Stateful SOCs Can Reduce Investigation Rework in AI-Accelerated Attacks

AI is making unsuccessful intrusion attempts cheaper and faster to repeat, increasing pressure on security operations centres to preserve investigative context between teams. The Hacker News, drawing on a three-part series by Conifers.ai Director of Solution Architects/CISO Jonathan Waknin, argues that the response is not simply more autonomous tooling: it is a stateful SOC that carries evidence, uncertainty, business constraints and decisions through an incident.
The article describes a familiar attacker loop. A low-privilege cloud account is compromised, a privilege-escalation attempt fails, and the operator uses a model to explain the error, correct a script and test another route within minutes. Google’s Threat Intelligence Group reported in early 2025 that state-backed actors were using generative AI for translation, scripting, troubleshooting and research. In May 2026, GTIG said it assessed with high confidence that an AI model assisted the discovery and exploit development of a two-factor bypass in an open-source administration tool.
GTIG worked with the affected vendor and disrupted that activity, but the report did not claim confirmed deployment of the exploit in the wild. That distinction matters: attribution and prevalence remain difficult to establish. The broader pattern is AI becoming embedded in attacker workflows, reducing the time and effort required for iterative research and troubleshooting.
Where security operations lose the case context
Defensive work should also operate as a loop: gather context, form a hypothesis, validate scope, act and use the outcome to improve detection. In many SOCs, however, queues, console boundaries and approvals interrupt that cycle. An alert may be acknowledged quickly yet still take hours to reconstruct as analysts identify the user, verify endpoint management, locate telemetry and repeat the case for each owner.
The article calls this interval decision latency. Mean time to acknowledge and mean time to remediate may not show it, because they obscure the time spent rebuilding an already investigated situation. The loss compounds as intelligence, hunting, detection engineering, investigation and remediation pass information among teams.
Five categories are especially vulnerable in those handoffs: entity identity; evidence and provenance; hypotheses and confidence; telemetry sufficiency; and decision ownership and constraints. A ticket can carry a severity label and a recommendation while omitting the assumptions behind the alert, competing explanations, unavailable data or the operational impact of containment.
Shared state rather than a “unicorn” analyst
A worked example follows a finance employee who signs in from an unfamiliar hosting provider, satisfies MFA, creates a mailbox forwarding rule and begins accessing finance SharePoint files in an unusual pattern. The available evidence can fit either legitimate travel and a new service or a stolen authenticated session. Endpoint scope remains unknown when the device is unmanaged and lacks process or network telemetry.
The identity team may also know that disabling the account would interrupt an active payroll run. Revoking live sessions and removing the forwarding rule can be lower-risk steps, while account suspension and business continuity require the appropriate authority and context. If the investigation reaches that team only as a one-line instruction, the organisation has transferred a task rather than a decision.
The proposed architecture retains five forms of operational memory: environmental state about identities, devices, workloads and owners; evidence state with source and timing; decision state covering hypotheses and alternatives; control state for actions, approvals and preservation requirements; and learning state for corrections and rule improvements. SIEM, EDR, identity and case-management platforms can contribute to that shared model without being replaced.
AI agents need explicit boundaries
The article warns that adding agents to a stateless SOC only speeds up a flawed operating model. In a shared-state model, agents can gather evidence, present recommendations for human approval, execute after explicit approval or act automatically only when policy, confidence, entity type and potential impact permit it. Authority remains separate from an agent’s confidence, and control decisions should be versioned and auditable.
For security leaders, the practical implication is to identify where incident context is repeatedly rebuilt by hand, record what an investigation could not observe alongside what it concluded, define action owners and approval paths before an incident, and route validated lessons back to detection and hunting owners. That creates a durable operational memory so the next analyst inherits a case with its reasoning, limits and business context intact.

