Security teams are experimenting with LLMs as an analytical layer inside the SOC, but “predictive” defense is really about earlier signal correlation, tighter triage, and stricter control of machine output.