Local LLM Deployment for SOC: How Many Incidents Can One NVIDIA RTX PRO 6000 Handle?
In the second part of their experiment, analysts from R-Vision evaluated how a locally deployed large language model performs under realistic SOC workloads rather than isolated laboratory benchmarks. The configuration remained consistent with Part 1: the Qwen3.5-122B-A10B-GPTQ model served by vLLM on an NVIDIA RTX PRO 6000 Blackwell Max-Q GPU equipped with 96 GB of video memory.
The team shifted focus from measuring raw concurrency and generation speed to simulating actual Security Operations Center operations. Real anonymized incidents from their internal SOC were used instead of synthetic test cases. The model handled five core tasks: ranking open incidents by priority, summarizing key events and assets, searching for similar recent incidents, performing retrospective searches across deeper history, and generating preliminary verdicts based on prior steps.
Two distinct load profiles were tested. In a calm shift scenario, 3–5 L1/L2 analysts managed a steady flow of 10–15 incidents per hour. Background SOAR orchestration typically processed one or two incidents concurrently, generating up to six parallel requests during the data-collection phase. Interactive analyst chats added another two to three concurrent sessions, keeping overall concurrency between 8 and 12 requests.
Under peak conditions, such as a mass phishing campaign, 5–7 analysts faced 50–100 incidents arriving rapidly. When all 16 sequences were allocated to the background pipeline, up to four incidents could be processed simultaneously on the first phase (12 requests). With five sequences reserved for interactive work, three incidents could run in parallel. A full enrichment cycle of approximately 60 seconds allowed the queue of 50 incidents to be cleared in roughly 15–20 minutes.
To prevent interactive sessions from starving background tasks, an AI Gateway layer was introduced. It separated traffic into two pools: a high-priority “Interactive” pool limited to five concurrent requests with context up to 120k tokens, and a lower-priority “Background SOAR” pool supporting up to 11 concurrent requests with shorter contexts. The gateway also enforced context-length limits and dynamic prioritization to protect KV-cache capacity.
The experiment confirmed that one RTX PRO 6000 can sustain a background throughput of five incidents per minute, equating to 300 incidents per hour or 7,200 per day, when processing typical 10k–20k token incidents. The Mixture-of-Experts architecture of Qwen3.5-122B-A10B delivered effective intelligence close to a 122B model while maintaining generation speeds comparable to a 10B model, and disabling the thinking mode further improved responsiveness without sacrificing verdict quality for SOC tasks.
Related articles
AgentForger Vulnerability in ChatGPT Workspace Agents Enabled Malicious AI Deployment via Single Phishing Link
A vulnerability in ChatGPT Workspace Agents allowed attackers to create and deploy a malicious AI agent inside an organization from a single phishing link. Named AgentForger, the flaw was fixed by OpenAI on June 8, 2026. The attack exploited a permissive parameter in the Agent Builder that accepted instructions directly through the URL. An authenticated user opening the prepared link would trigger automatic execution of the command without additional confirmation. The victim required access to Workspace Agents and at least one pre-authorized enterprise connector such as Outlook, Gmail, Google Drive, Slack, Teams, or Google Calendar. The malicious prompt instructed the platform to create an agent, connect available applications, disable approval requests, publish the component, and schedule it for recurring operation. In the demonstration, the agent monitored emails from the attacker with subjects starting with “TASK” and executed the contained instructions while returning results to the attacker-controlled address.
AI Coding Tools Under Fire: Grok Build Uploads Entire Git Histories, Claude Code Suspected of Silent Transfers
Security researcher cereblab uncovered that Grok Build 0.2.93 establishes separate HTTPS channels to exfiltrate full Git repositories, resulting in a 27800-fold traffic discrepancy between task context and storage uploads to Google Cloud Storage buckets. The tool ignores user instructions such as "do not read" and decouples the improve_model_enabled client switch from the server-controlled trace_upload_enabled flag, allowing continued uploads even when privacy settings are disabled. Similar concerns emerged around Claude Code, which maintains undisclosed WebSocket connections that transmit file paths, dependency trees, and code metadata without user awareness or audit logs. Comparative traffic audits showed that Codex and Gemini produced no anomalous outbound activity, while Grok Build and Claude Code were the only tools confirmed to perform data transfers beyond user authorization. The incidents highlight systemic issues including server-side remote control of client behavior, lack of third-party audits for closed-source binaries, and the conflict between model training data needs and user data sovereignty. Experts recommend zero-trust measures such as network blocking, Docker sandboxing without mounting .git directories, git filter-repo sanitization, and preference for auditable open-source alternatives like Continue.dev or locally deployed Ollama models.
PentesterFlow Launches Open-Source AI CLI Tool for Penetration Testers and Bug Bounty Hunters
PentesterFlow is a new open-source, human-in-the-loop AI command-line tool designed specifically for penetration testers and bug bounty hunters. It automates the full workflow from reconnaissance to report generation while requiring explicit analyst approval before executing sensitive commands. The tool addresses common issues in agentic AI security tools such as hallucinations, weak context retention, and poor tool integration by incorporating built-in pentesting skills and evidence-based vulnerability confirmation. It supports connections to local or hosted LLMs including Ollama, Gemini, Groq, and others, and features continuous local learning that stores user preferences and lessons without retraining models. A key differentiator is its integration with Burp Suite and a permission-based execution model that includes a YOLO mode for isolated environments. The project positions itself as a transparent alternative to fully autonomous tools like PentAGI and PentestGPT.
Optimizing Cybersecurity Content for LLMs: How Sites Can Enter Generative AI Answers
Search engines and AI services like ChatGPT, Gemini, Perplexity, Copilot and Google AI Overviews increasingly deliver synthesized answers instead of link lists. For cybersecurity publishers this changes competition because high traditional rankings no longer guarantee visibility or accurate citation. The article explains GEO, AEO and LLMO practices, shows how material moves through indexing, fragment selection and summarization stages, and stresses the need for self-contained facts that survive extraction and paraphrasing. It provides concrete writing frameworks for vulnerability reports, including required fields such as CVE identifiers, affected versions, attack conditions and real-world exploitation evidence. Technical requirements cover correct robots.txt handling for Googlebot, OAI-SearchBot, GPTBot and Bingbot plus the use of IndexNow for rapid updates. The piece also warns about poisoning risks, prompt injection and slopsquatting attacks that can feed false data into generative systems.