Call For Paper - Presentations

Lessons learned while building an Agentic SOC: The good, the bad, and the scary.
2026-09-10 , Großer Saal

The AI powered SOC is coming whether you are ready or not, as attackers use AI to accelerate their operations we have to also go faster. Moving from a traditional SOC to an "Agentic" SOC is often pitched as a magic bullet for SOC automation, but because you can't stop your SOC sometimes the process feels like upgrading your engine while going 200 km/h on the Autobahn, and the upgrades you make are sometimes superseded the moment you add it.

This talk bypasses the AI hype to share the real internal journey at Elastic as we integrated AI agents and processes into our daily SecOps. I'll talk about the Agentic Boundary: the point where the agent stops and the human starts, the lessons learned when building the agents, and how to connect your data to the agents. I'll cover the 'good' where AI Agents are doing amazing things like L1 triage and timeline creation, the 'bad' where agents used a bunch of time and tokens to provide mediocre or wrong results, and some of the 'scary' such as how AI agents can turn on you to be the cause of a security incident instead of a helper. This talk will also address the scariest AI topic of them all: 'will this replace me?'

Aaron Jewitt is a Principal Detection Engineer on the Elastic Infosec team. A 20-year security veteran with 10 years of offensive experience at the NSA and 10 years of experience defending networks, he specializes in detection engineering and high-velocity automation. Aaron is currently leading internal efforts to integrate AI agents into daily SecOps. Aaron lives in Germany and is a two-time speaker at BSides Frankfurt, dedicated to sharing practical, real-world lessons from the front lines of defense.