Black Hat USA 2026: Constructing the Agentic SOC, One Stay Occasion at a Time

Cisco was proud to return to Black Hat USA because the Official Safety Cloud Supplier and the longest-standing accomplice of the Black Hat Community Operations Heart (NOC) and Safety Operations Heart (SOC). In 2026, we accomplished our eleventh yr serving to shield the Black Hat community, working facet by facet with the Black Hat NOC leaders and official know-how companions: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.
The primary mission of the NOC/SOC is straight ahead: preserve the convention community working safely and reliably. Black Hat is a novel atmosphere. It brings collectively trainings, briefings, safety researchers, distributors, companions, press, attendees, and a variety of non-public and managed units. Exercise that will be alarming on a company community is anticipated in a coaching room, whereas actual threats can nonetheless seem in the identical telemetry. That’s what makes the Black Hat NOC/SOC such a robust proving floor for safety operations.
This yr, the Cisco and Splunk crew not solely protected Black Hat USA, but additionally used the chance to study, validate, and construct. Our work targeted on stay NOC/SOC visibility, Splunk Enterprise Safety detection engineering, menace looking, malware and artifact evaluation, AI safety, and Agentic SOC improvement that may carry ahead into Cisco GSX, Splunk .conf26, and future occasion SOCs.
Shield First, Then Hunt and Innovate
Cisco offers crucial infrastructure to the Black Hat NOC/SOC, and our first duty is to ensure these methods are working correctly and built-in with the broader accomplice atmosphere. Solely after the muse is secure will we shift extra consideration to looking, detection engineering, and innovation. The NOC management enabled Cisco and different companions to introduce further pre-approved software program and {hardware} options, enhancing our inner effectivity and increasing our visibility capabilities; nonetheless, Cisco will not be the official supplier for Prolonged Detection & Response, Safety Occasion and Incident Administration, Firewall, Community Detection & Response or Collaboration.
For Black Hat USA 2026, the Cisco and Splunk crew introduced collectively telemetry and workflows throughout Cisco Safety, Splunk Safety, and partner-provided community and safety controls. Splunk ingested logs included DHCP, DNS from Cisco Safe Entry, Jamf, Splunk Assault Analyzer, Cisco Safe Malware Analytics, Arista community information, Corelight, Palo Alto Networks firewall information, Cisco Safe Firewall, Cisco Safe Community Analytics, ThousandEyes and Duo. Findings have been investigated in Splunk Safety, with menace intelligence supplied by Cisco Talos, and licenses donated by alphaMountain, Pulsedive, and StealthMole; together with neighborhood sources.
That breadth of telemetry is vital as a result of the Black Hat atmosphere doesn’t behave like a standard enterprise. There are high-noise coaching networks, public attendee networks, registration and occasion infrastructure, sponsor methods, cloud dependencies, and significant operational providers. The worth of the NOC/SOC comes from becoming a member of these indicators rapidly sufficient to grasp what is going on and whether or not motion is required.
Splunk Enterprise Safety as Proof and Detection Engineering Layer
A significant focus our crew at Black Hat USA 2026 was Splunk Enterprise Safety (ES) in motion. Splunk Cloud and Splunk ES gave our crew a searchable proof layer throughout various telemetry sources, whereas Splunk ES offers a spot to construct, tune, take a look at, and operationalize detections from actual occasion information.
The crew constructed and improved detections from the 100-plus Black Hat coaching programs and from stay NOC/SOC observations. These detections not solely shield Black Hat USA, but additionally will likely be used at Cisco GSX and the primary Agentic SOC at Splunk .conf26. This is without doubt one of the strongest values of the occasion SOC mannequin: the work doesn’t finish when the occasion closes. Searches, dashboards, detections, playbooks, and classes realized change into reusable content material for the subsequent deployment.
Advancing the Agentic SOC
Black Hat USA 2026 can also be a improvement atmosphere for the Agentic SOC. At Cisco Stay Americas 2026, we noticed a brand new working mannequin emerge: agentic workflows can scale back repetitive triage work, whereas human analysts validate proof, make judgment calls, and concentrate on higher-value investigation. Black Hat offers us a really totally different proving floor for that very same construction.
For this occasion, the crew ready Cloud Management AI Studio and Agent Builder testing, together with AI-assisted investigation workflows that assist summarization, triage, proof gathering, and handoff. The objective is to not take away people from safety operations. The objective is to make the human work higher: sooner context, higher beginning factors, stronger documentation, and extra time for menace looking and deeper evaluation.
The Black Hat NOC/SOC is a very vital place to check this mannequin as a result of the atmosphere is noisy, momentary, and extremely collaborative. The identical sign might must be understood by Cisco, Splunk, Black Hat management, and accomplice groups. Agentic workflows are solely helpful in the event that they protect proof, respect operational boundaries, and assist the people chargeable for the ultimate determination.
Stay Dashboards within the NOC Outpost
For attendees on the Enterprise Corridor, the NOC Outpost included stay dashboards from the Black Hat NOC/SOC. These dashboards weren’t canned demonstrations. They present the operational heartbeat of the occasion community and assist attendees perceive how telemetry turns into situational consciousness.
The Outpost gave the crew a option to clarify the story behind the dashboards: Cisco and Splunk are serving to function and shield an actual occasion community, whereas additionally utilizing that atmosphere to check detection engineering, workflow integration, and the subsequent technology of SOC operations. Employees from the NOC/SOC have been obtainable within the sales space throughout scheduled shifts to assist translate the stay information into sensible safety operations classes.
The NOC Outpost helped make the hidden work of the NOC/SOC seen, explainable, and helpful to the broader Black Hat neighborhood.
Collaboration Throughout the Black Hat NOC/SOC
Black Hat is without doubt one of the uncommon environments the place direct opponents work collectively as a result of the mission is greater than any single vendor. The community has to work, the occasion must be protected, and the NOC/SOC should be capable to examine rapidly when one thing uncommon seems.
Cisco and Splunk work alongside the official community and safety suppliers. Every accomplice brings a special vantage level. The worth comes from operationalizing these vantage factors in a brief setup window, then utilizing them collectively below actual circumstances.
That collaboration can also be why Black Hat continues to be such an vital innovation atmosphere. Integrations, dashboards, escalation paths, and detection logic are examined towards actual site visitors, actual constraints, and actual accomplice workflows. The work is sensible as a result of the atmosphere calls for it.
Learn the Crew Tales
Our crew printed a sequence of blogs that go deeper into the applied sciences, investigations, and improvements from the occasion:
Acknowledgments
Thanks to the Cisco and Splunk NOC/SOC crew getting ready, working, looking, engineering, documenting, and supporting Black Hat USA 2026:
- Agentic SOC Innovation/{Hardware}: Ryan Maclennan and Aditya Sankar
- Splunk Enterprise Safety: Josh Wilson
- Splunk Safety Analysts: Jake Ruddy and Danny Rodriguez, Jr.
- DNS/SOC Analysts: Steve Vida and Kaustubh Vajarkar
- ThousandEyes/Firewall: Adam Kilgore, Alex Guckin and Matthew Bair (Packsize)
- Splunk IR: Tony Iacobelli (Doordash)
- NOC/SOC Dashboards – Enterprise Corridor: Erik Dove and Arshad Saeed
- Distant Help – Integrations: Ivan Berlinson
- Distant Help – Detections: Nasreddine Bencherchali and Onur Erdogan
- Distant Help – SOC Analyst: Aditya Raghavan and Cam Dunn
Thanks additionally to the Black Hat NOC management and our accomplice groups throughout the occasion. The power of the Black Hat NOC/SOC comes from collaboration: engineers, analysts, product groups, companions, and occasion leaders working collectively in a high-pressure atmosphere with a shared mission. Palo Alto Networks (particularly James Holland and Jason Reverri), Corelight (particularly Mark Overholser and Eldon Koyle), Arista Networks (particularly Landon Harsh), Lumen, Endace (particularly Michael Morris and Cary Wright), Jamf (particularly Adam Derrick) and your entire Black Hat / Informa Tech employees (particularly Grifter ‘Neil Wyler’, Bart Stump, Steve Fink, James Pope, Michael Spicer, Jess Jung and Steve Oldenbourg).
About Black Hat
Black Hat is the cybersecurity business’s most established and in-depth safety occasion sequence. Based in 1997, these annual, multi-day occasions present attendees with the most recent in cybersecurity analysis, improvement, and developments. Pushed by the wants of the neighborhood, Black Hat occasions showcase content material immediately from the neighborhood by means of Briefings displays, Trainings programs, Summits, and extra. Because the occasion sequence the place all profession ranges and educational disciplines convene to collaborate, community, and talk about the cybersecurity matters that matter most to them, attendees can discover Black Hat occasions in the USA, Canada, Europe, Center East and Africa, and Asia. For extra info, please go to www.BlackHat.com.



