LIVE · cybersecurity feed
Live wire

soc

ai

Machine Speed, Human Judgement: How AI Changed the SOC in 2026

The article provides an inside perspective on how artificial intelligence and automation are reshaping security operations centers (SOCs). It highlights the integration of AI, automated processes, and agent-based workflows as key drivers of change in modern security.

ai

What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

A product manager shared insights gained from working at the Cisco Live Security Operations Center. The experience highlighted the effective use of artificial intelligence, Splunk Enterprise Security, and Extended Detection and Response (XDR) technologies for accelerating threat investigations and improving the development of security detection and response tools.

sochigh

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic's InfoSec team has developed an automated security operations center (SOC) that significantly reduces alert triage time. By using deterministic queries and specialized AI agents, the system handles most alert investigations before human analysts are involved, cutting down a 30-minute process to under three minutes. This approach leverages Elastic's own technology stack and focuses on efficient, cost-effective automation to manage increasing alert volumes.

ai

5 Myths About AI in the SOC Security Teams Need to Rethink

Security operations teams are increasingly adopting AI, but common assumptions about its role need reevaluation. Experts suggest AI should augment, not replace, human analysts by handling repetitive tasks and data processing. While automation is beneficial for enrichment and triage, critical actions still require human oversight. Transparency and explainability are crucial for building trust and ensuring analysts can confidently use AI outputs.

threat intelligence

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.