IT EventsBook

Discussions

Community guidelines

Be specific and constructive. No vendor spam — promoting your own product belongs in a listing. Anyone can read; posting needs a free account.

ai SOC analyst tool...
 
Notifications
Clear all
ai SOC analyst tools, useful automation or expensive autocomplete?
5 Posts
3 Users
0 Reactions
3 Views
packetlost
(@packetlost)
Active Member
Joined: 4 weeks ago
Posts: 7
Topic starter   [#68]

Our Microsoft Sentinel rep is pushing Security Copilot as an add on. The demo summarizes alerts, writes KQL queries and suggests next steps. It looks nice, but our problem is noisy data and weak playbooks. Has this actually reduced investigation time for anyone, or does it just write confident summaries of bad alerts??



   
Quote
blue_team_bob
(@blue_team_bob)
Active Member
Joined: 2 weeks ago
Posts: 9
 

tbh, it helped with the boring parts, mainly timeline summaries and turning plain English into a first query. It did not fix detection quality. If the alert has missing host context, the AI still has missing host context. We got value only after connecting asset, identity and case data.



   
ReplyQuote
route_table
(@route_table)
Active Member
Joined: 2 weeks ago
Posts: 8
 

Don't let the vendor use mean time to close as the only success metric. People close low value alerts faster and the chart looks amazing. We sampled cases and checked whether the conclusion was supported by evidence. The model invented a cause often enough that analysts still had to verify everything.



   
ReplyQuote
packetlost
(@packetlost)
Active Member
Joined: 4 weeks ago
Posts: 7
Topic starter  

That's my concern. I can probably get budget for a pilot, not for another data project. What would you measure in the first month??



   
ReplyQuote
blue_team_bob
(@blue_team_bob)
Active Member
Joined: 2 weeks ago
Posts: 9
 

Pick two repeatable workflows. Measure analyst time, query edits, missed evidence and wrong recommendations. Keep the model read only. If it cannot show where each claim came from, do not put the summary in the incident record. A narrow win is better than buying an AI tier for every alert.



   
ReplyQuote
Share:
Scroll to Top