Cisco sign
– Getty Images

Cisco has teased its ongoing push into the agentic AI space, outlining an agent concept capable of handling investigations for security incidents.

The concept, demoed at the recent GovWare Conference in Singapore, saw Cisco engineers take one of its security-optimized AI models – Foundation-Sec-8B – and wrap it with an agentic framework to create an autonomous agent for Security Operations Center (SOC) use cases.

The model was equipped with Python-based tools allowing it to extract observables like IP addresses from incidents, run investigations in Cisco XDR, and compile event summaries.

In the proof-of-concept demonstration, the agent acted as a virtual SOC analyst, autonomously deciding when to execute investigation functions and interpreting returned data to produce final summaries – showcasing how agentic frameworks can reduce manual investigation workflows from hours to minutes.

Cisco engineers Ahmadreza Edalat and Aditya Sankar wrote in a blog post that the specialized AI model, combined with agent frameworks, can “empower SOC teams to work faster, smarter, and with greater precision, turning what used to be hours of manual investigation into minutes of automated insight.”

Cisco’s engineering teams have been exploring agentic AI for some time, with small language models (SLMs) central to its efforts, with their compact footprint enabling users to employ them at the edge.

Speaking with SDxCentral in September, Lawrence Huang, SVP and GM of network platform and wireless at Cisco, said the shift to SLMs could give rise to “more edge processing devices in the infrastructure.”

“That's what I believe as you think about the different use cases … and this is only going to explode the number of devices that IT teams need to think about,” Huang added.

The small model powering Cisco’s latest security demo was released back in April. Foundation-Sec-8B is an open source model, meaning anyone can use it and apply it to their security operations. The model itself is actually a fine-tuned version of Meta’s Llama 3.1 model, and marked Cisco’s first step into open source AI development for security.

Yaron Singer, VP of AI and security at Foundation AI, Cisco, said upon release that the model is designed to “help security teams think faster, act with precision, and scale operations without compromise.”

Meanwhile, Jeetu Patel, Cisco’s CPO, said Foundation-Sec-8B “gives security teams everywhere a powerful building block to accelerate defense, reduce fatigue, and gain clarity in complex threat environments.”

In addition to security, Cisco is exploring ways for customers to use agentic AI to accelerate data extraction from across their networks.

The networking giant helped establish the Agntcy project to be a de facto listing of AI agents.

The framework was donated to the Linux Foundation earlier this year, with Cisco staying on as a formative member for its development.