By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: AnomaliPublished October 20, 2025

TL;DR: AI-enhanced threat actors can now scale attacks far beyond manual handling, driving alert overload and making legacy SIEM and response models increasingly costly and slow, according to Anomali. The real challenge is no longer whether teams can analyse more data, but whether their detection and response model can keep pace with AI-amplified volume.


At a glance

What this is: This is Anomali’s analysis of how AI is increasing attack volume, overwhelming manual security operations, and pushing defenders toward modern data and response platforms.

Why it matters: It matters because SOC, IAM, and security architecture teams must now treat alert volume, automation, and response speed as governance problems, not just tooling choices.

By the numbers:

  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

👉 Read Anomali's analysis of AI-driven threats and modern SOC response


Context

AI-driven threats change the operating assumptions behind modern detection and response. When attackers can generate large volumes of activity at machine speed, the limiting factor becomes analyst attention, triage quality, and whether telemetry can be searched and acted on quickly enough. In that environment, AI-driven threats become a governance issue for security programmes, not just a detection problem.

The article also sits near the boundary between SOC operations and identity governance because automation only helps when defenders can confidently map activity back to users, workloads, and privileged access paths. Where AI is used on the attacker side, the corresponding defence question is whether identity, data, and alert workflows are already instrumented well enough to keep up.


Key questions

Q: How should security teams use AI to reduce SOC alert fatigue without losing coverage?

A: Use AI to gather context and prioritise investigation, not to suppress uncertainty. The best pattern is machine-speed enrichment across identity, endpoint, cloud, and history signals, followed by human review for ambiguous or high-impact events. That preserves coverage while reducing repetitive analyst work and prevents static tuning from hiding real attack paths.

Q: Why do AI-driven attacks change SOC operating assumptions?

A: They compress attacker cycles from days or weeks into hours or minutes, which breaks the assumption that defenders have time to investigate before acting. When the adversary iterates faster than human review, the SOC has to shift from ticket-driven response to policy-driven execution with tight controls around privilege and approval.

Q: What breaks when analysts cannot search historical telemetry quickly?

A: What breaks is incident scoping. Without fast historical search, teams cannot connect related events, reconstruct attacker behaviour, or prove how far an intrusion spread. That slows containment and makes post-incident decisions less accurate. Search performance and retention therefore become operational controls, not just data-management choices.

Q: What should organisations do when AI increases vulnerability volume?

A: They should harden the remediation pipeline before adding more discovery capacity. That means clear ownership, automated routing, retest verification, and metrics that show whether exposures actually closed. Without that foundation, AI simply magnifies the backlog and makes existing workflow defects more visible to leadership.


Technical breakdown

Why AI-driven threat volume breaks manual SOC models

AI-assisted attackers can generate scripts, phishing attempts, scans, and follow-on actions at a scale that manual workflows were never designed to absorb. The key issue is not only speed, but consistency: machine-generated activity produces many similar events, which makes pattern recognition harder and pushes analysts into repetitive triage. Legacy SIEM approaches that depend on human review of each alert become brittle when alert volume rises faster than staffing or process maturity. Practical implication: SOC teams need automation that prioritises and enriches events before analysts see them.

Practical implication: prioritise automated enrichment, deduplication, and alert suppression before adding more analysts.

How modern data access changes threat hunting

Modern defence depends on being able to query large telemetry sets quickly enough to reconstruct attacker behaviour across weeks or months. If defenders cannot search historical data at speed, they lose the ability to identify indicators of compromise, correlate related events, and prove scope during an investigation. AI can help here by turning natural-language questions into faster searches and by surfacing patterns that would be expensive to find manually. Practical implication: the search layer matters as much as the detection layer, especially for retrospective hunts.

Practical implication: build search and retention capability for retrospective hunting, not just live alerting.

Why alert fidelity is now a resilience control

Alert fidelity is the degree to which security alerts reflect meaningful risk rather than noise. In high-volume environments, poor fidelity creates operational drag, response fatigue, and missed incidents. AI-assisted enrichment and workflow automation can improve fidelity by grouping related events, adding context, and routing only higher-value cases to analysts. That does not remove the need for human judgement, but it changes where human time is best spent. Practical implication: measure detection quality by actionability, not only by raw alert count.

Practical implication: track actionability and analyst effort per incident as core resilience metrics.


Threat narrative

Attacker objective: The attacker objective is to overwhelm defender visibility and increase the chance that malicious activity persists long enough to achieve fraud, intrusion, or exfiltration.

  1. Entry begins with AI-assisted mass scanning, scripted probing, or phishing that can be generated and launched at very high volume.
  2. Escalation follows when defenders struggle to separate signal from noise, giving attackers more time to hide in routine activity and widen their foothold.
  3. Impact is delayed detection, higher investigation cost, and weaker containment because analysts cannot manually review the full event stream in time.

NHI Mgmt Group analysis

AI-driven threat volume is becoming a control problem, not just a tooling problem. When attackers can scale activity faster than analysts can triage it, the security programme is measured by its ability to absorb noise, not just detect compromise. That makes response architecture, queue design, and automation governance part of core defence. Practitioners should treat alert volume as a resilience indicator, not an operational inconvenience.

Alert fidelity is the real currency of modern SOC performance. Raw event counts tell teams little unless those events can be prioritised into meaningful cases. AI-assisted enrichment can improve fidelity, but only if the underlying telemetry is trustworthy and the response workflow is tuned to reduce analyst drag. The practical conclusion is that detection quality must be judged by how fast it leads to containment, not by how many alerts are produced.

Machine-speed attacks expose a broader identity and access governance gap. In many environments, defenders still struggle to link suspicious behaviour to the user, workload, or privilege path that enabled it. That means identity context is part of SOC effectiveness, especially where service accounts, API keys, and automation tokens are involved. The stronger the identity map, the less attacker noise can hide in plain sight.

Legacy SIEM economics are increasingly misaligned with AI-amplified threat conditions. When pricing, retention, and manual triage all assume bounded event growth, AI-driven attack volume makes the cost model unstable. The issue is not simply that systems are old, but that the operating assumptions behind them no longer hold. Practitioners should reassess whether their telemetry architecture still matches their threat model.

Modern defence needs an analytics layer that turns scale into decision advantage. AI in security only matters when it shortens investigation time, improves context, and reduces the number of cases that require full human review. That shifts the governance question from “can we add AI?” to “where does AI materially change analyst throughput and response quality?” Teams should place that question at the centre of programme design.

What this signals

AI-driven attacks will keep pushing security teams toward architectures that optimise for triage throughput rather than raw event capture. That means programme owners should care less about whether a platform can store more data and more about whether it can turn noisy telemetry into defendable decisions fast enough to matter.

Alert-fidelity debt: when every new attacker technique adds more noise than the SOC can suppress, the organisation accumulates a hidden operations burden. Teams should watch for analyst burnout, missed escalations, and rising cost per incident as early signs that the current model no longer matches the threat environment.


For practitioners

  • Automate first-pass triage Use enrichment, deduplication, and severity scoring to collapse repetitive alerts before they reach analysts. The goal is to reserve human time for cases with verified risk, not for sorting identical low-value events. Build the workflow around alert fidelity and measurable reduction in analyst touches.
  • Expand retrospective hunt capability Make sure analysts can query months or years of telemetry quickly enough to reconstruct attacker behaviour after initial detection. Search performance, retention, and index design should support incident scoping, not just live monitoring.
  • Map alerts to identity context Connect suspicious activity to the user, workload, API key, or service account that generated it so investigations are not isolated from access governance. This is especially important where automation and non-human identities create ambiguous attribution.
  • Reassess SIEM economics against current threat volume Test whether current storage, ingestion, and response costs still make sense under AI-amplified attack conditions. If volume growth is driving spend faster than response value, the architecture may need redesign rather than incremental tuning.

Key takeaways

  • AI-driven threat activity is forcing security teams to treat alert overload as a governance problem, not just a staffing issue.
  • The operational gap is speed to decision, because manual triage cannot keep pace with machine-generated attack volume.
  • Teams that improve enrichment, search, and identity context will contain more incidents with less analyst drag.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous monitoring and detection are central to handling AI-driven alert overload.
NIST SP 800-53 Rev 5SI-4System monitoring is directly implicated when attackers generate high volumes of noisy activity.
CIS Controls v8CIS-8 , Audit Log ManagementLog management becomes more valuable when defenders need rapid retrospective hunting.
MITRE ATT&CKTA0007 , Discovery; TA0011 , Command and Control; TA0040 , ImpactThe article describes adversaries using AI to scale scanning, probing, and operational overload.

Strengthen CIS-8 so historical telemetry is searchable enough for fast scoping and incident reconstruction.


Key terms

  • Alert Fidelity: Alert fidelity is the degree to which security alerts represent meaningful risk instead of noise. High fidelity helps analysts focus on incidents that need action. In practice, it depends on correlation quality, enrichment, and the accuracy of detection logic.
  • Indicator Of Compromise: A measurable sign that suspicious or malicious activity may have occurred, such as an IP address, hash, domain, email, or credential artifact. In operational programmes, an IOC only matters when it can be normalized and used in detection or response workflows.
  • Telemetry Retention: Telemetry retention is how long security logs, events, and related data are kept for investigation and compliance. Longer retention supports retrospective hunting and incident reconstruction, but only if search performance and indexing are strong enough to make the data usable.

What's in the full article

Anomali's full post covers the operational detail this post intentionally leaves for the source:

  • How its Copilot workflow turns analyst questions into search queries for threat hunting and investigation.
  • Examples of using AI to search historical data lakes for indicators of compromise across months or years.
  • The cost and migration arguments the webinar used to compare legacy SIEM with a modern defence model.
  • The practical workflow changes discussed for automating enrichment, routing, and low-complexity cases.

👉 Anomali's full post covers the webinar discussion, AI-assisted hunting workflow, and migration arguments in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader security programmes they already run.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org