incident response
5 stories
Inside the Modern SOC: The Identity Front Door
Attackers are increasingly leveraging compromised identities and social engineering tactics to gain initial access into corporate networks, bypassing traditional security measures. This shift means security teams must focus on identity context and behavioral analysis, rather than just login credentials, to detect and respond to threats effectively. Unified security telemetry and automated correlation are crucial for SOCs to identify sophisticated, identity-driven attacks before they escalate.

Blackpoint AI SOC Agent autonomously contains identity-based attacks
Blackpoint Cyber has released an AI-powered security agent designed to automatically detect and neutralize identity-based cyberattacks. This agent focuses on threats targeting cloud-based productivity suites like Microsoft 365 and Google Workspace. By leveraging a combination of artificial intelligence and human oversight, the system aims to significantly reduce the time it takes to contain compromised accounts and prevent further damage.

SharpHound Recon Attack – How AI enhanced the threat hunt
Researchers integrated an AI-driven security agent with full packet capture technology at Cisco Live AMER 2026 to automate threat hunting and analysis. The system successfully identified a potential SharpHound reconnaissance attack, analyzed network traffic, and accurately determined it to be a benign near-miss, saving significant analyst time and demonstrating the AI's potential to boost SOC efficiency.

What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
A product manager shared insights gained from working at the Cisco Live Security Operations Center. The experience highlighted the effective use of artificial intelligence, Splunk Enterprise Security, and Extended Detection and Response (XDR) technologies for accelerating threat investigations and improving the development of security detection and response tools.

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
Kaspersky's 2025 compromise assessments revealed that many organizations struggle with undetected threats, with a significant portion of high-severity incidents remaining hidden for months or even years. A substantial percentage of these missed threats were only identified through proactive assessments, highlighting gaps in existing security tools' alerting capabilities. The analysis also noted that attackers frequently utilize remote management tools and living-off-the-land binaries, and that malicious files can persist even in backups.