At Cisco Live Americas 2026, a SOC team investigated suspicious LDAP activity potentially indicating a SharpHound Active Directory reconnaissance attack. Using an Agentic SOC architecture that combined Cisco XDR, Splunk Enterprise Security, and Endace full packet capture via a Model Context Protocol (MCP) server, they built a Tier-2 AI analyst agent that autonomously pulled incident context, retrieved relevant packets, queried Splunk logs, and produced a structured threat assessment report. The agent concluded the activity was a benign near-miss, saving hours of manual analysis. Notably, the agent self-corrected a time-field error on its second pass and wrote the lesson back into its skill file. The post details the architecture, integration approach, and how AI-assisted analysis accelerated decision-making for analysts of all experience levels.