The alert problem every SOC knows
Security operations centers are drowning in alerts. Volume grows faster than teams can hire; many of those alerts turn out to be false positives, and yet everyone still must be looked at. Under that load, the alerts that matter get delayed or missed — and the cost shows up as analyst burnout, inconsistent decisions, slow response, and dangerous dwell time for real threats. You can’t simply hire your way out of it, because experienced analysts are scarce and expensive. This is precisely the gap agentic AI is built to close.
Instant Attack Verification: an AI security analyst
At the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst. When a detection fires, it investigates the way a human tier-1 or tier-2 analyst would: it gathers the relevant evidence, examines the devices and users involved, reasons over the logs, decides whether the alert is a real threat or a false positive, judges scope and impact, recommends what to do, and writes up a full report that shows it’s working. The ambition behind it is straightforward but bold — 100x scalability, quality, and speed in security operations, achieved by pairing human expertise with AI rather than replacing it.
From triage to investigation
SOC work is tiered, and the capability covers both tiers in a single automated flow. As a tier-1 analyst, it triages the incoming flood: it ingests every detection, so nothing sits unreviewed, enriches each alert with context, filters out the noise of false positives, and prioritizes what is real. As a tier-2 analyst, it runs the deeper investigation that triage escalates — correlating evidence across endpoint, network, cloud, and identity data, reconstructing a timeline and an incident graph of how events connect, determining how far a threat spread, classifying the incident, and recommending both immediate containment and longer-term hardening. It documents all of it with a full evidence trail. In effect, it compresses a loop that normally spans several people and hours into one automated pipeline, escalating to a human wherever judgment or authority is required.
Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.
AI-generated analysis with full evidence traceability in a single pane of glass — the narrative links entities, indicators, and MITRE techniques inline for the analyst to verify.
How do we measure success?
Building an agentic SOC analyst is a product problem as much as a modeling one. The technology can already triage and investigate; whether it delivers comes down to three things — trust earned through measured accuracy and explainability, resilience against adversaries, and thoughtful human oversight. Get that right, and the economics follow.
Measuring success starts with one central tension: automation rate versus concordance. Automation rate — the share of alerts handled with no human — tells the capacity story. Concordance — how often the agent’s verdict matches a human analyst — tells the trust story. The discipline is never letting the first outrun the second. Beneath them, effectiveness is precision and recall, and above all false negatives: the catastrophic miss of a real threat. Operationally, you watch time-to-investigate, throughput, and reliability.
The economy is simple to frame. Take the cost of one investigation by a human versus the agent, multiply by volume and automation rate, then subtract the sustaining costs you can’t avoid — evaluation, monitoring, and the human oversight that remains. Faster triage adds a second saving by shrinking dwell time, which lowers expected breach cost.
But the economy only holds on two guardrails. The first is adversarial safety, and it’s non-negotiable because a security agent’s inputs are attacker-controlled: treat every piece of evidence as untrusted data rather than instructions, isolate tenants and privileges, gate high-impact actions behind a human, and red-team continuously. The second is human-in-the-loop design, which is how trust becomes real — autonomy earned incrementally, consequential actions kept gated, and analyst corrections fed back as a learning loop. Trust, in the end, is the currency that unlocks the economics.
Where Instant Attack Verification meets the Cisco Data Fabric
Cisco Data Fabric, powered by the Splunk Platform and generally available since August 2026, is an architecture — not a product — for connecting data, context, and action across domains so that both people and AI agents can reach the right data and act on it safely. Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly. Federated Search could let the capability reach data in place across S3, Azure, Snowflake, and Databricks instead of maintaining bespoke connectors. The Machine Data Lake offers durable, low-cost retention for both live evidence and the stable datasets it needs to evaluate itself. The Catalog helps agents discover the right data rather than assume fixed sources. AI Canvas is a natural home for investigations and their approvals. And the Splunk MCP Server is the interoperability layer that lets the capability orchestrate the fabric — or be called an agent.
The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is a specialized agent that runs on top of it. One answers how to reach the right data cheaply across everything and let agents act safely; the other answers how to investigate a security detection like a seasoned analyst. They are complementary layers — and it is exactly the kind of agentic action the Data Fabric exists to enable.