generative AI for data analysis

Agentic SOC tools arrive as attacker dwell times hit new lows.

At RSA Conference 2026, CrowdStrike, Cisco, and Palo Alto Networks all introduced advanced agentic SOC tools, yet a significant gap in agent behavioral baselines persists across their offerings.

4 min readVentureBeat
Agentic SOC tools arrive as attacker dwell times hit new lows.

The security industry loves a good race, but the one playing out in front of us is a sprint where the finish line keeps moving. Attackers have already broken out of the network in 27 seconds, and the average dwell time has collapsed to 29 minutes. That is not a warning about tomorrow; it is the operating reality of today. Meanwhile, the tools we built to defend against human adversaries are now staring down a wall of machine-speed activity that looks identical to the humans they were designed to protect. The vendors at RSAC 2026 offered two distinct architectural paths forward, but neither one answers the question that should be keeping every CISO up at night: what does normal agent behavior actually look like in your environment?

Let's be direct about what CrowdStrike and Cisco/Splunk are really selling. Approach A, embedding AI agents inside the SIEM, gives you faster triage and guided response. Approach B, pushing detection upstream into the ingestion pipeline, reduces the noise before it hits the analyst queue. Both are useful. Both are necessary. But neither vendor shipped an agent behavioral baseline. That is not a minor oversight; it is the gap that will define the next wave of security failures. You can automate triage all day, but if your detection rules are built on the assumption that an agent acting like a human is normal, you have not solved the problem. You have just made the false positives faster. The process tree lineage CrowdStrike walks to distinguish agent from human activity is clever, and the runtime protection Palo Alto Networks is building matters, but they are reactive controls. They catch the agent that already went rogue. They do not tell you what a compromised agent is supposed to look like before it acts.

The practical takeaway for security leaders is uncomfortable but actionable. You cannot wait for a vendor to define normal for you. You have to build that baseline yourself, starting with a simple inventory. Do you know which of the 1,800 AI applications CrowdStrike detects are running on your endpoints? Can your SOC stack tell the difference between Louis launching Chrome from his desktop and an agent doing it on his behalf? If the answer is no, your triage rules are applying the wrong behavioral models to the wrong activity. The supply chain risk is just as pressing. DefenseClaw scans skills before deployment, and CrowdStrike catches compromised skills at runtime, but no single vendor covers the full lifecycle. You need both layers, and you need to pressure-test your playbook against the reality that an authorized agent can execute unauthorized actions at machine speed.

The 27-second breakout time is not a problem for the SOC to solve alone. It is a governance problem that starts with the board. The vendors have given you the tools to keep up, but they have also handed you the responsibility to define what acceptable agent behavior means in your organization. If you do not know which agents are running, what they are authorized to do, and who is accountable when one goes wrong, you are not ready to deploy them in production. The gap between the 85% of enterprises piloting AI agents and the 5% that have moved to production is not a technology gap. It is a trust gap, and no SIEM migration or pipeline detection feature is going to close it for you. Start with the inventory. Build the baseline. Rewrite the playbook. The next 90 days will determine whether your SOC operates in this reality or gets buried under it.

From VentureBeat

CrowdStrike CEO George Kurtz highlighted in his RSA Conference 2026 keynote that the fastest recorded adversary breakout time has dropped to 27 seconds. The average is now 29 minutes, down from 48 minutes in 2024. That is how much time defenders have before a threat spreads. Now CrowdStrike sensors detect more than 1,800 distinct AI applications running on enterprise endpoints, representing nearly 160 million unique application instances. Every one generates detection events, identity events, and data access logs flowing into SIEM systems architected for human-speed workflows.

Read the original at VentureBeat