❌

Reading view

Admin in the Loop: Firewalls and the Agentic SOC

Discover how Cisco Secure Firewall and Cloud Control stream structured Snort 3 and EVE telemetry into Splunk ES to power the .conf26 Agentic SOC pipeline.
  •  

The Zero-Day Blind Spot: Why Your Agentic SOC needs Retrospective Packet Replay

Learn how the .conf26 Agentic SOC paired Endace full PCAP with Cisco Secure Firewall and Talos rules to retrospectively replay wire data against zero-days.
  •  

Splunk .conf26: Tracking the Triage Agent in the Agentic SOC

How Cisco used Splunk as the SOC data platform at .conf26 to unify security telemetry and track the Splunk AI Triage Agent with human-validated workflows.
  •  

Thrown into the SOC: A Black Hat First-Timer’s Story

A Black Hat SOC analyst shares how agentic workflows, Splunk ES, packet evidence, and human mentorship accelerated triage & investigation in the NOC/SOC.
  •  

SharpHound Recon Attack – How AI enhanced the threat hunt

During the Cisco Live Americas 2026 Agentic SOC, we discovered and investigated suspicious LDAP activity both manually and with the assistance of AI. This helped us understand how the Agentic SOC can improve the threat-hunting process.
  •  
  •  
  •  

Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia

At Black Hat Asia, we tested a private AI SOC workflow built with Ollama, NVIDIA GPU acceleration, Open WebUI, OpenClaw, DefenseClaw, Cisco AI Defense and MCP integrations, with Splunk audit visibility.
  •  
❌