Ismael Valenzuela
SANS webcast artwork for The Agentic SOC, featuring Ismael Valenzuela

SANS Webcast · September 8, 2026

The Agentic SOC: Defending With, and Against, Autonomous AI

Ismael Valenzuela

Can an attacker hijack an AI agent’s intent and turn its legitimate access against you?

What this session covers.

An agentic SOC uses AI agents to triage alerts, investigate threats, and take response actions. Once those agents can make decisions and use tools, we need to be clear about whose instructions they follow, where their authority stops, and how we verify the results.

In this SANS Institute webcast, I explore how an attacker can hijack an AI agent’s intent and turn its legitimate access against the defender. That includes indirect prompt injection, where instructions embedded in content such as a tool response redirect the agent’s behavior.

I built two cinematic demos around the same scripted incident. In the first, an attacker steers an agent into isolating the wrong system. We then replay the scenario with evidence checks and a policy boundary that blocks the dangerous action while allowing a narrowly scoped response.

We also look at least agency: extending least privilege to limit what an agent can decide and do. Which actions can we safely delegate? Which need human approval? What evidence tells us the response actually worked?

These are the security architecture questions we work through in SEC530. Trust boundaries, visibility, and verification matter more than ever when we delegate decisions to agents. Think Red, Act Blue.

For more on the identity and Zero Trust architecture behind this session, explore these resources I authored for SANS. They grew out of my earlier presentation, The Replicant Problem: Zero Trust in the Age of Autonomous AI Agents.

Article

The Agent Identity Problem: Applying Zero Trust to AI Agents

Why valid identities and tokens can still leave agentic workflows exposed, and how action-level authorization, agent inventories, and defensive tripwires help address the problem.

Checklist

Zero Trust for AI Agents: The Security Checklist

A practical checklist for inventorying AI agents, limiting their privileges, enforcing Zero Trust boundaries, monitoring behavior, and preparing an incident response plan.

Threat map

Agentic AI Threat Map

A reference mapping the OWASP Top 10 for Agentic Applications to defensive controls, helping teams threat-model agentic workflows and assess their control coverage.