I’m a little surprised with one of the statements given in huggingface‘s report.
“To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events.”
17,000 events? Big whoop. Security teams of medium sized companies process millions of events daily.
There’s a big debate in the cyber industry about the AI SOC and whether or not it’s necessary. It seems to me they are using that report to push that idea.
Agree. The F100s I contract with are easily pushing billions if not trillions.
Many of them have tried the LLM triage/SOC Analyst to…varying success.
One opened a legit P2 a few days ago actually. Great work right? Upon closer inspection it had decided this activity was a false positive for a solid month before.
The compromise (not significant in the end) was well done and over with by that point.
Others are swamped in so many FPs being bubbled up as true positives that they essentially just ignore it.
Given this is HuggingFace, I'd expect that's less about thought leadership and more using what they know well, in a critical situation.