Skip to content
Live Agentic SOC at .conf26 Protects Attendees Amid Dynamic Threats

Live Agentic SOC at .conf26 Protects Attendees Amid Dynamic Threats

First seen 8 Oct 2026, 23:42 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 00:39 UTC
  • •The Agentic SOC protected over 5,145 attendees at .conf26 using advanced security technologies.
  • •AI agents assisted human analysts in triaging alerts and gathering evidence without replacing their judgment.
  • •The event demonstrated the challenges of cybersecurity in dynamic environments with high traffic and unmanaged devices.

During Splunk.conf26 in Denver, a live Agentic Security Operations Center (SOC) was established to protect over 5,145 attendees from various cybersecurity threats. The SOC utilized Cisco and Splunk technologies to monitor multi-gigabit traffic and respond to security incidents in real-time. Analysts faced the challenge of distinguishing benign anomalies from malicious activity in a high-throughput environment filled with unmanaged devices. The SOC architecture included autonomous triage agents, which assisted human analysts in evidence gathering and decision-making. The event highlighted the importance of maintaining a secure network while ensuring a seamless attendee experience. No specific CVEs or were reported, but the event served as a proving ground for innovative security operations. The SOC's mission was to protect first and innovate later, emphasizing the role of human analysts in validating AI-generated insights.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
Live SOC operational at .conf26
The SOC protected attendees and monitored traffic during the conference, utilizing Cisco and Splunk technologies.
Blogs.Cisco
2026-10-08
AI Triage Agent utilized
AI agents helped analysts summarize findings and prepare for investigations, enhancing the SOC's efficiency.
Blogs.Cisco

More articles in this cluster (9)

Following this threat?

Track Corepack and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What technologies were used in the SOC?
The SOC utilized Cisco Cloud Control, Splunk Enterprise Security, and Endace telemetry for threat detection and response.
How did the SOC handle false positives?
Analysts were trained to discern benign anomalies from malicious activity, minimizing false-positive alerts.
What was the main goal of the SOC at .conf26?
The primary goal was to protect the network and attendees while allowing for innovation in security operations.