SOC Alert Triage Agent
Reviews SIEM alerts and records evidence-backed dispositions.
Reads incoming security alerts, enriches them with asset, identity and threat-intel context, correlates them with related signals, and disposes benign alerts with a written rationale. Confirmed intrusions escalate to the hunter agent with the timeline already reconstructed and a containment recommendation pre-staged.
Authority
Act within policy
Team role
Routes work to specialists
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Cybersecurity / SOC
Desk workflow
Detection, then triage, then investigation, then containment, then threat hunt and remediation, with evidence and ownership carried from the initial alert through resolution.
Collaboration
Calls several specialists in parallel
Decision boundary
Acts only within an explicit policy, permission and escalation boundary.
Systems and capabilities involved
SIEM / SOAR platform
read alerts, write dispositions
Threat-intel feeds
RAG over IOC + TTP corpus
EDR / identity provider
endpoint + auth context
Enrichment sandbox
log parsing, IOC lookups
Threat-hunter agent
escalate confirmed leads
Handoffs
What this role gives and receives
Capabilities offered
The handoffs name the next owner or specialist and the work that moves between them.
Handoff to
External handoff
Operations (enterprise incident-response agents) for confirmed breaches
Context
What the role needs to do the work
- Current work
- The alert, enrichment pulled, correlated signals, disposition lean.
- Prior interactions
- Prior alerts on the same asset/identity and their outcomes.
- Policies and reference
- MITRE ATT&CK mappings, asset criticality, known-good baselines.
- Working method
- Triage playbooks refined from oversight-agent overrides.
Illustrative workflow
How the work moves
Starting point
Impossible-travel alert: same identity authenticating from two continents in 20 minutes.
- 01
Enrich both logins with device, IP reputation and prior session history.
- 02
Correlate with EDR: one device is unmanaged and just downloaded a credential dumper.
- 03
Map to ATT&CK (valid accounts leading to credential access); reconstruct the timeline.
- 04
Pre-stage a containment recommendation (disable identity, isolate host).
Result
Escalates to the hunter agent as a likely account takeover with the timeline, ATT&CK mapping and a ready containment action; benign impossible-travel cases auto-close instead.
Checks and boundaries
What must be tested or reviewed
- 01Guardrail: cannot auto-close alerts on crown-jewel assets; forced escalation to the hunter agent.
- 02Daily replay against a labelled true-positive set; a missed intrusion is a Sev-1.
- 03Agent-as-judge sampling of closed alerts; precision/recall vs. the gold set.
- 04Full trace of enrichment retained for forensic audit.
Human authority
Acts only within an explicit policy, permission and escalation boundary.
Keep exploring