Enhancing Threat Detection and Response Automation in SOCs through Agentic Large Language Models
  • 분류 2026년 2월
  • 작성일 2025.10.20
  • 작성자 이스마일
  • 조회수 128

Cyber defense operations face escalating complexity, demanding intelligence, scalability, and adaptive automation. We introduce two core contributions toward next-generation SOC systems:
(1) Security Event Response Copilot (SERC): an AI-powered framework integrating Retrieval-Augmented Generation (RAG) with Large Language Models (LLMs) for contextual, real-time security event reasoning. Trained on structured threat intelligence and incident data, SERC enhances precision, reduces analyst workload, and improves response speed.
(2) Agentic-LLM Hyper-Automation SOAR: a scalable, self-adapting orchestration engine that replaces rigid rule-based playbooks with dynamic, AI-generated workflows. This system autonomously adjusts to threat evolution, ensuring continuous efficiency in incident triage and mitigation.

Together, these innovations redefine SOC automation by merging intelligent retrieval with adaptive orchestration, advancing the field toward AI-driven, hyper-automated security operations capable of evolving alongside emerging cyber threats.