Why would a security team want AI agents to investigate fewer alerts, on purpose?
On the @TEISS teissTalk panel, Dropzone AI Founder and CEO Edward Wu explains a mode some customers asked for. It sends about 1% of alerts straight to the analysts, and the AI agents leave those alone.
The idea comes from airport security, where staff slip test items into luggage to check if TSA screeners are paying attention.
The full episode is on demand here 👉 bit.ly/4gqAQHa
"I didn't need a rep to explain what an agentic SOC does. The booth explained it to me while I was still walking in."
A Black Hat attendee on the AI SOC Diner, where AI SOC Analyst and AI Threat Hunter worked real alerts, live and unscripted, all week.
The question of the week moved from "does it work" to "show your work."
If you were there, what would it take for an AI agent to earn a spot in your SOC?
36.090622, -115.179115
Course locked. Destination: Black Hat USA 2026.
Droppert grabbed his diner cap, fired up the thrusters, and set a course for Mandalay Bay. The @DropzoneAI AI SOC Diner opens Aug 4th-6th in the Business Hall at Booth 3740.
Reinforcements have arrived. 🔊
Turn on @CNBC at 5:15pm ET today because @DropzoneAI made it on national TV! 🚀
We're also in a segment on @AllAccessGarcia on the 27th. We'll share the details next week.
Dropzone AI set out to build the agentic SOC when others called it a someday idea. Now it's real, and on the national stage. 🚀
Reinforcements have arrived.
Deterministic verdicts from a non-deterministic model.
From RSAC 2026, @SecWeekly talks with Edward Wu, Founder and CEO of Dropzone AI, on how a coordinated AI agent team investigates and hunts at machine speed, and why the reasoning stays visible.
Link to the Edwards segment👉 bit.ly/4gFYKAh
"What just happened?" Here's how the AI SOC Analyst answers it: alert → collect evidence → reason recursively → verdict in plain English → contain confirmed threats → remember.
No black box. Just the reasoning, on the record, for your team to sign off on.
See it investigate on real alerts → dropzone.ai/self-guided-demo
AI in the SOC is going from assisting analysts to acting on its own, and the proof just hasn't caught up yet.
The 2026 Gartner® Hype Cycle™ for Security Operations maps the shift and warns hard about "GenAI washing" and "agent washing."
Download your copy 👉 bit.ly/4vUYulg
The AI Threat Hunter gives you 280+ prebuilt hunt packs, ready on demand or on a schedule. Start one and it surfaces only what matters. In one real environment it caught web shell tunneling that would've taken an analyst over a week.
See what it finds 👉 bit.ly/4agSB9x
#ThreatHunting
The AI SOC Analyst shows its work. Every query, every reason behind the verdict.
You set the direction; it executes at machine speed. The AI Threat Hunter hunts what never trips an alert.
Try it on a real alert. Link to our self-guided demo 👉 bit.ly/4blh9yz
Reinforcements have arrived.
A quiet alert queue isn't a clean environment. Lateral movement, living-off-the-land, and valid-account abuse sit below the detection threshold and surface only when someone hunts. A thorough hunt is hours of cross-tool work, so teams manage a few a quarter.
Autonomous hunting makes it hypothesis-driven, federated, and continuous, with analysts directing instead of querying.
See how autonomous threat hunting works → bit.ly/4agSB9x
ALT This image displays a computer screen with an interface titled "T1572: Protocol Tunneling." It includes sections labeled Summary, Recommendations, and Results, with bullet points and highlighted text. The interface shows statistical data, risk levels, and dates, with categories such as Urgent, Notable, and Informational. There are also references to networking terms like DMZ and SSH.
Patrick Duffy is joining Dropzone AI as Head of Product.
He joins from Material Security, after building the MDR category's first automated remediation capability at Expel. At Dropzone AI, he'll lead product and UX as we grow the Agentic SOC, building AI agents security teams trust for high-confidence work across investigation, threat hunting, and incident response.
Welcome to the team, Patrick!
Read the Press Release bit.ly/4xCi4EA
Dropzone AI is a 2026 Intellyx Digital Innovator Award winner.
The recognition follows our analyst briefing with @Intellyx on the Agentic SOC: AI agents that investigate alerts, respond to emerging threats, and hunt attackers, so security teams scale detection and response without scaling headcount.
Full 2026 winners list: bit.ly/4dVfUYM
A quiet alert queue isn't a clean environment. Lateral movement, living-off-the-land, and valid-account abuse sit below the detection threshold and surface only when someone hunts. A thorough hunt is hours of cross-tool work, so teams manage a few a quarter.
Autonomous hunting makes it hypothesis-driven, federated, and continuous, with analysts directing instead of querying.
See how it works -> dropzone.ai/product/ai-threa…