# SecOps Unpacked > Welcome to SecOps Unpacked, a space dedicated to breaking down the realities of modern Security Operations. Here, I focus on practical insights across detection engineering, automation, incident response, and the shift toward AI-powered SOCs. You’ll find frameworks, playbooks, research, and tools that help security teams operate with purpose, whether you’re writing rules, scaling a detection program, or exploring how AI fits into your workflows. If your goal is to make your SOC faster, smarter, and built on what actually works, you’ll feel at home here. Trusted by practitioners, engineers, leaders, and founders who want clarity in SecOps. Join other security practitioners who are already learning, building, and automating with SecOps Unpacked. This file provides information about SecOps Unpacked to help large language models understand and reference this publication's content. ## Posts - [The sad state of SOC workload reports, and how YOU (yes, YOU) can help](https://www.cybersec-automation.com/p/the-sad-state-of-soc-workload-reports) - [A Metric Ton of Problems: Why SOC Metrics Fail Us](https://www.cybersec-automation.com/p/a-metric-ton-of-problems-why-soc-metrics-fail-us): Thoughts on SOC metrics after a career in SecOps - [Pure Play AI SOC or Add-On: Does It Even Matter Anymore?](https://www.cybersec-automation.com/p/pure-play-ai-soc-or-add-on): The SecOps Shift Map one year later - [Introducing ASEF](https://www.cybersec-automation.com/p/asef-ai-soc-evaluation-framework): The AI SOC Evaluation Framework - [SIEM deployment unpacked](https://www.cybersec-automation.com/p/siem-deployment-unpacked): Lessons from 30+ SIEM onboarding projects - [Agentic Threat Hunting](https://www.cybersec-automation.com/p/agentic-threat-hunting): Why It's Harder Than It Looks - [Agent Builders for SecOps](https://www.cybersec-automation.com/p/agent-builders-for-secops): Not All Agent Builders Are the Same: It Comes Down to the Harness - [Building the AI for SecOps Vendor Landscape](https://www.cybersec-automation.com/p/building-the-ai-for-secops-vendor-landscape) - [SecOps Agents and AI SOC: SIEM vs Standalone vs SOAR](https://www.cybersec-automation.com/p/secops-agents-and-ai-soc-siem-vs-standalone-vs-soar) - [We Automated the Easy Part. Now Fix Your Detections.](https://www.cybersec-automation.com/p/we-automated-the-easy-part-now-fix-your-detections) - [Why AI Won't Replace the Human Who Owns the Risk in Security Operations](https://www.cybersec-automation.com/p/why-ai-won-t-replace-the-human-who-owns-the-risk-in-security-operations): The Accountability Anchor (Part 2) - [RSAC 2026: Predictions Validated, AI SOC Is Now a Feature, and the Adoption Mess Continues](https://www.cybersec-automation.com/p/rsac-2026-secops-summery) - [The Last Human in the Room](https://www.cybersec-automation.com/p/the-last-human-in-the-room): Why AI Needs Your Signature to Exist (Part 1) - [Why Faster Detection Created a Bigger Problem](https://www.cybersec-automation.com/p/why-faster-detection-created-a-bigger-problem): Agentic SecOps 2025 trends and 2026 predictions - [We built a framework to score AI SOC response capabilities](https://www.cybersec-automation.com/p/ai-response-maturity-model): Introducing AI Response Maturity Model [ARMM] - [The Fear of Not Doing Enough](https://www.cybersec-automation.com/p/the-fear-of-not-doing-enough): Why Security Teams Keep Generating Work They Can't Handle - [The SOC Autonomy Trap](https://www.cybersec-automation.com/p/the-soc-autonomy-trap): Why 'Fully Autonomous SOC' is a Design Mistake - [Understanding Semantic Layers in Security Operations](https://www.cybersec-automation.com/p/understanding-semantic-layers-in-security-operations) - [Can AI Drive Response?](https://www.cybersec-automation.com/p/can-ai-drive-response): Why the Right Side Still Needs Forensics and Automation - [SOC Reality Check](https://www.cybersec-automation.com/p/soc-reality-check): Why Detection Is Only Half the Battle - [From PDF Playbooks to Machine-Executable Logic ](https://www.cybersec-automation.com/p/from-pdf-playbooks-to-machine-executable-logic) - [How AI Transforms Detection Engineering](https://www.cybersec-automation.com/p/how-ai-transforms-detection-engineering): From Narrow Precision to Broad Coverage - [Rebranding Announcement](https://www.cybersec-automation.com/p/rebranding-announcement): CyberSec Automation is now SecOps Unpacked - [AI SOC Core Component](https://www.cybersec-automation.com/p/ai-soc-core-component) - [AI SOCs You Can Actually Control and Customize](https://www.cybersec-automation.com/p/ai-socs-you-can-actually-control-and-customize) - [AI SOC Shift Left and Shift Right!](https://www.cybersec-automation.com/p/ai-soc-shift-left-and-shift-right): Introducing the AI SOC Shift Map - [Is Your AI SOC Optimistic or Pessimistic? ](https://www.cybersec-automation.com/p/is-your-ai-soc-optimistic-or-pessimistic-14264e1a9be330ff): Memory, Bias, and Drift in Real SOCs - [The Monthly Debrief: CyberSec Automation Podcast Roundup](https://www.cybersec-automation.com/p/the-monthly-debrief-cybersec-automation-podcast-roundup-ed181766ffb4c951): Jul-Aug / 25 - [Why SOC Analysts Ignore Your Playbooks](https://www.cybersec-automation.com/p/why-soc-analysts-ignore-your-playbooks-72e6ec0f57d03b15): Are Your SOC Playbooks Broken? - [Stop Chasing the Single Pane of Glass](https://www.cybersec-automation.com/p/stop-chasing-the-single-pane-of-glass-1555d42f940d3642): Start Building It - [Automate Smarter, Not Louder: Using Interactive AI Feedback Loops](https://www.cybersec-automation.com/p/automate-smarter-not-louder-using-interactive-ai-feedback-loops): DSAEM Loop (Detect > SOP > Automate > Emulate > Measure - [Will MCP, A2A and AG-UI help us the Single pane of glass for SecOps](https://www.cybersec-automation.com/p/will-mcp-a2a-and-ag-ui-help-us-the-single-pane-of-glass-for-secops-c12d22215aa28244) - [Measuring ROI of AI agents in security operations](https://www.cybersec-automation.com/p/measuring-roi-of-ai-agents-in-security-operations-9a67fdab64192ed0): Introducing PICERL Index