L1 SOC Triage Agent

L1 SOC Triage Agent

The L1 SOC Triage Agent performs the initial triage of Microsoft Sentinel incidents in a fast, standardized way. It aggregates essential context (entities, severity, MITRE ATT&CK tactics, related alerts and signals) and classifies the next action (close, escalate, contain). It produces a single Markdown report with an executive summary, correlated evidence, analyst reasoning, and actionable recommendations—formatted for easy paste into ticketing systems.

Customer value

  • Speeds up L1 time-to-respond with incident-centric correlation (no hopping across multiple panes).
  • Standardizes triage decisions (“true positive / benign / needs investigation”) to reduce analyst variance.
  • Delivers a single executive-ready output (evidence + prioritized recommendations), ready for ServiceNow/Jira.
  • Uses existing data (Sentinel/Defender) and handles missing signals gracefully.

Functional design (high level)

Input

Incident: GUID, incident number, or incident URL.

L1 verdict options

Close — Benign / False Positive

Remediate — Action Required

Escalate — Further Investigation Needed (Tier 2)

Report output

Concise Markdown report with Executive Summary, Incident Context & Entities, Correlated Evidence, Analyst Reasoning, Recommended Actions, and Coverage & Limitations.

Manual trigger
On-demand
Invocation
Analyst provides Incident (GUID / number / URL)
Output
Markdown

Triage workflow

1) Incident ingestion

Receives Incident parameter (GUID/number/URL) and retrieves incident details and entities using GetIncident and GetIncidentEntities.

2) Contextual enrichment

Defender: EnrichIncidentWithDeviceContext, EnrichIncidentWithFileContext

Purview: GetDataRiskSummary, GetUserRiskSummary, ZoomIntoPurviewDataRisk, ZoomIntoPurviewUserRisk

Threat Intelligence (DTI): FindThreatIntelligence, GetSummaryForIndicators

Sentinel: GetSentinelIncidents (related/similar alerts)

NL2KQLDefenderSentinel: enables natural-language query generation to validate hypotheses

3) L1 analysis & decision

Correlates findings across enabled skillsets and determines the next action using objective evidence such as MITRE ATT&CK mapping, IOC correlation, device exposure, and user risk signals.

4) Report generation

Produces a concise Markdown report and clearly identifies data sources and reasoning for the verdict.

Enablement & how to run

Required skillsets

Sentinel

Defender (via NL2KQLDefenderSentinel)

Purview

Fusion

ThreatIntelligence.DTI

M365

SOCTriageAgent (agent’s own group)

Prerequisites

Microsoft Sentinel workspace with permissions to read incidents and entities.

Skillsets enabled and configured: Sentinel, Defender, Purview, ThreatIntelligence.DTI, NL2KQLDefenderSentinel, M365, Fusion.

Deployment steps

1) Set up L1 SOC Triage Agent in the secure store.

2) Enable all required skillsets listed above.

3) Ensure Security Copilot plugin permissions include access to these data sources.

Want faster, standardized L1 triage for Sentinel incidents?
Contact us to enable L1 SOC Triage Agent and generate executive-ready markdown triage reports for ticketing systems. Incident-driven. Evidence-based. Markdown-only output suitable for handoff to Tier 2 and stakeholders.

Request contact