Om sesjonen
This talk walks through building an (actually useful) multi-agent pipeline for security operations on top of Sentinel Data Lake, Sentinel MCP, Triage, Security Copilot, Claude, custom internal MCPs, tools, Agent Skills and personas.
From initial "How can we use AI to assist in detection engineering? How viable is AI for prototyping, work in progress queries, sanity checks, quality control?" to an end-to-end "Agentic SOC workflow" that can assist almost every function in SecOps with alert and incident investigation, triage, threat hunting, threat research, detection gap analysis, tuning and rule creation, all by itself.
Built on Eirik's own offensive and defensive expertise, the rest of SecOps's knowledge, experience, playbooks, ways of working, internal and external context, references, prompts, personas and instructions, offensive security and threat actor datasets, our own rulesets and over 10,000 external detection and threat hunting rules from public repositories, with the investigations and threat hunts visualized in a custom dashboard.
The talk covers the architecture, the multi-agent workflow, what the agents actually do (with demos), how safeguards and constraints prevent the system from going off the rails, and honest lessons learned about where AI agents are actually good at security work and where they are certainly not. Attendees will get a concrete understanding of how to build something like this, what good actually looks like, and whether this approach makes sense for your team.
Come see our multi-agent team assist our human heroes in catching some bad guys.