Research seriesL3offensive security
A sophisticated attacker who knows the defender runs an autonomous SOC stops evading signatures and starts evading the pipeline itself: crafting telemetry to manipulate the LLM triage analyst, constructing behavior statistically indistinguishable from baseline, flooding the alert queue to bury a true positive, and weaponizing the SOC's autonomous responder to quarantine production systems. This threat lab analyzes the autonomous SOC detection-triage-investigation-response pipeline as an adversarial attack surface — the threat model for each vector, how each attack degrades SOC effectiveness, and the countermeasures and architectural controls that raise the cost. Grounded in MITRE ATLAS, OWASP Agentic Security Initiative, NIST AI RMF, and the adversarial machine-learning literature.
Attacker-crafted SIEM events and EDR telemetry can manipulate LLM-based SOC triage analysts — a named, understudied attack surface with formal countermeasures.
When an attacker optimizes their actions to match the defender's behavioral baseline, statistical anomaly detection converges toward random guessing — a named, formal limit with specific countermeasures.
Autonomous SOC triage has a finite attention budget; three adversarial strategies — flooding, suppression, and priority gaming — exploit that budget as a structural attack surface.
An attacker who triggers a deliberate false positive in an autonomous SOC can cause the defender's own response automation to quarantine production systems, revoke valid credentials, or block critical network paths.
An attacker who can corrupt forensic artifacts before the LLM investigator ingests them can redirect the incident narrative, suppress the attack's true scope, and embed false conclusions in the official record.