I’m a little surprised with one of the statements given in huggingface‘s report.
“To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events.”
17,000 events? Big whoop. Security teams of medium sized companies process millions of events daily.
There’s a big debate in the cyber industry about the AI SOC and whether or not it’s necessary. It seems to me they are using that report to push that idea.