
Security Researchers: Digital Fighters Series
Vega: “An attacker only needs one vulnerability, defending is an endless chase”
Eran Ayalon, Head of Research at Vega Security, describes how knowledge sharing and collaboration make Israel the spearhead of the global cyber world, as part of CTech’s Security Researchers series.
“An attacker only needs one vulnerability to get in, while defending is an endless chase, and offensive AI tools are widening that gap fast,” explains Eran Ayalon, Head of Research at cyber startup Vega Security. “What I most want to crack is a new generation of AI-powered defenses that can finally keep up.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
“As a sports fan, I always compare my team to a sports team,” Ayalon continues. He began his career in an Israeli Air Force cyber unit, and joined Vega after serving as Director of Security Research at Cybereason. “I am all for bringing in the best talent there is, but research is a special profession, full of very specific strengths,” he explains. “At the end of the day we are defenders, and the goal is to keep pace so that as attackers get more sophisticated, the defensive side does too.”
You can read the entire interview below.
ID Card
Company name: Vega Security
Founders: Shay Sandler (CEO), Eli Rozen (CTO)
Year of founding: 2024
Current number of employees: 150
Company Description:
Vega Security is building an agentic cyber defense platform; our answer to the post-SIEM era. Built on a Security Analytics Mesh, Vega connects to security data wherever it already lives, without requiring migration or centralization, and provides a unified layer for detection, investigation, hunting, and triage. By putting AI to work as an active part of security operations, Vega helps teams investigate threats faster, improve detection and visibility, and overcome challenges practitioners have learned to live with: fragmented data, expensive migrations, noisy detections, and too much manual work.
About Vega's Security Research Team:
The security research group is really the beating heart of the platform. In my view, a security research team, especially inside a company that builds a security product, is one of the most important functions there is. We are people who live this field, and most of us came from the other side of the fence, as the people who actually used defensive products day-to-day. That makes it easy for us to connect to what customers really need. We know where it hurts for them, and translating that into a product that makes their life easier and keeps their environment safe is a fascinating challenge, and honestly a huge amount of fun.
As a sports fan, I always compare my team to a sports team. I am all for bringing in the best talent there is, but research is a special profession, full of very specific strengths. There is the one who is great at cloud, the one who is strong at code and reverse engineering, and the one who lives and breathes threat intelligence and building products from scratch. So the goal is less about putting several stars in the same position and more about bringing in top talent whose strengths cover all of these different areas. To me, that is the real craft, assembling that range so that between us we cover as much of the lineup as possible.
What is your background in cyber, and what led you to specialize in security research?
I started my career in the Israeli Air Force, in a cyber security unit responsible for monitoring and responding to cyber events. In that work, I investigated a wide range of cyber incidents while maintaining the defensive products that helped us detect and respond. What always pulled me in was the "how do you detect this attack" part, and how you do that inside a product that works at such a large scale. I found myself drawn to the product side of it, and I always wanted to be part of a company that builds the products that help SOC teams stay protected.
After that I joined Cybereason in the security research group. I came in as a researcher and got to work across a whole range of products: EDR, EPP, CWP, XDR and more. Over time I ended up as the Director of the security research group, which was a fascinating role where I really got to drive the security strategy across the platform's products and work with the strongest researchers I have known.
One piece of research I am most proud of is the work I did in the world of container escape. At the time, organizations were starting to use containers more and more across their operations, which opened up an entirely new attack surface that had barely been discussed until then. My group and I found a lot of attack techniques there that had never been seen before, and we felt we had hit on a hot topic: we got countless responses from the industry, invitations to conferences, contributions to MITRE, and more.
Coming to Vega after more than a decade in the field, and getting the stage to translate all of that knowledge and experience together with such a strong group, in the evolving world of AI, is a huge gift, and I am sure we will keep building amazing things, and that this is only the beginning.
What does your security research team look like in action?
Our day-to-day is simple on paper: keep asking how we make the product better and keep our customers protected from the threats that are most relevant to them. That means living the world of cyber and technology, and looking at every new vulnerability or new technology that comes out through one question: how could this threaten our customers, and then putting relevant protection in place immediately.
We choose research topics through an internal prioritization of which threats are most relevant to our customers, combined with listening to what is happening in the field. We are always glad to help customers with the specific problems bothering them and give them the treatment they need. Right now the AI space in particular is picking up speed, because the daily operation of organizations leans more and more on AI tools, and as a direct result the attack surface around that area is growing exponentially. Our goal is to have protection ready before attackers even understand how to exploit this new world.
How does the research team influence your company at large?
The group's influence across the company is very significant, in my view. As Vega's security people, we are the ones who best know how to translate new threats and new technologies into better protection for our customers. Part of our job is to bring that knowledge into every relevant conversation in the company, from strategic leadership discussions all the way down to close work with product and developers who are building a specific feature and need the security angle. We own the product's content and the security quality of its features, and we make sure the product keeps advancing in step with the threats our customers face, so they get the best protection possible.
What has been your team’s most significant security discovery to date?
The most significant thing the group has done, in my view, is developing the concept and the science behind "detection skills". To me this is far more than finding a vulnerability or writing one detection or another. It is the realization that the entire way detection products, and the industry, have worked is no longer relevant. As someone who grew up in SOC and wrote detections myself, I know how hard it is to maintain detections, keep them updated, tune them, and pass knowledge between different analysts from one shift to the next. Detection skills change that: a detection is no longer just the query, it is a whole pipeline that includes triage, investigation, and tuning.
Take behavioral detections as an example. They are very strong, but because they fire on statistical anomalies, they often flag legitimate activity too. A good case is impossible travel, a technique that alerts when the same user is active from two different geographic locations. It catches a lot of real incidents, but it also comes with plenty of legitimate behavior that is hard to exclude at the query level, like VPN use or shared infrastructure. In the past, when an alert like that reached an analyst, these were probably the first questions they asked themselves: is this a VPN? Is there some known IT activity behind it? Instead of running that same inevitable loop every time and chasing an endless exclusion list, the analyst can now define it as part of the detection itself: here is the query, but before you raise an alert, check these things, and if that is the case, do not even alert me on it.
From my experience, a lot of what SOC teams do repeats itself, and it is time to make their lives easier by letting them write whole detection pipelines and use the right skills to translate their own knowledge into that pipeline. I am incredibly proud of this project, and I see it as an important first cornerstone in adapting the world of SecOps to the AI era and making our customers' lives easier.
Who or what is your 'Moby Dick'?
My “Moby Dick” is not a single vulnerability, it is the defender's problem itself: how we keep our defenses continuously renewing and staying ahead of the pace of AI. An attacker only needs one vulnerability to get in, while defending is an endless chase, and offensive AI tools are widening that gap fast. What I most want to crack is a new generation of AI-powered defenses that can finally keep up.
How would you characterize the competition between research teams today?
Honestly, I do not really see it as competition between the research teams themselves. From my experience it is actually the opposite, there are wonderful collaborations between researchers. It is more of a shared push by a lot of smart people with a common goal, and that kind of collaboration only moves everyone forward and raises the level of the researchers and of the whole industry, certainly here in Israel. Globally, I think it is exactly that collaboration and knowledge sharing coming out of the Israeli industry that makes us, as a country, the spearhead of the cyber world. As long as those connections keep growing and getting stronger, I do not see another country coming close to us in its knowledge or its community.
That is also why I think it is very hard, almost impossible, to measure teams against each other by dry numbers like conference appearances or CTF rankings. Every team has its own uniqueness, its own expertise, and its own goals, and it changes depending on whether you are a team whose purpose is to build a product, or a team whose entire essence is to research vulnerabilities, find new things, and publish PR and blogs.
In my view, a research team is ultimately measured on two things. The first is how significant it is and how much it contributes to the success of the organization it is part of, whether that is putting the company on the map through blogs, improving the product, or making sure customers are happy. The second is whether we, as a team, are making the world a safer place, and this is where sharing knowledge with the industry comes in, through meetups, blogs and conferences. At the end of the day we are defenders, and the goal is to keep pace so that as attackers get more sophisticated, the defensive side does too.
On a personal level, something I care about a lot within the team is seeing the people themselves grow and improve. I follow a lot of researchers in the industry, and it is a pleasure to watch, over the years, the incredible discoveries of people who keep developing and growing. I really enjoy seeing people progress, and I think that as a research leader it is a must to see your people on a constant upward curve.
What is your take on the future of the human security researcher?
There is no denying AI, and in security research, just like in every other tech role, integrating it into your day to day is now a must. From my own experience it is genuinely useful: it helps you write code, learn a new topic, or build tools quickly. But in terms of pure security knowledge, and the real sparks of insight, I very much doubt it can replace researchers.
A researcher's work is not black and white. It involves endless non-trivial reasoning, a lot of creativity, and out-of-the-box thinking, and from what I see, at least at this stage, AI is still very far from doing that work at the same quality. The real discoveries usually come from a researcher's gut feeling that something here just feels strange, and then knowing where to dig deeper. There is not always data to back it up, it is simply a researcher's instinct, a mix of knowledge and experience brought into the work, and that is the part I think will be very hard for AI to replace.
This matters even more when you look at the attackers' side. AI makes their capabilities far easier and opens an almost endless attack surface that, unfortunately, we have only seen a small part of so far. That is exactly why I do not see the future as AI instead of researchers, but as experienced human minds combined with AI. Researchers need to make AI an inseparable part of the work, but without a strong researcher conducting the operation behind a set of agents, it simply will not reach a high enough quality.














