Editorial illustration for Former Cybersecurity Founder Applies Threat Analysis to AI Data
Former Cybersecurity Founder Applies Threat Analysis to...
Shapor Naghibzadeh spent 2009 in a Google war room, trying to explain to his own company what Chinese-backed hackers had done inside its servers during Operation Aurora. That work taught him something that stuck: verified knowledge takes forever to assemble by hand, and most organizations never get there. He spent six years building tools at Google to help security analysts sort through messy data faster, then co-founded Chronicle in 2016 out of Google's X Labs to sell that same capability to other companies.
Now he's betting that large language models can do for general data analysis what those cybersecurity tools did for threat hunting, and do it much faster. His new startup, QueryStory, came out of stealth today with Naghibzadeh as CEO. He's joined by CTO Stanley Yang, a former Google colleague who was lead engineer at EvolutionIQ, and CPO David Glusic, who spent years at Accenture.
The pitch centers on how investigators actually work: asking question after question of a dataset until a pattern emerges, then stitching those answers into something coherent. Naghibzadeh thinks that process, once slow and expert-driven, can now run at the speed of an LLM query.
“What we’re doing is bridging that trust gap for AI to give enterprises answers that they can act on,” Naghibzadeh said. “Instead of, you know, like renting human judgment and armies of forward deployed engineers, we productized that.”
Why this matters
QueryStory's pitch rests on a real problem: LLMs are fluent enough to sound authoritative while being wrong, and most analytics tools built on top of them don't have a way to catch that. Naghibzadeh's background gives the idea some credibility, tracing Operation Aurora through Google's networks in 2009 is a different discipline than prompt engineering, but the instinct to treat "verified knowledge" as a discrete, buildable layer is the same one that made incident response work. Whether that translates to a product that actually catches hallucinations in data analysis, rather than just reassuring users with confident-sounding citations, is the open question.
For founders building on top of LLMs, the lesson here isn't the specific company but the framing: security threat-hunting and AI output verification are starting to look like the same job, just applied to different adversaries. Worth watching whether QueryStory can show, with real customer data, that its verification layer catches errors a base LLM would have missed, and not just that it says it can.
Further Reading
- A Lifecycle and Application-Stack Survey of Large Language Model Security - arXiv
- LLM Security: Vulnerabilities, Attacks, Defenses, and Emerging Risks - arXiv
- A Survey on Data Security in Large Language Models - arXiv
- From Prompt Injections to Protocol Exploits: Threats in LLM Agent Ecosystems - arXiv
- Generative AI for cyber threat intelligence: applications and challenges - Springer