Articles

September 7, 2026

SECURITY

Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

8 min read

At Black Hat USA, we used Splunk Detection Editor Alpha to turn Cisco SNA alarms into risk events with context, drilldowns & analyst-ready investigation paths.

July 7, 2026

SECURITY

AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026

7 min read

An Agentic Incident Mate that triages a Cisco Extended Detection and Response (XDR) incident end-to-end across XDR, EndaceProbe, and Splunk Enterprise Security, and returns a Tier-2 report in minutes.

June 15, 2026

SECURITY

Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia

1 min read

At Black Hat Asia, we tested a private AI SOC workflow built with Ollama, NVIDIA GPU acceleration, Open WebUI, OpenClaw, DefenseClaw, Cisco AI Defense and MCP integrations, with Splunk audit visibility.