SOC Practitioners Assess LLM Integration: 15 Use Cases, Limited Readiness
A new study from arXiv (2608.00672) investigates the integration of Large Language Models (LLMs) into Security Operations Centers (SOCs). Based on 25 semi-structured interviews with SOC practitioners who have prior LLM experience, the research identifies 15 LLM use cases across six functional categories. While practitioners value LLMs for automating repetitive, low-level tasks such as report automation, they rate high-impact tasks like incident analysis as not yet feasible, citing limitations in technical depth and context awareness. The study aims to anticipate challenges and identify opportunities for responsible integration of LLM-based tools into SOC workflows.
Key facts
- 25 semi-structured interviews conducted with SOC practitioners
- 15 LLM use cases identified
- Use cases grouped into six functional categories
- LLMs valued for automating repetitive, low-level tasks
- High-impact tasks like incident analysis rated as not yet feasible
- Practitioners report limitations in technical depth and context awareness
- Study published on arXiv with identifier 2608.00672
- Research addresses gap in understanding LLM suitability for SOC workflows
Entities
Institutions
- arXiv