A Conversation With Cliff Crosland @unsupervised-learning
A Conversation With Cliff Crosland  @unsupervised-learning
Uploaded June 2026 | Updated September 2026, 2 weeks ago
Check out Scanner here! - https://ul.live/scanner_yt

Sat down with Cliff to talk about how Scanner is changing the game for security log analysis by making massive object storage searches insanely fast. We dive into how their platform acts as a high-speed data substrate that pairs perfectly with AI agents to automate threat hunting, alert triage, and detection engineering. Honestly, this is one of the most exciting pieces of tech I've seen in years, and I'm already figuring out how to build my own skills on top of it!

What We Talk About:

Ditching the Clusters for S3: How legacy, cluster-based SIEMs break down under modern data volumes, and why Scanner leans entirely into cheap, scalable S3 object storage while eliminating the usual latency issues.

The Magic of Serverless & Schema-less Data: How Scanner bypasses tedious data engineering by natively ingesting raw, messy data, relying on a completely ephemeral compute engine that spins up from nothing only when you ask a question.

Petabyte-Scale Threat Hunting in Seconds: Moving beyond basic detection and response to search across years of historical data, completing deep-dive threat hunts in mere seconds instead of waiting hours.

Teaming Up with AI Agents: How to use autonomous AI tools to headless-query the data, auto-triage false positives, find visibility gaps, and generate shareable HTML reports so you aren't doing the heavy lifting at 3 a.m..

A Foundational Data Substrate: Why Scanner is much bigger than just a search tool; it's a foundational data layer designed to feed massive, lightning-fast context to your entire security program and custom tools.

00:00 - Introductions.
00:15 - What is the main problem Scanner is solving.
01:05 - What is the "magic" that allows the platform to look at that much data so incredibly fast?.
05:51 - What does the onboarding process look like, and do users need to get their data into S3?.
07:46 - How the platform handles caching for queries that need to be run every minute.
09:20 - Discussing use cases beyond standard detection and response.
11:11 - Hitting the limits of physics: How much data can it actually cover, and how fast can it go?.
13:18 - How Scanner acts as a partner for AI, and what the actual product interface looks like.
18:13 - The "Aha!" moment: Realizing Scanner operates as a foundational data plane or substrate.
20:23 - What types of data and file formats the system can ingest for schema-less analysis.
22:34 - Using an AI layer to automatically write and expand your security detection program.
28:36 - Having AI analyze your company's context and crown jewels to completely automate your defenses.
35:28 - Upcoming conference announcements (BSides, Black Hat) and where listeners can try out Scanner.

Subscribe to the newsletter at:
danielmiessler.com/subscribe

Join the UL community at:
danielmiessler.com/upgrade

Follow on X:
https://x.com/danielmiessler

Follow on LinkedIn:
linkedin.com/in/danielmiessler
A Conversation With Cliff CroslandAmazons New Alexa Powered By Claude AIThinking of Building a Startup? Use This Framework FirstDanger! Ai-Powered Spear Phishing is here!A Conversation With Arshan DabirsiaghiMy AI upgrades itself. Heres how.Chinese Drone Company Removed Geofencing System from US DronesChina Is Developing AI FAST0.5% Of Your Brain Is PlasticStartup Artisan Says to Stop Hiring HumansPharma Stock Have Crashed!A Conversation with Jason Haddix from Flare
Unsupervised Learning |

A Conversation With Cliff Crosland

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER