The Hunting Imperative: Why AI Shifts the Battlefield Deeper
Tyler Oliver and Richard Olver attended BSides San Francisco and RSA 2026, and the mood was telling. The community is nervous — not just about the adversary, but about its own future. AI is lowering the cost of initial compromise to near zero while post-compromise operations grow quieter and more sophisticated. The AI SOC market promises answers but is still wrestling with trust, integration gaps, and investigations that sprawl beyond any single tool's reach. This is not a piece about despair. It is about where the line actually holds — and why the people doing the hard work of threat hunting matter more now than they ever have.
Richard and I had the opportunity to attend BSides San Francisco and RSA 2026 back to back, and if I am being honest, the experience left us with a lot to process. The conversations, the demos, the hallway catch-ups with old colleagues — all of it pointed toward an industry at an inflection point. This is our attempt to make sense of what we heard, what we saw, and what we think it means for the people doing the hard work of defending organisations every day.
The Mood on the Ground
The tone at the start of the week was striking. Anna Westelius from Netflix delivered a talk that was equal parts sharp and sobering. The puns were excellent, nobody can take that away from her, but underneath the humour was a thread of genuine anxiety that ran through the whole room. The community is nervous. Not just about the adversary, though that concern is well founded, but about something closer to home.
Economic pressure, shrinking budgets, and a vendor and investor community loudly proclaiming that AI is coming for security jobs has left a lot of skilled practitioners questioning their place in the industry they have spent careers building. That fear is not irrational. It is a rational response to a noisy and often irresponsible narrative being pushed from the top down.
We hope this piece gives some of those people a bit of light, both in and at the end of the tunnel.
The Automation Advantage Belongs to the Attacker
The threat landscape has crossed a threshold. AI-assisted reconnaissance and exploitation tools now scan, identify, and compromise vulnerable systems at a scale and speed no human operator could match. The SolarWinds breach illustrated how attackers could systematically target thousands of organisations through a single trusted supplier, moving with precision across victim environments while remaining undetected for months. That operation required significant human planning. The next generation of attacks will not.
Leaked documentation referencing Anthropic's unreleased Mythos model describes systems capable of exploiting vulnerabilities in ways that far exceed the efforts of defenders. Separate research already shows large language models achieving upwards of 90% accuracy on automated penetration testing tasks. Initial compromise is becoming a commodity. The perimeter, as a concept worth defending in isolation, is already obsolete.
The AI SOC: Real Value, Real Limits
The security industry has responded with a wave of AI-powered SOC platforms. The pitch is compelling: ingest telemetry at scale, correlate alerts automatically, reduce analyst workload, and surface the signals that matter faster than any human team could manage alone.
That value is real. AI SOC tooling genuinely reduces alert fatigue, accelerates triage, and handles the high-volume, low-complexity work that previously consumed analyst capacity. Platforms from vendors like CrowdStrike, Microsoft, and a growing field of AI SOC specialists have demonstrated measurable improvements in mean time to detect on known threat patterns. For organisations struggling with analyst shortages and alert overload, these tools provide meaningful relief.
But conversations at RSA 2026 revealed that these vendors are still struggling to gain meaningful traction, and the reasons are instructive.
The first is trust. Giving an AI agent autonomous action, the ability to isolate a host, block a user, or trigger a response workflow, requires a level of confidence that most security leaders are not yet ready to extend. CISOs are right to be cautious about placing autonomous control over critical response actions in systems that cannot yet explain their reasoning in terms a business can audit.
The second is integration. Migrating from an established XDR platform to an AI SOC is not a clean handover. Organisations that have spent years building detection coverage, tuning rules, and establishing baselines cannot afford a visibility gap during transition. Many AI SOC vendors still cannot guarantee continuity of coverage across that move, which stalls procurement conversations before they start.
The third is investigation depth. When an alert escalates into a real incident, investigations rarely stay within a single product boundary. Forensic analysis, endpoint telemetry, identity logs, and data from business applications like ERP and finance systems all become relevant. AI SOC platforms today largely struggle when an investigation crosses those boundaries. Pulling together broader state data from across the business, the kind of context a skilled human investigator instinctively reaches for, remains a largely unsolved problem.
These are not reasons to dismiss the AI SOC category. They are reasons to understand what it can and cannot do today. An AI SOC cannot reason about intent, apply business context to an ambiguous action, or ask whether a set of individually normal behaviours, considered together, represents something that should not be happening. That is not a product deficiency the next software release will close. It is a structural limitation of pattern-based detection applied to an adversary that is actively modelling and evading the patterns.
The Real Problem Starts After the Door Opens
Once an attacker establishes a foothold, they move toward the assets that matter: financial systems, intellectual property, operational technology, cloud control planes. Many of these environments are bespoke, undocumented, or proprietary. They carry no public CVEs and no vendor-published attack signatures. Automated detection tools, trained on known patterns, struggle to generate meaningful signal here.
The 2016 Bangladesh Bank heist demonstrated what happens when attackers understand business context well enough to blend in. Fraudulent SWIFT transfers were structured to mimic legitimate transactions. Automated controls passed them. A human, asking the right question at the right time, caught the anomaly before losses reached their full intended scale. The lesson was not that humans are sufficient alone. It was that human judgment, applied at the right moment, remains irreplaceable.
The Threat of Tomorrow: AI Agents That Never Surface
The assumption that attackers revert to visible human behaviour after initial compromise no longer holds. AI agents can sustain post-compromise operations while actively emulating legitimate user behaviour. They can mirror an employee's working hours, replicate typical data access volumes, pace lateral movement to stay below velocity thresholds, and adjust in real time as detection signals shift.
Consider this scenario. An AI agent compromises a contractor account through an automated credential stuffing campaign against a legacy VPN appliance. Rather than moving aggressively, the agent spends four weeks mapping the target organisation's internal environment. It accesses only what the compromised contractor would plausibly access. It works only during that contractor's observed working hours. It generates no anomaly scores because every individual action falls within the baseline the AI SOC was trained on.
During week five, the agent identifies the organisation's treasury management system. It has learned enough about internal approval workflows to understand which transaction types require dual authorisation and which do not. It begins a slow exfiltration of financial data, structured to remain below the reporting thresholds that would trigger automated review. No alert fires. No human investigates. The organisation discovers the breach six months later during an external audit.
The component capabilities behind this scenario all exist today. What is changing is the integration of those capabilities into persistent, autonomous agents that can operate across an entire intrusion lifecycle without human direction.
RSA 2026: The Offensive Frontier Moves Fast
Armadin, built on the deep red team expertise of former Mandiant practitioners now operating within Google's ecosystem, represents a significant step forward in codifying elite offensive capability into scalable tooling. What previously existed as institutional knowledge inside the world's most respected incident response teams is becoming repeatable, automatable, and accessible at scale.
RSA also served as a reminder of how much talent has spread outward from Mandiant's orbit. It was genuinely great to catch up with colleagues still doing exceptional work within the Mandiant and Google machine. But it was equally energising to see those who have taken the harder road. Evan Pena, formerly of Mandiant and now driving Armadin forward, is a great example of that leap: taking practitioner-grade offensive expertise and channelling it into a product that gives defenders the same clarity about their exposure that the best red teams have always had. The startup path is chaotic by design, but the people making that jump are often the ones closest to where the threat is actually heading.
The Breach and Attack Simulation space, led by vendors like Picus Security, has matured alongside this. BAS platforms continuously test whether defensive controls actually stop the attacks they claim to stop, moving security validation from point-in-time assessments to continuous coverage. That is genuinely valuable. But the same dynamic applies here as across the broader AI SOC market: these tools validate against known techniques. As offensive AI generates novel tradecraft faster than BAS libraries can be updated, the validation gap widens.
The Market Is Messy — But the Signal Is There
The defensive ecosystem is not vapourware, and it is worth saying that clearly. Serious capability exists. Vendors with deep practitioner roots are giving blue teams genuine insight into their own exposure. AI-assisted investigation tooling, when scoped correctly and integrated properly, does accelerate the work of skilled analysts. The key word is augmentation. The tools that earn trust are the ones that make hunters faster and sharper, not the ones that claim to replace them.
But not every vendor on the RSA show floor is solving a real problem. Some products are genuinely transformative. Others are familiar capabilities rebadged with an AI wrapper and a higher price tag. A tool that creates false confidence is more dangerous than no tool at all, and the burden of due diligence on security leaders has never been higher.
What Security Leaders Should Prioritise
The cat and mouse game between red and blue, between those who would compromise and those who defend, has always been the defining dynamic of this industry. AI has changed the speed and scale of that game but not its fundamental nature. Attackers innovate. Defenders adapt. The cycle continues.
What has changed is where the most important moves in that game now happen. Automated tooling handles the edges of the board. The centre, post-compromise, deep environment, bespoke systems, ambiguous behaviour, remains a human and AI problem that requires investment, skill, and judgment.
To the practitioners who left BSides and RSA feeling uncertain about their place in this industry: your judgment, your context, your ability to ask why something does not feel right even when the data says otherwise — that is not being automated away. It is becoming more valuable. The adversary is patient, adaptive, and increasingly invisible. The answer is not more automation alone. It is human expertise, amplified by AI, applied with rigour at depth.
Keep pressure on your vendors. Invest in your hunters. Do not confuse a compelling demo with a solved problem. And do not let the noise convince you that the people doing this work no longer matter. They are, more than ever, the thing that holds the line.