This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Beyond the Alert: How Agentic AI Is Rewriting the SOC Playbook

Download resources

About this session

Patrick Moubarak, a CrowdStrike solutions engineer based in Montreal, argues traditional security operations centres cannot keep pace with AI-accelerated adversaries and sets out a path to what he calls the agentic SOC. He opens with CrowdStrike's own threat intelligence: a North Korea-linked group it tracks using mainstream AI tools such as ChatGPT, Gemini and GitHub Copilot to fake identities and land remote IT jobs inside Western companies, part of an 89 percent year-over-year rise in AI-enabled attacks and a shrinking "breakout time" between initial access and lateral movement. He frames today's SOC problems as three gaps, context, staffing and speed, produced by dozens of disconnected tools, roughly ten thousand daily alerts and 20-to-40-minute manual triage. His fix replaces siloed telemetry with one unified, AI-ready data platform where purpose-built agents for threat hunting, investigation and orchestration run inside human-defined guardrails, moving analysts from being "in the loop" to being "on the loop." He cites CrowdStrike's own managed-detection metrics and closes with a three-step model: onboard the data, operationalize it, then orchestrate agentic response, comparing the shift to progressively autonomous self-driving cars.

The traditional SOC is drowning—too many alerts, too few analysts, and adversaries moving at machine speed. What if your SOC could think, reason, and act autonomously? In this session, we'll explore how CrowdStrike's agentic AI transforms security operations from reactive triage to proactive, self-driving defense. Discover how AI agents investigate threats, correlate signals, and take action in seconds—freeing your team to focus on what humans do best. Come see the future of the SOC, and leave knowing how to start building it today.

Key takeaways

  • Expect AI-enabled adversaries to use mainstream tools like ChatGPT, Gemini and Copilot for recon, fake personas and job fraud, not only for writing malware; treat this as routine tradecraft.
  • Consolidate telemetry into one normalized, AI-ready data plane before automating; bolting agents onto dozens of siloed tools only speeds up the existing 'swivel chair' triage problem.
  • Shift from human-in-the-loop to human-on-the-loop: let agents complete well-defined, low-risk investigative tasks end to end, and reserve human sign-off for actions with real business impact.
  • Put guardrails, accountability and explainability in place before scaling automation; CrowdStrike frames unclear governance as the main reason agentic SOC pilots stall at proof of concept.
  • Track breakout time, not just alert count, as the real pressure metric: some intrusions now reach lateral movement in seconds, faster than manual triage can respond.

Speakers

Patrick Moubarak
Patrick Moubarak
Cybersecurity Expert · CrowdStrike
Patrick Moubarak est un expert en cybersécurité au sein de l'équipe d'ingénierie de solutions chez CrowdStrike. Il compte plus de 18 ans d'expérience en réseaux, cybersécurité et protection des identités. Il accompagne les organisations dans… Read moreRead less

Patrick Moubarak est un expert en cybersécurité au sein de l'équipe d'ingénierie de solutions chez CrowdStrike. Il compte plus de 18 ans d'expérience en réseaux, cybersécurité et protection des identités. Il accompagne les organisations dans l'adoption de nouvelles technologies pour accomplir la mission d'arrêter les brèches. Basé à Montréal, Patrick est titulaire d'un diplôme en génie informatique de l'Université McGill et de plusieurs certifications professionnelles."

Resources

Photos

Tags

More from GoSec 2026

Also from Patrick Moubarak

On the same topic