How an AI-Powered SOC Investigator Uncovered a Multi-Platform Data Theft Campaign
Wiz Research has shared a behind-the-scenes look at how its autonomous SOC investigator, the Blue Agent, works, using a real investigation as a case study. The alert began with unusual VPN activity tied to a CI/CD service account, a scenario that could easily be mistaken for a remote developer using a personal VPN.
Instead of stopping there, the Blue Agent dug into the details. It found that the account triggering the alert, svc_automation, was a non-human service account created back in 2018 purely for automated pipeline tasks. The login used a Kali Linux user agent, a tool often associated with offensive security testing, and the traffic came from an IP address linked to a hosting provider commonly used for VPN exit nodes, geolocated in Taiwan. None of these signals alone proved malicious activity, but together they pointed to something worth investigating further.
By following this trail across multiple cloud platforms, the Blue Agent eventually uncovered a broader attack: compromised credentials across several accounts, stolen source code, and custom tools already deployed to exfiltrate data. This case illustrates how automated investigation tools can correlate seemingly minor anomalies into evidence of a serious breach before analysts even get involved.