Skip to content
Technology agents
Enterprise OperationsTechnologyCybersecurity / SOC

SOC Alert Triage Agent

Reviews SIEM alerts and records evidence-backed dispositions.

Reads incoming security alerts, enriches them with asset, identity and threat-intel context, correlates them with related signals, and disposes benign alerts with a written rationale. Confirmed intrusions escalate to the hunter agent with the timeline already reconstructed and a containment recommendation pre-staged.

Authority

Act within policy

Team role

Routes work to specialists

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Cybersecurity / SOC

Desk workflow

Detection, then triage, then investigation, then containment, then threat hunt and remediation, with evidence and ownership carried from the initial alert through resolution.

Collaboration

Calls several specialists in parallel

Decision boundary

Acts only within an explicit policy, permission and escalation boundary.

Systems and capabilities involved

  • SIEM / SOAR platform

    read alerts, write dispositions

  • Threat-intel feeds

    RAG over IOC + TTP corpus

  • EDR / identity provider

    endpoint + auth context

  • Enrichment sandbox

    log parsing, IOC lookups

  • Threat-hunter agent

    escalate confirmed leads

Handoffs

What this role gives and receives

Capabilities offered

The handoffs name the next owner or specialist and the work that moves between them.

External handoff

Operations (enterprise incident-response agents) for confirmed breaches

Context

What the role needs to do the work

Current work
The alert, enrichment pulled, correlated signals, disposition lean.
Prior interactions
Prior alerts on the same asset/identity and their outcomes.
Policies and reference
MITRE ATT&CK mappings, asset criticality, known-good baselines.
Working method
Triage playbooks refined from oversight-agent overrides.

Illustrative workflow

How the work moves

Starting point

Impossible-travel alert: same identity authenticating from two continents in 20 minutes.

  1. 01

    Enrich both logins with device, IP reputation and prior session history.

  2. 02

    Correlate with EDR: one device is unmanaged and just downloaded a credential dumper.

  3. 03

    Map to ATT&CK (valid accounts leading to credential access); reconstruct the timeline.

  4. 04

    Pre-stage a containment recommendation (disable identity, isolate host).

Result

Escalates to the hunter agent as a likely account takeover with the timeline, ATT&CK mapping and a ready containment action; benign impossible-travel cases auto-close instead.

Checks and boundaries

What must be tested or reviewed

  1. 01Guardrail: cannot auto-close alerts on crown-jewel assets; forced escalation to the hunter agent.
  2. 02Daily replay against a labelled true-positive set; a missed intrusion is a Sev-1.
  3. 03Agent-as-judge sampling of closed alerts; precision/recall vs. the gold set.
  4. 04Full trace of enrichment retained for forensic audit.

Human authority

Acts only within an explicit policy, permission and escalation boundary.

Keep exploring