Tag: soc
-
AI SOC vs Traditional SOC: What’s the Difference?
The debate over AI SOC vs traditional SOC has moved from theoretical to urgent. Security teams face record alert volumes, a persistent analyst shortage, and adversaries who now automate their attacks while the traditional Security Operations Center, built on manual triage and rule-based tooling, struggles to keep pace. The AI-powered SOC is the response: First…
-
AI SOC vs Traditional SOC: What’s the Difference?
The debate over AI SOC vs traditional SOC has moved from theoretical to urgent. Security teams face record alert volumes, a persistent analyst shortage, and adversaries who now automate their attacks while the traditional Security Operations Center, built on manual triage and rule-based tooling, struggles to keep pace. The AI-powered SOC is the response: First…
-
CISA Red Team Fully Compromised Two Critical Infrastructure Orgs
CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain control and had their cloud environments compromised. One of them didn’t know until CISA…
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide…
-
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here’s how to choose. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/choose-your-fighter-balancing-competing-requirements-to-select-models-for-your-ai-soc/
-
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an enterprise-wide compromise. The August 25 advisory contrasts two critical-infrastructure organizations: one missed the intrusion entirely, while the other contained initial access quickly but still exposed major identity and cloud security weaknesses.…
-
The Best Agentic SOC for CrowdStrike in 2026 (and Where Charlotte AI Fits)
The 8 best agentic SOC platforms for CrowdStrike Falcon in 2026, compared. What Charlotte AI’s agents do today, how credits work, and where the gap is. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-best-agentic-soc-for-crowdstrike-in-2026-and-where-charlotte-ai-fits/
-
How to Run a Recurring DDoS Testing Program
A practical guide to setting the cadence, onboarding the SOC, closing findings, and working with your testing vendor between engagements Running DDoS testing as a recurring program means linking every planned simulation to remediation, retesting, SOC training, and the next material change in the environment. Unlike a one-off project, it does not end when the……
-
The agentic SOC: How to build machine-speed defense for the AI era
First seen on scworld.com Jump to article: www.scworld.com/resource/the-agentic-soc-how-to-build-machine-speed-defense-for-the-ai-era
-
Wazuh and AI For Enhanced SOC Workflows
Artificial Intelligence (AI) has become one of this decade’s defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate First seen on thehackernews.com Jump…
-
SOC 2 vs HIPAA Pentest Requirements for HealthTech Startups
Key Takeaways SOC 2 does not explicitly name penetration testing as mandatory, but auditors expect one in practice for any company handling sensitive data at scale. HIPAA does not name penetration testing as a required control either, it requires a risk analysis, and a pentest is the most common way companies demonstrate one was performed…The…
-
SOC 2 vs HIPAA Pentest Requirements for HealthTech Startups
Key Takeaways SOC 2 does not explicitly name penetration testing as mandatory, but auditors expect one in practice for any company handling sensitive data at scale. HIPAA does not name penetration testing as a required control either, it requires a risk analysis, and a pentest is the most common way companies demonstrate one was performed…The…
-
Cribl Acquires AI Assets from Radiant Security to Further SOC Ambitions
Cribl this week revealed it has acquired technology assets from Radiant Security that will provide the foundation for building a security operations center (SOC) based on artificial intelligence (AI). The AI technologies acquired from Radiant Security enable AI agents to autonomously triage, investigate, and resolve security alerts. Cribl, via the acquisition of this intellectual property,..…

