Somewhere right now, malware running on a compromised machine is checking in with an AI model, asking it for a new version of itself. Google's Threat Intelligence Group caught this happening in late 2025. The malware, nicknamed PROMPTFLUX, does this every hour it runs, and each version comes back looking different from the last. By the time a security tool learns to recognize it, it has already changed shape again.
This isn't a rare glitch or a lab experiment. It's a preview of how a growing share of attacks work today and why legacy SIEM platforms built to detect known patterns are starting to fall behind.
Legacy security tools were built to detect, not to adapt
A SIEM is a system that collects logs from every part of a company's network and looks for signs of an attack. For years, it worked like a security guard with a very long memory. The guard learns what a break-in looks like - a certain kind of file, a pattern of behavior, a code signature, and watches for anything that matches.
This works well as long as attackers keep doing things the same way. And for a long time, they did. Building new malware took real time and skill, so attackers reused the same code, phishing templates and tricks. A security tool that remembered those techniques could catch most of what came its way.
AI broke that assumption.
Attackers can now build something new every single time
IBM's 2026 X-Force Threat Intelligence Index found that attackers are using AI to conduct research, scan for weaknesses and rewrite phishing emails and malware on the fly. Rather than inventing entirely new techniques, they're using AI to speed up reconnaissance, discover vulnerabilities faster and craft more convincing phishing campaigns.
For example, the report found that the number of active ransomware groups grew by 49% in a single year, largely driven by smaller, short-lived operators entering the space. The barrier to entry has dropped: these groups reuse leaked tools, follow established playbooks and lean on AI to automate the parts of an attack that used to require skill, like researching a target, writing a convincing lure or adjusting course when something doesn't work.
The result is that launching an attack takes less effort than it once did, and the attacks a company sees this month can look nothing like the ones it saw last month, even when they're coming from copies of the same basic playbook.
Here's the simplest way to put it: A security guard who memorizes faces cannot stop a burglar who changes their face every time they show up. That's the situation legacy SIEM is in today.
More alerts, less time and the same old approach
The problem isn't just that attacks look new. It's that there are more of them, and each one competes for an analyst's attention.
When a security team has to manually check thousands of alerts a day, most of which are false alarms, two things happen.
- Real threats take longer to get noticed.
- Tired analysts start skipping over things that look routine, even when they aren't.
IBM's 2025 Cost of a Data Breach report found that companies take an average of 241 days to spot and shut down a breach. While this number is on a downward trend, it's still about 8 months before anyone catches an attacker sitting inside a network.
There is some good news buried in the same report. Companies that use AI and automation in their security operations cut response time by 80 days and save close to $1.9 million per breach, compared to companies that don't. The tools that use AI to fight AI are already showing a real, measurable difference.
A different question changes everything
Older SIEM tools ask one question over and over: Does this match something bad I've seen before?
A newer style of SIEM, built from the ground up with AI, asks a different question: Does this look normal for this person, this device, this network?
That single change matters more than it sounds like it should. Here's why.
An attacker can rewrite their malware's code every hour. What's much harder to change is what the malware needs to do once it's inside a network. It still has to look through files, find valuable data, move from one computer to another and eventually send something out. Those actions leave a trail, even when the code behind them looks completely new each time.
| Old rule-based SIEM | AI-native SIEM | |
| What it looks for | A match to a known bad pattern. | Behavior that doesn't fit the normal pattern for that user or device. |
| How it handles new attacks | Struggles until someone writes a new rule. | Can flag it immediately as unusual, even if it's never been seen before. |
| How it handles alert volume | Sends every match straight to an analyst. | Groups related signals together and ranks them by how serious they look. |
| What it needs from a human | Constant rule updates as threats change. | Time to teach it what "normal" looks like for that specific company. |
This behavior-first approach is built around a few core ideas:
- It learns what normal looks like. Instead of relying only on a list of known threats, it builds a picture of how each user, device and part of the network usually behaves. Anything that breaks that pattern gets flagged, even if nobody has ever seen that exact attack before.
- It connects small things. A login at an odd hour on its own isn't much. Neither is a slightly unusual file transfer. But when the same system links those two things into a single flagged case, an analyst can see the full picture in seconds rather than missing it across two separate low-priority alerts.
- It needs fewer new rules to stay useful. A team doesn't have to keep writing detection rules for malware that's already changed shape by the time the rule ships. The system adjusts on its own as it learns more about the environment.
What this means for the people doing the work
This shift changes what a typical day looks like for a security analyst. Less time is spent asking, "Have I seen this exact thing before?" and more time is spent asking, "Does this deserve a closer look, and what else does it connect to?"
That's a more useful use of a skilled analyst's time, but it does mean trusting a system that flags items based on behavior rather than a clean match against a known threat.
As AI continues to reshape the threat landscape, the focus is increasingly on identifying meaningful signals sooner and giving analysts the context they need to investigate with confidence.
For a closer look at how this shift is changing security operations and what it means for modern detection strategies, explore our eBook, Finding signal in the noise.
Author Bio: Austin O'Saben is a Product Marketing Manager at Kaseya focused on cybersecurity solutions for MSPs and small to mid-sized businesses. He helps translate complex security technologies, such as EDR, MDR, and cloud security into practical strategies that help IT providers better protect their customers. Austin works closely with product and security teams to educate the MSP community on emerging threats, best practices, and modern threat detection.
Austin O'Saben — Product Marketing Manager at Kaseya https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiihbE5qGKjcXudrOXSdY4lj8_xbj6ZVpP53pvhPmkG5dv_dqTbn-0h3-SWsWvnf2yJVpT3RVbA8coIYAS5vSRmnW235vr9lyuIDZRWXxU0aAYWaf8xAK1ybHGyhQh8cddYi-dMIIsGdEz8_hlmm_5xWZ8VpeuDPx0xcB2LAXaZCDMswR1c58csRoG3YyY/s1700-e365/Austin.png


