Redefining Detection Engineering With Interactive AI Agents in the SOC
Overview
| Experience | In Person |
|---|---|
| Track | Cybersecurity |
| Industry | Financial Services |
| Technologies | Genie |
| Skill Level | Intermediate |
| DOWNLOAD SESSION SLIDES | |
AI is transforming how Security Operations Centers (SOCs) operate, with tools that augment detection engineers and analysts to combat threats. We show how one SOC at a major hedge fund adopted AI to enhance detection engineering, accelerating creation, and minimizing response time.
By integrating the Mosaic AI Agent Framework with Databricks Notebooks & Apps, this SOC provided detection engineers an AI assistant within their existing workflow.
This agent accelerates detection baselining, anomaly detection, and filtering false positives while giving engineers control over final logic, ensuring human expertise remains central. The modular architecture enables adding capabilities like MITRE ATT&CK mapping, threat intelligence enrichment, and custom patterns without rewriting core logic.
We demonstrate this assistant and how Databricks AI tools, including Genie and MLflow Evaluation, contribute to faster development, increased efficiency, and shortened response times to emerging threats.
Session Speakers
Chandhana Padmanabhan
/Sr Specialist Solutions Architect
Databricks
Riley Nastase
/Senior AI / ML Engineer
Rearc
Full Summary
Redefining detection engineering with interactive AI agents in the SOC
Security teams face a widening asymmetry: adversaries can pivot in minutes, while high quality detections often take weeks of exploratory work. The conversation argues for agentic AI that speeds up the tedious parts of baselining and rule authoring without displacing the human expertise that makes detections reliable.
FAQ
Not necessarily. Much of baselining can be captured in a handful of parameterized tools, which yields consistent outputs and safer operation. With Lakewatch and Genie, interactive SQL is easier, but expressing guardrails as structured skills still improves quality.
By reframing the agent's objective. Prompts direct the agent to explore data, highlight ambiguities, and return decisions to a human. Backtesting candidate thresholds against historical data helps tune sensitivity before a rule is scheduled.
Analysts guide the agent as it profiles data, proposes segmentations, and evaluates thresholds. At key junctures, such as excluding IT admins or choosing alert thresholds, the agent pauses and defers to human judgment before proceeding.
Yes. The speakers open sourced the skills used in the Lakewatch demo and noted they can be dropped into the .assistant folder for Genie to run the same baselining workflow against your data.
Engineers often write detections differently, which complicates review and maintenance. Encoding common steps as shared tools or skills gives teams consistent building blocks, improving reuse and reducing the cost of collaboration.