# Cisco Talos

Published articles for Cisco Talos.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

DevFeed: [Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time](<https://devfeed.tech/articles/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time-8414.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc/>)

Author: Jessica (Bair) Oppenheimer

Published: 2026-09-07T15:00:58Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [duo](<https://devfeed.tech/tags/duo.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [thousandeyes](<https://devfeed.tech/tags/thousandeyes.md>)

### AI overview

Cisco describes its work protecting the Black Hat USA 2026 network alongside NOC leaders and technology partners. The team combined security telemetry and workflows to support visibility, detection engineering, threat hunting, malware analysis, AI protection, and Agentic SOC development.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences. Learn about the latest innovations for the Agentic SOC.

## Thrown into the SOC: A Black Hat First-Timer's Story

DevFeed: [Thrown into the SOC: A Black Hat First-Timer's Story](<https://devfeed.tech/articles/thrown-into-the-soc-a-black-hat-first-timer-s-story-8410.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc-first-timer/>)

Author: Danny Rodriguez

Published: 2026-09-07T15:00:54Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [incident](<https://devfeed.tech/topics/incident.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-xdr](<https://devfeed.tech/tags/cisco-xdr.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [duo](<https://devfeed.tech/tags/duo.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

A first-time SOC analyst reflects on a short Black Hat NOC rotation, focusing on evidence-based alert triage, uncertainty, and how AI agents can help investigators ask better questions.

### Source excerpt

A Black Hat SOC analyst shares how agentic workflows, Splunk ES, packet evidence, and human mentorship accelerated triage & investigation in the NOC/SOC.

## Black Hat USA 2026: Safeguarding DNS with Secure Access

DevFeed: [Black Hat USA 2026: Safeguarding DNS with Secure Access](<https://devfeed.tech/articles/black-hat-usa-2026-safeguarding-dns-with-secure-access-8407.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc-dns/>)

Author: Steve Vida

Published: 2026-09-07T15:00:32Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>)

Tags: [apple](<https://devfeed.tech/tags/apple.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-security-cloud](<https://devfeed.tech/tags/cisco-security-cloud.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-xdr](<https://devfeed.tech/tags/cisco-xdr.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dns](<https://devfeed.tech/tags/dns.md>), [google](<https://devfeed.tech/tags/google.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Cisco reports on using Secure Access and DNS telemetry to protect the Black Hat USA 2026 network. The article highlights blocking unapproved encrypted DNS resolvers, DNS request statistics, and activity classified as hacking.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences, over a decade providing DNS Security. Learn about protecting DNS with Secure Access.

## When the sensor starts thinking: SnortML, agentic AI, and the evolving architecture of intrusion detection

DevFeed: [When the sensor starts thinking: SnortML, agentic AI, and the evolving architecture of intrusion detection](<https://devfeed.tech/articles/when-the-sensor-starts-thinking-snortml-agentic-ai-and-the-evolving-architecture-of-intrusion-detection-2187.md>)

Original publisher: [Read original article](<https://stackoverflow.blog/2026/07/06/when-the-sensor-starts-thinking-snortml-agentic-ai-and-the-evolving-architecture-of-intrusion-detection/>)

Author: Samaresh Kumar Singh

Published: 2026-07-06T15:23:34Z

Content type: article

Language: en

Sources: [Stack Overflow Blog](<https://devfeed.tech/sources/stack-overflow-blog.md>)

Topics: [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cisco Talos](<https://devfeed.tech/topics/cisco-talos.md>), [Network](<https://devfeed.tech/topics/network.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Publish-subscribe pattern](<https://devfeed.tech/topics/pubsub.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [cc-by-sa](<https://devfeed.tech/tags/cc-by-sa.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [inference](<https://devfeed.tech/tags/inference.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [network](<https://devfeed.tech/tags/network.md>), [se-stackoverflow](<https://devfeed.tech/tags/se-stackoverflow.md>), [se-tech](<https://devfeed.tech/tags/se-tech.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article examines how SnortML adds local machine-learning inference to Snort 3's intrusion-detection pipeline. It contrasts signature-based detection, which provides precise coverage for known exploits, with machine-learning detection aimed at identifying novel or modified attack behavior. It also places SnortML alongside the broader rise of agentic AI in network defense, while treating the two as developments operating at different architectural layers.

### Source excerpt

Signature-based detection has always known what it was looking for. Machine learning and autonomous agents are changing the question entirely, shifting from "does this match a known pattern?" to "does this actually make sense in context?"

## Cisco Talos empowers threat researchers while reducing TCO by 75% with ClickHouse Cloud

DevFeed: [Cisco Talos empowers threat researchers while reducing TCO by 75% with ClickHouse Cloud](<https://devfeed.tech/articles/cisco-talos-empowers-threat-researchers-while-reducing-tco-by-75-with-clickhouse-cloud-5043.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/cisco>)

Author: ClickHouse

Published: 2026-06-15T00:00:00Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [Cisco Talos](<https://devfeed.tech/topics/cisco-talos.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [data](<https://devfeed.tech/topics/data.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [databricks](<https://devfeed.tech/topics/databricks.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [parquet](<https://devfeed.tech/topics/parquet.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [databricks](<https://devfeed.tech/tags/databricks.md>), [event-driven](<https://devfeed.tech/tags/event-driven.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [parquet](<https://devfeed.tech/tags/parquet.md>), [s3](<https://devfeed.tech/tags/s3.md>), [serverless](<https://devfeed.tech/tags/serverless.md>)

### AI overview

Cisco Talos migrated a nearly 2-trillion-row, 2 PB threat-intelligence dataset from self-managed ClickHouse to ClickHouse Cloud on AWS with zero downtime and a complete data match. The move reduced storage costs by about 90% and total cost of ownership by about 75%.

### Source excerpt

Cisco Talos runs a threat intelligence reputation service on ClickHouse Cloud, classifying file hashes so researchers can make fast, accurate security decisions.

## Marriott Deploys Cisco Umbrella DNS-Layer Security Across Nearly 5,000 Properties to Block Access to CSAM

DevFeed: [Marriott Deploys Cisco Umbrella DNS-Layer Security Across Nearly 5,000 Properties to Block Access to CSAM](<https://devfeed.tech/articles/marriott-leads-the-way-in-the-fight-to-protect-children-online-20377.md>)

Original publisher: [Read original article](<https://umbrella.cisco.com/blog/marriott-leads-way-in-fight-to-protect-children-online>)

Author: Negisa Taymourian

Published: 2024-03-12T08:00:00Z

Content type: article

Language: en

Sources: [OpenDNS](<https://devfeed.tech/sources/opendns.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [customer-focus](<https://devfeed.tech/tags/customer-focus.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dns-layer-security](<https://devfeed.tech/tags/dns-layer-security.md>), [dns-security](<https://devfeed.tech/tags/dns-security.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [security](<https://devfeed.tech/tags/security.md>), [security-service-edge](<https://devfeed.tech/tags/security-service-edge.md>), [sse](<https://devfeed.tech/tags/sse.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

The article describes Marriott's deployment of Cisco Umbrella DNS-layer security across nearly 5,000 properties to block access to child sexual abuse materials and other malicious or unwanted domains. It highlights deployment speed, scalability, guest-network performance, manageability, and Cisco Talos threat intelligence.

### Source excerpt

Marriott has rapidly deployed Cisco DNS-layer security across thousands of properties to advance human rights by limiting access to CSAM materials. The post Marriott Leads the Way in the Fight to Protect Children Online appeared first on Cisco Umbrella.