Inside the Agentic SOC at Black Hat USA 2026



Most of what looks like an attack at Black Hat USA is a training exercise. Finding the traffic that isn’t is the entire job of the SOC inside the NOC — and this year, we ran an AI Triage Agent alongside our analysts to see what it would take to trust it with that call.

In this video, Jessica walks through three things that had to be true at BlackHat before an AI agent could get anywhere near triaging a real security finding at the most hostile network in cybersecurity — and what happens when any one of them is missing.

What you’ll learn:
– Why the exact same alert can mean a training exercise or a live intrusion — and what actually tells them apart
– The three things that have to be true before an AI agent can be trusted with SOC triage: evidence, context, and a real handoff
– Why “environment quality” matters as much as data quality, and the blind spot most AI agents have by default
– A real finding from Black Hat USA 2026: a phishing-classified JavaScript file the agent flagged with its own confidence level attached — and where it told us it wasn’t sure
– What we built that mattered more than any tuning we did on the model

Chapters:
0:42 – 11 years at Black Hat, and what’s new this year
1:36 – Why the same alert, with the same data, has a different answer here
2:27 – AI Truth #1: Evidence
4:16 – AI Truth #2: Context
5:44 – AI Truth #3: The Handoff
6:16 – What Black Hat proved about Agentic SOC
7:18 – What’s breaking in your SOC?

Sources & further reading:
– Black Hat USA 2026 — Network Operations Center: https://blogs.cisco.com/security/bhusa-2026-soc
– Security for the Agentic Era: The Cisco + Splunk Guide to Black Hat 2026: https://www.splunk.com/en_us/blog/security/cisco-splunk-guide-to-black-hat-2026.html

💬 Which of the three is breaking for you — the evidence, the context, or the handoff? Drop it in the comments.

🔔 Subscribe to Cybersecurity Explored for more

#BlackHat #SecurityOperations #AgenticAI #CybersecurityExplored

source

Author: Cybersecurity Explored

Leave a Reply