Solutions/Autonomous SOC

An autonomous SOC where humans keep the critical calls.

Jutsu AgentSOC gives the repetitive work of security operations to AI agents. Uncertain alerts go to an analyst, and every response action is logged and can be reverted.

Escalates uncertain alertsApproval or policy gatesReversible actions
Start free
AgentSOC · SOC overview
AgentSOC dashboard
Agents do the legwork
Six agents split the work: detection, enrichment, triage, response, reporting, and learning.
People decide the hard cases
When triage can't settle an alert with confidence, an analyst gets it.
Gated response
Response runs on analyst approval or within policies you define.
Everything on record
Each action is auditable, and AgentSOAR actions can be reverted.
Explainer

What is an autonomous SOC?

Autonomy is a question of who decides what

An autonomous security operations center (SOC) uses software agents to do the routine work of a SOC without waiting for a person to start each step. That work includes collecting and normalizing events, adding context, deciding how serious an alert is, grouping related alerts, and taking the first response.

Autonomous does not mean unattended. A useful definition says which decisions the system may make alone and which it must hand to a person. If a design can't answer that, it is automation without guardrails.

How the work flows in AgentSOC

Jutsu describes AgentSOC as a single AI-native platform that replaces a stack of disconnected tools: a SIEM, a separate SOAR, threat-intelligence feeds, and standalone reporting. Each event that enters the platform passes through the same pipeline.

  • Ingest: events arrive from Wazuh, Google Workspace, syslog, or the Ingest API.
  • Normalize and triage: each alert gets a category, severity, risk score, and verdict.
  • Enrich: indicators are checked against threat intelligence such as VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise, MalwareBazaar, Kaspersky OpenTIP, MISP, CISA KEV, and IP-API geolocation.
  • Correlate: related alerts become incidents, including multi-hop attack chains such as lateral movement.
  • Respond: AgentSOAR runs response actions against connected cloud, email, and identity providers.
  • Report: incident reports and SOC, compliance, and executive reports are generated for you.

Where humans stay in control

AgentSOC bounds its own autonomy in four ways. They are why your team can let agents work through the queue without losing control of what happens in production.

  • Escalation: alerts the agents can't resolve with confidence go to an analyst for investigation.
  • Approval-based response: from the Startup plan, an analyst approves an action before it runs.
  • Policy-guided automation: from the Growth plan, actions your policies allow can run on their own.
  • Audit and revert: every AgentSOAR execution is recorded with its status, and actions such as blocking an IP, isolating a host, or disabling a user can be reverted.

Roles for a tiered team

Role-based access follows the shape of a real SOC. Organizations can assign owner, admin, member, and analyst roles, including L1, L2, and L3 analysts. Cases carry evidence, comments, and escalation, so a handoff from the agents to an analyst, or from L2 to L3, keeps its context.

How it works

Three steps, end to end.

1

Connect your sources

Stream Wazuh, Google Workspace, and syslog events into one pipeline, or post custom events to the Ingest API.

2

Agents work every alert

Alerts are triaged, enriched with threat intelligence, and correlated into incidents around the clock.

3

You keep the critical calls

Confirmed threats run through response under your approval or policy. Uncertain ones go to an analyst.

Capabilities

The agents behind the autonomous SOC.

Detection agent

Looks for suspicious behavior across the environments you connect.

Enrichment agent

Adds threat-intelligence, asset, user, and cloud context to each alert.

Triage agent

Sets each alert's severity and confidence, and escalates the uncertain ones.

Response agent

Builds a remediation plan and carries it out through AgentSOAR, within your gates.

Reporting agent

Writes incident reports plus SOC, compliance, and executive reports.

Learning agent

Uses analyst feedback to improve detections and reasoning.

FAQ

Common questions.

See an autonomous SOC on your own alerts.

Book a demo, or start on the Free plan with no credit card.

Start free

Subscribe to our newsletter

Get the latest security tips, product updates, and news delivered to your inbox.