July 20, 2026

SharpHound Recon Attack – How AI enhanced the threat hunt

In brief

Cisco describes how its Cisco Live AMER 2026 security operations team used agentic AI, Cisco XDR, Splunk Enterprise Security, and Endace full packet capture to investigate a possible SharpHound reconnaissance attack. Analysts had found several cleartext LDAP sessions from attendee devices to external LDAP servers, including bind requests containing high-profile organization names. Because continuous anonymous LDAP bind attempts can indicate reconnaissance activity that may expose Active Directory information, the team created an incident in Cisco XDR and asked an agentic SOC workflow to assess the case.

The AI workflow retrieved the XDR incident context, pulled the relevant packet captures from Endace, queried supporting Splunk logs, and produced a structured report within minutes. It concluded that the incident was benign, but the article emphasizes the operational value: the agent explained its reasoning, checked the broader “blast radius,” and even corrected an initial mistake after confusing event time with first-seen time. Cisco presents this as evidence that agentic AI can speed up SOC investigations, help less experienced analysts interpret packet data, and allow human teams to focus on higher-risk threats.

Source: Cisco Blogs

Explore More Insightful Articles: