L1 SOC Triage Agent
The L1 SOC Triage Agent performs the initial triage of Microsoft Sentinel incidents in a fast, standardized way. It aggregates essential context (entities, severity, MITRE ATT&CK tactics, related alerts and signals) and classifies the next action (close, escalate, contain). It produces a single Markdown report with an executive summary, correlated evidence, analyst reasoning, and actionable recommendations—formatted for easy paste into ticketing systems.
Incident: GUID, incident number, or incident URL.
Close — Benign / False Positive
Remediate — Action Required
Escalate — Further Investigation Needed (Tier 2)
Concise Markdown report with Executive Summary, Incident Context & Entities, Correlated Evidence, Analyst Reasoning, Recommended Actions, and Coverage & Limitations.
Receives Incident parameter (GUID/number/URL) and retrieves incident details and entities using GetIncident and GetIncidentEntities.
Defender: EnrichIncidentWithDeviceContext, EnrichIncidentWithFileContext
Purview: GetDataRiskSummary, GetUserRiskSummary, ZoomIntoPurviewDataRisk, ZoomIntoPurviewUserRisk
Threat Intelligence (DTI): FindThreatIntelligence, GetSummaryForIndicators
Sentinel: GetSentinelIncidents (related/similar alerts)
NL2KQLDefenderSentinel: enables natural-language query generation to validate hypotheses
Correlates findings across enabled skillsets and determines the next action using objective evidence such as MITRE ATT&CK mapping, IOC correlation, device exposure, and user risk signals.
Produces a concise Markdown report and clearly identifies data sources and reasoning for the verdict.
Sentinel
Defender (via NL2KQLDefenderSentinel)
Purview
Fusion
ThreatIntelligence.DTI
M365
SOCTriageAgent (agent’s own group)
Microsoft Sentinel workspace with permissions to read incidents and entities.
Skillsets enabled and configured: Sentinel, Defender, Purview, ThreatIntelligence.DTI, NL2KQLDefenderSentinel, M365, Fusion.
1) Set up L1 SOC Triage Agent in the secure store.
2) Enable all required skillsets listed above.
3) Ensure Security Copilot plugin permissions include access to these data sources.
Want faster, standardized L1 triage for Sentinel incidents?
Contact us to enable L1 SOC Triage Agent and generate executive-ready markdown triage reports for ticketing systems.
Incident-driven. Evidence-based. Markdown-only output suitable for handoff to Tier 2 and stakeholders.