Cisco served as the Official Security Cloud Provider and a long-standing partner for the Black Hat USA 2026 Network Operations Center (NOC) and Security Operations Center (SOC), marking its eleventh year in this role. The company collaborated with other official technology partners, including Palo Alto Networks, Arista, Corelight, Jamf, and Lumen, to ensure the conference network's safe and reliable operation.
The Black Hat environment is distinct, encompassing training sessions, briefings, and a wide array of devices from security researchers, vendors, and attendees. This unique setting makes the Black Hat NOC/SOC a critical testing ground for security operations, where typical corporate network alarms might be expected activity in a training room, while genuine threats can still emerge from the same telemetry.
For Black Hat USA 2026, the Cisco and Splunk team focused on live NOC/SOC visibility, Splunk Enterprise Security (ES) detection engineering, threat hunting, malware and artifact analysis, AI protection, and the advancement of Agentic SOC development. These efforts are intended to carry forward into future events, including Cisco GSX and Splunk .conf26.
Cisco's primary responsibility was to ensure its critical infrastructure systems were operational and integrated with the broader partner environment. Once this foundation was stable, the team shifted focus to hunting, detection engineering, and innovation. The NOC leadership permitted Cisco and other partners to introduce additional pre-approved software and hardware solutions to enhance efficiency and expand visibility. However, Cisco was not the official provider for Extended Detection & Response, Security Event and Incident Management, Firewall, Network Detection & Response, or Collaboration.
The Cisco and Splunk team integrated telemetry and workflows from Cisco Security, Splunk Security, and partner-provided network and security controls. Splunk ingested logs from various sources, including DHCP and DNS from Cisco Secure Access, Jamf, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Arista network data, Corelight, Palo Alto Networks firewall data, Cisco Secure Firewall, Cisco Secure Network Analytics, ThousandEyes, and Duo. Findings were investigated within Splunk Security, utilizing threat intelligence from Cisco Talos and licenses donated by alphaMountain, Pulsedive, and StealthMole, alongside community sources.
This broad telemetry was crucial due to the diverse nature of the Black Hat environment, which includes high-noise training networks, public attendee networks, registration and event infrastructure, sponsor systems, cloud dependencies, and critical operational services. The value of the NOC/SOC stemmed from its ability to quickly consolidate these signals to understand events and determine necessary actions.
A significant focus for the team at Black Hat USA 2026 was the practical application of Splunk Enterprise Security. Splunk Cloud and Splunk ES provided a searchable evidence layer across disparate telemetry sources, and Splunk ES served as a platform to build, tune, test, and operationalize detections based on real event data. The team developed and refined detections drawing from over 100 Black Hat training courses and live NOC/SOC observations. These detections will be applied to protect future events like Cisco GSX and will contribute to the first Agentic SOC at Splunk .conf26, demonstrating the reusability of content developed in this event SOC model.
Black Hat USA 2026 also functioned as a development environment for the Agentic SOC. Building on an operating model introduced at Cisco Live Americas 2026, which uses agentic workflows to reduce repetitive triage, the Black Hat environment provided a different testing ground. The team prepared Cloud Control AI Studio and Agent Builder for testing, along with AI-assisted investigation workflows designed to support summarization, triage, evidence gathering, and handoff. The objective is to enhance human security operations by providing faster context, improved starting points, stronger documentation, and more time for threat hunting and deeper analysis, rather than replacing human analysts.
The Black Hat NOC/SOC was particularly important for testing this model due to its noisy, temporary, and highly collaborative nature, requiring signals to be understood by multiple teams including Cisco, Splunk, Black Hat leadership, and other partners. Agentic workflows are effective only if they preserve evidence, respect operational boundaries, and support human decision-makers.
Attendees in the Business Hall could view live dashboards from the Black Hat NOC/SOC at the NOC Outpost. These dashboards displayed the operational status of the event network, illustrating how telemetry translates into situational awareness. Staff from the NOC/SOC were available to explain the data and provide practical security operations lessons, making the work of the NOC/SOC visible and useful to the broader Black Hat community.
Black Hat is a unique environment where competitors collaborate for a shared mission: ensuring network functionality, event protection, and rapid investigation of unusual occurrences. Cisco and Splunk worked alongside other official network and security providers, each contributing a distinct perspective. The value derived from operationalizing these perspectives quickly and using them collectively under real-world conditions. This collaborative environment also fosters innovation, as integrations, dashboards, escalation paths, and detection logic are tested against actual traffic, constraints, and partner workflows.






