Cybersecurity Research

How an AI-Powered SOC Investigator Uncovered a Multi-Platform Data Theft Campaign

Wiz Research · 29 Sept 2026
Key Takeaway Regularly audit service accounts for unexpected login patterns, such as VPN usage or unusual tools, since these accounts should never behave like human users.

Wiz Research has shared a behind-the-scenes look at how its autonomous SOC investigator, the Blue Agent, works, using a real investigation as a case study. The alert began with unusual VPN activity tied to a CI/CD service account, a scenario that could easily be mistaken for a remote developer using a personal VPN.

Instead of stopping there, the Blue Agent dug into the details. It found that the account triggering the alert, svc_automation, was a non-human service account created back in 2018 purely for automated pipeline tasks. The login used a Kali Linux user agent, a tool often associated with offensive security testing, and the traffic came from an IP address linked to a hosting provider commonly used for VPN exit nodes, geolocated in Taiwan. None of these signals alone proved malicious activity, but together they pointed to something worth investigating further.

By following this trail across multiple cloud platforms, the Blue Agent eventually uncovered a broader attack: compromised credentials across several accounts, stolen source code, and custom tools already deployed to exfiltrate data. This case illustrates how automated investigation tools can correlate seemingly minor anomalies into evidence of a serious breach before analysts even get involved.

cloud security data exfiltration AWS security SOC automation credential compromise

Summarised by CISO AI from Wiz Research. We link back to every original so you can read it yourself.