An Intellyx Brief from Black Hat 2026
Gravwell was at Black Hat 2026 with a security data platform and structure-on-read data lake designed to augment or replace legacy SIEMs. Gravwell ingests and retains full-fidelity security telemetry in its original form, then lets analysts apply structure at query time using a piped query language rather than requiring data to be normalized to a predefined schema before ingestion. Its APIs and integrations also allow external security and AI tools to query and interact with that data, providing a flexible, cost-efficient foundation for security analytics at scale.
Their platform has openly available documentation and a REST API, including a direct-search API that allows external systems to query Gravwell. of AI security tooling can use it as a source of truth and insights. Customers don’t have to reshape the underlying data to fit a predefined model; they can retain the raw data and structure, extract, correlate, or enrich it differently depending on the use case. The goal here is to customize the data to fit the customer’s security platforms and make telemetry easier to search and more affordable to utilize at scale with a wide variety of tooling.
Of course, no modern company would appear at this show without their own AI, and Gravwell’s is more pragmatic than some others, and it’s simple conversational presence really there to help enhance the analyst’s understanding of what is detectable and correlation of large data sets, rather than claiming to “autonomously” burn through tokens for functions the automated platform already does quicker and cheaper with its machine learning and automation.

Hot take from the show: “You go around an event like Black Hat and you’ll see a bunch of vendors talking about how you can save on your SIEM costs by reducing the amount of logs you send, and I think that’s fundamentally the wrong approach,” says Gravwell CEO & co-founder Corey Thuen. “As somebody who’s cut my teeth on the offensive side of security, I used to find zero-days, and sometimes it’s just one log entry that tells you how the attack got in, and you don’t know which ones are important until you see them all. The whole idea of not seeing 100 percent of our logs, or only ingesting a few of them to save expenses is BS, because the technology to read them all is already there.”
Copyright ©2026 Intellyx B.V. Intellyx is the change agent analyst firm focused on customer-driven, technology-empowered enterprise transformation. Our thought leadership distills insights across the rapidly evolving enterprise IT landscape, and our advisory helps you and your customers see through the hype and get beyond the fear of technology disruption to take action and realize value through change. At the time of writing, Gravwell is not an Intellyx customer. No AI was used to write this article. To be considered for a Brain Candy article or have us visit you at an event, email us at pr@intellyx.com.


