Back
AI Made Failed Attacks Cheap to Retry: Why SOC Handoffs Leak Context
SiTech AI Team3 წთ. საკითხავი

AI Made Failed Attacks Cheap to Retry: Why SOC Handoffs Leak Context

AI has cut the cost of a failed intrusion attempt to minutes, so the strain lands on the SOC, where threat intelligence, hunting, detection engineering, investigation and remediation pass context that rarely survives the transfer.

Security leaders keep debating whether AI will produce a new class of cyberattack. The nearer change is quieter: AI has made a failed attack cheap to retry. An attacker who fails at privilege escalation on a low-privilege cloud account used to spend hours on documentation and scripts; with a model in the loop, a fresh path is under test within minutes.

What the threat reporting shows

In early 2025, Google's Threat Intelligence Group (GTIG) found state-backed actors using generative AI for productivity work, and by late 2025 the same team tracked malware that queried a model mid-execution while Anthropic disclosed shutting down an extortion operation that leaned on AI at nearly every stage. In May 2026, GTIG reported that cyber crime actors found a two-factor bypass in an open-source administration tool and built working exploits, assessing with high confidence that an AI model supported both the discovery and the development. That is assessed assistance, not confirmed deployment, yet the direction points to AI inside attacker workflows.

Attacks run as loops, defense keeps restarting

Textbooks draw the attack lifecycle as a line: reconnaissance, access, escalation, impact. A working attacker runs a loop instead: watch, guess, try, read the result, adjust, with AI compressing the time between those steps.

Defense is supposed to loop the same way, but queues and handoffs interrupt it at every joint: the alert idles unassigned, the identity picture lives in another console, a telemetry gap becomes a backlog item. An alert can be acknowledged in minutes and then spend hours being reconstructed, and that interval is decision latency.

Five functions, five lossy handoffs

The work is described in five functions: threat intelligence, threat hunting, detection engineering, investigation and remediation. The problem is rarely the functions; it is the transfer between them, where each handoff squeezes knowledge into an indicator or a ticket.

Five things have to survive: the identity at the center of the case, evidence and provenance, the leading hypothesis and confidence, telemetry sufficiency and decision ownership. Lose the first and two teams investigate the same user under different names; lose the last and a correct recommendation sits in a queue.

What a stateful SOC remembers

The fix is architectural: the SOC has to become stateful. Evidence and case histories are kept for years, but the reasoning around them and the constraints on who could act rarely survive a handoff. Shared operational memory would span five kinds of state: environmental, evidence, decision, control and learning, fed by the SIEM, the EDR, the identity platform and the case system.

The hardest discipline is treating unknown as a legitimate answer. When endpoint telemetry is missing, a weak system files the finding as no malicious process activity observed, technically true and operationally misleading; a stateful system records that the endpoint could not be checked and routes the gap to whoever owns device management. NIST's updated guidance in SP 800-61r3 points the same way.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.