Black Hat USA 2026: Proving the Splunk ES Foundation for the Agentic SOC

Security Jessica Oppenheimer

Black Hat USA is one of the most valuable security operations environments in the world because it is not a lab. It is a live, high-noise, high-consequence network where security research, training traffic, attendee devices, partner infrastructure, sponsor demos, public Wi-Fi, and operational services all exist at once. Activity that would trigger an urgent response in an enterprise may be expected in a training room. At the same time, real threats can still appear in the same telemetry.

That tension is exactly why Black Hat is such a powerful proving ground for the next generation of security operations. At Black Hat USA 2026, the Cisco and Splunk team used the event not only to help protect the network, but also to validate how Splunk Enterprise Security (ES) can become the operational center of gravity for the Agentic SOC.

Cisco returned as the Official Security Cloud Provider and the longest-standing partner in the Black Hat NOC/SOC. The NOC leadership enabled Cisco and other partners to introduce additional pre-approved software and hardware solutions, enhancing our internal efficiency and expanding our visibility capabilities; however, Cisco is not the official provider for Extended Detection & Response, Security Event and Incident Management, Firewall, Network Detection & Response or Collaboration.

bhusa-1.jpg

Working alongside Black Hat leadership and technology partners including Palo Alto Networks, Arista, Corelight, Jamf, and Lumen, the team focused on a practical mission: turning live event telemetry into evidence, detections, findings, AI-assisted triage, and reusable content, to improve the SOC deployments at Cisco GSX and Splunk .conf26, where Splunk ES served as the analyst workspace for the led Agentic SOC.

Building the Evidence Layer in Splunk

The first requirement for an Agentic SOC is not the agent. It is the evidence. Before an AI workflow can summarize an incident, before a detection can be trusted, and before an analyst can validate a finding, the underlying telemetry must be present, parsed, searchable, and understandable.

At Black Hat USA 2026, the team brought a broad set of data into Splunk Enterprise SEcurity (ES). That data included:

bhusa-2.jpg

That breadth mattered because no single telemetry source tells the whole story in an event SOC. DHCP helps identify which device had an address at a specific time. DNS shows what domains were resolved. Firewall, Zeek, Corelight, and network metadata help explain connection behavior. Malware analysis provides verdicts and artifact context. ThousandEyes helps separate security signals from performance and availability issues. Splunk ES gives analysts one place to connect those signals into an investigation.

Adding Event Context to Reduce Noise

Event SOCs live or die by context. Black Hat training rooms intentionally generate activity that looks suspicious: malware analysis, offensive security, cloud attacks, wireless exploitation, incident response labs, AI security testing, and more. Without event-specific context, analysts can waste time chasing expected training activity or miss when similar behavior appears on a public attendee or infrastructure segment.

To improve the signal, the team (thank you, Josh Wilson) added network and physical room location context for more than 90 training courses. That allowed detections and Findings in Splunk ES to be interpreted against where activity originated and what was happening in that location.

When malicious-looking behavior appeared, analysts and the Triage Agent could ask better questions immediately: is this activity expected in the room where it occurred? Is it on a public attendee network? Is it touching critical event infrastructure? Is it isolated to one device, or does it appear across multiple networks or users?

This is one of the most important lessons for the Agentic SOC: AI quality depends on data quality, but also on environment quality. The more operational context Splunk ES has, the more useful the agentic workflow becomes for the human analyst. Check out this video on why clean data and context are so important before you connect up any AI Agent.

From Detections to Findings to Agentic Triage

A major workflow tested at Black Hat USA was the path from detection to Splunk ES Finding to AI-assisted triage. When Splunk ES produced a Finding, the Triage Agent reviewed the available evidence, summarized what it could prove, identified gaps, and recommended a disposition. Instead of starting from a raw alert queue, analysts started from an evidence package.

bhusa-3.jpg

One example involved a high-scoring file submission from Corelight file activity between an internal host and an external IP address. The Triage Agent summarized the activity as a phishing-classified JavaScript file delivered during a live login or payment web session. It assessed the Finding as a high-severity true positive suspicious activity case with high confidence, while also showing where external reputation checks were inconclusive and required human judgment. Findings were enriched with threat intelligence provided by Cisco Talos.

bhusa-4.jpg

The goal is for AI to prepare a clear, evidence-backed first pass that a human can validate quickly. In a live SOC, that saves time and improves consistency because analysts can focus on the questions that matter most: does the evidence support the conclusion, what is the impact, and what should happen next?

Making Agentic Triage Operational

The team also built an analyst notification bot to close a practical workflow gap. When the Triage Agent finished analyzing a Finding, the bot notified analysts with the Finding name, timestamp, affected entity, AI triage summary, determination, severity, confidence, entity context, investigation tool outputs, and a direct link back into Splunk ES.

That small automation had an outsized value. In a busy event, SOC analysts cannot constantly poll every console or wait for background analysis to complete. The bot created a lightweight handoff from machine-speed triage to human validation, helping analysts know when a Finding was ready and where to continue the investigation.

Detection Engineering on Real Black Hat Data

Black Hat USA also gave the Splunk detection engineering team a live proving ground. Working with event data, the team coordinated new and refined detections that powered the Agentic SOC at Splunk .conf26.

In parallel, the team ran an automated validation process across more than 2,100 public detections from Splunk Security Research. The goal was to identify which detections were most relevant to the Black Hat dataset, which could be validated against available telemetry, and which should be customized for future event SOCs.

That process helped move from a broad library of detections to a practical event SOC backlog. The team could prioritize detections that mapped to real telemetry, real event noise, and real analyst workflows.

Helping Analysts Move into Splunk ES

The shift was not only technical. Several analysts were using Splunk ES as the primary investigation workspace for the first time, after previous event SOC workflows that often began elsewhere. The Splunk ES engineer helped analysts understand how to find and work Findings, read risk context, pivot into supporting telemetry, interpret Triage Agent output, and decide whether to close, hunt, escalate, or respond.

That mentoring reinforced one of the most important points about the Agentic SOC: AI does not remove the need for analysts. It changes where analysts start. Instead of manually assembling context from multiple tools, analysts begin with evidence, a summary, a confidence assessment, and recommended next steps. Humans still validate conclusions, understand event context, and make decisions.

bhusa-5.jpg

What Black Hat Proved for .conf26

The most important outcome from Black Hat USA 2026 was that Splunk ES proved it could serve as the system of record for agent-assisted investigation when the data, detections, and workflows are ready. Data onboarding, entity context, training-room mapping, detection validation, Triage Agent analysis, analyst notifications, and human validation are not separate projects. They are pieces of the same operating model.

Black Hat also showed why live event SOCs are such strong validation environments for product and engineering teams. The telemetry is real. The noise is real. The missing data is real. The partner handoffs are real. The analyst pressure is real. That makes the lessons more useful than a controlled demo because the operating model must survive the environment.

As the team prepared for Splunk .conf26, the work from Black Hat became a foundation: validated data sources, prioritized detections, stronger ES workflows, analyst feedback, notification patterns, and a clearer path for how the Triage Agent supports human validation.

The Agentic SOC is not about replacing security teams with automation. It is about giving analysts a better starting point, preserving evidence, improving confidence, and making every event a learning loop for the next deployment.

Acknowledgments

Thank you to the Cisco and Splunk NOC/SOC team preparing, operating, hunting, engineering, documenting, and supporting Black Hat USA 2026:

bhusa-6.jpg

Thank you also to the Black Hat NOC leadership and our partner teams across the event. The strength of the Black Hat NOC/SOC comes from collaboration: engineers, analysts, product teams, partners, and event leaders working together in a high-pressure environment with a shared mission. Palo Alto Networks (especially James Holland and Jason Reverri), Corelight (especially Mark Overholser and Eldon Koyle), Arista Networks (especially Landon Harsh), Lumen, Endace (especially Michael Morris and Cary Wright), Jamf (especially Adam Derrick) and the entire Black Hat / Informa Tech staff (especially Grifter ‘Neil Wyler’, Bart Stump, Steve Fink, James Pope, Michael Spicer, Jess Jung and Steve Oldenbourg).

bhusa-7.jpg

About Black Hat

Black Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit www.Black Hat.com.

Related Articles

PCI Compliance Done Right with Splunk
Security
3 Minute Read

PCI Compliance Done Right with Splunk

Check out the added features to support PCI compliance in the latest Splunk App for PCI Compliance version 5.1, now generally available.
Atlassian Confluence Vulnerability CVE-2022-26134
Security
7 Minute Read

Atlassian Confluence Vulnerability CVE-2022-26134

Get a closer look at the Atlassian Confluence Vulnerability CVE-2022-26134, including a breakdown of what happened, how to detect it, and MITRE ATT&CK mappings.
Celebrating 2024 Worldwide BOTS Day
Security
2 Minute Read

Celebrating 2024 Worldwide BOTS Day

After a successful launch of BOTS at .conf24, we’re ready to take it to the masses with two worldwide BOTSv9 competitions.