Cisco Builds the Agentic SOC at Black Hat USA 2026
Cisco and Splunk used the Black Hat USA 2026 network operations environment to test live detection engineering, AI-assisted investigations, and a human-led Agentic SOC model.
Xcademia Team
Xcademia Research Team

Cisco Uses Black Hat USA as a Live SOC Testing Ground
Cisco and Splunk used Black Hat USA 2026 not only to help protect the conference network, but also as a live environment for testing security operations, detection engineering, threat hunting and AI-assisted workflows.
Cisco said it returned as the Official Security Cloud Provider and marked its 11th year working with the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC). The environment presented an unusual security challenge because legitimate training activity, research, personal devices and potentially malicious behavior can generate similar signals.
That made the event a practical environment for testing how security teams can collect, investigate and act on large amounts of telemetry while maintaining operational context.

Protect First, Then Hunt and Innovate
Cisco described a simple operating principle for the event: establish a stable security and infrastructure foundation first, then move toward hunting, detection engineering and innovation.
For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry from Cisco Security, Splunk Security and partner technologies. The data included DHCP and DNS information, Jamf, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Arista network data, Corelight, Palo Alto Networks firewall data, Cisco Secure Firewall, Cisco Secure Network Analytics, ThousandEyes and Duo. Findings were investigated in Splunk Security, with threat intelligence from Cisco Talos and additional community sources.
The approach was particularly relevant because Black Hat does not resemble a conventional enterprise network. Training environments can generate high volumes of legitimate activity, while attendee networks, registration infrastructure, sponsor systems and operational services create additional sources of telemetry.
The challenge is therefore not simply collecting more data. It is connecting those signals quickly enough to determine whether activity requires investigation or action.
Splunk Enterprise Security Becomes the Detection Layer
Splunk Enterprise Security was another major part of the operation.
Cisco said Splunk Cloud and Splunk Enterprise Security provided a searchable evidence layer across the different telemetry sources. The team used the platform to build, tune, test and operationalize detections using real event data.
The team also developed and improved detections based on activity from more than 100 Black Hat training courses as well as observations from the live NOC/SOC.
Importantly, Cisco said the resulting searches, dashboards, detections and playbooks are intended to continue beyond Black Hat USA. The company plans to use this work at Cisco GSX and at the first Agentic SOC at Splunk .conf26.
This illustrates one of the key ideas behind event-based SOC operations: the event itself becomes a source of reusable security engineering work.
Moving Toward an Agentic SOC
The most notable part of Cisco's Black Hat USA 2026 work was its focus on the Agentic SOC.
Cisco described agentic workflows as a way to reduce repetitive triage work while keeping human analysts responsible for validating evidence, making decisions and conducting deeper investigations.
For Black Hat, the team prepared Cloud Control AI Studio and Agent Builder testing, along with AI-assisted investigation workflows supporting activities such as summarization, triage, evidence gathering and handoff.
Cisco emphasized that the objective is not to remove people from security operations.
Instead, the model is designed to give analysts faster context, better starting points and stronger documentation, while creating more time for threat hunting and deeper analysis.
The Black Hat environment also provides an important test because it is temporary, noisy and collaborative. A single security signal may need to be understood by Cisco, Splunk, Black Hat leadership and other technology partners.
Cisco therefore says agentic workflows need to preserve evidence, respect operational boundaries and support the people responsible for final decisions.

Live Dashboards Made SOC Operations Visible
Cisco also used the NOC Outpost in the Business Hall to show live dashboards from the Black Hat NOC/SOC.
According to Cisco, these were operational dashboards rather than pre-recorded demonstrations. They provided a view into the event network and showed how telemetry can be converted into situational awareness.
The Outpost also gave Cisco and Splunk a way to explain the operational work behind those dashboards. NOC/SOC staff were available during scheduled shifts to help attendees understand the live data and connect it to practical security operations.
That helped expose a part of event security that is normally invisible to attendees: the continuous monitoring, investigation and coordination required to keep a large security conference operating safely.
Collaboration Remains Central to the SOC
Cisco also highlighted collaboration between technology providers as an important part of the Black Hat NOC/SOC.
The environment brought together Cisco and Splunk with official network and security providers, including Palo Alto Networks, Corelight, Arista Networks, Lumen and Jamf. Each partner contributed a different perspective and source of operational visibility.
Cisco's broader point is that these integrations have to work under real conditions. Dashboards, detection logic, escalation paths and technology integrations can be evaluated against actual event traffic and operational constraints rather than only controlled demonstrations.

What Black Hat USA 2026 Shows About the Agentic SOC
The Black Hat deployment illustrates a broader industry shift toward security operations that combine automation and AI assistance with human oversight.
The source does not suggest that AI replaces the SOC analyst. Instead, Cisco's approach places AI-assisted workflows inside an existing operational structure where analysts continue to evaluate evidence and make final judgments.
For security teams, the model highlights an important distinction. Building an Agentic SOC is not simply about adding AI to a security platform. It also requires reliable telemetry, searchable evidence, tuned detections, operational workflows and clear boundaries around how automated assistance is used.
Black Hat provides a particularly useful environment for testing that combination because its network combines high-noise training activity, attendee networks, partner systems and critical operational services, while genuine security threats can also appear in the same telemetry.
Conclusion
Cisco's Black Hat USA 2026 deployment demonstrates how a live event SOC can serve two purposes at once: protecting the network and providing a real-world environment for security engineering.
The Cisco and Splunk team used the event to improve detections, connect diverse telemetry, expose live operational dashboards and test AI-assisted investigation workflows.
The Agentic SOC work is positioned as an evolution of that process, with AI helping analysts summarize, triage, gather evidence and hand off investigations while humans retain responsibility for validation and final decisions.
As security operations become more complex, the Black Hat model shows why the combination of broad visibility, detection engineering, automation and human judgment remains central to SOC development.
Source: Cisco Blogs
About the Author