# Agentic SOC

Published articles for Agentic SOC.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike Delivers the Next Evolution of the Agentic SOC

DevFeed: [CrowdStrike Delivers the Next Evolution of the Agentic SOC](<https://devfeed.tech/articles/crowdstrike-delivers-the-next-evolution-of-the-agentic-soc-8304.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/>)

Author: Brandon Benke

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [data](<https://devfeed.tech/topics/data.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [identity](<https://devfeed.tech/tags/identity.md>), [network](<https://devfeed.tech/tags/network.md>), [operations](<https://devfeed.tech/tags/operations.md>), [platform](<https://devfeed.tech/tags/platform.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>)

### AI overview

CrowdStrike describes the next evolution of its agentic SOC, where analysts and AI agents work together in a unified system to investigate and respond to threats in real time. The Falcon platform combines data generation, enrichment, investigation, orchestration, and governance, with capabilities for detection-ready third-party data and coordinated specialist agents.

### Source excerpt

Expert agents that reason together, learn your environment, and run on data CrowdStrike owns. See how we deliver the agentic SOC. Learn more!

## Teaching AI to Reason Through Detection Triage

DevFeed: [Teaching AI to Reason Through Detection Triage](<https://devfeed.tech/articles/teaching-ai-to-reason-through-detection-triage-8310.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/teaching-ai-to-reason-through-detection-triage/>)

Author: Amol Khanna - Manu Nandan - Cristian Viorel Popa - Joan Pujol-Roig - Diana Bolocan - Laura Vasilie - Alexandru Apostu - Chase Helwig - Mihaela Gaman - Mickey Brautbar - Edward Raff - Chase Midler - Sv

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chain-of-thought](<https://devfeed.tech/tags/chain-of-thought.md>), [classification](<https://devfeed.tech/tags/classification.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [language-models](<https://devfeed.tech/tags/language-models.md>), [llm](<https://devfeed.tech/tags/llm.md>), [model](<https://devfeed.tech/tags/model.md>), [nemotron](<https://devfeed.tech/tags/nemotron.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [open](<https://devfeed.tech/tags/open.md>), [reasoning](<https://devfeed.tech/tags/reasoning.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

CrowdStrike describes research on a reasoning-enabled language-model classifier for security detection triage. The model produces a verdict and an auditable rationale, with the stated goals of improving accuracy, transparency, and safe alert automation.

### Source excerpt

New CrowdStrike research shows how step-by-step reasoning can improve detection triage accuracy, transparency, and safe automation.

## Building an Agentic SOC on a Stream

DevFeed: [Building an Agentic SOC on a Stream](<https://devfeed.tech/articles/building-an-agentic-soc-on-a-stream-11549.md>)

Original publisher: [Read original article](<https://www.confluent.io/blog/building-an-agentic-soc-on-a-stream/>)

Author: Pavel Lineitsev

Published: 2026-09-10T19:19:05Z

Content type: article

Language: en

Sources: [Confluent: Data in motion](<https://devfeed.tech/sources/confluent-data-in-motion.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Streaming](<https://devfeed.tech/topics/streaming.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [data loss prevention](<https://devfeed.tech/topics/data-loss-prevention.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [automation](<https://devfeed.tech/tags/automation.md>), [confluent-cloud](<https://devfeed.tech/tags/confluent-cloud.md>), [data-loss-prevention](<https://devfeed.tech/tags/data-loss-prevention.md>), [security](<https://devfeed.tech/tags/security.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [soc](<https://devfeed.tech/tags/soc.md>), [streaming](<https://devfeed.tech/tags/streaming.md>)

### AI overview

This article describes an Agentic SOC that uses AI agents and a continuous streaming architecture to investigate security alerts. Its pipeline combines central triage, specialized evidence agents, adversarial evaluation, and a self-learning knowledge base to analyze every alert, escalate higher-value cases, and surface true positives for analyst review. The approach is intended to address the backlog of low-priority alerts, including Data Loss Prevention alerts, whose volume makes manual investigation impractical.

### Source excerpt

Discover how our security team built an automated multi-agent investigation pipeline that scaled alert triage throughput using a continuous streaming architecture.

## Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

DevFeed: [Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time](<https://devfeed.tech/articles/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time-8414.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc/>)

Author: Jessica (Bair) Oppenheimer

Published: 2026-09-07T15:00:58Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [duo](<https://devfeed.tech/tags/duo.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [thousandeyes](<https://devfeed.tech/tags/thousandeyes.md>)

### AI overview

Cisco describes its work protecting the Black Hat USA 2026 network alongside NOC leaders and technology partners. The team combined security telemetry and workflows to support visibility, detection engineering, threat hunting, malware analysis, AI protection, and Agentic SOC development.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences. Learn about the latest innovations for the Agentic SOC.

## From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

DevFeed: [From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For](<https://devfeed.tech/articles/from-isolated-agents-to-collective-intelligence-why-a2a-is-the-protocol-the-agentic-soc-has-been-waiting-for-8402.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/a2a-mcp-open-protocol-stack-multi-agent-soc/>)

Author: Jeff Yeo

Published: 2026-08-28T15:00:11Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [agents](<https://devfeed.tech/tags/agents.md>), [announcement](<https://devfeed.tech/tags/announcement.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [artificial-intelligence-ai](<https://devfeed.tech/tags/artificial-intelligence-ai.md>), [integration](<https://devfeed.tech/tags/integration.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [security](<https://devfeed.tech/tags/security.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

This article presents A2A as a protocol for enabling agents from different vendors and platforms to hand work to one another in a multi-agent security operations center. It explains that A2A complements MCP: MCP connects agents to data and tools, while A2A connects agents to other agents. The article describes this as a conceptual architecture because production security-agent handoffs mediated by A2A are not yet shipping.

### Source excerpt

The Agentic SOC needs two protocols, not one. Learn how MCP and A2A work together as the vertical and horizontal layers of multi-agent security operations

## How SLED can win the cybersecurity race with agentic AI

DevFeed: [How SLED can win the cybersecurity race with agentic AI](<https://devfeed.tech/articles/how-sled-can-win-the-cybersecurity-race-with-agentic-ai-4837.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/sled-agentic-ai-cybersecurity>)

Author: Bobby Suber

Published: 2026-08-21T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [Language models](<https://devfeed.tech/topics/language-models.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-search](<https://devfeed.tech/tags/ai-search.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [public-sector-education-non-profit-government](<https://devfeed.tech/tags/public-sector-education-non-profit-government.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article describes how AI-enabled attacks are pressuring state, local, and education security teams, and presents an agentic SOC as a way to accelerate investigations by correlating alerts, gathering context, and preparing response plans.

### Source excerpt

AI-accelerated attacks are outpacing SLED security teams. Learn how state, local, and education organizations are closing the gap by fixing their data foundation first.