VMTech
Discuss a project

AI adoption is reshaping the enterprise SOC alert stream

AI adoption is reshaping the enterprise SOC alert stream

Intezer’s review of roughly 16.9 million security operations centre alerts found that about 73,000 were related to AI tools and agents. That is only 0.43% of the total alert volume, but the number of AI-related alerts rose 685% between February and June 2026.

The research presents a sharply uneven picture for security teams. Of AI-related alerts examined, 94.1% were classified as noise, 5.8% as genuine security risks and 0.02% as real attacks. The immediate operational challenge is therefore not simply detecting attacks against or through AI, but separating routine agent activity from the smaller set of exposures that merit intervention.

AI creates two distinct SOC workloads

One workload comes from technical users. Coding agents can launch shells, read credential stores, download packages, create network tunnels and run security tooling as part of legitimate development. Many of those actions resemble early intrusion behaviour to endpoint detections written before AI agents became commonplace.

The other workload is quieter. Employees may grant OAuth consent to third-party AI applications, upload documents or share information with generative-AI services. Such activity may not generate endpoint telemetry, yet it can move corporate data to external providers and expand the consequences of a compromised AI account or prompt-injection event.

High-severity alerts can be ordinary developer activity

Intezer found that automated triage assigned a benign verdict to 79.8% of AI-related alerts and automatically suppressed 81.7%. Only 5.4% were escalated to a human analyst. The figures underline that an alert’s severity label is not enough to establish that an AI-driven action is malicious.

In one example, a detection responsible for 55% of critical verdict alerts identified the Windows binary Expand.exe as a lateral-tool-transfer event. Investigation found that a developer’s coding agent was setting up a shell environment. Other examples involved signed Anthropic Claude Desktop installation activity flagged as ransomware operations, and normal OpenAI Codex orchestration activity identified as a possible reverse TCP shell.

Confirmed attacks in the dataset were rare and did not stem from an organisation’s own AI agent causing a compromise. Instead, Intezer observed phishing campaigns using familiar AI brands as lures, including fraudulent messages impersonating Anthropic, Google/Gemini and OpenAI. Familiarity with AI product notifications can make brand-based pretexts more credible to recipients.

Unsafe configurations create the more meaningful exposure

The 5.8% classified as risk included coding agents launched with permission-bypass options, which stop the agent from requesting user approval before acting. Intezer noted that these invocations were legitimate developer work in examined samples, but they remove a safeguard if an agent is asked to execute unsafe or malicious code.

Other observed cases included an AI code editor opening an ngrok reverse tunnel to the public internet, an agent dumping the macOS keychain into a temporary file, and OAuth consent or data-protection alerts involving generative-AI services. These are not necessarily compromises, but they are exposures that can be obscured by the much larger volume of false positives.

A practical response for security teams

Intezer recommends tuning the noisiest legacy detections that fire on routine AI-agent behaviour, while proactively looking for permission-bypass flags, unauthorised tunnels and risky OAuth grants. It also recommends defining policies for information shared with third-party AI platforms.

Teams need to establish whether a suspicious action was performed by a user or by an agent acting with that user’s credentials. Running AI tools in a restricted Docker container or virtual machine can limit their reach and make activity easier to distinguish. The practical implication is to reduce alert noise while focusing investigations on permissions, network exposure, credentials and data flows that can create real business risk.

#cybersecurity#securityoperations#aiagents#socalerts
Open analytics
On the site 0 views
min read 4 12.09.2026
Instagram

AI adoption is reshaping the enterprise SOC alert stream

Open the post on Instagram ↗