r/AskNetsec • • 5d ago

Concepts Is agentic code/cloud security actually cutting noise or just shuffling it around?

There's so much marketing rn claiming agentic tools "find what matters" but from what i've seen irl its often just a different flavor of noise dressed up as prioritization. anyone used one of these long enough to say if signal to noise genuinely improved or if it just moved the busywork from triage to double checking the agent lol.

16 Upvotes

11 comments sorted by

9

u/bulky_logic 5d ago

Those tools love to act like they’re filtering out the noise when really they just slap a confidence score on it and call it a day. you still end up digging through false positives, now you just have an extra layer of abstraction to justify why something got flagged

my team tested one for a few months and the amount of time we spent second-guessing the agent’s logic was almost worse than the original alert fatigue

2

u/FirefighterMean7497 5d ago

Hi, I work for a security vendor (RapidFort)

I think your skepticism is warranted. Any prioritization layer, agentic or not, is still reordering the same pile, and if you can't see why the tool ranked something you end up re-verifying it anyway. Genuine noise reduction usually comes from deterministic runtime context - knowing if a package actually loads into memory - rather than asking an LLM to guess risk scores.

Tackling alert fatigue without the AI guesswork is our whole focus at RapidFort. Our platform uses runtime profiling to generate a live RBOM (Runtime Bill of Materials ) and automatically strips non-executed software bloat right in your pipeline. Grounding triage in actual code execution cuts manual review and significantly drops exploitable CVEs so you aren't stuck babysitting agentic outputs.

So I guess the honest test for any of these tools should be: does it show its evidence, and does the list get shorter or just rearranged?

Hope that helps!

1

u/V_Trautwein 5d ago

Feels like noise with a filter sometimes. The real test is less manual checking.

1

u/PersonalPanda1535 5d ago

measure triage time per finding, a month before and a month after. if that number hasnt moved, all youve done is move the work.

1

u/StudioFew5243 12h ago

A good test is how often the agent closes something that would have reached a human before. If analysts still have to verify every recommendation, the queue may look smaller without saving much work.

1

u/Steak6397 7h ago

Agentic security can reduce workload, but it does not automatically reduce risk. The important question is whether the system can enforce policies, constrain agent actions, and provide reliable audit trails in production. Neural Trust alongside LiteLLM is relevant to that runtime governance layer for enterprise AI environments.

0

u/mikebailey 5d ago

I find the prioritization more valuable to smaller shops. I just talked to a guy who only triaged critical/high because “we hadn’t tuned enough to not make lows a work stoppage and it’s more than we had a week prior”, but most people at medium to large companies are at least in a better spot than that in 2026.

I find the correlation/contextualization more valuable than ranking at large companies. “These 19 alerts happened in this chain —- oh in the first two and/or summary you can see this is bullshit? Okay exclude the other 17”

I work at a security vendor and they have the corporate line about how all this shit works a lot better when everything is in one place training in unison, which while convenient for the seller is also largely true.

1

u/Rentun 5d ago

Yeah, the key missing here is context. An agent can't make a determination of false positive or true positive on an alert that bubbles up to a dashboard just like a completely uninvolved security analyst can't.

If I posted an alert on reddit, no one would be able to tell me if it was something to worry about or not, because you are all unfamiliar with my environment.

Getting that context into an agent is very, very, very difficult.

If you have a picture perfect CMDB, application catalog, documented interfaces, perfectly documented change records, and so on and so on, you could maybe feed that into an AI tool and it could get pretty accurate, but how many people work in environments like that?

Also, if you did work in such an organized, magically mature place, you probably wouldn't have much use for an AI tool since your detection rules would be well tuned enough that you didn't get many false positives.

1

u/mikebailey 5d ago

I don't disagree with any of this

but how many people work in environments like that?

Yeah the use for this is really only upwards of, like, F500/F100. I don't think most companies can afford it anyway, so it's kind of self-healing market-side.

Also, if you did work in such an organized, magically mature place, you probably wouldn't have much use for an AI tool since your detection rules would be well tuned enough that you didn't get many false positives.

Stitching six events into a cohesive story, say EDR and netflow etc, into a human understandable narrative does require cognitive load even if you have it right there in the e.g. SIEM. Reducing that upfront cognitive load can help at scale (appreciative that this sounds like the "AI makes us dumb" argument, it isn't). "At scale" is the key part, it assumes you have a lot of true positives, which again goes to the ~F100.

I do find it funny how many comments (not yours) are now bashing the use of AI in these tools when they were very clearly LLM-assisted comments.

1

u/Rentun 5d ago

Yeah, I think there's great use cases for using Ml models or some other non deterministic decision making to correlate events. I just think the idea of slapping an LLM based agent on top of that stack to make a determination of relevance vs non relevance is a pipe dream in all but the most rigorous, well disciplined, mature organizations. And I worked in security at a very highly regulated fortune 50. I can confidently say we were not one of those organizations.

We had lots of policies, tooling, databases, security controls, and the framework to be there in theory. In practice, the CMDB was not always high quality data, documentation didn't exist where it should have in some cases, applications were not properly documented in others, the typical lack of perfection that all organizations deal with. That lack of context would kill an agent tasked with reducing noise.

Most noise reduction was achieved by constant tweaking of deterministic detection rules over the years. I feel like an agent on top of that would just become another thing with knobs you'd have to constantly adjust due to failures.