arXiv — cs.AI preprintsInternational9 October 2026
From Investigation Failures to Reliable SOC Agents: Understanding and Improving LLM-Based Alert Triage
This is an official announcement record
Firsthand records what arXiv — cs.AI preprints announced and links to the original. The wording below is theirs, not ours.
arXiv:2610.10608v1 Announce Type: cross Abstract: Security operations centers (SOCs) must triage large volumes of alerts, most of which are benign, while missed attacks can remain uninvestigated. Tool-using large language model (LLM) agents can retrieve evidence during triage, but it remains unclear how reasoning strategies determine what to gather and when an investigation is sufficient to close an alert. We study five representative approaches spanning single-pass tool use, iterative retrieval, sampled investigations, self-review, and explicit verification. To support this study, we build AL
Read the official announcement
Opens arxiv.org
More from arXiv — cs.AI preprints
- An Explainable Header-Centric Framework for Large-Scale Semantic Table Interpretation and Data Quality Assessment9 October 2026
- Synthesis Through Simulation: Generating Coherent Enterprise Data via Scalable Agent-System Interaction9 October 2026
- Agent-Controlled Forgetting for Tool-Using Agents: Reversible Context Curation in Practice9 October 2026
- Verification and Self-Improvement in Agentic AI: Foundations and Limits9 October 2026
- The Harness as the Only Mutable Surface: Compliance-Bounded Self-Evolution of LLM Agents in Credit Pipelines, with a Measured Admission Gate9 October 2026
This content is for informational purposes only and is not professional advice. Specifications, prices, plan tiers, and features change frequently and may differ from what is shown here; verify current details on the manufacturer's or company's official page before purchasing. Ratings are based on analysis of published documentation, not independent lab testing.