01
From fixed automation to adaptive investigation
Security teams already automate assignment, enrichment, ticketing and notifications. Agentic AI can go further by understanding the incident category, selecting approved tools, forming hypotheses, gathering supporting and contradicting evidence, reassessing risk and preparing a structured recommendation.
The objective is not to replace analysts. It is to reduce repetitive investigation work while improving consistency, context and decision quality.
02
A practical Agentic SOC architecture
- Classify the incident, affected entities, SLA and relevant playbook.
- Use specialised workflows for identity, email, endpoint, cloud, network and exposure investigations.
- Expose only approved, authenticated and logged security functions.
- Score suspicious evidence, risk-lowering context, confidence and potential impact separately.
- Place human approval between a recommendation and sensitive remediation.
- Preserve tools, queries, evidence, assumptions, decisions, actions and failures in an audit layer.
03
Four investigation patterns
An unusual sign-in needs both risk-increasing and risk-lowering context. A trusted sender can still be compromised, requiring email, identity and endpoint correlation. An incident-to-ticket workflow needs retries, idempotency and failure monitoring. A noisy detection should produce a reviewable tuning recommendation rather than an invisible production change.
These patterns show why the strongest investigation systems combine security telemetry, operational resilience and analyst judgement.
04
Explain the risk, do not just score it
A single opaque score is not sufficient. Analysts need to understand which signals increased risk, which signals reduced it, how reliable the evidence was, what was missing and what could change the conclusion.
- Signal risk and observed behaviour.
- Identity and asset importance.
- Evidence confidence and completeness.
- Risk-lowering business and technical context.
- Potential impact if the activity is malicious.
05
Automate evidence, govern remediation
Evidence collection, IOC enrichment, historical searches, entity mapping, timelines, ticketing, tagging and SLA monitoring are good candidates for automation. Disabling users, revoking critical sessions, isolating production systems or closing high-severity incidents normally requires approval.
Microsoft Defender XDR and Microsoft Sentinel provide useful foundations for this model through evidence verdicts, pending remediation actions, automation rules, tasks and Logic Apps playbooks.
06
A 90-day path to a governed pilot
- Days 1-30: select high-volume categories, define evidence and closure criteria, validate telemetry and map permissions.
- Days 31-60: build read-only tools, category workflows, evidence normalisation, risk scoring and audit records.
- Days 61-90: test historical cases, run in analyst-assist mode, compare findings, add approvals and automate only low-risk actions.
07
Measure operational outcomes
Success is not the number of summaries an AI generates. Measure evidence-collection time, investigation time, containment time, analyst handling, false positives, reopened incidents, incorrect recommendations, automation failures and analyst acceptance.
The strongest outcome may be a substantially faster investigation with the analyst still accountable for the final decision.
References
