This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Le futur est aujourd’hui : Construire le SOC de Demain Alimenté par l’IA – Stratégies pour la détection unifiée, l’automatisation et les opérations de sécurité résilientes

Download resources

About this session

Alexandre Argeris and Didier Turcot-Vezina, both recently joined Splunk (a Cisco company) from operational security backgrounds, present the SOC of the future built around three pillars: AI-driven efficiency, broad-spectrum detection, and unified operations to fix tool sprawl, alert fatigue and manual playbooks. Argeris frames the problem (95 percent of CISOs report a recent incident, dozens of disconnected tools, thin threat-intel context) and previews Splunk's AI layer: an AI Assistant for writing and explaining SPL queries, an Enterprise Security AI Assistant for level-1 triage, Attack Analyzer's LLM-assisted malware reverse engineering, and AI Canvas, a natural-language graphical investigation assistant. Turcot-Vezina then walks a simulated analyst workflow in Enterprise Security 8, prioritizing a finding by risk, pivoting into MITRE ATT&CK coverage and threat-intel enrichment without copy-pasting between tools, running a guided response plan, and triggering a CrowdStrike quarantine playbook through the bidirectional Splunk SOAR integration, closing the incident end to end from one interface. A long audience Q&A covers what the AI does and does not automate (it suggests, but an analyst always confirms disposition), pricing, the new public Splunk MCP server and its data-access guardrails, over 300 SOAR connectors, secret detection in logs, and Cisco product integration.

Les centres d'opérations de sécurité sont à un point critique. Face à des équipes submergées par un nombre toujours grandissant d'alertes et une charge de travail en constante évolution, les approches traditionnelles échouent contre les menaces avancées. Cette présentation explore comment les organisations peuvent transformer leurs SOC à travers trois piliers fondamentaux : l'efficacité pilotée par l'IA afin d'obtenir des gains de productivité significatifs, la révolution d'une détection à large spectre pour la chasse proactive aux menaces et les opérations unifiées pour résoudre le problème des outils de sécurité dispersés qui créent des silos opérationnels. Les participants repartiront avec des stratégies concrètes pour transformer des SOC axés sur la maintenance en opérations de sécurité stratégiques, alimentées par l'IA et capables de devancer les acteurs de menaces sophistiqués en utilisant les solutions Splunk.

Key takeaways

  • Enrich detections with threat-intel and entity context inline rather than making analysts copy-paste indicators into separate lookup tools; it both speeds investigation and reduces error.
  • Treat AI triage suggestions as recommendations an analyst must confirm, not as autonomous dispositions, especially early in adoption where error-handling at scale can create more cleanup work than it saves.
  • Roll out new detection content gradually rather than activating all 1,800+ out-of-the-box rules at once, to avoid flooding analysts with an alert deluge.
  • Use a bidirectional SIEM-SOAR integration so analysts can trigger response actions (like an EDR quarantine) and log evidence directly from the investigation, without switching tools.
  • If exposing your security data lake to an LLM through an MCP server, configure role-based access on the MCP server itself, and add a dedicated AI guardrail layer for genuinely sensitive data.

Speakers

Alexandre Argeris
Alexandre Argeris
Senior Splunk Solution Designer · Splunk
Alexandre has more than 25 years of technical experience in the IT industry with a security focus. Working as a Cyber Security Sales Consultant for 12 years at Cisco, his daily goal was to help customers across Canada to mitigate their cyber… Read moreRead less

Alexandre has more than 25 years of technical experience in the IT industry with a security focus. Working as a Cyber Security Sales Consultant for 12 years at Cisco, his daily goal was to help customers across Canada to mitigate their cyber security challenges using the Cisco Security Solutions. In the last 2 months, he has moved to Splunk, a Cisco company, where he is helping customers with Data Analytics for Security, Observability and AI. Prior to joining Cisco, Alexandre has been implementing security architectures and solutions for many major companies in Canada. He has also spoke at many different BSides Security conferences and present at Cisco Connect across Canada for many years and Cisco Live EU & US for the last 3 years.

Didier Turcot-Vézina
Didier Turcot-Vézina
Senior Security Solutions Architect · Splunk

Resources

Tags

More from GoSec 2025

Also from Alexandre Argeris

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.