LIVE · cybersecurity feed
Live wire
ai

What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

A product manager shared insights gained from working at the Cisco Live Security Operations Center. The experience highlighted the effective use of artificial intelligence, Splunk Enterprise Security, and Extended Detection and Response (XDR) technologies for accelerating threat investigations and improving the development of security detection and response tools.

zeroday.news · 25d ago

Working within the live Security Operations Center (SOC) at Cisco Live AMER provided valuable insights into the practical application of AI, detection, and response technologies, according to a product manager's recent account. The SOC at the event functions as a real-time security operation, integrating analysts, telemetry, detection mechanisms, and response workflows across the conference network.

The experience combined customer interactions with hands-on investigation within the SOC environment. By engaging with security operations teams and observing their workflows, the product manager identified common challenges such as investigation slowdowns, loss of context, and the need for manual data correlation. The direct involvement in the Cisco Live SOC allowed for a deeper understanding of these pain points through real-time investigations.

A key takeaway was that effective detection and response is fundamentally a workflow challenge rather than a singular product solution. Investigations often span multiple tools and data sources, beginning with a detection in a firewall, being enriched by XDR, requiring historical data from Splunk Enterprise Security, and potentially needing packet capture analysis. The analyst's role involves synthesizing this information to determine if a detection is a true positive or false positive, whether an action was blocked, and if an asset is compromised.

Artificial intelligence proved to be a significant aid in accelerating the investigation process. It helped in quickly orienting the analyst by providing intelligence, context, and initial hypotheses, which was particularly beneficial in an unfamiliar environment. While AI did not replace the analyst's investigative actions, it reduced the time needed to understand the situation, identify critical elements, and determine next steps. AI assisted in translating complex log data, normalizing timestamps, interpreting network addresses, summarizing packet evidence, and distinguishing between a rule match and an actual compromise.

Real-world investigations highlighted the importance of reaching clear, evidence-backed conclusions, even when no compromise was confirmed. These outcomes, such as a blocked connection with no evidence of compromise or a signature match identified as a likely false positive due to normal network behavior, are crucial. Such findings allow analysts to quickly dismiss benign alerts and focus on more significant threats, underscoring the value of efficient investigation workflows.

The synergy between Splunk Enterprise Security and XDR was evident throughout the investigations. Splunk Enterprise Security excelled in providing depth, enabling detailed searches across raw events, validation of timestamps, and examination of activity before and after a detection. XDR served as an effective starting point, offering hypotheses, key evidence, and analysis that connected related entities and detections.

The combined use of these tools facilitated a smoother investigative flow. XDR provided an overview of the investigation's scope, while Splunk allowed for deep dives into the details, corroborating XDR's findings with more granular evidence. This collaborative approach was particularly valuable for an analyst new to the environment, helping to quickly resolve numerous investigations with a high degree of confidence.

The experience underscored the need for seamless integration between investigation views and deep evidence search capabilities. The ideal scenario involves a unified experience where analysts can review all relevant data, extract supporting evidence, and reach conclusions rapidly and with confidence. This approach avoids forcing analysts to choose between an investigation map and data depth, instead combining their strengths for faster decision-making.

The product manager concluded that future detection and response products should be designed as connected investigation systems that minimize the "translation work" for analysts. AI can empower analysts to ask the right questions more quickly without diminishing their critical judgment. The goal is to build products that make complexity understandable, preserve evidence, respect analyst judgment, and transform customer challenges into improved workflows.

aisocsplunkxdrincident response
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.