A Network Engineer Walks into the Agentic SOC: What AI Taught Me About Security Operations
Security Dan BurkeKey takeaways
- AI agents summarized security findings with evidence and context, allowing even first-time analysts to start investigations well-prepared instead of from scratch.
- Full packet capture let analysts verify AI findings using real network data, correctly identifying both a malware campaign and a harmless false alarm.
- AI didn't replace human analysts but helped them collaborate more easily, letting people with different backgrounds work together on the same evidence.
Splunk .conf26 felt like a special event long before I first sat down in the Agentic SOC. This year, the conference was held in Denver, my hometown. Even better, the selected venue was the Colorado Convention Center, in the heart of downtown, and one of my favorite spots in the entire city. I hoped to be able to attend, but I knew it was a long shot – as a Cisco Solutions Engineer with a background in network engineering, I didn’t expect my packet analysis skills or network architecture knowledge to be relevant at the event. I had no experience as a SOC analyst, so the notion of working in the Agentic SOC didn’t even cross my mind.
Less than two weeks before the event, a colleague reached out to let me know that there was an opportunity for SEs in the Denver area to attend the conference as Tier 1 analysts working on the Agentic SOC team. I was told we’d get all the training we’d need beforehand, though I wasn’t sure how this could possibly be true. I’d never worked in a SOC or in any other cybersecurity role in my life. Regardless, I applied and was shocked and delighted to be accepted. I expected to be assigned hours of online training and hands-on labs, but instead I was told that a single 2-hour training session one day prior to the event would be sufficient…
The SOC in a Box
Training was a whirlwind of covering the various tools that we’d be using while working as analysts, the many telemetry sources that we’d have access to, and introducing the heart of the operation, the SOC in a Box. This was a seriously impressive deployable environment that brought together networking, security, compute, packet capture, analytics, automation, and AI capabilities in a portable kit that could be shipped around the world and brought online wherever needed. I came away from training impressed, but feeling a bit overwhelmed – there was so much to look at, I wasn’t sure where I’d even begin during my first day in the SOC.
Welcome to the Agentic SOC
I arrived at the Agentic SOC first thing Monday morning. I was introduced to the team, a group of seasoned pros, all with expert knowledge and years of experience working in SOCs at prestigious events like the Black Hat conferences, the Super Bowl, even the Olympic Games! Everyone was very welcoming, but I immediately felt like a fish out of water, thinking to myself “Well, no chance that I’ll be of any use to a team like this”. I was given access to all the analyst tools, and a quick hands-on run through of the workflow. The team had integrated everything into Cisco Cloud Control, giving me a unified view of the entire stack, as well as the ability to query AI about any of the data or tools I may have questions about. The primary tool that I’d be using, though, was Splunk Enterprise Security, the Unified Threat Detection, Investigation, and Response (TDIR) platform for the SOC. I was shown how easy it was to review a finding in Splunk ES, and pivot into a drilldown to investigate further. I was also introduced to the capability that changed everything for me - the agentic AI that was helping to analyze, correlate, summarize, and prepare findings from the massive amount of telemetry being collected.
My AI Wingman
The AI capabilities built into the Agentic SOC were a game changer for me for a couple of reasons. First of all, it’s important to realize that the data coming into the SOC was not synthetic data for a demo or a proof-of-concept; this was real production data being collected from the conference’s own network environment, in accordance with the privacy and data handling agreements when joining the network. Network traffic from attendee, staff, and event systems was all captured and analyzed in real time. The result was a volume of data and telemetry far too great for a small team of analysts to handle, which is why the AI triage agent was used to analyze this data in real time. Detections and risk-based alerting surfaced activity of interest, and the AI triage workflow enriched and summarized the data for human validation.
More importantly for me, these findings were presented to the human analysts with a significant amount of data and context already available for review. The AI SOC Analyst’s Triage Agent created a curated summary, including evidence and justifications, along with details of all the tools that it used and queries it had run to gather the evidence. This allowed even a first-time human analyst like me to be the human in the loop, and apply human judgment and wisdom to the AI’s findings. When I had questions or was confused about a finding, I was able to query the AI Assistant and get an explanation. I was starting on step 10 of the investigation instead of step 1, and I quickly realized that by collaborating with an AI wingman like this one, I might actually be useful in the SOC. As I began to explore the many drill downs that I could use to validate the AI’s findings, I had an epiphany.
Agents Prepared. Humans Decided. Evidence Proved.
The Agentic SOC was designed to allow AI agents to perform the initial review of any potential findings, and then present these initial findings to a human analyst who would ultimately decide if there was a legitimate threat. The final and most important step is to collect the evidence that proves the human decision was justified. Fortunately, the Endace appliances deployed in the SOC in a Box were performing a full packet capture of all network traffic at the event, providing the best possible source of evidence for investigations, the actual data that was transmitted. Once I saw that I could pivot directly from a finding in the Splunk ES queue and into the packet captures, my epiphany hit me – I could use my own expertise to meaningfully contribute to SOC operations, even among this team of experts. As a network engineer, I’ve performed packet analysis and troubleshooting using Wireshark countless times over the years, and I’m very good at it. As soon as I started to pivot directly into a Wireshark instance, with a capture containing all the packets related to a finding, I was back in my element. Suddenly, I was no longer just a first-time analyst, I was an expert in my own right working among peers to track down threats.
From Collaborating with AI to Collaborating with Humans
Now that I had the help of the AI agents to understand the tasks at hand, and I had my trusty Wireshark to dig into the packets, I began contributing to investigations in earnest. In one investigation, I was able to help confirm an AI finding by showing that an endpoint was generating an unusually high volume of traffic to disreputable websites, in a possible instance of click-fraud malware. In another, I was able to refute the AI’s finding of suspicious activity, involving multiple devices downloading the same gzip-formatted file from an external server. A close look at the packets revealed that these were consistent with the Steam video game client. This is where human context mattered, as I know that at a technology conference full of people with their personal devices, some Steam related data is to be expected. AI saw something that looked unusual, even suspicious, but a human in the loop was needed to make the final decision. When we found the Steam traffic going to a device with a machine name that looked like a .conf asset, we escalated to the Network Operations Center and event team to review for code of conduct on official devices.
My favorite investigation involved a handful of attendee devices that were connecting to suspicious domains. After a careful review of the packets, I confirmed that the AI assessment of potential malicious activity was likely to be accurate. I flagged the case for review by a senior analyst, and Richard Marsh, a professional Incident Response Analysis Manager working in the SOC with us, picked it up. Richard reviewed the initial AI assessment, examined my supporting evidence, and ultimately was able to positively identify the findings as related to a known malware campaign involving fake anti-virus style scareware. What stood out to me most as I worked these investigations was that in every instance, what started as a collaboration between a human and an AI, ended with a collaboration between multiple humans. Rather than being confined to our own silos, every human in the Agentic SOC was able to look at the same investigation records, the same supporting evidence, and the same AI-generated context. This reduced the friction that so often happens when different teams bring their own tools and vocabularies to the same incident. It allowed us to work as a whole that was greater than the sum of its parts.
The Future of the SOC
The biggest takeaway I had from my time working in the Agentic SOC was a simple one – AI is not going to replace humans in security operations, not anytime soon at least. In the Agentic SOC, AI didn’t replace human judgment, it augmented it. That said, it’s quite clear to me that AI is likely to become a mainstay in every successful SOC, in fact, I think these agentic capabilities are already essential. The reasons are simple and boil down to this: AI allows humans to play to their strengths, and minimize their weaknesses. AI helps to direct human focus by sorting the potentially meaningful signals from the torrent of background noise. It helps to compensate for gaps in human skills and knowledge, while magnifying human expertise. AI can make a new SOC analyst capable of doing useful work on their very first day, something that I didn’t really believe could be possible until I was that new analyst. By organizing context, evidence, and preparing the workflow, AI allowed me to immediately begin contributing, despite my lack of specialized SOC knowledge and skills.
Most of all, AI helps humans collaborate with one another, providing a shared understanding that enables experts of different backgrounds to work together effortlessly. After my experience in the Agentic SOC at Splunk .conf26, it’s hard for me to imagine a future of security operations without agentic workflows that make human analysts better, faster, and more effective.
Check out the other blogs by my human colleagues in the .conf26 Agentic SOC.
Related Articles

SOC, Amore Mio! Following .italo's Tracks to a More Mature SOC

Introducing Attack Range v3.0
