CrowdStrike, Cisco and Palo Alto Networks all shipped agentic SOC tools at RSAC 2026 — the agent behavioral baseline gap survived all three

Hey there! Did you catch CrowdStrike CEO George Kurtz’s keynote at RSA Conference 2026? He mentioned that the fastest recorded adversary breakout time has dropped to just 27 seconds. That’s crazy, right? And the average time is now 29 minutes, down from 48 minutes in 2024. Defenders really have their work cut out for them. CrowdStrike sensors are doing some amazing work, detecting over 1,800 distinct AI applications on enterprise endpoints. That’s a whopping 160 million unique application instances generating a ton of data for SIEM systems to handle efficiently.

Meanwhile, Cisco found that 85% of surveyed enterprise customers are experimenting with AI agents, but only 5% have moved them into production. Why the gap? Well, security teams are struggling to answer some basic questions about these agents. It’s a complex landscape out there, as Etay Maor from Cato Networks pointed out at RSAC 2026. We’re diving headfirst into the world of AI, but are we prepared for the challenges it brings?

One interesting point made at the conference was how agents running on enterprise systems can be indistinguishable from human activity in security logs. Elia Zaitsev from CrowdStrike explained how they are tackling this issue by delving deep into process trees to differentiate between agent-controlled processes and human-controlled ones. Without this level of visibility, compromised agents could go undetected, posing a significant threat.

And let’s not forget about the recent ClawHavoc supply chain attack targeting AI agent ecosystems. Kurtz highlighted the dangers of such attacks during his keynote, emphasizing the need for better security measures in the AI space.

So, what can you do to stay ahead of the game? Here are five things you can start doing right now:

  1. Take stock of all the agents running on your endpoints. Knowledge is power!

  2. Make sure your SOC tools can differentiate between agent and human activity.

  3. Align your security architecture with your current SIEM setup.

  4. Develop a baseline for agent behavior to better detect anomalies.

  5. Test your agent supply chain to identify and address vulnerabilities.

Remember, the SOC landscape is evolving rapidly, and it’s crucial to adapt to these changes to protect your systems effectively. Stay vigilant, stay informed, and keep innovating!

Leave a Reply

Your email address will not be published. Required fields are marked *