Home / Current Issue / Paper 1720191
AI-Powered Cyber Threat Detection and Automated Incident Response
Subject area: Science,Engineering and Technology · Area of research: Artificial Intelligence
DOI: https://doi.org/10.64388/IREV10I1-1720191
Abstract
As the volume, speed and sophistication of cyberattacks continue to increase, the ability of traditional signature-based and manually-operated security controls has not kept up, which is leading to the broad use of artificial intelligence (AI) throughout the cybersecurity lifecycle. This paper summarizes the latest advances in intrusion detection, explainable AI, ransomware and phishing detection, and security orchestration, automation, and response (SOAR) platforms and their role in cyber threat detection and automated incident response. The methodology employed in this literature review was narrative because it enabled identification and synthesis of peer-reviewed literature and authoritative technical standards of machine learning, deep learning and agentic artificial intelligence applications in security operations. The review concludes that AI-based detection systems consistently beat traditional rule-based detection systems on both reported accuracy and false positive metrics, explainability is emerging as a central requirement to enable analysts to build trust in the technology and to ensure regulatory compliance, and automation of incident response, especially with SOAR and new agentic architectures, significantly lowers mean time to containment and analyst workload. Meanwhile, the review outlines ongoing challenges such as combating adversarial use of AI models, addressing data quality issues, handling the complexity of integrating AI systems, and the ongoing need for human oversight. The paper argues that the auto-D&A should be used as an asset to augment human security analysts and not supplant them, and provides tips for companies looking to implement these technologies in responsible ways.
Keywords
Artificial Intelligence, Cyber Threat Detection, Automated Incident Response, Machine Learning, Security Orchestration, Explainable AI
How to cite this paper
@article{1720191,
author = {Darshankumar Jaysukh Dhanani},
title = {AI-Powered Cyber Threat Detection and Automated Incident Response},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {1},
pages = {3043-3054},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1720191.pdf},
abstract = {As the volume, speed and sophistication of cyberattacks continue to increase, the ability of traditional signature-based and manually-operated security controls has not kept up, which is leading to the broad use of artificial intelligence (AI) throughout the cybersecurity lifecycle. This paper summarizes the latest advances in intrusion detection, explainable AI, ransomware and phishing detection, and security orchestration, automation, and response (SOAR) platforms and their role in cyber threat detection and automated incident response. The methodology employed in this literature review was narrative because it enabled identification and synthesis of peer-reviewed literature and authoritative technical standards of machine learning, deep learning and agentic artificial intelligence applications in security operations. The review concludes that AI-based detection systems consistently beat traditional rule-based detection systems on both reported accuracy and false positive metrics, explainability is emerging as a central requirement to enable analysts to build trust in the technology and to ensure regulatory compliance, and automation of incident response, especially with SOAR and new agentic architectures, significantly lowers mean time to containment and analyst workload. Meanwhile, the review outlines ongoing challenges such as combating adversarial use of AI models, addressing data quality issues, handling the complexity of integrating AI systems, and the ongoing need for human oversight. The paper argues that the auto-D&A should be used as an asset to augment human security analysts and not supplant them, and provides tips for companies looking to implement these technologies in responsible ways.},
keywords = {Artificial Intelligence, Cyber Threat Detection, Automated Incident Response, Machine Learning, Security Orchestration, Explainable AI},
month = {July},
doi = {https://doi.org/10.64388/IREV10I1-1720191}
}