惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
T
Threatpost
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
Recorded Future
Recorded Future
小众软件
小众软件
N
Netflix TechBlog - Medium
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
LangChain Blog
博客园 - 聂微东
美团技术团队
F
Fortinet All Blogs
I
InfoQ
U
Unit 42
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
The Cloudflare Blog
罗磊的独立博客
Stack Overflow Blog
Stack Overflow Blog
J
Java Code Geeks
S
SegmentFault 最新的问题
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
GbyAI
GbyAI
有赞技术团队
有赞技术团队
博客园 - 【当耐特】
H
Help Net Security
B
Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
Jina AI
Jina AI
The Register - Security
The Register - Security
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 叶小钗
Recent Announcements
Recent Announcements
D
DataBreaches.Net
IT之家
IT之家
雷峰网
雷峰网
Y
Y Combinator Blog
W
WeLiveSecurity
P
Proofpoint News Feed
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
量子位
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 司徒正美
月光博客
月光博客
The Hacker News
The Hacker News

Security @ Cisco Blogs

We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
Elevating Expertise in the SOC
Erik Dove · 2026-07-08 · via Security @ Cisco Blogs

As one of the experienced Tier Two Analysts in the Security Operations Center during Cisco Live Americas 2026, my job was to validate all the events coming into the queue from new SOC Analysts, who were expected to work with Tier 2 capabilities with the assistance of Agentic AI. The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture. I would say they were like the first responders to an accident. They say what they think happened in the notes of the case and based on the evidence identified by the scene of the crime. They can tell a story remarkably close to what really happened with today’s technology. What Cisco has been able to do with the advancements of AI is promote that first responder into a full Investigator.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis. They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace. Below, I am going to guide you through that process that elevated our new team of eight analysts with less than three days on the job, to being able to support an event sprawl of 199TB of data captured, over 62,000 unique clients, that then elevated into 187 incidents.

The Queue

When being a first responder, we have indicators just like a 911 dispatch, to direct someone with some previous education, on what all the signals and signs of the disturbance will mean and how to resolve it. Analysts can assign themselves to the numbered incidents that have lower or higher severity. They are also able to see a creation date, and activity date with indicators on who is assigned to each incident (not shown).

Figure 1. The queue Tier One SOC Analysts pick from, to work on.

Instant Attack Verification

In each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question. In this summary, a confidence rating on the type of compromise and what Tactic or Technique it might include in its analysis. Below you can see that this incident is likely a True Positive (meaning the detection looks real) and there is Low Confidence meaning (there wasn’t enough evidence to support the Initial access request, as we did not have an agent installed on the device of the conference attendee). So, where do we go from here? AI has validated the traffic but not the reason as to why it is happening in the first place.

Figure 2. Cisco SOC Analysts take the next step in defining why an issue took place.

Pivot to Endace

Endace is a beautiful product that records and gives full packet capture throughout the whole event. I asked the new recruits to follow the data and find the story on the incident. Why find the story? Bad URLs and applications are not things people do normally; there must be a reason as to how this was triggered. Maybe someone left a service running on their computer; an email was sent unencrypted, or their password was in the clear using a service that is not secure. We can pivot to Vision with Endace from any of the SOC tooling, to find all that data during that time frame, track down the user, and inform them of the security issue so they can communicate securely in the future.

Figure 3. Pivot screen from Splunk Security to Endace Vision.

Endace Power

The pivot hyperlink opens you into Endace with an Applied Filter to the IP node you just pivoted from. You are using a directionless filter, and it gives you 10 minutes of data from the timestamp you came from in your incident. Also included in the window is all the traffic by Application.

Figure 4. Applications identified in the traffic based on the Type for the applied filters.

Chords of Conversation

The window also Includes a wheel of lighting, showing all the other nodes communicating to the node in question during this investigation period. When we see the data to all the other places this is giving us, it paints a picture of what was going on at that node. The brighter and thicker the Chord the more data moving through it. The goal is to find the communication to hopefully the other endpoint in the incident.

Figure 5. Chords of all the devices connected to the node in question.

Change the conversation between just the source and destination in the incident to find out what might be triggering the event.

Figure 6. IP Conversation between two nodes either on the network or the internet.

So, you can identify just the conversation you are looking for and the applications running.

Figure 7. Applications identified between two nodes either on the network or the internet.

Now that you have found the communication this incident has a data size of 11MB. 11MB of data doesn’t just appear without reason. Investigate further. Open into Wireshark by clicking on the tools in Endace.

Figure 8. Pivot menu in Endace to get to Wireshark for the conversation in the investigation.

Here you get all the data that happened durring that time frame; and you can hopefully find some credentials that lead you to the misconfiguration, malware, or password in the clear to educate the event attendee of how to secure their device in the future.

Figure 9. Wireshark details of the event from the pivot within Endace.

In summary, the advice given to the new SOC Analysts was to search further than a validated communcation from the AI agents, and see if there was more data to work with. Endace showed over and over that its worth Investigating further to resolve an issue with the tools within their fingertips. A little education and direction gave the Investigators a productive set of skills to resolve incidents with lessons learned for them and the attendees.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

Cisco Cybersecurity Viewpoints

Where security insights and innovation meet. Read the e-book, see the video, dive into the infographic and more...

Why Cisco Security?

Explore our Products & Services