Vvanakor
Back to writing
AI & Security2 min read

What agentic AI actually changes in a SOC

Agentic AISOCAutomation

The part that is actually new

Models that reason about security data are not new. Models that take actions are.

That single shift moves every interesting problem downstream. A model that writes a bad summary wastes an analyst's minute. A model that isolates the wrong host at 02:00 takes out a service. The reasoning quality debate is mostly a distraction from the containment question.

What holds up

Triage, when the agent is allowed to abstain. Most alerts are neither clearly benign nor clearly malicious, and the useful output is often a ranked set of questions rather than a verdict.

Correlation across streams that no human queries together — identity, endpoint, cloud control plane. This is tedious work, it is mechanical, and it is where an agent earns its keep.

Hypothesis generation for hunting. Not the hunt itself. The part where you ask what would this look like if it were happening here, and get twenty framings instead of the three you had.

What does not hold up yet

Autonomous containment without hard blast radius limits. Not because the reasoning is bad, but because the failure is asymmetric — a missed detection costs you time, a bad containment costs you the service.

Anything that depends on the agent being calibrated. Most are not. An agent confident nine times out of ten and correct six times out of ten will train your analysts to ignore it, and they will be right to.

The new surface

An agent with memory has a new thing to attack: not the model, not the tools, the beliefs. Write a false premise into memory and every subsequent decision is downstream of it. Nothing is dropped for a signature to match, and behaviour stays consistent with the premises the agent holds.

I wrote that up properly in MISC 147. The short version is that it is persistence, not exploitation, and most detection stacks are not looking at the layer where it lives.

Where I have landed

Agentic AI is useful in a SOC in roughly the way automation has always been useful: it does the boring part faster than you and makes new mistakes you have not learned to expect yet.

Build the guardrails before the capability. It is the same lesson every time, and it is ignored every time.

Back to writing