
SOC Analysts' Reliance on LLMs: Impact on Skills and Response Times
CybersecurityAutomationSkillDevelopmentLLMs
The post describes a situation where SOC analysts are using LLMs integrated into their ticketing tool to get assistance with tickets and have access to an enterprise version of a well-known LLM. The analysts provide commands and signature names to the LLM, but not logs, and ask what can be investigated. The post questions whether dependence on LLMs should be avoided and how this could affect the skills of analysts over time.