The first decision on every alert
Triage is the first decision a SOC makes about an alert: is it real, how serious is it, and who should handle it next. In many teams a tier-1 analyst makes that call by hand for every alert, which means opening several tools to gather context first.
AI alert triage gives that first pass to AI agents that work from the alert and its context. People spend their time on alerts that need judgment instead of on the ones that can be settled from data the platform already has.
How triage works in AgentSOC
In AgentSOC, triage is a stage in a continuous pipeline, not a separate tool. Alerts are normalized as they arrive and then classified, enriched, and correlated.
- Classification: each alert gets a category, a severity, a risk score, and a verdict.
- Enrichment: indicators are checked against VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise, MalwareBazaar, Kaspersky OpenTIP, MISP, CISA KEV, and IP-API geolocation.
- Correlation: related alerts are grouped into incidents with their own severity and confidence.
- Audit trail: analysts can filter, mark as seen, and escalate alerts, and each alert keeps its history.
What happens after the verdict
A verdict is only useful if something happens next. When triage confirms a threat, AgentSOC runs a response playbook through its built-in AgentSOAR engine, or through Shuffle if you run your own. When triage can't decide, the alert is escalated to an analyst, and an L2 or L3 investigation can continue as a case.
Notifications go out by email, Slack, Telegram, or PagerDuty, with severity-based SLA targets. The Security Copilot answers plain-language questions about your alerts, incidents, cases, and enrichment data.
