Security triage

Every alert arrives with its homework done.

A detection fires. Before an analyst opens it, the context is already gathered, the runbook is already loaded, and the tools are already connected. Read-only, and only the ones you allowed.

The shape

Trigger, context, workspace.

Everything between the event and the first turn is gathered by an automation, so the agent never starts from nothing.

Trigger

Splunk · detection 4471

Impossible travel · svc-payments

Two successful logins, 4,100km apart, 18 minutes.

Gathered first

  • Asset owner and on-call rota from the CMDB
  • 24 hours of authentication events for the principal
  • Related detections on the same asset this week
  • The runbook for this detection ID
  • The last six tickets that closed as false positive

Composed of

soc-triage

mcp
splunk, crowdstrike (read-only)
tools
github
ttl
2h

An analyst opens a workspace that has already done the legwork, and spends their time on the decision instead of the gathering.

What it displaces

Before and after.

Forty minutes proving an alert is not real

Four minutes deciding whether it is

A runbook nobody opens because finding it takes longer than guessing

The runbook already in the workspace, for this detection ID

An AI SOC product with someone else's detection logic

Your runbooks, your model, your data boundary

Start with the context already gathered.

Create an account, compose a template, and start your first harness.