Skip to content
Search
paper2026Unreviewed

LLM-powered SOC Assistants: Prompt Injection Risks in Threat Triage

Tayyeb Nadeem Somro, Bilal Arshad, Ammara Gul

Abstract

Security Operations Centres (SOCs) are increasingly deploying Large Language Model (LLM) assistants to accelerate threat triage, alert prioritisation, and incident response. While these systems offer substantial productivity gains, their integration into security-critical pipelines introduces a novel and underexplored attack surface: prompt injection. This paper investigates how adversaries can manipulate LLM-powered SOC assistants by embedding malicious instructions within security alerts, log

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{somro2026llmpowered,
  title = {{LLM-powered SOC Assistants: Prompt Injection Risks in Threat Triage}},
  author = {Tayyeb Nadeem Somro and Bilal Arshad and Ammara Gul},
  year = {2026},
  doi = {10.2139/ssrn.7179658},
  url = {https://doi.org/10.2139/ssrn.7179658}
}