{"slug": "black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time", "title": "Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time", "summary": "Cisco completed its 11th year as the official Security Cloud Provider and NOC/SOC partner at Black Hat USA 2026, protecting the conference network alongside Palo Alto Networks, Arista, Corelight, Jamf, and Lumen. The Cisco and Splunk team used the event to develop and validate detections for Splunk Enterprise Security, with a focus on building an Agentic SOC that will be showcased at Cisco GSX and Splunk .conf26.", "body_md": "Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the [Black Hat Network Operations Center](https://blackhat.com/us-26/noc.html) (NOC) and Security Operations Center (SOC). In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.\n\nThe first mission of the NOC/SOC is straight forward: keep the conference network operating safely and reliably. Black Hat is a unique environment. It brings together trainings, briefings, security researchers, vendors, partners, press, attendees, and a wide range of personal and managed devices. Activity that would be alarming on a corporate network is expected in a training room, while real threats can still appear in the same telemetry. That is what makes the Black Hat NOC/SOC such a powerful proving ground for security operations.\n\nThis year, the Cisco and Splunk team not only protected Black Hat USA, but also used the opportunity to learn, validate, and build. Our work focused on live NOC/SOC visibility, Splunk Enterprise Security detection engineering, threat hunting, malware and artifact analysis, AI protection, and Agentic SOC development that will carry forward into Cisco GSX, Splunk .conf26, and future event SOCs.\n\n## Protect First, Then Hunt and Innovate\n\nCisco provides critical infrastructure to the Black Hat NOC/SOC, and our first responsibility is to make sure those systems are operating properly and integrated with the broader partner environment. Only after the foundation is stable do we shift more attention to hunting, detection engineering, and innovation. The NOC leadership enabled Cisco and other partners to introduce additional pre-approved software and hardware solutions, enhancing our internal efficiency and expanding our visibility capabilities; however, Cisco is not the official provider for Extended Detection & Response, Security Event and Incident Management, Firewall, Network Detection & Response or Collaboration.\n\nFor Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls. Splunk ingested logs included DHCP, DNS from Cisco Secure Access, Jamf, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Arista network data, Corelight, Palo Alto Networks firewall data, Cisco Secure Firewall, Cisco Secure Network Analytics, ThousandEyes and Duo. Findings were investigated in Splunk Security, with threat intelligence provided by Cisco Talos, and licenses donated by [alphaMountain](https://www.alphamountain.ai/), [Pulsedive](https://pulsedive.com/), and [StealthMole](https://www.stealthmole.com/); along with community sources.\n\nThat breadth of telemetry is important because the Black Hat environment does not behave like a normal enterprise. There are high-noise training networks, public attendee networks, registration and event infrastructure, sponsor systems, cloud dependencies, and critical operational services. The value of the NOC/SOC comes from joining those signals quickly enough to understand what is happening and whether action is required.\n\n## Splunk Enterprise Security as Evidence and Detection Engineering Layer\n\nA major focus our team at Black Hat USA 2026 was Splunk Enterprise Security (ES) in action. Splunk Cloud and Splunk ES gave our team a searchable evidence layer across diverse telemetry sources, while Splunk ES provides a place to build, tune, test, and operationalize detections from real event data.\n\nThe team built and improved detections from the 100-plus Black Hat training courses and from live NOC/SOC observations. These detections not only protect Black Hat USA, but also will be used at Cisco GSX and the first Agentic SOC at Splunk .conf26. This is one of the strongest values of the event SOC model: the work does not end when the event closes. Searches, dashboards, detections, playbooks, and lessons learned become reusable content for the next deployment.\n\n## Advancing the Agentic SOC\n\nBlack Hat USA 2026 is also a development environment for the Agentic SOC. At [Cisco Live Americas 2026](https://blogs.cisco.com/security/clamer-soc-2026), we saw a new operating model emerge: agentic workflows can reduce repetitive triage work, while human analysts validate evidence, make judgment calls, and focus on higher-value investigation. Black Hat gives us a very different proving ground for that same structure.\n\nFor this event, the team prepared Cloud Control AI Studio and Agent Builder testing, along with AI-assisted investigation workflows that support summarization, triage, evidence gathering, and handoff. The goal is not to remove humans from security operations. The goal is to make the human work better: faster context, better starting points, stronger documentation, and more time for threat hunting and deeper analysis.\n\nThe Black Hat NOC/SOC is a particularly important place to test this model because the environment is noisy, temporary, and highly collaborative. The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner teams. Agentic workflows are only useful if they preserve evidence, respect operational boundaries, and support the humans responsible for the final decision.\n\n## Live Dashboards in the NOC Outpost\n\nFor attendees at the Business Hall, the NOC Outpost included live dashboards from the Black Hat NOC/SOC. These dashboards were not canned demonstrations. They show the operational heartbeat of the event network and help attendees understand how telemetry becomes situational awareness.\n\nThe Outpost gave the team a way to explain the story behind the dashboards: Cisco and Splunk are helping operate and protect a real event network, while also using that environment to test detection engineering, workflow integration, and the next generation of SOC operations. Staff from the NOC/SOC were available in the booth during scheduled shifts to help translate the live data into practical security operations lessons.\n\nThe NOC Outpost helped make the hidden work of the NOC/SOC visible, explainable, and useful to the broader Black Hat community.\n\n## Collaboration Across the Black Hat NOC/SOC\n\nBlack Hat is one of the rare environments where direct competitors work together because the mission is bigger than any single vendor. The network has to work, the event has to be protected, and the NOC/SOC must be able to investigate quickly when something unusual appears.\n\nCisco and Splunk work alongside the official network and security providers. Each partner brings a different vantage point. The value comes from operationalizing those vantage points in a short setup window, then using them together under real conditions.\n\nThat collaboration is also why Black Hat continues to be such an important innovation environment. Integrations, dashboards, escalation paths, and detection logic are tested against real traffic, real constraints, and real partner workflows. The work is practical because the environment demands it.\n\n## Read the Team Stories\n\nOur team published a series of blogs that go deeper into the technologies, investigations, and innovations from the event:\n\n## Acknowledgments\n\nThank you to the Cisco and Splunk NOC/SOC team preparing, operating, hunting, engineering, documenting, and supporting Black Hat USA 2026:\n\n- **Agentic SOC Innovation/Hardware** : Ryan Maclennan and Aditya Sankar\n- **Splunk Enterprise Security:** Josh Wilson\n- **Splunk Security Analysts** : Jake Ruddy and Danny Rodriguez, Jr.\n- **DNS/SOC Analysts** : Steve Vida and Kaustubh Vajarkar\n- **ThousandEyes/Firewall:** Adam Kilgore, Alex Guckin and Matthew Bair (Packsize)\n- **Splunk IR** : Tony Iacobelli (Doordash)\n- **NOC/SOC Dashboards – Business Hall** : Erik Dove and Arshad Saeed\n- **Remote Support – Integrations** : Ivan Berlinson\n- **Remote Support – Detections** : Nasreddine Bencherchali and Onur Erdogan\n- **Remote Support – SOC Analyst** : Aditya Raghavan and Cam Dunn\n\nThank you also to the Black Hat NOC leadership and our partner teams across the event. The strength of the Black Hat NOC/SOC comes from collaboration: engineers, analysts, product teams, partners, and event leaders working together in a high-pressure environment with a shared mission. **Palo Alto Networks** (especially James Holland and Jason Reverri), **Corelight** (especially Mark Overholser and Eldon Koyle), **Arista Networks** (especially Landon Harsh), **Lumen**, **Endace** (especially Michael Morris and Cary Wright), **Jamf** (especially Adam Derrick) and the entire **Black Hat / Informa Tech** staff (especially Grifter ‘Neil Wyler’, Bart Stump, Steve Fink, James Pope, Michael Spicer, Jess Jung and Steve Oldenbourg).\n\n## About Black Hat\n\nBlack Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit [www.BlackHat.com](http://www.blackhat.com/).", "url": "https://wpnews.pro/news/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time", "canonical_source": "https://blogs.cisco.com/security/bhusa-2026-soc", "published_at": "2026-09-07 15:00:58+00:00", "updated_at": "2026-09-07 15:26:21.023208+00:00", "lang": "en", "topics": ["ai-agents", "ai-products", "ai-infrastructure"], "entities": ["Cisco", "Splunk", "Black Hat USA", "Palo Alto Networks", "Arista", "Corelight", "Jamf", "Lumen"], "alternates": {"html": "https://wpnews.pro/news/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time", "markdown": "https://wpnews.pro/news/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time.md", "text": "https://wpnews.pro/news/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time.txt", "jsonld": "https://wpnews.pro/news/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time.jsonld"}}