Service

Agentic Assisted SOC


A managed security operations service for Microsoft Sentinel. Agents investigate every incident at full depth, 24 hours a day. Your analysts and ours judge, authorise and are accountable. You choose where the handover to your team sits.

The problem

A security queue is mostly noise wrapped around a small amount of signal, and every alert takes time to check. To survive the volume, teams sample, close by severity or trust the alert's own summary, so depth falls as the queue rises and the wrong closures go unnoticed. The analysts who could do better are spending their hours on alerts that turn out to be nothing.

How the work divides

  • Agents take on the part of the work that eats analyst time: investigation, correlation and writing up the evidence. Every incident is reconstructed from your raw sign-in, directory, audit and mail data, the same way every time, at any hour.
  • Your analysts and ours judge, authorise and are accountable. Nothing changes in your estate without a person approving it, and genuine compromises are never closed by us: they are escalated with the full evidence and held for your sign-off.
  • Every incident carries its analysis, timeline and verdict, on the incident itself, whichever option you choose.

What runs inside it

  • Incident triage and closure, continuously, 24 hours a day.
  • Hunting for what never alerted.
  • Tuning that makes the queue smaller every month.

Two ways to run it

  • Fully Managed: we take L1 and L2 and close the queue. L3 is joint, because containment decisions in your estate belong with you.
  • Hybrid: we investigate, validate and write the verdict onto every incident. Your team picks it up from L2 with the evidence already assembled. The handover point is yours to set, and to move as your team changes.
Always on, and contractable

Agents pick up each incident the moment it is raised, with no rota, no hand-over between shifts and no wait for a person to come on duty. Because the depth and the timing do not depend on who is working, response times can be written into a contract.

The evidence

  • In one review of 90 incidents, 2 were genuine compromises, both contained, 15 were real attacks that had already been fully blocked, and 71 were routine activity. All 88 still had to be investigated to be sure, and that is the work the agents took on, so the analysts' time went on the two that mattered.
  • A customer example: across 291 incidents that were automatically triaged in a day, only 16 needed an analyst's attention, 7 of which were escalated as potential compromises. The other 275 did not.
  • The tuning inside this service has, across two customers, taken about 13,200 unnecessary alerts a year off the queue and handed back more than 2,400 analyst hours.
The economics

The price tracks the incident queue, which is the work. If an incident is not raised, you are not billed for it, and the unit price falls as volume rises. A quieter queue costs you less, so tuning it is in our interest as well as yours.

Interested in Agentic Assisted SOC?


A brief, no-cost call confirms fit. Tell us what you run and what you need, and we will tell you plainly whether we can help.

Talk to us