惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
T
Tailwind CSS Blog
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
博客园 - 叶小钗
N
Netflix TechBlog - Medium
罗磊的独立博客
量子位
MyScale Blog
MyScale Blog
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
B
Blog
腾讯CDC
爱范儿
爱范儿
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
F
Fortinet All Blogs
雷峰网
雷峰网
G
Google Developers Blog
Google DeepMind News
Google DeepMind News

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026
Meet Instant Attack Verification: Agentic AI for Tier-1 a...
Prerna Dass · 2026-08-17 · via Security @ Cisco Blogs

The alert problem every SOC knows

Security operations centers are drowning in alerts. Volume grows faster than teams can hire; many of those alerts turn out to be false positives, and yet everyone still must be looked at. Under that load, the alerts that matter get delayed or missed — and the cost shows up as analyst burnout, inconsistent decisions, slow response, and dangerous dwell time for real threats. You can’t simply hire your way out of it, because experienced analysts are scarce and expensive. This is precisely the gap agentic AI is built to close.

Instant Attack Verification: an AI security analyst

At the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst. When a detection fires, it investigates the way a human tier-1 or tier-2 analyst would: it gathers the relevant evidence, examines the devices and users involved, reasons over the logs, decides whether the alert is a real threat or a false positive, judges scope and impact, recommends what to do, and writes up a full report that shows it’s working. The ambition behind it is straightforward but bold — 100x scalability, quality, and speed in security operations, achieved by pairing human expertise with AI rather than replacing it.

From triage to investigation

SOC work is tiered, and the capability covers both tiers in a single automated flow. As a tier-1 analyst, it triages the incoming flood: it ingests every detection, so nothing sits unreviewed, enriches each alert with context, filters out the noise of false positives, and prioritizes what is real. As a tier-2 analyst, it runs the deeper investigation that triage escalates — correlating evidence across endpoint, network, cloud, and identity data, reconstructing a timeline and an incident graph of how events connect, determining how far a threat spread, classifying the incident, and recommending both immediate containment and longer-term hardening. It documents all of it with a full evidence trail. In effect, it compresses a loop that normally spans several people and hours into one automated pipeline, escalating to a human wherever judgment or authority is required.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

AI-generated analysis with full evidence traceability in a single pane of glass — the narrative links entities, indicators, and MITRE techniques inline for the analyst to verify.

How do we measure success?

Building an agentic SOC analyst is a product problem as much as a modeling one. The technology can already triage and investigate; whether it delivers comes down to three things — trust earned through measured accuracy and explainability, resilience against adversaries, and thoughtful human oversight. Get that right, and the economics follow.

Measuring success starts with one central tension: automation rate versus concordance. Automation rate — the share of alerts handled with no human — tells the capacity story. Concordance — how often the agent’s verdict matches a human analyst — tells the trust story. The discipline is never letting the first outrun the second. Beneath them, effectiveness is precision and recall, and above all false negatives: the catastrophic miss of a real threat. Operationally, you watch time-to-investigate, throughput, and reliability.

The economy is simple to frame. Take the cost of one investigation by a human versus the agent, multiply by volume and automation rate, then subtract the sustaining costs you can’t avoid — evaluation, monitoring, and the human oversight that remains. Faster triage adds a second saving by shrinking dwell time, which lowers expected breach cost.

But the economy only holds on two guardrails. The first is adversarial safety, and it’s non-negotiable because a security agent’s inputs are attacker-controlled: treat every piece of evidence as untrusted data rather than instructions, isolate tenants and privileges, gate high-impact actions behind a human, and red-team continuously. The second is human-in-the-loop design, which is how trust becomes real — autonomy earned incrementally, consequential actions kept gated, and analyst corrections fed back as a learning loop. Trust, in the end, is the currency that unlocks the economics.

Where Instant Attack Verification meets the Cisco Data Fabric

Cisco Data Fabric, powered by the Splunk Platform and generally available since August 2026, is an architecture — not a product — for connecting data, context, and action across domains so that both people and AI agents can reach the right data and act on it safely. Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly. Federated Search could let the capability reach data in place across S3, Azure, Snowflake, and Databricks instead of maintaining bespoke connectors. The Machine Data Lake offers durable, low-cost retention for both live evidence and the stable datasets it needs to evaluate itself. The Catalog helps agents discover the right data rather than assume fixed sources. AI Canvas is a natural home for investigations and their approvals. And the Splunk MCP Server is the interoperability layer that lets the capability orchestrate the fabric — or be called an agent.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is a specialized agent that runs on top of it. One answers how to reach the right data cheaply across everything and let agents act safely; the other answers how to investigate a security detection like a seasoned analyst. They are complementary layers — and it is exactly the kind of agentic action the Data Fabric exists to enable.