CapabilityCognitive automation2026-03-26
Microsoft researchers found AI-generated versions of 92 production detections matched the attack technique 99.4% of the time but reproduced the engineers' exclusions only 8.9% of the time
Security analyst (SOC)occupation page →Event date / reported
2026-03-26
Evidence stage
CapabilityA demo, benchmark or paper shows the task can be done. Updates what the technology can do — not what employers will do.
Tasks this bears on
Writing the detection
Turning what you learned from one incident into a rule that catches the next one without drowning the queue.
Being augmented≈ Platform inference
Where this applies
Microsoft researchers testing AI-assisted authoring of security detections against 92 of the company's production detections across five platforms and three query languages, generating 5,796 detections with eleven models. Generated detections matched the targeted attack technique 99.4% of the time and were syntactically valid 95.9% of the time, but matched the original exclusion logic only 8.9% of the time; the authors write that detection logic relies on unwritten environmental context, and that AI can accelerate drafting the skeleton and syntax while human engineers remain essential for environment-specific context and exclusions. It is a test against existing detections, not a deployment, and Microsoft sells security detection products.
What this means
A company with thousands of detections tested whether AI could write them: it gets the attack technique and the syntax almost always right, and the exclusions — the part that encodes what is normal here — almost always wrong. The cheap half of this task is the writing; the expensive half is still the knowing.
What it does not yet show
A test against one company's detections, not a deployment; it does not show how security teams actually use such tools or with what results.
What you can check
Open arXiv:2603.25930 ("AVDA: Autonomous Vibe Detection Authoring for Cybersecurity") and find "struggle with exclusion parity (8.9%)".
Does it change the assessment?
No — and this stage does not move it either. A "Capability" record is real evidence, but it does not upgrade a task judgement on its own. The 1 linked judgement above stand where they were.
Source
Fatih Bulut, Carlo DePaolis et al. (Microsoft) — "AVDA: Autonomous Vibe Detection Authoring for Cybersecurity", arXiv:2603.25930v1 (26 March 2026) · verified 2026-09-28 · Claude (VOLO agent) · interpreted 2026-09-28 · Claude (VOLO agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.