Reduced Breakout Time Demands an Agentic SOC
For security teams to keep up with their adversaries, it’s becoming clear they must enable AI agents within the SOC. “We need to start to move to investigations at machine speed,” Sentonas said. “This is why the old SOC model is broken in many ways.”
Current models frequently involve separate human agents tackling endpoint security, identity security and cloud security. When an attacker has the capability to move in minutes or less, organizations can’t afford to spend hours on an investigation. That’s where the agentic SOC comes in.
With an agentic SOC, there would still be agents working on endpoint, identity and cloud security. But they would work simultaneously and collaboratively, speeding up the process because they’re sharing memory and information.
“No handoffs, no waiting, no starting over,” Sentonas said. “That’s the difference between a collection of agents and an agentic SOC. Not working independently, but working together in that shared space, giving you the ability to stay in control.”
DISCOVER: Find out how mature your security posture is with a self-assessment.
CrowdStrike Is Already Helping Organizations Create Agentic SOCs
According to Austin Murphy, vice president of managed services at CrowdStrike, “We started working on our agentic workflows over a year ago.”
“The agents that are powering the agentic SOC are created by Falcon Complete because it’s what we’ve been using behind the scenes for us, and now there’s an opportunity to expand the number of customers that can benefit from what we’ve built to help ourselves become more efficient, more consistent,” Murphy said.
Murphy anticipates that the agentic SOC will change the roles of defenders and the ways they interact with agents. He referenced the often-repeated phrase “human in the loop,” which he said means that “agents can only take you so far, and then it escalates to a human to finish up if it ever gets stuck.”
But he also mentioned “human on the loop,” which is a concept he said CrowdStrike is working on internally. He noted that the current state of AI was trained on data produced when humans were performing the work. “Well, if they stop performing the work, we’re going to lose the data to train the next version. So, when we refer to human on the loop, we have a human analyst parallel working the same detection that an agent does.” This approach allows CrowdStrike to perform data comparisons between the human and the agent and continually maintain and improve the agents.
