Program Sikkerhetsfestivalen 2026

Incident Management

Multi-Agent Orchestration to Catch Bad Guys

Tirsdag 9 · Victoria Scandic, sal 3

EnglishDeep-dive 40 min

Eirik Sveen

Eirik Sveen

Lead Detection Engineer @ Storebrand

Eirik currently works as a "Lead Detection Engineer" at Storebrand. He has previously worked as a "Red Team Operator" at the Danish company Banshie specializing in red teaming and TIBER, and as the "Red Team Lead" at Orange Cyberdefense Norway. Eirik is a senior security consultant specializing in red teaming, threat actor emulation, and cloud and infrastructure security. Eirik loves to (responsibly) break into clients' systems and enjoys combining social manipulation with modern phishing and payload delivery techniques. Eirik is one of the hosts of the Norwegian security podcast "5H3LLcast" and has previously given talks at both at Sikkerhetsfestivalen and Hackcon.

This talk walks through building an (actually useful) multi-agent pipeline for security operations on top of Sentinel Data Lake, Sentinel MCP, Triage, Security Copilot, Claude, custom internal MCPs, tools, Agent Skills and personas.

From initial "How can we use AI to assist in detection engineering? How viable is AI for prototyping, work in progress queries, sanity checks, quality control?" to an end-to-end "Agentic SOC workflow" that can assist almost every function in SecOps with alert and incident investigation, triage, threat hunting, threat research, detection gap analysis, tuning and rule creation, all by itself.

Built on Eirik's own offensive and defensive expertise, the rest of SecOps's knowledge, experience, playbooks, ways of working, internal and external context, references, prompts, personas and instructions, offensive security and threat actor datasets, our own rulesets and over 10,000 external detection and threat hunting rules from public repositories, with the investigations and threat hunts visualized in a custom dashboard.

The talk covers the architecture, the multi-agent workflow, what the agents actually do (with demos), how safeguards and constraints prevent the system from going off the rails, and honest lessons learned about where AI agents are actually good at security work and where they are certainly not. Attendees will get a concrete understanding of how to build something like this, what good actually looks like, and whether this approach makes sense for your team.

Come see our multi-agent team assist our human heroes in catching some bad guys.

  1. Insecure Vibes: The Risks of AI-Assisted Coding 1 · Frimurerlosjen, rom 1
  2. When defenders go low, we go high(level) - bypassing application control using stage 1 beacons 1 · Frimurerlosjen, rom 2
  3. PQC-migrasjon for store virksomheter 10 · HeartBox ,Teatersalen
  4. Hawaii Pizza – How dare you? (or do I really care?) 10 · HeartBox, Byscenen
  5. Sikkerhetskrav i randsonen: Slik treffer sikkerhetskravene underleverandørene 11- Breiseth, Storlon
  6. A Recipe for Resilience: Using Purdue and IEC 62443 to Secure Europe's Food Supply 2 · Home hotel Hammer, moen nede
  7. The Endpoint that walks: Mobile Devices as Physical Security Risks 2 · Home hotel Hammer, moen oppe
  8. Innsiderisiko: forskningsperspektiver og foreløpige funn 3 · Hvelvet, Gullsalen
  9. Sykt mange sikkerhetskrav i offentlig anskaffelse: Må det være sånn? 4 · Kommunestyresalen, Lillehammer rådhus
  10. En felles IAM-virkelighet for offentlig sektor, er det mulig? 5 · Kulturhuset Banken, Expedisjon
  11. Maritime næring i skuddlinjen - erfaringer fra dagene da USA og Israel angrep Iran 5 · Kulturhuset Banken, Festsalen
  12. Når tiden forsvinner. Strategier for fremtidens digitale beredskapsarbeid 5 · Kulturhuset Banken, Holbøsalen
  13. AI i digital etterforskning 5 · Kulturhuset Banken, Kafeen
  14. Maverick RiskJockey: en AI-drevet CISO-funksjon 6 · Lillehammer kino, sal 2
  15. 10 «dumme» spørsmål - og hva de avslører om sikkerhetskulturen 6 · Lillehammer kino, sal 4
  16. Podcast O3C 7 · Microbryggeriet
  17. Et tu, vendor? A story of vendor ransomware leaks and heartaches 9 · Victoria Scandic, sal 1+2