The Agentic SOC Mindset: Why the Future Requires More Than Just Technology
In this blog
Intro
To set the record straight, this is not another reading on analyst fatigue, expensive SIEMs and data gaps. While those problems are ever present, I want to focus on the problems that we are seeing with customers all over the world in the agentic era.
For decades, the SOC has largely been a reactive body built on static correlation rules and known IOCs from threat intelligence feeds. This approach worked reasonably well when attackers moved at human speed, giving analysts the time needed to detect, triage and respond before significant damage occurred. However, today's landscape is outpacing that model. Bad actors are automating their workflows, living off the land and leveraging AI to move through the kill chain at machine speed, resulting in break-out speeds that went from days and hours to minutes.
The gap between traditional detection and modern attacks continues to widen. Reactive defense and signature-based methods alone can no longer keep pace with today's threat landscape. The focus needs to shift towards ML-driven anomaly detection and behavioral analysis. But detection alone isn't enough. Identifying a threat in real time means little if the response can't move at that same speed. And here lies the heart of the SOC problem in the agentic era.... machine speed mindset. Please don't think that AI SOC solutions will magically fix all of your issues out of the box. What they do, however, is give teams the toolsets they need to move faster.
Mindset 1: Shift in detection engineering
The speed of new frontier attacks must be matched with alerting and responding at the same pace. As defenders, we no longer have the upper hand where break-out times took 1-4 hours. Decisions now must happen in minutes, and the only way to keep pace is to embrace AI securely, with a clear understanding of what data is protected and which assets are truly your business's crown jewels.
The days of stopping breaches with static correlations and hash matching will never cease to exist, but it's effectiveness is another story entirely. Detection engineering has shifted from alerting on what's known to surfacing what's unknown. The need for ML-driven anomaly detection at machine speed has never been higher. Within anomalous behavior detection, there are three categories worth exploring: entity-centric analysis, temporal analysis and peer grouping.
Entity centric
Instead of looking at alerts as isolated events, we need to look at the entities that are generating them, and doing so requires a behavioral baseline. The question we are no longer asking is, "Is this activity malicious?". Instead, we now ask, "Is this activity abnormal for this entity?". This distinction matters enormously in an agentic SOC. AI agents need a stable baseline before they can reason and flag deviations with confidence. By tying detections to the entity rather than the event, AI can catch subtle indicators of attack that static, event-based correlation rules would never surface. It's also foundational to the trust-building process. Entity baselines give the AI agent and the analyst a shared reference point, making it easier to validate whether agents' determination makes sense for that entity.
Temporal analysis
Where entity-centric analysis asks the question, "is this normal for this specific entity," temporal analysis asks, "does the timing, sequence, or speed of this activity make sense?" Instead of profiling a single entity, temporal analysis looks at the overall picture across time. It takes into account how quickly actions take place, in what order and how that compares to what is expected. This is where machine speed attacks become visible in ways entity-based baselines alone can miss. A compromised account might behave in ways that's technically normal for that user, but the speed at which reconnaissance, privilege escalation and lateral movement occur reveals an attack humans can't do manually.
In an AI SOC, temporal analysis allows detections to catch the compression of the attack chain through metrics like the speed that actions occur and time of day. Together, entity-centric and temporal analysis complement each other. One asks whether the actor's behavior fits their own history. The other asks whether the pace and pattern of events fit reality.
Peer grouping
Instead of comparing an entity's behavior to its own baseline, peer grouping takes a different approach. The question shifts from, "Is normal for a specific user?" to, "Does this make sense compared to others in the same role or group?" We can say this is a comparative baseline instead of individual.
In an AI SOC, peer grouping gives agents a wider frame of reference, reducing false positives from noisy endpoints and evolving behavior. These 3 types of detections form a layered approach: one grounded in individual history, one in pace and sequence and one in comparison to its peers. Together, this gives AI the context needed to separate real threats from common noise.
Mindset 2: Shift in tolerance for automation
The rollout process for an agentic SOC will look different for every organization, and in the early stages, AI won't be a magic button. Instead, it'll be a magnifying glass that shines a spotlight on current operations. If your team lacks solid response processes, workflows and data management, your new AI powered SOC will be a Ferrari that you can only drive 15 mph.
Trust in AI agents remains one of the biggest hurdles to overcome, and it becomes a severe limiting factor in most organizations, especially when underlying processes aren't mature enough to support them. But when those foundations are already in place, teams can validate agent decisions against consistent, well-defined workflows instead of trying to hit a moving target. This is the starting block of building trust within.
Building foundations
As I mentioned earlier, a critical step before diving into the AI SOC is internal preparation. Having actions, workflows and playbooks in place is going to be the plumbline that all things AI/Automation are measured against. Ideally, these are concepts that have been tried and tested, giving your team an idea of what "normal" is supposed to look like. When you have a baseline established, this allows teams to hand over these tasks to an agent with a method of determining if the outcomes are what were expected or not. Without comparables to reference, analysts have no reliable way to judge whether those results are correct.
Pilot automation
Once foundations are established and teams have a baseline of expected outcomes, we can begin to roll out pilot automations. The goal is not to merely push all workflows to an agent, but to test a limited set and monitor the results. Take what would be considered "low risk" tasks to your organization and insert a human in the loop approval process at the end before actions are taken.
Review
A critical aspect of the next stage is reviewing the output. For low-risk actions, the initial push will be up front, but reviewing the outcomes will be a continual process, especially as more advanced cases are handed to agents. This is where we begin to see a lot of the T1 analysts' work shift: from initial triage activity to agent tuning. All their time in the hot seat gives them the experience needed to know if agents are outputting the proper results. If they are, you can move to a more autonomous function with confidence. However, if they are not, we need to re-examine workflows, find out where steps are going wrong and tune the expected outputs.
Implementation
When your agents begin to produce expected outcomes, AI can begin to consume more of the larger use cases. Maybe the pilot test was against a defined user group or network block; perhaps now it's time to safely expand that scope. You've done your homework. You've tested and tuned the agents. Now is the time to loosen the grip. When teams have a hard time automating, they get stuck in the Ferrari going 15mph. It's great to alert in real time, but triaging and remediating at machine speed is the new bar.
Now, this was just a crash course into automating and building trust with agents. The strategy for this can go much deeper. For much more depth, I'd highly recommend that you look at the Argus Series created by my teammate Zach Carnes: "ARGUS: A Framework for Autonomous Blue Team Operations" and "There's No Maturity Model for Autonomous Containment. So we Built One"
Mindset 3: The shift from static playbooks
For years, SOCs have leveraged playbooks as both the brain dump and the central nervous system of operations that allowed teams to capture institutional knowledge and direct analysts on how to respond. Playbooks have facilitated continuity, standardized processes and ensured consistency in how cases are resolved and documented. They brought order to chaos and helped new analysts transition to the team.
The downside is that this model begins to break down in the Agentic SOC era. Playbooks were largely based on a "if this, then this" model where static correlations drove most of the outputs. The shift in detection engineering adds a new layer of complexity to this by surfacing alerts and activity that no playbook has been created for. How can a team write a playbook for something they never wrote a detection for?
Today, we are seeing agents begin to gather context, reason and recommend next steps based on their investigation. Instead of manually updating documentation when a non-standard occurrence takes place, agents are dynamically creating the playbooks to best fit the activity surfaced based on the integrations and tool sets accessible to it. In successful organizations, we are seeing playbooks shift to processes centered on reviewing and tuning agent outputs rather than continuing to build on a monolithic approach.
Don't hear what I am not saying. I am not recommending that a team gets rid of their current playbooks. Most have a purpose and will play a pivotal role in baseline creation. However, I am saying that if we want to mature and be capable of keeping up with attacks at machine speed, centering playbooks needs to gravitate towards agent outputs. Accepting more risk with automation only works if the playbooks themselves keep pace, evolving alongside the agents rather than lagging behind them
Summary
Unfortunately, a "one size fits all" answer to most problems in the SOC doesn't exist, and that is what WWT's SOC of the Future discussion targets. Great teams build around people, process and technology: not the other way around. At the core of every successful organization are thought leaders: Teams of people that know the pain, look ahead, break molds and evolve as fast as the enemy.