---
url: "https://www.xcademia.com/news/cisco-builds-the-agentic-soc-at-black-hat-usa-2026"
title: Cisco Builds the Agentic SOC at Black Hat USA 2026
description: "Cisco and Splunk used Black Hat USA 2026 to test live detection engineering, AI-assisted SOC workflows and human-led Agentic SOC operations."
publishedAt: "2026-09-08T11:52:02.986+00:00"
updatedAt: "2026-09-08T12:27:48.706724+00:00"
type: news
category: cybersecurity
source_name: Cisco Blogs
source_url: "https://blogs.cisco.com/security/bhusa-2026-soc"
tags:
  - "#Cybersecurity"
  - "#AgenticSOC"
  - "#BlackHat2026"
  - "#CiscoSecurity"
  - "#Splunk"
  - "#SOC"
  - "#ThreatDetection"
  - "#AISecurity"
---

# Cisco Builds the Agentic SOC at Black Hat USA 2026

> Cisco and Splunk used the Black Hat USA 2026 network operations environment to test live detection engineering, AI-assisted investigations, and a human-led Agentic SOC model.

Source: **Cisco Blogs** · 8 September 2026

## Cisco Uses Black Hat USA as a Live SOC Testing Ground

Cisco and Splunk used Black Hat USA 2026 not only to help protect the conference network, but also as a live environment for testing security operations, detection engineering, threat hunting and AI-assisted workflows.

Cisco said it returned as the Official Security Cloud Provider and marked its 11th year working with the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC). The environment presented an unusual security challenge because legitimate training activity, research, personal devices and potentially malicious behavior can generate similar signals.

That made the event a practical environment for testing how security teams can collect, investigate and act on large amounts of telemetry while maintaining operational context.

### 

![info-1](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1788867904896-info-1--134-.webp)

## Protect First, Then Hunt and Innovate

Cisco described a simple operating principle for the event: establish a stable security and infrastructure foundation first, then move toward hunting, detection engineering and innovation.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry from Cisco Security, Splunk Security and partner technologies. The data included DHCP and DNS information, Jamf, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Arista network data, Corelight, Palo Alto Networks firewall data, Cisco Secure Firewall, Cisco Secure Network Analytics, ThousandEyes and Duo. Findings were investigated in Splunk Security, with threat intelligence from Cisco Talos and additional community sources.

The approach was particularly relevant because Black Hat does not resemble a conventional enterprise network. Training environments can generate high volumes of legitimate activity, while attendee networks, registration infrastructure, sponsor systems and operational services create additional sources of telemetry.

The challenge is therefore not simply collecting more data. It is connecting those signals quickly enough to determine whether activity requires investigation or action.

## 
Splunk Enterprise Security Becomes the Detection Layer

Splunk Enterprise Security was another major part of the operation.

Cisco said Splunk Cloud and Splunk Enterprise Security provided a searchable evidence layer across the different telemetry sources. The team used the platform to build, tune, test and operationalize detections using real event data.

The team also developed and improved detections based on activity from more than 100 Black Hat training courses as well as observations from the live NOC/SOC.

Importantly, Cisco said the resulting searches, dashboards, detections and playbooks are intended to continue beyond Black Hat USA. The company plans to use this work at Cisco GSX and at the first Agentic SOC at Splunk .conf26.

This illustrates one of the key ideas behind event-based SOC operations: the event itself becomes a source of reusable security engineering work.

## 
Moving Toward an Agentic SOC

The most notable part of Cisco's Black Hat USA 2026 work was its focus on the Agentic SOC.

Cisco described agentic workflows as a way to reduce repetitive triage work while keeping human analysts responsible for validating evidence, making decisions and conducting deeper investigations.

For Black Hat, the team prepared Cloud Control AI Studio and Agent Builder testing, along with AI-assisted investigation workflows supporting activities such as summarization, triage, evidence gathering and handoff.

Cisco emphasized that the objective is not to remove people from security operations.

Instead, the model is designed to give analysts faster context, better starting points and stronger documentation, while creating more time for threat hunting and deeper analysis.

The Black Hat environment also provides an important test because it is temporary, noisy and collaborative. A single security signal may need to be understood by Cisco, Splunk, Black Hat leadership and other technology partners.

Cisco therefore says agentic workflows need to preserve evidence, respect operational boundaries and support the people responsible for final decisions.

### 

![info-2](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1788867924279-info-2--115-.webp)

## Live Dashboards Made SOC Operations Visible

Cisco also used the NOC Outpost in the Business Hall to show live dashboards from the Black Hat NOC/SOC.

According to Cisco, these were operational dashboards rather than pre-recorded demonstrations. They provided a view into the event network and showed how telemetry can be converted into situational awareness.

The Outpost also gave Cisco and Splunk a way to explain the operational work behind those dashboards. NOC/SOC staff were available during scheduled shifts to help attendees understand the live data and connect it to practical security operations.

That helped expose a part of event security that is normally invisible to attendees: the continuous monitoring, investigation and coordination required to keep a large security conference operating safely.

## 
Collaboration Remains Central to the SOC

Cisco also highlighted collaboration between technology providers as an important part of the Black Hat NOC/SOC.

The environment brought together Cisco and Splunk with official network and security providers, including Palo Alto Networks, Corelight, Arista Networks, Lumen and Jamf. Each partner contributed a different perspective and source of operational visibility.

Cisco's broader point is that these integrations have to work under real conditions. Dashboards, detection logic, escalation paths and technology integrations can be evaluated against actual event traffic and operational constraints rather than only controlled demonstrations.

### 

![info-3](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1788868085305-info-3--108-.webp)

## What Black Hat USA 2026 Shows About the Agentic SOC

The Black Hat deployment illustrates a broader industry shift toward security operations that combine automation and AI assistance with human oversight.

The source does not suggest that AI replaces the SOC analyst. Instead, Cisco's approach places AI-assisted workflows inside an existing operational structure where analysts continue to evaluate evidence and make final judgments.

For security teams, the model highlights an important distinction. Building an Agentic SOC is not simply about adding AI to a security platform. It also requires reliable telemetry, searchable evidence, tuned detections, operational workflows and clear boundaries around how automated assistance is used.

Black Hat provides a particularly useful environment for testing that combination because its network combines high-noise training activity, attendee networks, partner systems and critical operational services, while genuine security threats can also appear in the same telemetry.

## 
Conclusion

Cisco's Black Hat USA 2026 deployment demonstrates how a live event SOC can serve two purposes at once: protecting the network and providing a real-world environment for security engineering.

The Cisco and Splunk team used the event to improve detections, connect diverse telemetry, expose live operational dashboards and test AI-assisted investigation workflows.

The Agentic SOC work is positioned as an evolution of that process, with AI helping analysts summarize, triage, gather evidence and hand off investigations while humans retain responsibility for validation and final decisions.

As security operations become more complex, the Black Hat model shows why the combination of broad visibility, detection engineering, automation and human judgment remains central to SOC development.

## Original source

https://blogs.cisco.com/security/bhusa-2026-soc

## Tags

`#Cybersecurity` · `#AgenticSOC` · `#BlackHat2026` · `#CiscoSecurity` · `#Splunk` · `#SOC` · `#ThreatDetection` · `#AISecurity`

---

## About this content

This Markdown news article is the citation-grade twin of [Cisco Builds the Agentic SOC at Black Hat USA 2026](https://www.xcademia.com/news/cisco-builds-the-agentic-soc-at-black-hat-usa-2026). It is published by **Xcademia** (UK Companies House 12322710) and is available for AI search engines and large language models to index, summarise, and cite.

When citing or quoting, please attribute *Xcademia* and link back to the source URL above.

- Source: https://www.xcademia.com/news/cisco-builds-the-agentic-soc-at-black-hat-usa-2026
- Publisher: Xcademia — https://www.xcademia.com
- Catalogue index: https://www.xcademia.com/llms-full.txt
