2026Unreviewed
LLM-powered SOC Assistants: Prompt Injection Risks in Threat Triage
Tayyeb Nadeem Somro, Bilal Arshad, Ammara Gul
Abstract
Security Operations Centres (SOCs) are increasingly deploying Large Language Model (LLM) assistants to accelerate threat triage, alert prioritisation, and incident response. While these systems offer substantial productivity gains, their integration into security-critical pipelines introduces a novel and underexplored attack surface: prompt injection. This paper investigates how adversaries can manipulate LLM-powered SOC assistants by embedding malicious instructions within security alerts, log
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{somro2026llmpowered,
title = {{LLM-powered SOC Assistants: Prompt Injection Risks in Threat Triage}},
author = {Tayyeb Nadeem Somro and Bilal Arshad and Ammara Gul},
year = {2026},
doi = {10.2139/ssrn.7179658},
url = {https://doi.org/10.2139/ssrn.7179658}
}