惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Commits to openclaw:main
Recent Commits to openclaw:main
MyScale Blog
MyScale Blog
A
About on SuperTechFans
爱范儿
爱范儿
L
LangChain Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
Check Point Blog
博客园 - Franky
Recent Announcements
Recent Announcements
Recorded Future
Recorded Future
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
U
Unit 42
雷峰网
雷峰网
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
博客园_首页
Engineering at Meta
Engineering at Meta
量子位
The Cloudflare Blog
B
Blog RSS Feed
N
Netflix TechBlog - Medium
罗磊的独立博客
Vercel News
Vercel News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
V
Vulnerabilities – Threatpost
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Cisco Talos Blog
Cisco Talos Blog
B
Blog
I
InfoQ
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
月光博客
月光博客
T
Tor Project blog
D
DataBreaches.Net
T
The Exploit Database - CXSecurity.com
D
Docker
C
Cyber Attacks, Cyber Crime and Cyber Security
阮一峰的网络日志
阮一峰的网络日志
G
Google Developers Blog
P
Proofpoint News Feed
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Blog — PlanetScale
Blog — PlanetScale
aimingoo的专栏
aimingoo的专栏
C
Cisco Blogs
MongoDB | Blog
MongoDB | Blog
Simon Willison's Weblog
Simon Willison's Weblog

Security @ Cisco Blogs

We third-party tested our firewall built for AI-scale. The test tools hit their limit first. Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
SharpHound Recon Attack - How AI enhanced the threat hunt
Manoj Sudhakara · 2026-07-08 · via Security @ Cisco Blogs

Cisco Live AMER 2026 was the perfect place to put the Agentic SOC to work, protecting the attendees and conference infrastructure. We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting. Within minutes, the agent returned an accurate and descriptive assessment of the threat, concluding that it was a benign near miss. This saved us many hours of work, giving us confidence that the Agentic SOC will be a massive boost to security and productivity. This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Full Packet Data – A gold mine for Agentic AI

At Cisco Live AMER 2026 we deployed always-on, full packet capture as a source of forensic evidence, integrated with Agentic AI, to support the conference SOC directives of Protect, Educate, and Innovate. Always-on, full packet capture provides unique insight into all activity on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams, as well as an unmatched data lake of all network activity for the emergent Agentic SOC.

The challenge when human analysts analyze packet data is whether they have the expertise and experience to interpret and understand what packets are telling them: because not everyone is a packet guru.

To make full use of this rich network data, we decided to integrate Endace full packet capture with the Agentic AI capabilities built into Cisco XDR and Splunk Enterprise Security, along with our custom agentic tool. The goal was to empower our incident responders with powerful evidence and reasoning to expedite the decision-making for suspicious activity. Some of our analysts were spending their first day ever in a SOC, so our goal was to help them be productive quickly using Agentic AI. This was also a great opportunity to understand how Agentic AI helps productivity in the SOC.

Agentic AI Augmented Architecture

Our Agentic SOC Architecture is a natural evolution of the SOC Architecture we have been deploying for the last several years, heavily leveraging telemetry and insights derived from network data we monitor, analyze and capture throughout each event. We rely on logs generated by Cisco Firepower, Secure Network Analytics, Secure Access, AI Defense, Splunk Attack Analyzer, Secure Malware Analytics, and EndaceProbe (which also generates Zeek logs and reconstructs file content from the packet data it records). Splunk Enterprise Security was the repository for all these logs and data, while EndaceProbe was the repository for full packet data for the entire week of the event.

We implemented a Model Context Protocol (MCP) server for Endace to integrate with Cisco Cloud Control, allowing us to build Agentic AI integrations with Splunk, Cisco XDR and other components of the SOC (see Baz Shaw’s blog for more detail: Cisco Live 2026 – Using LLMs and Endace Full Packet Capture for Incident Response).

With the Endace MCP server in place, we built a lightweight Agentic Tier-2 SOC analyst that consumes a single XDR incident and investigates it end-to-end. It builds on the agentic capabilities already in our products. Under the hood, it combines the Endace MCP (for packet capture and decode) with a Splunk MCP (for querying the Zeek logs and other indexes) and the Cisco XDR APIs (for incident, asset, and observable context), all orchestrated by a reasoning agent that we tailored with Cisco Live context — the venue’s IP ranges, the Splunk index layout, and the SOC’s rules of engagement. The result is a single entry point: give it an incident ID, and it pulls the XDR context, retrieves the relevant Endace packets, runs targeted Splunk queries, and returns a structured report. (For the full architecture of the tool and how we built it, see the deep-dive: “AIM — Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026.”)

Investigating a Potential SharpHound Attack

At each SOC event we spend some of our time being curious and threat hunting for suspicious activity. Previously we had seen insecure AD as a serious threat to some attendees at another Cisco Live event, so we decided to take another look, first using humans rather than Agents.

Reviewing the packet data from three days of conference activity, we quickly found several LDAP sessions initiated in the clear by attendee devices. In total, 48 devices were attempting to initiate LDAP binds to external LDAP servers using both IPv4 and IPv6 addresses.

The high-profile organization names found in the LDAP bind requests were particularly concerning. We theorized that the behavior of continuous attempts at anonymous binds may be a sign of SharpHound reconnaissance. This recon, if successful, can result in LDAP enumeration exposing sensitive details that may be used to compromise an organization.

Agentic AI Massively Speeds our Analysis

At this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat. Our first step was to create an incident in Cisco XDR. The incident included a description, the incident time, and an IP tuple and port. Then the XDR Attack Storyboard kicked in as the primary agent, delivering an automatic first-pass assessment of the incident. Building on top of that assessment, our Tier-2 agent (AIM) took it further — working the incident in stages and deciding each next step based on what the previous one returned (truly agentic). First, it read the XDR incident context, then pivoted to Endace full packet capture to pull the actual LDAP/389 session (within an analyst-approved 15-minute capture window) and then gathered more supporting evidence from Splunk logs, all autonomously.

Within a few minutes we were presented with a well-written report that described the incident, data gathered, reasoning, assessment, and disposition along with the next steps. For first-time analysts especially, this was a goldmine — the Agent interpreted the packets on its own, doing the hard part. As SOC analysts, we could review the Agent’s work and take the next steps.

The Agent also produced step-by-step execution logs; every query and decision — so the full reasoning trail can be handed to Tier-3 if escalation is ever needed — showing exactly how it reached its conclusion. It even zoomed out to check other attendees in the later time window: a blast-radius check, done automatically. In this case, the incident was benign, and the recommendation was to close it as a benign/near-miss. Because we provide the Agent with access to Always-On, full packet data, it was able to review all packet data to map out the blast radius entirely and assess all incidents of this threat.

Building Skills

It was particularly encouraging to see the agent first fail, then learn from its mistake. Initially it mixed up “event time” and “first-seen” time. On the first pass, it found no packet evidence because it was searching for the wrong time period. On the second pass, it learned to use the “first-seen” time, found the packet evidence, and wrote that lesson back into its skill file so it would know for next time.

Conclusion

The Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security. The well-reasoned assessments it provides allow us humans to make fast and robust decisions. This, in turn, enables us to focus our precious time on the most serious threats.

Acknowledgements

Our thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Berlinson for the opportunity to integrate EndaceProbes with the Cisco Live Agentic SOC architecture. The SOC team is a collection of Cisco and Splunk experts across many domains who were a pleasure to work and innovate with, and we came away with a great appreciation for the power of the Cisco Security and Splunk tools. The Endace and Cisco teams were able to prove out integration innovations and test them in earnest in a real-world environment in preparation for making them generally available to the market.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas: