Feed aggregator

Reimagining the SOC for the agentic era in Microsoft Defender

Microsoft Malware Protection Center - Wed, 09/23/2026 - 12:00pm
The physics of cybersecurity are changing. So must the security operations center (SOC).

Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework.

That shift has exposed a hard truth: security cannot operate at AI speed when protection and operations are built as separate systems. Every handoff, integration, and boundary slows defenders down. Agents inherit that complexity.

For agentic security to work, the industry needs a different model. It needs a modern cyber stack with the breadth to see across the environment and the depth to investigate and act. Security operations and native protection must function as one system. This is the integrated security operations center (ISOC).

Today we are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for security information and event management (SIEM) and threat protection together. It gives people and agents a shared foundation to see, understand, and act across the environment, without the complexity of operating separate systems.

Get started with ISOC in Microsoft Defender const currentTheme = localStorage.getItem('blogInABoxCurrentTheme') || (window.matchMedia('(prefers-color-scheme: dark)').matches ? 'dark' : 'light'); // Modify player theme based on localStorage value. let options = {"autoplay":false,"hideControls":null,"language":"en-us","loop":false,"partnerName":"cloud-blogs","poster":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/image\/microsoftcorp\/1306391-hayete-announce_tbmnl_en-us?wid=1280","title":"1306391-hayete-announce","sources":[{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-hayete-announce-0x1080-6439k","type":"video\/mp4","quality":"HQ"},{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-hayete-announce-0x720-3266k","type":"video\/mp4","quality":"HD"},{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-hayete-announce-0x540-2160k","type":"video\/mp4","quality":"SD"},{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-hayete-announce-0x360-958k","type":"video\/mp4","quality":"LO"}],"ccFiles":[{"url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-json\/bloginabox\/v1\/get-captions?url=https%3A%2F%2Fwww.microsoft.com%2Fcontent%2Fdam%2Fmicrosoft%2Fbade%2Fvideos%2Fproducts-and-services%2Fen-us%2Fsecurity%2F1306391-hayete-announce%2F1306391-hayete-announce_cc_en-us.ttml","locale":"en-us","ccType":"TTML"}],"downloadableFiles":[{"url":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-hayete-announce_transcript_en-us","locale":"en-us","mediaType":"transcript"}]}; if (currentTheme) { options.playButtonTheme = currentTheme; } document.addEventListener('DOMContentLoaded', () => { ump("ump-6ab403fc99cfc", options); }); Built for agentic security

In July 2026, we introduced the end-to-end cyber stack alongside Project Perception, with the focus of delivering the right models, a harness, and specialized agents to help defenders perceive, reason, and act at machine speed. But we are innovating at every layer of the stack, because intelligence and orchestration alone are not enough. Agents depend on the rest of the stack working as one.

They need signals and sensors that provide visibility, context that turns those signals into understanding, and actuators that translate decisions into protection. With ISOC, these layers work in unison, so agents can move beyond isolated tasks and help operate an agentic SOC.

Signals and sensors give the system awareness.

Context turns those signals into understanding.

Actuators turn insights into protective action.

ISOC brings these capabilities together as a foundation, so humans and agents can operate as one system, each contributing what they do best. Agents provide the speed and scale to execute continuously, while people set priorities, apply judgment, and define the outcomes that matter. Together, they empower defenders to keep pace with AI-powered threat actors and achieve better security outcomes.

Integrated protection loop

With ISOC enabling signals, context, and controls to work as one, it breaks the pattern of linear security workflows. The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.

Attack disruption in Microsoft Defender shows what this makes possible. Rich telemetry and controls enable the system to detect, predict, and adapt to an attacker while the attack is still unfolding. It disrupts threats in progress and anticipates where attackers may move next. It’s a protection loop that uses exposure insights to strengthen protection in near real-time with threat intelligence focusing the loop on the threats that matter most.

ISOC brings together the capabilities needed to make this loop native, eliminating the burden of assembling, tuning, and maintaining it yourself. And as protection advances, new capabilities can become part of that loop. The result is stronger protection and a different way of working, where practitioners spend less time chasing individual signals and more time applying judgment, setting priorities, and driving security outcomes.

Designed for the practitioner

For too long, practitioners have had to compensate for the boundaries in their security architecture, stitching together signals, rebuilding context, and moving between tools just to get the information and controls needed to act.

ISOC changes their starting point. The capabilities practitioners need to investigate, hunt, automate, manage incidents, understand threats, and take action are brought together and available by default. Instead of organizing their work around the boundaries between tools, teams can organize around the security outcome they are trying to achieve.

And that foundation gets more powerful as autonomy grows. The integrated protection loop can take on more of the continuous work of detecting and defending against threats, while agents help practitioners investigate, reason, and act using the same context and controls already available to them.

There’s no separate agentic layer to assemble or new operating model to stitch together. Practitioners can multiply their expertise where they already work, shifting more of their time from operating the security stack to directing the defense.

const currentTheme = localStorage.getItem('blogInABoxCurrentTheme') || (window.matchMedia('(prefers-color-scheme: dark)').matches ? 'dark' : 'light'); // Modify player theme based on localStorage value. let options = {"autoplay":false,"hideControls":null,"language":"en-us","loop":false,"partnerName":"cloud-blogs","poster":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/image\/microsoftcorp\/1306391-rob-demo-1_tbmnl_en-us?wid=1280","title":"1306391-rob-demo-1","sources":[{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-rob-demo-1-0x1080-6439k","type":"video\/mp4","quality":"HQ"},{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-rob-demo-1-0x720-3266k","type":"video\/mp4","quality":"HD"},{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-rob-demo-1-0x540-2160k","type":"video\/mp4","quality":"SD"},{"src":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-rob-demo-1-0x360-958k","type":"video\/mp4","quality":"LO"}],"ccFiles":[{"url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-json\/bloginabox\/v1\/get-captions?url=https%3A%2F%2Fwww.microsoft.com%2Fcontent%2Fdam%2Fmicrosoft%2Fbade%2Fvideos%2Fproducts-and-services%2Fen-us%2Fsecurity%2F1306391-rob-demo-1%2F1306391-rob-demo-1_cc_en-us.ttml","locale":"en-us","ccType":"TTML"}],"downloadableFiles":[{"url":"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/1306391-rob-demo-1_transcript_en-us","locale":"en-us","mediaType":"transcript"}]}; if (currentTheme) { options.playButtonTheme = currentTheme; } document.addEventListener('DOMContentLoaded', () => { ump("ump-6ab403fc9d00d", options); }); The path forward

Security has always been a race between attackers and defenders. AI changes the speed, scale, and economics of that race. The next SOC will not be defined by how many AI features it has, but by whether people and agents can perceive, reason, and act across an environment as one system.

Integrated security operations center (ISOC) in Microsoft Defender is available in preview today. Watch a recording of the full announcement or download the whitepaper: Agentic SOC: The new operating model for continuous defense.

Prevent and disrupt threats with Microsoft Defender

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post Reimagining the SOC for the agentic era in Microsoft Defender appeared first on Microsoft Security Blog.

Categories: Microsoft

Show HN: Open Code for Jev

Hacker News - Wed, 09/23/2026 - 11:25am

Hi everyone, I built this TUI for jev with the main goal to make Jev immediately accessible and to be able to have decision templates similar to how we have skills for LLMs.

Additionally I wanted to have a dashboard for our own software displaying the usage of Jev and being able to improve the decisions over time by giving jev feedback in the context.

I really love the look and feel of early open code so this is what I went with.

Please let me know what you think about it.

Comments URL: https://news.ycombinator.com/item?id=49817558

Points: 1

# Comments: 0

Categories: Hacker News

SEO Specialist

Hacker News - Wed, 09/23/2026 - 11:19am

Comments URL: https://news.ycombinator.com/item?id=49817477

Points: 1

# Comments: 0

Categories: Hacker News

Ask HN: Anyone working in Intellingent Doc Processing (IDP)? What do you do?

Hacker News - Wed, 09/23/2026 - 11:15am

Just curious - what does your day-to-day look like? What kinds of documents do you process, what tools do you use? Do you enjoy it?

Comments URL: https://news.ycombinator.com/item?id=49817416

Points: 1

# Comments: 0

Categories: Hacker News

GPT-6 Astra has gained the ability to drive a car

Hacker News - Wed, 09/23/2026 - 11:14am

Article URL: https://drivingbench.com/

Comments URL: https://news.ycombinator.com/item?id=49817404

Points: 2

# Comments: 0

Categories: Hacker News

Pages