October 2, 2026

SharpHound Recon Attack – How AI enhanced the threat hunt

In brief

At Cisco Live AMER 2026, Cisco and Endace tested an agentic security-operations architecture that combined Cisco XDR, Splunk Enterprise Security and Endace’s continuous full-packet capture. The system used Model Context Protocol servers and a custom Tier-2 AI analyst to gather incident context, retrieve relevant packet data, query logs and produce structured assessments. During threat hunting, analysts found 48 attendee devices attempting unencrypted LDAP connections to external servers. Repeated anonymous bind attempts and recognizable organization names raised concerns that SharpHound, an Active Directory reconnaissance tool, might be enumerating sensitive information for a possible attack.

The AI agent investigated the activity within minutes, reconstructed the relevant LDAP sessions, checked related events across the network and documented every query and decision for human review. It concluded that the incident was a benign near miss rather than a successful SharpHound attack, saving analysts many hours of manual packet analysis. The exercise also exposed an error: the agent initially searched the wrong time window after confusing the event time with the “first-seen” timestamp. It corrected the mistake, found the evidence and recorded the lesson in its skill file. Cisco presents the case as evidence that agentic AI, supported by complete network telemetry and human oversight, can accelerate investigations and help inexperienced analysts make better-informed decisions.

Source: Cisco Blogs

‍

‍

Explore More Insightful Articles: