafted by category creators and industry veterans known for redefining the cybersecurity landscape. Meet our team and learn our mission to rewirew security operations! (334 words) - [Abstract Welcomes OmegaBlack To Growing Roster of New Customers | Abstract](/content/blog/abstract-security-welcomes-omegablack-to-growing-roster-of-new-customers.html): Abstract, building the future of AI enabled security operations, today announced it has added threat intelligence expert OmegaBlack along with several new MSSP customers over the past two months. (513 words) - [Apache Tika Flaw: CVE-2025-66516 Enables XXE Injection | Abstract](/content/blog/critical-apache-tika-vulnerability-cve-2025-66516-enables-xxe-injection.html): A critical XXE flaw in Apache Tika (CVE-2025-66516) allows file reads, SSRF, and DoS via malicious PDFs. Affected versions, IoCs, and required patches. (1,163 words) - [C2 Corner: Follow the Money | Abstract](/content/blog/c2-corner-follow-the-money/index.html): Why most threat intelligence programs fail to influence decisions—and how mapping intelligence to revenue, dependencies, and exposure changes that. (1,214 words) - [Newsroom | Abstract](/content/newsroom/index.html): Latest press releases, company updates, and news from Abstract. Stay informed about our AI-powered security platform innovations. (640 words) - [Abstract Named to Rising in Cyber 2026 | Abstract](/content/blog/abstract-named-to-rising-in-cyber-2026-list-of-top-cybersecurity-startups.html): CISO-Voted List Recognizes the 30 Private Cybersecurity Companies Shaping Enterprise Security in the Age of AI (634 words) - [C2 Corner: Detection Doesn’t Fail First: Data Does | Abstract](/content/blog/c2-corner-detection-doesnt-fail-first-data-does/index.html): Detection doesn’t fail because teams lack skill. It fails when telemetry, data pipelines, and security engineering aren’t built for modern detection. (1,551 words) - [C2 Corner: The Tactician and the Strategist in Cyber Threat Intelligence | Abstract](/content/blog/c2-corner-the-tactician-and-the-strategist-in-cyber-threat-intelligence.html): In Cyber Threat Intel, AI is the Tactician. Humans are the Strategists. (1,170 words) - [SecOps, SIEM & Threat Detection — The Abstract Canvas Blog](/content/abstract-canvas/index.html): Explore Abstract's blog covering security operations, SIEM, data pipelines, threat detection, and composable security architecture insights. (423 words) - [Automating macOS Incident Response: DFIR-as-Code in Action Against AppleProcessHub | Abstract](/content/blog/automating-macos-incident-response-dfir-as-code-in-action-against-appleprocesshub.html): Learn how DFIR-as-Code transforms MacOS incident response by automating forensic processes, enhancing efficiency, and reducing human error. (1,215 words) - [Critical Ivanti EPMM Flaws: CVE-2026-1281 & 1340 | Abstract](/content/blog/critical-ivanti-epmm-vulnerabilities-cve-2026-1281-cve-2026-1340.html): CISA added two critical Ivanti EPMM flaws to the KEV catalog. How CVE-2026-1281 and CVE-2026-1340 are exploited, detected via Apache logs, and fixed. (774 words) - [C2 Corner: Security as a Product | Abstract](/content/blog/c2-corner-security-as-a-product/index.html): Security controls work better when teams want to use them. Learn how the "jobs to be done" framework and participatory design can reshape your security program. (1,158 words) - [10 Cybersecurity Focus Areas That Actually Move the Needle | Abstract](/content/blog/10-cybersecurity-focus-areas-that-actually-move-the-needle.html) (463 words) - [Composable SIEM Manifesto | Abstract](/content/manifesto/index.html): Abstract's vision for composable SIEM architecture: modular, AI-enabled security operations with flexible data collection, detection, and retention. (1,092 words) - [C2 Corner: Rebooting Security Operations: Mission First, People Always | Abstract](/content/blog/c2-corner-rebooting-security-operations-mission-first-people-always.html): Reboot SecOps with integrated tooling, realistic training, AI as a force multiplier, and people-first leadership built for a modern SOC. (1,108 words) - [C2 Corner: Climbing the Mountain Again and Again | Abstract](/content/blog/climbing-the-mountain-again-and-again/index.html): Cybersecurity careers are rarely linear. Explore how structure and perseverance help professionals navigate industry resets and long-term growth. (1,029 words) - [C2 Corner: Why I Mentor | Abstract](/content/blog/c2-corner-why-i-mentor/index.html): A reflection from Jim Routh on mentorship, leadership, and paying it forward—sharing lived experience from decades as a CISO and mentor in cybersecurity. (966 words) - [C2 Corner: Stop Automating the SOC. Start Automating Remediation. | Abstract](/content/blog/c2-corner-stop-automating-the-soc-start-automating-remediation.html): SOC automation often stops at detection while real fixes lag. Learn how to cut noise, align IT & security, and automate remediation to reduce risk. (758 words) - [90% of Your Splunk Data Helps Attackers, Not Analysts | Abstract](/content/blog/90-of-your-splunk-data-is-helping-attackers-not-analysts.html): Most Splunk environments hold 90%+ data that’s never read, driving cost and noise. Our free app analyzes your indexes to show what you can safely cut. (815 words) - [Partners | Abstract](/content/partners/index.html): Join Abstract's partner program. Unlock revenue with competitive margins, collaborate with cutting-edge cybersecurity, and grow with exclusive tools. (181 words) - [Abstract for Startups | Abstract](/content/for-startups/index.html): Your first SIEM shouldn't be your biggest headache. Abstract grows with you — easy to run, built-in detections, and a team that has your back. (453 words) - [AI Agents & Automated SOCs: End-to-End Workflows | Abstract](/content/blog/ai-agents-and-automated-socs-centering-end-to-end-workflows-for-real-impact.html): AI agents can streamline the SOC, but only on clean data and end-to-end workflows. How automation cuts noise and strengthens modern security operations. (743 words) - [AI-Enabled Secops - Platform | Abstract](/content/platform/ai-enabled-secops/index.html): AI-driven security operations with intelligent detection, behavioral analytics, and automated response. Reduce alert noise and accelerate investigations. (718 words) - [Abstract Joins Torq AMP Alliance for Agentic SecOps | Abstract](/content/blog/abstract-joins-torq-amp-alliance-program-to-accelerate-agentic-secops.html): Abstract joins the Torq AMP Alliance to accelerate agentic SecOps by combining pipeline-first detection engineering with AI-driven SOC automation. (541 words) - [Abstract Named in SACR’s 2025 SDPP Market Guide: The Rise of Security Data Pipelines | Abstract](/content/blog/2025-security-data-pipeline-platforms-market-guide/index.html) (643 words) - [Abstract + Amazon Security Lake + OCSF = Upgraded Security Data Management! | Abstract](/content/blog/abstract-security-amazon-security-lake-ocsf-upgraded-security-data-management.html) (584 words) - [C2 Corner: Achieving Fortune 50 Security With a SMB Budget | Abstract](/content/blog/c2-corner-achieving-fortune-50-security-with-a-smb-budget.html) (739 words) - [Detections - Platform | Abstract](/content/platform/detections/index.html): Modern detection models for security operations: in-stream, historical, and decoupled detection. Portable logic that scales independently from storage. (355 words) - [Retention - Abstract Composable SIEM](/content/platform/retention/index.html): Intelligent tiered retention strategies for security data. Right data, right tier, right cost—optimize storage for real-time detection and compliance. (451 words) - [Abstract Partners with Netskope on Real-Time Security Data | Abstract](/content/blog/abstract-security-partners-with-netskope-to-turn-security-data-into-real-time-decisions.html): Abstract partners with Netskope to bring detection into the data stream, giving joint customers real-time decisions on security data in motion. (567 words) - [Breaking the SIEM Mold: Security Data Ops at Black Hat | Abstract](/content/blog/breaking-the-siem-mold-security-data-operations-whats-next-live-at-black-hat.html) (25 words) - [See Your Splunk Data Reduction Before Touching a Pipeline](/content/abstract-splunk-data-reduction-calculator-app/index.html): Most Splunk environments hold 90%+ data that's never read. Install our app to see volume by index, optimization opportunities, and projected savings. (193 words) - [Abstract Intel Gallery](/content/abstract-intel-gallery/index.html): Operationalize threat intelligence with Abstract Intel Gallery. Enrich events with real-time IOCs, correlate adversary infrastructure, and enhance detection. (146 words) - [Abstract and Chris Camacho: Threat intelligence - the next evolution | Abstract](/content/blog/abstract-and-chris-camacho-threat-intelligence-the-next-evolution.html) (222 words) - [Events | Abstract](/content/events/index.html): Join Abstract at our events! Discover upcoming security operations conferences, webinars, and industry gatherings. Connect with our team. (74 words) - [Abstract Partners with Analytica42 on Google SecOps | Abstract](/content/blog/abstract-security-joins-forces-with-analytica42-to-supercharge-integration-delivery-to-google-secops-and-more.html) (25 words) - [Abstract Technical Product Brief](/content/abstract-technical-product-brief/index.html): Get the technical product brief on Abstract's composable SIEM: data collection, streaming detection, retention, and AI SecOps in one platform. (124 words) - [Modern Day SIEM Migration Strategy | Abstract](/content/modern-day-siem-migration-strategy/index.html): Collaborative whitepaper by Abstract and Analytica42 on modern SIEM migration strategies. Make your SIEM part of the solution, not the challenge. (108 words) - [Applied Data Strategy Ebook | Abstract](/content/applied-security-data-strategy-ebook/index.html): A step-by-step guide to building a robust security data strategy, informed by industry experts. Download the free ebook today. (15,480 words) - [Priced to Move: The Underground Markets of Modern Cyberattacks](/content/reports/priced-to-move/index.html): ASTRO Research Report: The Underground Markets of Modern Cyberattacks (7,466 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives