At Cisco Live Americas 2026, a SOC team investigated suspicious LDAP activity potentially indicating a SharpHound Active Directory reconnaissance attack. Using an Agentic SOC architecture that combined Cisco XDR, Splunk Enterprise Security, and Endace full packet capture via a Model Context Protocol (MCP) server, they built a Tier-2 AI analyst agent that autonomously pulled incident context, retrieved relevant packets, queried Splunk logs, and produced a structured threat assessment report. The agent concluded the activity was a benign near-miss, saving hours of manual analysis. Notably, the agent self-corrected a time-field error on its second pass and wrote the lesson back into its skill file. The post details the architecture, integration approach, and how AI-assisted analysis accelerated decision-making for analysts of all experience levels.

8m read timeFrom blogs.cisco.com
Post cover image
Table of contents
Full Packet Data – A gold mine for Agentic AIAgentic AI Augmented ArchitectureInvestigating a Potential SharpHound AttackAgentic AI Massively Speeds our AnalysisBuilding SkillsConclusionAcknowledgements
84 Impressions