A Black Hat SOC analyst shares how agentic workflows, Splunk ES, packet evidence, and human mentorship accelerated triage & investigation in the NOC/SOC.
Learn how the Black Hat NOC/SOC used ThousandEyes, Linux command-line testing, and packet evidence to monitor distributed latency, isolate DNS issues, and validate network performance during a live cybersecurity event.
Cisco is the Security Cloud Provider for the Black Hat conferences, over a decade providing DNS Security. Learn about protecting DNS with Secure Access.
At Black Hat USA, we used Splunk Detection Editor Alpha to turn Cisco SNA alarms into risk events with context, drilldowns & analyst-ready investigation paths.
During the Cisco Live Americas 2026 Agentic SOC, we discovered and investigated suspicious LDAP activity both manually and with the assistance of AI. This helped us understand how the Agentic SOC can improve the threat-hunting process.
At Cisco Live AMER 2026, the Cisco Event SOC turned live operations into education through SOC tours, speaker sessions, and World of Solutions conversations.
A product managerβs view from the Cisco Live SOC on using AI, Splunk ES, and XDR to investigate faster and build better detection and response products.
A Cisco product engineer's first-time journey through the Cisco Live AMER 2026 Security Operations Center β from cabling the "SOC in a Box" on day one to teardown.
Inside the Cisco Live Americas 2026 Agentic SOC, Cisco Security and Splunk Security used evidence-backed AI workflows, human validation, and integrated telemetry to protect, educate, and innovate.
An Agentic Incident Mate that triages a Cisco Extended Detection and Response (XDR) incident end-to-end across XDR, EndaceProbe, and Splunk Enterprise Security, and returns a Tier-2 report in minutes.
Inside the Cisco Live Americas 2026 Agentic SOC, Cisco Security and Splunk Security used evidence-backed AI workflows, human validation, and integrated telemetry to protect, educate, and innovate.