SOC Daily Brief Agent

SOC Daily Brief Agent

The SOC Daily Brief Agent generates a leadership-ready daily brief for the last 24 hours from Microsoft Sentinel and Defender XDR. It delivers a structured Markdown report with SecOps Efficiency (MTTT/MTTC), MITRE ATT&CK trends, automation health, and prioritized SOC Lead actions—ready for governance meetings and ticketing systems.

Customer value

  • Saves 30–60 min daily by eliminating manual SOC lead review across queues, dashboards, and workbooks.
  • Surfaces SecOps Efficiency with MTTT/MTTC, closing classification, product trends, and MITRE tactics.
  • Delivers a leadership-ready output with executive summary, prioritized actions, and audit/data quality notes.
  • Supports interactive follow-up via Chat with agent for scoped questions—read-only boundary preserved.

At a glance

Lookback

Fixed 24 hours. No runtime inputs for scheduled runs.

Trigger

DailyRun schedule, manual run, or Chat with agent.

Output

Markdown report designed for governance notes and ServiceNow/Jira paste.

Schedule trigger
Every 24h
Execution
DailyRun trigger, manual run, or Chat with agent
Output
Markdown

Daily brief workflow

1) Data collection

Aggregates incident lifecycle, queue metrics, alert patterns, detection drivers, SecOps Efficiency (MTTT/MTTC), and trends.

2) Enrichment

Sentinel: incident, alert, health, and efficiency signals

Defender XDR: evidence when available

Automation: playbook/rule health telemetry

3) Analysis

Determines operational status and highlights items that need SOC Lead attention (queue risk, efficiency issues, data gaps).

4) Report

Produces a concise Markdown brief separating facts, insights, recommendations, and data quality notes.

Enablement & how to run

Required skillsets

Sentinel

M365 (Defender XDR / Advanced Hunting)

Generic

Agent package skillset (orchestrator, chat, report generator + KQL skills)

Prerequisites

Microsoft Sentinel workspace with read access to incidents and entities.

Security Copilot workspace access with Security Reader (or equivalent).

Deployment steps

1) Set up SOC Daily Brief Agent in the Microsoft Security Store.

2) Enable required skillsets.

3) Validate via manual runs (5–10 business days).

4) Enable DailyRun for automated daily execution.

Want a daily, leadership-ready SOC brief with zero manual effort?
Contact us to enable SOC Daily Brief Agent and generate automated daily governance reports with SecOps Efficiency metrics, MITRE trends, and audit-ready evidence. Schedule-driven. Evidence-based. Markdown-only output suitable for SOC governance and stakeholder handoff.

Request contact