Evolving to Autonomous Defense: New Agentic SOC Capabilities
Security John MorganAI is accelerating attacks faster than human-led security operations can keep pace with and closing that gap requires a SOC that can act at the same speed—without losing the governance leaders require.
At .conf26, we are showcasing how organizations can evolve toward a proactive, AI-driven defense. By harnessing automation and intelligent workflows, modern security operations centers (SOCs) can deliver rapid, consistent threat detection and response. This equips teams with the precision and agility needed to keep pace with today’s most sophisticated threats.
Today, I am proud to announce that Splunk is expanding its Agentic SOC Workforce with a set of new purpose-built skills, across detection, investigation, response, and governance, while expanding the value across our core portfolio to strengthen and democratize the agentic SOC for every organization. By connecting the full path from security signal to decision, action, and verified risk reduction, Splunk enables organizations to defend autonomously, block attacks at the source, and continuously mitigate critical exposure.
Defend Autonomously
As organizations evolve from basic triage to autonomous, agentic defense, security teams need to scale their agentic workforce. To help teams make that shift, we are introducing the continued expansion of the Agentic SOC Workforce. Splunk is enhancing existing capabilities and introducing new agentic skills within the way SOC teams already operate: detection and security engineering, threat hunting, investigation and response, and governance and policy.
The Agentic SOC Workforce are trusted extensions of the security team, designed to help analysts and engineers move faster while keeping humans in control.
- Detection & Security Engineering helps teams build and tune trusted coverage faster.
- Threat Hunting helps find and disrupt emerging threats with malware analysis and proactive hunting.
- Investigation & Response helps contain and resolve threats faster through triage, investigation, and response.
- Governance & Policy keeps autonomy grounded in SOPs, exposure context, approvals, and auditability.
Together, these agents deliver a breadth of skills to help customers defend autonomously with trusted AI, shared context, approvals, auditability, and policy built in. The result is a SOC that can defend at machine speed while keeping practitioners accountable, informed, and in control.
Splunk is expanding the value of its Enterprise Security Essentials and Premier editions, making the agentic SOC accessible to every organization and enabling all editions to defend against AI-driven threats at machine speed. Together, Essentials and Premier provide a clear path to evolve the agentic SOC: minimizing exposure, prioritizing what matters, and responding at machine speed.
Stop Attacks at the Source: Distributed Defenses with Enterprise-wide Visibility
With more than 1,300 security integrations, Splunk connects signals across the enterprise, from network, firewall, identity, cloud, and endpoint controls to deliver the visibility needed to detect the first sign of compromise and trigger action at the source.
We are advancing integrations across our Cisco Security portfolio to bring more differentiated value to customers. For example, combining Cisco Hybrid Mesh Firewall’s protocol-level inspection and enforcement with Splunk’s detection, investigation, and response workflows enables coordinated prevention and policy enforcement across security controls. The result: faster containment measured in minutes not hours, a smaller blast radius, and fewer gaps attackers can exploit to move laterally or escalate impact.
Lower-cost ingestion helps customers bring high-volume Cisco telemetry into Splunk more economically, while Cisco AI Defense, identity intelligence, secure access, and policy guardrails help organizations deploy AI agents safely and keep human and machine actions within policy. Combined with AI observability delivering visibility into token economics, performance, and hallucinations, all these integrations create a unified security platform that reduces operational complexity, improves visibility, and provides a trusted foundation for preventing attacks and deploying AI at scale.
Mitigate Critical Exposure
Splunk delivers continuous context across assets, identities, controls, and business criticality that supports two outcomes: proactively mitigating the exposures that matter most and immediately prioritizing them during an incident.
The new capabilities in Exposure Analytics help customers move from reactive vulnerability management to proactive risk reduction. This expanded functionality broadens asset visibility, preserves historical change context, and brings business-specific insights directly into prioritization.
Now available in Splunk Enterprise Security, Exposure Analytics delivers automated entity discovery across diverse asset types, historical tracking of how business entities evolve, and rich business context that tailors risk insight to the organization. Whether you are scaling your security operations or building your first agentic workflows, Splunk provides the comprehensive visibility required to eliminate critical exposures.
Related Articles

Find the Fingerprints and Traces of Threats with Splunk at RSAC 2021

Going Beyond Today’s Asset and Risk Intelligence: What’s New in Splunk ARI 1.2
