
SANS Webcast · September 8, 2026
The Agentic SOC: Defending With, and Against, Autonomous AI
Ismael Valenzuela
Can an attacker hijack an AI agent’s intent and turn its legitimate access against you?
What this session covers.
An agentic SOC uses AI agents to triage alerts, investigate threats, and take response actions. Once those agents can make decisions and use tools, we need to be clear about whose instructions they follow, where their authority stops, and how we verify the results.
In this SANS Institute webcast, I explore how an attacker can hijack an AI agent’s intent and turn its legitimate access against the defender. That includes indirect prompt injection, where instructions embedded in content such as a tool response redirect the agent’s behavior.
I built two cinematic demos around the same scripted incident. In the first, an attacker steers an agent into isolating the wrong system. We then replay the scenario with evidence checks and a policy boundary that blocks the dangerous action while allowing a narrowly scoped response.
We also look at least agency: extending least privilege to limit what an agent can decide and do. Which actions can we safely delegate? Which need human approval? What evidence tells us the response actually worked?
These are the security architecture questions we work through in SEC530. Trust boundaries, visibility, and verification matter more than ever when we delegate decisions to agents. Think Red, Act Blue.
Related resources by Ismael Valenzuela
For more on the identity and Zero Trust architecture behind this session, explore these resources I authored for SANS. They grew out of my earlier presentation, The Replicant Problem: Zero Trust in the Age of Autonomous AI Agents.
Article
The Agent Identity Problem: Applying Zero Trust to AI Agents
By Ismael Valenzuela · SANS Institute · Published June 15, 2026
Why valid identities and tokens can still leave agentic workflows exposed, and how action-level authorization, agent inventories, and defensive tripwires help address the problem.
Checklist
Zero Trust for AI Agents: The Security Checklist
By Ismael Valenzuela · SANS Institute · Published June 12, 2026
A practical checklist for inventorying AI agents, limiting their privileges, enforcing Zero Trust boundaries, monitoring behavior, and preparing an incident response plan.
Threat map
Agentic AI Threat Map
By Ismael Valenzuela · SANS Institute · Published June 12, 2026
A reference mapping the OWASP Top 10 for Agentic Applications to defensive controls, helping teams threat-model agentic workflows and assess their control coverage.
From the webinar
Webinar highlights







