Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI SOC automation skills: what this hackathon signals for SOC teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: A hackathon at the AI SOC Summit showed 17 security practitioners building 11 AI SOC agentic skills for alert triage, automated hunts, data enumeration, and report generation, with an average score of 84/100 and a four-point margin between winners, according to Crogl. The pattern suggests SOC teams will need tighter governance around AI-driven workflows, not just faster automation.

NHIMG editorial — based on content published by Crogl: A Deep Dive into Innovation: The AI SOC Summit Hackathon Recap

By the numbers:

Questions worth separating out

Q: How should security teams govern AI SOC agents that use SIEM and EDR tools?

A: They should treat AI SOC agents as controlled investigative systems, not generic automation.

Q: Why do AI SOC skills need identity and access controls beyond standard automation?

A: Because agentic workflows can select data sources, invoke tools, and shape outputs dynamically.

Q: What are the main failure modes when AI generates SOC triage or maturity reports?

A: The biggest failures are weak provenance, overbroad source access, and unreviewed publication.

Practitioner guidance

  • Define explicit tool scopes for each SOC skill Limit each AI SOC skill to the minimum data sources, query functions, and export actions it genuinely needs.
  • Require provenance on every automated triage output Capture which sources were queried, what filters were applied, and which prompt or rule set produced the result.
  • Separate report generation from publication rights Let the agent draft maturity or incident reports, but keep final release under a distinct approval step.

What's in the full article

Crogl's full blog covers the operational detail this post intentionally leaves for the source:

  • Specific descriptions of the winning AI SOC skills and how each one was implemented in the hackathon setting.
  • Judging context for the 11 submissions and the criteria that separated the dual winners from the rest of the field.
  • The practical mechanics behind each automation pattern, including data enumeration, report generation, and alert triage workflows.
  • Crogl's own event recap and follow-on announcements for readers tracking the summit's output.

👉 Read Crogl's AI SOC Summit hackathon recap and the winning agentic skills →

AI SOC automation skills: what this hackathon signals for SOC teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Agentic SOC automation creates a governance problem, not just a productivity gain. Once a workflow can choose tools, enumerate sources, and generate outputs, the control question shifts from speed to scope. The article's examples show how quickly an agent can move from finding data to shaping decisions, which is exactly where provenance and authorisation must stay visible. For practitioners, the lesson is to govern the workflow boundary, not just the model.

A question worth separating out:

Q: How do you know if AI-assisted SOC automation is reliable enough for production?

A: Test whether the same evidence consistently produces the same triage outcome, whether model outputs are explainable to analysts, and whether humans can override decisions without losing audit history. If those three conditions are not true, the workflow is still an assistant, not a dependable operational control.

👉 Read our full editorial: AI SOC hackathon automation points to faster triage and reporting



   
ReplyQuote
Share: