{"id":3707,"date":"2026-09-11T19:51:57","date_gmt":"2026-09-11T19:51:57","guid":{"rendered":"https:\/\/mscyber.tech\/?p=3707"},"modified":"2026-09-11T19:53:21","modified_gmt":"2026-09-11T19:53:21","slug":"la-inteligencia-artificial-en-el-soc","status":"publish","type":"post","link":"https:\/\/mscyber.tech\/es\/la-inteligencia-artificial-en-el-soc\/","title":{"rendered":"IA en el SOC: C\u00f3mo la inteligencia artificial transforma la supervisi\u00f3n de la seguridad"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3707\" class=\"elementor elementor-3707\" data-elementor-settings=\"{&quot;ha_cmc_init_switcher&quot;:&quot;no&quot;}\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7b90f3a e-flex e-con-boxed e-con e-parent\" data-id=\"7b90f3a\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-287547e elementor-alert-info elementor-widget elementor-widget-alert\" data-id=\"287547e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"alert.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-alert\" role=\"alert\">\n\n\t\t\t\t\t\t<span class=\"elementor-alert-title\">Definition: <\/span>\n\t\t\t\n\t\t\t\t\t\t<span class=\"elementor-alert-description\">AI in the SOC refers to the use of artificial intelligence, including machine learning and large language models, to automate and accelerate the work of a Security Operations Center. It investigates and triages security alerts, detects anomalies, and assists or automates response, allowing threats to be identified in minutes rather than hours and freeing human analysts to focus on complex incidents and threat hunting.<\/span>\n\t\t\t\n\t\t\t\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2603d8a elementor-widget elementor-widget-text-editor\" data-id=\"2603d8a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p class=\"FirstParagraph\"><span lang=\"EN-US\">Security monitoring has a math problem. The volume of alerts a modern environment produces has grown far faster than the number of analysts available to examine them, and the gap keeps widening. Artificial intelligence is the first technology that addresses this problem at its root, by doing the investigative work itself rather than just generating more alerts for humans to sort through. This article explains, in concrete terms, how AI actually works inside a SOC, how it changes the daily workflow, what it does to the metrics that matter, and, just as importantly, what it cannot do and why the human analyst is not going away.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5ea9594 elementor-widget elementor-widget-heading\" data-id=\"5ea9594\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The short answer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1cad4e7 elementor-widget elementor-widget-text-editor\" data-id=\"1cad4e7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Traditional security monitoring puts a human at the front of the line to look at every alert. AI moves that human back, and puts an automated investigator at the front instead. The AI examines each alert the way a skilled analyst would, gathers the context, reaches a verdict, and only escalates what genuinely needs a person. The result is faster detection, far less noise reaching humans, and analysts who spend their time on judgment rather than on repetitive triage.<\/p><p>That is the whole idea in one paragraph. Everything below explains how it works and where the limits are.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8ef5d0b elementor-widget elementor-widget-heading\" data-id=\"8ef5d0b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The bottleneck AI is built to solve<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-276bc79 elementor-widget elementor-widget-text-editor\" data-id=\"276bc79\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>To understand why AI matters in the SOC, you have to understand where the traditional model breaks. The weak point is the tier 1 triage layer, the front line where incoming alerts are first examined.<\/p><p>Three forces converge on that layer. The first is volume: security tools generate a flood of alerts, the large majority of which are false positives or low priority. The second is the talent shortage: there are simply not enough skilled analysts to examine that volume around the clock, a gap the ISC2 Cybersecurity Workforce Study measures in the millions of unfilled roles globally. The third is alert fatigue: analysts buried in repetitive, mostly harmless alerts become slower and more likely to miss the one that matters.<\/p><p>The consequence is dwell time, the period an attacker stays undetected in the environment. IBM\u2019s Cost of a Data Breach research consistently shows that the longer a breach goes undetected and uncontained, the more it costs. Every hour an alert sits in a human queue is an hour the attacker may be operating freely. AI attacks this bottleneck directly, which is why it is the most significant shift in security operations in years.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-10b5b1c elementor-widget elementor-widget-heading\" data-id=\"10b5b1c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How AI actually works inside the SOC<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-31abef5 elementor-widget elementor-widget-text-editor\" data-id=\"31abef5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>AI in the SOC is not a single feature. It is a set of capabilities that together change how monitoring is done. The main ones:<\/p><ul><li><strong>Autonomous alert investigation.<\/strong> Rather than simply flagging an alert, AI carries out the investigation itself. It gathers the surrounding context, pulls related logs and telemetry, checks the entities involved against threat intelligence, follows the same investigative steps a tier 1 or tier 2 analyst would, and reaches a reasoned verdict on whether the alert represents a real threat.<\/li><li><strong>Anomaly detection and behavioral analytics.<\/strong> Machine learning models learn what normal looks like for each user, device, and system, then flag meaningful deviations. This catches threats that have no known signature, such as a compromised account behaving abnormally.<\/li><li><strong>Correlation across signals.<\/strong> AI connects individually weak signals from different sources into a single coherent picture, surfacing multi-step attacks that no single alert would reveal.<\/li><li><strong>Natural language investigation and summarization.<\/strong> Large language models can read and explain alerts in plain language, summarize a complex incident for a human, and let analysts query the environment conversationally, which compresses the time to understand what happened.<\/li><li><strong>Automated and assisted response.<\/strong> Working with orchestration and automation tooling, AI can execute or recommend containment actions, such as isolating an endpoint or disabling an account, within the guardrails the organization defines.<\/li><\/ul><p>The through line is that AI does the reasoning work of investigation, not just the pattern matching of detection. That is what separates a modern AI SOC from an older system that simply generated smarter alerts.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c907b31 elementor-widget elementor-widget-heading\" data-id=\"c907b31\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Traditional SOC versus AI-driven SOC<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b3d3d92 elementor-widget elementor-widget-text-editor\" data-id=\"b3d3d92\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p class=\"FirstParagraph\"><span lang=\"EN-US\">The clearest way to see the change is to compare the two workflows side by side.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3e4d61c elementor-widget elementor-widget-html\" data-id=\"3e4d61c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t\t<!DOCTYPE html>\r\n<html lang=\"en\">\r\n<head>\r\n<meta charset=\"UTF-8\">\r\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\r\n<title>Traditional SOC vs AI-driven SOC (responsive)<\/title>\r\n<style>\r\n  \/* Paste from .ms-table-wrap down into your CMS. The .ms- prefix keeps it isolated from blog styles. *\/\r\n  body { margin: 40px; background: #ffffff; }\r\n\r\n  .ms-table-wrap {\r\n    max-width: 860px;\r\n    font-family: -apple-system, \"Segoe UI\", Roboto, \"Helvetica Neue\", Arial, sans-serif;\r\n    color: #3f3f46;\r\n    -webkit-font-smoothing: antialiased;\r\n  }\r\n\r\n  .ms-table {\r\n    width: 100%;\r\n    border-collapse: separate;\r\n    border-spacing: 0;\r\n    border: 1px solid #e5e7eb;\r\n    border-radius: 10px;\r\n    overflow: hidden;\r\n    font-size: 15px;\r\n    line-height: 1.5;\r\n  }\r\n\r\n  \/* Header: black bar, white bold text *\/\r\n  .ms-table thead th {\r\n    background: #1c1c1e;\r\n    color: #ffffff;\r\n    font-weight: 600;\r\n    text-align: left;\r\n    padding: 15px 20px;\r\n    white-space: nowrap;\r\n  }\r\n\r\n  \/* Body cells *\/\r\n  .ms-table tbody td,\r\n  .ms-table tbody th {\r\n    padding: 15px 20px;\r\n    text-align: left;\r\n    vertical-align: top;\r\n    border-top: 1px solid #ececee;\r\n  }\r\n\r\n  \/* First column: teal, bold (row header) *\/\r\n  .ms-table tbody th {\r\n    font-weight: 700;\r\n    color: #14808f;\r\n    width: 200px;\r\n  }\r\n\r\n  \/* Vertical dividers *\/\r\n  .ms-table tbody td { border-left: 1px solid #ececee; }\r\n  .ms-table thead th + th { border-left: 1px solid #33333a; }\r\n\r\n  \/* Zebra striping *\/\r\n  .ms-table tbody tr:nth-child(odd) th,\r\n  .ms-table tbody tr:nth-child(odd) td { background: #f5f6f7; }\r\n  .ms-table tbody tr:nth-child(even) th,\r\n  .ms-table tbody tr:nth-child(even) td { background: #ffffff; }\r\n\r\n  \/* ============================================================\r\n     RESPONSIVE: on narrow screens the table reflows into cards,\r\n     one card per row, so nothing gets cramped or cut off.\r\n     ============================================================ *\/\r\n  @media (max-width: 640px) {\r\n    .ms-table { border: 0; border-radius: 0; }\r\n\r\n    .ms-table thead {\r\n      position: absolute;\r\n      width: 1px; height: 1px;\r\n      padding: 0; margin: -1px;\r\n      overflow: hidden; clip: rect(0 0 0 0);\r\n      white-space: nowrap; border: 0;\r\n    }\r\n\r\n    .ms-table tbody tr {\r\n      display: block;\r\n      border: 1px solid #e5e7eb;\r\n      border-radius: 10px;\r\n      margin-bottom: 14px;\r\n      overflow: hidden;\r\n    }\r\n\r\n    .ms-table tbody th,\r\n    .ms-table tbody td {\r\n      display: block;\r\n      width: auto;\r\n      border-left: 0;\r\n      border-top: 0;\r\n      white-space: normal;\r\n      padding: 12px 16px;\r\n    }\r\n\r\n    .ms-table tbody tr:nth-child(odd) th,\r\n    .ms-table tbody tr:nth-child(even) th,\r\n    .ms-table tbody th {\r\n      background: #f5f6f7;\r\n      color: #14808f;\r\n      font-size: 17px;\r\n      border-bottom: 1px solid #ececee;\r\n    }\r\n\r\n    .ms-table tbody tr:nth-child(odd) td,\r\n    .ms-table tbody tr:nth-child(even) td,\r\n    .ms-table tbody td {\r\n      background: #ffffff;\r\n      border-top: 1px solid #f1f1f2;\r\n    }\r\n    .ms-table tbody td:first-of-type { border-top: 0; }\r\n\r\n    .ms-table tbody td::before {\r\n      content: attr(data-label);\r\n      display: block;\r\n      font-size: 12px;\r\n      font-weight: 700;\r\n      text-transform: uppercase;\r\n      letter-spacing: 0.04em;\r\n      color: #8a8f98;\r\n      margin-bottom: 3px;\r\n    }\r\n  }\r\n<\/style>\r\n<\/head>\r\n<body>\r\n\r\n<div class=\"ms-table-wrap\">\r\n  <table class=\"ms-table\">\r\n    <thead>\r\n      <tr>\r\n        <th scope=\"col\">Dimension<\/th>\r\n        <th scope=\"col\">Traditional SOC<\/th>\r\n        <th scope=\"col\">AI-driven SOC<\/th>\r\n      <\/tr>\r\n    <\/thead>\r\n    <tbody>\r\n      <tr>\r\n        <th scope=\"row\">Front-line triage<\/th>\r\n        <td data-label=\"Traditional SOC\">Human tier 1 examines alerts<\/td>\r\n        <td data-label=\"AI-driven SOC\">AI investigates every alert first<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Time from alert to verdict<\/th>\r\n        <td data-label=\"Traditional SOC\">Hours in a human queue<\/td>\r\n        <td data-label=\"AI-driven SOC\">Minutes or seconds<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Coverage capacity<\/th>\r\n        <td data-label=\"Traditional SOC\">Limited by analyst headcount<\/td>\r\n        <td data-label=\"AI-driven SOC\">Scales with data, not headcount<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Alert noise reaching humans<\/th>\r\n        <td data-label=\"Traditional SOC\">High, causing fatigue<\/td>\r\n        <td data-label=\"AI-driven SOC\">Filtered automatically before humans<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Analyst focus<\/th>\r\n        <td data-label=\"Traditional SOC\">Consumed by repetitive triage<\/td>\r\n        <td data-label=\"AI-driven SOC\">Freed for hunting and complex incidents<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Consistency<\/th>\r\n        <td data-label=\"Traditional SOC\">Varies by analyst and shift<\/td>\r\n        <td data-label=\"AI-driven SOC\">Uniform across every alert<\/td>\r\n      <\/tr>\r\n    <\/tbody>\r\n  <\/table>\r\n<\/div>\r\n\r\n<\/body>\r\n<\/html>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d5ce03b elementor-widget elementor-widget-text-editor\" data-id=\"d5ce03b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The point of the comparison is not that AI replaces the SOC. It is that AI removes the specific bottleneck that made traditional SOCs slow and expensive to scale, while the human role shifts up the value chain.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7946e58 elementor-widget elementor-widget-heading\" data-id=\"7946e58\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The types of AI used in a SOC<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9fc2583 elementor-widget elementor-widget-text-editor\" data-id=\"9fc2583\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p class=\"FirstParagraph\"><span lang=\"EN-US\">Not all AI in security is the same, and understanding the categories helps a buyer cut through marketing language. The main types:<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-85da958 elementor-widget elementor-widget-html\" data-id=\"85da958\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t\t<!DOCTYPE html>\r\n<html lang=\"en\">\r\n<head>\r\n<meta charset=\"UTF-8\">\r\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\r\n<title>Types of AI used in a SOC (responsive)<\/title>\r\n<style>\r\n  \/* Paste from .ms-table-wrap down into your CMS. The .ms- prefix keeps it isolated from blog styles. *\/\r\n  body { margin: 40px; background: #ffffff; }\r\n\r\n  .ms-table-wrap {\r\n    max-width: 760px;\r\n    font-family: -apple-system, \"Segoe UI\", Roboto, \"Helvetica Neue\", Arial, sans-serif;\r\n    color: #3f3f46;\r\n    -webkit-font-smoothing: antialiased;\r\n  }\r\n\r\n  .ms-table {\r\n    width: 100%;\r\n    border-collapse: separate;\r\n    border-spacing: 0;\r\n    border: 1px solid #e5e7eb;\r\n    border-radius: 10px;\r\n    overflow: hidden;\r\n    font-size: 15px;\r\n    line-height: 1.5;\r\n  }\r\n\r\n  \/* Header: black bar, white bold text *\/\r\n  .ms-table thead th {\r\n    background: #1c1c1e;\r\n    color: #ffffff;\r\n    font-weight: 600;\r\n    text-align: left;\r\n    padding: 15px 22px;\r\n    white-space: nowrap;\r\n  }\r\n\r\n  \/* Body cells *\/\r\n  .ms-table tbody td,\r\n  .ms-table tbody th {\r\n    padding: 15px 22px;\r\n    text-align: left;\r\n    vertical-align: top;\r\n    border-top: 1px solid #ececee;\r\n  }\r\n\r\n  \/* First column: teal, bold (row header) *\/\r\n  .ms-table tbody th {\r\n    font-weight: 700;\r\n    color: #14808f;\r\n    width: 240px;\r\n  }\r\n\r\n  \/* Vertical divider *\/\r\n  .ms-table tbody td { border-left: 1px solid #ececee; }\r\n  .ms-table thead th + th { border-left: 1px solid #33333a; }\r\n\r\n  \/* Zebra striping *\/\r\n  .ms-table tbody tr:nth-child(odd) th,\r\n  .ms-table tbody tr:nth-child(odd) td { background: #f5f6f7; }\r\n  .ms-table tbody tr:nth-child(even) th,\r\n  .ms-table tbody tr:nth-child(even) td { background: #ffffff; }\r\n\r\n  \/* ============================================================\r\n     RESPONSIVE: the first column is a multi-word term and the\r\n     second is a full sentence, so on narrow screens each row\r\n     becomes a card (term as title, description below) instead\r\n     of cramming two wide text columns side by side.\r\n     ============================================================ *\/\r\n  @media (max-width: 600px) {\r\n    .ms-table { border: 0; border-radius: 0; }\r\n\r\n    .ms-table thead {\r\n      position: absolute;\r\n      width: 1px; height: 1px;\r\n      padding: 0; margin: -1px;\r\n      overflow: hidden; clip: rect(0 0 0 0);\r\n      white-space: nowrap; border: 0;\r\n    }\r\n\r\n    .ms-table tbody tr {\r\n      display: block;\r\n      border: 1px solid #e5e7eb;\r\n      border-radius: 10px;\r\n      margin-bottom: 14px;\r\n      overflow: hidden;\r\n    }\r\n\r\n    .ms-table tbody th,\r\n    .ms-table tbody td {\r\n      display: block;\r\n      width: auto;\r\n      border-left: 0;\r\n      border-top: 0;\r\n      white-space: normal;\r\n      padding: 12px 16px;\r\n    }\r\n\r\n    .ms-table tbody tr:nth-child(odd) th,\r\n    .ms-table tbody tr:nth-child(even) th,\r\n    .ms-table tbody th {\r\n      background: #f5f6f7;\r\n      color: #14808f;\r\n      font-size: 17px;\r\n      border-bottom: 1px solid #ececee;\r\n    }\r\n\r\n    .ms-table tbody tr:nth-child(odd) td,\r\n    .ms-table tbody tr:nth-child(even) td,\r\n    .ms-table tbody td {\r\n      background: #ffffff;\r\n      border-top: 0;\r\n    }\r\n\r\n    .ms-table tbody td::before {\r\n      content: attr(data-label);\r\n      display: block;\r\n      font-size: 12px;\r\n      font-weight: 700;\r\n      text-transform: uppercase;\r\n      letter-spacing: 0.04em;\r\n      color: #8a8f98;\r\n      margin-bottom: 3px;\r\n    }\r\n  }\r\n<\/style>\r\n<\/head>\r\n<body>\r\n\r\n<div class=\"ms-table-wrap\">\r\n  <table class=\"ms-table\">\r\n    <thead>\r\n      <tr>\r\n        <th scope=\"col\">Type of AI<\/th>\r\n        <th scope=\"col\">What it does in the SOC<\/th>\r\n      <\/tr>\r\n    <\/thead>\r\n    <tbody>\r\n      <tr>\r\n        <th scope=\"row\">Machine learning classifiers<\/th>\r\n        <td data-label=\"What it does in the SOC\">Score and classify alerts by the likelihood of being a real threat<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Anomaly detection and UEBA<\/th>\r\n        <td data-label=\"What it does in the SOC\">Learn normal behavior for users and entities and flag deviations<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Large language models<\/th>\r\n        <td data-label=\"What it does in the SOC\">Investigate, summarize, and explain alerts in natural language<\/td>\r\n      <\/tr>\r\n      <tr>\r\n        <th scope=\"row\">Agentic AI<\/th>\r\n        <td data-label=\"What it does in the SOC\">Autonomously carry out multi-step investigation and response<\/td>\r\n      <\/tr>\r\n    <\/tbody>\r\n  <\/table>\r\n<\/div>\r\n\r\n<\/body>\r\n<\/html>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ed895a4 elementor-widget elementor-widget-text-editor\" data-id=\"ed895a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Most mature AI SOCs combine several of these. Anomaly detection surfaces the unusual, classifiers prioritize it, large language models investigate and explain it, and agentic systems act on the conclusion. The combination is more powerful than any single technique.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-585a013 elementor-widget elementor-widget-heading\" data-id=\"585a013\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The impact on the metrics that matter<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-804cc92 elementor-widget elementor-widget-text-editor\" data-id=\"804cc92\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The value of AI in the SOC is measurable, and it shows up in the core security operations metrics:<\/p><ul><li><strong>MTTD (mean time to detect)<\/strong> falls, because AI examines alerts the moment they arrive rather than when a human reaches them in a queue.<\/li><li><strong>MTTR (mean time to respond)<\/strong> falls, because investigation is completed in minutes and response can be automated within guardrails.<\/li><li><strong>Dwell time<\/strong> shrinks as a direct result, which is the metric most tied to the eventual cost of a breach.<\/li><li><strong>False positive burden<\/strong> drops for humans, because AI filters the noise before it reaches an analyst.<\/li><li><strong>Effective coverage<\/strong> rises, because AI capacity scales with data volume rather than headcount, making genuine 24\/7 depth achievable.<\/li><\/ul><p class=\"FirstParagraph\">The strategic effect is that the same team, augmented by AI, covers far more ground with better outcomes. That is why AI has become the defining feature of modern security operations rather than an optional add-on.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-529afca elementor-widget elementor-widget-text-editor\" data-id=\"529afca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The historical distinction is that a traditional MSSP tends to manage devices and pass alerts to the client, leaving the hard work of investigation and response with the customer. MDR emerged to fix that gap by focusing on outcomes, actually detecting and responding. A modern managed SOC combines broad monitoring with the response depth of MDR. When comparing providers, the sharpest question to ask is not what they monitor, but what they do when they find something.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8f60d4b elementor-widget elementor-widget-heading\" data-id=\"8f60d4b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What AI does not do: the limits and the human role<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-170b843 elementor-widget elementor-widget-text-editor\" data-id=\"170b843\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>An honest account of AI in the SOC has to be clear about its limits, because overselling it is itself a security risk. AI is a powerful tool, not a replacement for a security program.<\/p><p>AI is not infallible. It can produce false positives and, more dangerously, false negatives, and a system trusted blindly will eventually miss something or act wrongly. Attackers also adapt, and adversarial techniques designed to evade or manipulate machine learning models are a real and growing concern. AI struggles most with genuinely novel situations that fall outside its training and with the business context that determines whether a technically suspicious action is actually a problem. It also cannot own accountability: a decision to accept a risk, to notify a regulator, or to declare a major incident is a human responsibility.<\/p><p>This is why the mature model is not AI instead of analysts, but AI plus analysts. The AI handles the overwhelming volume of routine investigation at machine speed, and the human specialists apply judgment to the complex, the ambiguous, and the strategic. Threat hunting, incident command, tuning the system, and challenging its conclusions all remain human work. The organizations that get the most from AI are the ones that treat it as a force multiplier for their people, with human oversight built in, rather than as an autopilot to be left unattended.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aa1bd7f elementor-widget elementor-widget-heading\" data-id=\"aa1bd7f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">From assisted to autonomous: where the SOC is heading<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-43dd5a3 elementor-widget elementor-widget-text-editor\" data-id=\"43dd5a3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Security operations are moving along a spectrum. At one end is the assisted SOC, where AI helps human analysts work faster. At the other is the autonomous SOC, where AI independently investigates and resolves the large majority of alerts, escalating only what truly needs a person. Agentic AI, systems that can plan and execute multi-step tasks on their own, is what pushes the model toward that autonomous end.<\/p><p>The realistic near-term destination is not a SOC with no humans. It is a SOC where AI handles the routine end to end and humans supervise, hunt, and handle the hard cases, with clear guardrails on what the AI is allowed to do automatically. Organizations that adopt this model gain speed and coverage that a purely human SOC cannot match, while keeping the human judgment and accountability that security requires. The direction of travel is clear, and the competitive gap between AI-native operations and traditional ones is widening.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e3a581f elementor-widget elementor-widget-heading\" data-id=\"e3a581f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How Mercurius applies AI in its SOC<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0015648 elementor-widget elementor-widget-text-editor\" data-id=\"0015648\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Mercurius operates an AI-native SOC in which artificial intelligence carries the continuous investigation and triage, while certified specialists focus on hunting, complex incidents, and response. The design reflects the balance described above. AI reaches a verdict on alerts in minutes rather than leaving them in a human queue, filters the noise so analysts see what matters, and executes response within defined guardrails, while human experts retain oversight and own the decisions that require judgment and accountability.<\/p><p>The outcome for a client is a security operation that is faster, more consistent, and deeper than a purely human team of the same size, with the transparency to see what the AI concluded and why. It is the practical application of everything in this article: AI as a force multiplier for scarce human expertise, delivering measurable reductions in detection and response time.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bb7b591 elementor-widget elementor-widget-heading\" data-id=\"bb7b591\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Frequently asked questions<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d9a729 elementor-widget elementor-widget-text-editor\" data-id=\"2d9a729\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>What does AI do in a SOC?<\/strong> AI in a SOC autonomously investigates and triages security alerts, detects anomalies in user and system behavior, correlates weak signals into coherent incidents, and assists or automates response. Its main effect is to examine alerts at machine speed, cutting the time from alert to verdict and filtering noise before it reaches human analysts.<\/p><p><strong>Will AI replace SOC analysts?<\/strong> No.\u00a0AI replaces the repetitive triage work, not the analyst. It handles the high volume of routine investigation so human specialists can focus on threat hunting, complex incidents, tuning, and the decisions that require judgment and accountability. The proven model is AI plus analysts, with human oversight.<\/p><p><strong>How does AI reduce detection and response time?<\/strong> AI examines every alert the moment it arrives instead of waiting for a human to reach it in a queue, completes the investigation in minutes, and can trigger automated containment within guardrails. This lowers mean time to detect and mean time to respond, which in turn shrinks the attacker\u2019s dwell time.<\/p><p><strong>What are the limits of AI in security?<\/strong> AI can produce false positives and false negatives, can be targeted by adversarial techniques designed to evade or manipulate it, and struggles with genuinely novel situations and with business context. It also cannot hold accountability for decisions. These limits are why human oversight remains essential.<\/p><p><strong>What is an autonomous SOC?<\/strong> An autonomous SOC is one where AI independently investigates and resolves the large majority of alerts, escalating only what truly needs a human. It sits at one end of a spectrum that runs from the assisted SOC, where AI helps analysts, to fuller autonomy driven by agentic AI, always with human supervision and guardrails.<\/p><p><strong>What kinds of AI are used in a SOC?<\/strong> The main types are machine learning classifiers that prioritize alerts, anomaly detection and UEBA that flag abnormal behavior, large language models that investigate and explain in natural language, and agentic AI that carries out multi-step investigation and response. Mature SOCs combine several of these.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-63c64df e-con-full e-flex e-con e-child\" data-id=\"63c64df\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1f01ca9 elementor-widget elementor-widget-heading\" data-id=\"1f01ca9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Your team ins't missing threats. They're drowning in alerts.<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f68b31a elementor-widget elementor-widget-text-editor\" data-id=\"f68b31a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e4e80ba elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"e4e80ba\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\"><p class=\"lede\">Mercurius AI SOC pairs AI-driven triage with offensive-led human analysts \u2014 investigating every alert automatically and cutting detection-to-response from days to minutes. Operating 24\/7 across Brazil, Chile, and the U.S.<\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-887a49d elementor-widget elementor-widget-html\" data-id=\"887a49d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t\t<!-- ===== Mercurius \u00b7 SOC live triage card \u2014 Elementor HTML widget ===== -->\r\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=JetBrains+Mono:wght@400;500&display=swap\" rel=\"stylesheet\">\r\n\r\n<div class=\"ms-console-wrap\">\r\n  <div class=\"ms-console\" aria-hidden=\"true\">\r\n    <div class=\"ms-console-head\">\r\n      <span class=\"ms-t\">SOC \/\/ live triage<\/span>\r\n      <span class=\"ms-pulse\"><i><\/i> ACTIVE<\/span>\r\n    <\/div>\r\n    <div class=\"ms-rows\" id=\"msConsoleRows\">\r\n      <div class=\"ms-row\"><span>EDR \u00b7 endpoint scan<\/span><span class=\"ms-lvl noise\">noise<\/span><\/div>\r\n      <div class=\"ms-row\"><span>auth \u00b7 failed login \u00d73<\/span><span class=\"ms-lvl noise\">noise<\/span><\/div>\r\n      <div class=\"ms-row hot\"><span>identity \u00b7 impossible travel<\/span><span class=\"ms-lvl sig\">SIGNAL<\/span><\/div>\r\n      <div class=\"ms-row\"><span>cloud \u00b7 config drift<\/span><span class=\"ms-lvl noise\">noise<\/span><\/div>\r\n      <div class=\"ms-row hot\"><span>lateral \u00b7 SMB enumeration<\/span><span class=\"ms-lvl sig\">SIGNAL<\/span><\/div>\r\n      <div class=\"ms-row\"><span>dns \u00b7 routine lookup<\/span><span class=\"ms-lvl noise\">noise<\/span><\/div>\r\n    <\/div>\r\n    <div class=\"ms-console-foot\">\r\n      <span id=\"msCfCount\">9,214 alerts today<\/span>\r\n      <span class=\"ms-orange\" id=\"msCfSig\">2 escalated<\/span>\r\n    <\/div>\r\n  <\/div>\r\n<\/div>\r\n\r\n<style>\r\n  .ms-console-wrap{\r\n    --ms-line:#2C2F3C; --ms-line-soft:#22242E;\r\n    --ms-white:#FFFFFF; --ms-silver:#C9D2E2; --ms-muted:#7E8798; --ms-muted-2:#5A6274;\r\n    --ms-cyan:#5CDAF5; --ms-orange-bright:#FFB266;\r\n    display:flex; padding:0; background:transparent;\r\n  }\r\n  .ms-console{\r\n    width:100%; background:#1B1D25; border:1px solid var(--ms-line);\r\n    border-radius:14px; padding:18px; font-family:'JetBrains Mono',monospace; font-size:12.5px;\r\n    line-height:1.5; box-shadow:0 24px 60px rgba(0,0,0,.45); box-sizing:border-box;\r\n  }\r\n  .ms-console *{box-sizing:border-box}\r\n  .ms-console-head{display:flex; align-items:center; justify-content:space-between;\r\n    border-bottom:1px solid var(--ms-line-soft); padding-bottom:12px; margin-bottom:12px}\r\n  .ms-console-head .ms-t{color:var(--ms-silver); letter-spacing:.06em}\r\n  .ms-pulse{display:inline-flex; align-items:center; gap:7px; color:var(--ms-cyan); letter-spacing:.04em}\r\n  .ms-pulse i{width:7px; height:7px; border-radius:50%; background:var(--ms-cyan);\r\n    animation:msBlink 1.6s ease-in-out infinite}\r\n  @keyframes msBlink{0%,100%{opacity:1}50%{opacity:.25}}\r\n  .ms-row{display:flex; align-items:center; justify-content:space-between; padding:7px 0; color:var(--ms-muted)}\r\n  .ms-row.hot{color:var(--ms-silver)}\r\n  .ms-lvl{padding:1px 7px; border-radius:4px; font-size:11px; letter-spacing:.05em}\r\n  .ms-lvl.noise{background:#1d2029; color:var(--ms-muted-2)}\r\n  .ms-lvl.sig{background:rgba(255,154,58,.15); color:var(--ms-orange-bright)}\r\n  .ms-console-foot{margin-top:12px; padding-top:12px; border-top:1px solid var(--ms-line-soft);\r\n    display:flex; justify-content:space-between; color:var(--ms-muted-2); font-size:11px}\r\n  .ms-console-foot .ms-orange{color:var(--ms-orange-bright)}\r\n  @media(prefers-reduced-motion:reduce){.ms-console-wrap *{animation:none!important;transition:none!important}}\r\n<\/style>\r\n\r\n<script>\r\n(function(){\r\n  if(window.matchMedia('(prefers-reduced-motion: reduce)').matches) return;\r\n  var rows = document.getElementById('msConsoleRows');\r\n  var cfCount = document.getElementById('msCfCount');\r\n  var cfSig = document.getElementById('msCfSig');\r\n  if(!rows) return;\r\n  var noise = ['EDR \u00b7 process spawn','auth \u00b7 token refresh','dns \u00b7 routine lookup','cloud \u00b7 API call',\r\n    'edr \u00b7 file write','vpn \u00b7 session start','proxy \u00b7 web request','smtp \u00b7 outbound mail'];\r\n  var signals = ['identity \u00b7 impossible travel','lateral \u00b7 SMB enumeration','exfil \u00b7 large upload',\r\n    'persistence \u00b7 scheduled task','priv-esc \u00b7 token manipulation'];\r\n  var count = 9214, sig = 2;\r\n  setInterval(function(){\r\n    var isSig = Math.random() < 0.22;\r\n    var txt = isSig ? signals[Math.floor(Math.random()*signals.length)] : noise[Math.floor(Math.random()*noise.length)];\r\n    var row = document.createElement('div');\r\n    row.className = 'ms-row' + (isSig ? ' hot' : '');\r\n    row.style.opacity = '0';\r\n    row.innerHTML = '<span>'+txt+'<\/span><span class=\"ms-lvl '+(isSig?'sig':'noise')+'\">'+(isSig?'SIGNAL':'noise')+'<\/span>';\r\n    rows.insertBefore(row, rows.firstChild);\r\n    requestAnimationFrame(function(){ row.style.transition='opacity .5s'; row.style.opacity='1'; });\r\n    while(rows.children.length > 6) rows.removeChild(rows.lastChild);\r\n    count += Math.floor(2+Math.random()*9);\r\n    if(isSig) sig++;\r\n    cfCount.textContent = count.toLocaleString('en-US') + ' alerts today';\r\n    cfSig.textContent = sig + ' escalated';\r\n  }, 2600);\r\n})();\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a614bb8 elementor-widget elementor-widget-heading\" data-id=\"a614bb8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">See what your SOC is missing.<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-055dd3a elementor-button-info elementor-align-justify animated-fast elementor-invisible elementor-widget elementor-widget-button\" data-id=\"055dd3a\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;headShake&quot;}\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/mscyber.tech\/ai-soc\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Learn More<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>La IA en el SOC automatiza la clasificaci\u00f3n e investigaci\u00f3n de alertas, reduciendo el tiempo de detecci\u00f3n y la fatiga de los analistas. Conozca c\u00f3mo funciona, sus l\u00edmites y su impacto en la seguridad.<\/p>","protected":false},"author":5,"featured_media":3711,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[],"class_list":["post-3707","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-soc-ai"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI in the SOC: How Artificial Intelligence transforms security monitoring - Mercurius Cybersecurity<\/title>\n<meta name=\"description\" content=\"AI in the SOC automates alert triage and investigation, cutting detection time and analyst fatigue. Learn how it works, its limits, and its impact on security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/mscyber.tech\/es\/la-inteligencia-artificial-en-el-soc\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI in the SOC: How Artificial Intelligence transforms security monitoring - Mercurius Cybersecurity\" \/>\n<meta property=\"og:description\" content=\"AI in the SOC automates alert triage and investigation, cutting detection time and analyst fatigue. Learn how it works, its limits, and its impact on security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/mscyber.tech\/es\/la-inteligencia-artificial-en-el-soc\/\" \/>\n<meta property=\"og:site_name\" content=\"Mercurius Cybersecurity\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-11T19:51:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-11T19:53:21+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/mscyber.tech\/wp-content\/uploads\/2026\/09\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"kaue.simoes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"kaue.simoes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/\"},\"author\":{\"name\":\"kaue.simoes\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#\\\/schema\\\/person\\\/2e057da44c0b9c841b3b8acba1459547\"},\"headline\":\"AI in the SOC: How Artificial Intelligence transforms security monitoring\",\"datePublished\":\"2026-09-11T19:51:57+00:00\",\"dateModified\":\"2026-09-11T19:53:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/\"},\"wordCount\":2210,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mscyber.tech\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg\",\"articleSection\":[\"SOC AI\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/\",\"url\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/\",\"name\":\"AI in the SOC: How Artificial Intelligence transforms security monitoring - Mercurius Cybersecurity\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mscyber.tech\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg\",\"datePublished\":\"2026-09-11T19:51:57+00:00\",\"dateModified\":\"2026-09-11T19:53:21+00:00\",\"description\":\"AI in the SOC automates alert triage and investigation, cutting detection time and analyst fatigue. Learn how it works, its limits, and its impact on security.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#primaryimage\",\"url\":\"https:\\\/\\\/mscyber.tech\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg\",\"contentUrl\":\"https:\\\/\\\/mscyber.tech\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg\",\"width\":600,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/ai-in-the-soc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/mscyber.tech\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI in the SOC: How Artificial Intelligence transforms security monitoring\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#website\",\"url\":\"https:\\\/\\\/mscyber.tech\\\/\",\"name\":\"Mercurius Cybersecurity\",\"description\":\"AI-Driven Cyber resilience for critical organizations\",\"publisher\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/mscyber.tech\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#organization\",\"name\":\"Mercurius Cybersecurity\",\"url\":\"https:\\\/\\\/mscyber.tech\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/mscyber.tech\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/MERCURIUS-LOGO-Light-Color-2.svg\",\"contentUrl\":\"https:\\\/\\\/mscyber.tech\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/MERCURIUS-LOGO-Light-Color-2.svg\",\"width\":289,\"height\":48,\"caption\":\"Mercurius Cybersecurity\"},\"image\":{\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/mscyber.tech\\\/#\\\/schema\\\/person\\\/2e057da44c0b9c841b3b8acba1459547\",\"name\":\"kaue.simoes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/63c12ac971cb2964499a31feebfd9948fa35f6fa184fe2c25d8444b67112460a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/63c12ac971cb2964499a31feebfd9948fa35f6fa184fe2c25d8444b67112460a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/63c12ac971cb2964499a31feebfd9948fa35f6fa184fe2c25d8444b67112460a?s=96&d=mm&r=g\",\"caption\":\"kaue.simoes\"},\"url\":\"https:\\\/\\\/mscyber.tech\\\/es\\\/author\\\/kaue-simoes\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"IA en el SOC: C\u00f3mo la inteligencia artificial transforma el monitoreo de seguridad - Mercurius Cybersecurity","description":"La IA en el SOC automatiza la clasificaci\u00f3n e investigaci\u00f3n de alertas, reduciendo el tiempo de detecci\u00f3n y la fatiga de los analistas. Conozca c\u00f3mo funciona, sus l\u00edmites y su impacto en la seguridad.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/mscyber.tech\/es\/la-inteligencia-artificial-en-el-soc\/","og_locale":"es_ES","og_type":"article","og_title":"AI in the SOC: How Artificial Intelligence transforms security monitoring - Mercurius Cybersecurity","og_description":"AI in the SOC automates alert triage and investigation, cutting detection time and analyst fatigue. Learn how it works, its limits, and its impact on security.","og_url":"https:\/\/mscyber.tech\/es\/la-inteligencia-artificial-en-el-soc\/","og_site_name":"Mercurius Cybersecurity","article_published_time":"2026-09-11T19:51:57+00:00","article_modified_time":"2026-09-11T19:53:21+00:00","og_image":[{"width":600,"height":450,"url":"http:\/\/mscyber.tech\/wp-content\/uploads\/2026\/09\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg","type":"image\/jpeg"}],"author":"kaue.simoes","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"kaue.simoes","Tiempo de lectura":"14 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#article","isPartOf":{"@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/"},"author":{"name":"kaue.simoes","@id":"https:\/\/mscyber.tech\/#\/schema\/person\/2e057da44c0b9c841b3b8acba1459547"},"headline":"AI in the SOC: How Artificial Intelligence transforms security monitoring","datePublished":"2026-09-11T19:51:57+00:00","dateModified":"2026-09-11T19:53:21+00:00","mainEntityOfPage":{"@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/"},"wordCount":2210,"commentCount":0,"publisher":{"@id":"https:\/\/mscyber.tech\/#organization"},"image":{"@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#primaryimage"},"thumbnailUrl":"https:\/\/mscyber.tech\/wp-content\/uploads\/2026\/09\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg","articleSection":["SOC AI"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/mscyber.tech\/ai-in-the-soc\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/","url":"https:\/\/mscyber.tech\/ai-in-the-soc\/","name":"IA en el SOC: C\u00f3mo la inteligencia artificial transforma el monitoreo de seguridad - Mercurius Cybersecurity","isPartOf":{"@id":"https:\/\/mscyber.tech\/#website"},"primaryImageOfPage":{"@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#primaryimage"},"image":{"@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#primaryimage"},"thumbnailUrl":"https:\/\/mscyber.tech\/wp-content\/uploads\/2026\/09\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg","datePublished":"2026-09-11T19:51:57+00:00","dateModified":"2026-09-11T19:53:21+00:00","description":"La IA en el SOC automatiza la clasificaci\u00f3n e investigaci\u00f3n de alertas, reduciendo el tiempo de detecci\u00f3n y la fatiga de los analistas. Conozca c\u00f3mo funciona, sus l\u00edmites y su impacto en la seguridad.","breadcrumb":{"@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/mscyber.tech\/ai-in-the-soc\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#primaryimage","url":"https:\/\/mscyber.tech\/wp-content\/uploads\/2026\/09\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg","contentUrl":"https:\/\/mscyber.tech\/wp-content\/uploads\/2026\/09\/Artificial-intelligence-triaging-security-alerts-inside-a-SOC.jpg","width":600,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/mscyber.tech\/ai-in-the-soc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/mscyber.tech\/"},{"@type":"ListItem","position":2,"name":"AI in the SOC: How Artificial Intelligence transforms security monitoring"}]},{"@type":"WebSite","@id":"https:\/\/mscyber.tech\/#website","url":"https:\/\/mscyber.tech\/","name":"Mercurius Ciberseguridad","description":"Resiliencia cibern\u00e9tica impulsada por IA para organizaciones cr\u00edticas","publisher":{"@id":"https:\/\/mscyber.tech\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/mscyber.tech\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/mscyber.tech\/#organization","name":"Mercurius Ciberseguridad","url":"https:\/\/mscyber.tech\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/mscyber.tech\/#\/schema\/logo\/image\/","url":"https:\/\/mscyber.tech\/wp-content\/uploads\/2025\/09\/MERCURIUS-LOGO-Light-Color-2.svg","contentUrl":"https:\/\/mscyber.tech\/wp-content\/uploads\/2025\/09\/MERCURIUS-LOGO-Light-Color-2.svg","width":289,"height":48,"caption":"Mercurius Cybersecurity"},"image":{"@id":"https:\/\/mscyber.tech\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/mscyber.tech\/#\/schema\/person\/2e057da44c0b9c841b3b8acba1459547","name":"kaue.simoes","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/63c12ac971cb2964499a31feebfd9948fa35f6fa184fe2c25d8444b67112460a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/63c12ac971cb2964499a31feebfd9948fa35f6fa184fe2c25d8444b67112460a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63c12ac971cb2964499a31feebfd9948fa35f6fa184fe2c25d8444b67112460a?s=96&d=mm&r=g","caption":"kaue.simoes"},"url":"https:\/\/mscyber.tech\/es\/author\/kaue-simoes\/"}]}},"_links":{"self":[{"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/posts\/3707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/comments?post=3707"}],"version-history":[{"count":5,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/posts\/3707\/revisions"}],"predecessor-version":[{"id":3714,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/posts\/3707\/revisions\/3714"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/media\/3711"}],"wp:attachment":[{"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/media?parent=3707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/categories?post=3707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mscyber.tech\/es\/wp-json\/wp\/v2\/tags?post=3707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}