Cisco's 'Instant Attack Verification' agentic AI framework was deployed during Cisco Live EMEA 2026 to automate SOC Tier 1/2 analyst tasks including log collection, threat intelligence enrichment, and incident classification. Over the event week, the system autonomously triaged 179 incidents, correctly dismissing 176 as false positives and surfacing 3 genuine threats — including a camera authentication bypass campaign and a Talos-flagged C2 connection — with MITRE ATT&CK mappings and confidence scores. The result: analyst workload equivalent to a full week was reduced to reviewing three pre-analyzed reports. The system is positioned as a force multiplier, not a replacement, with humans retaining final judgment.

5m read timeFrom blogs.cisco.com
Post cover image
Table of contents
Instant Attack VerificationHow did Instant Attack Verification do at Cisco Live EMEA 2026?Oh, it’s the cameras! (again…)Concluding

Sort: