SOC Monthly Brief Agent

The SOC Monthly Brief Agent generates an executive-ready SOC leadership review comparing the current month-to-date with the previous completed calendar month. It consolidates incident lifecycle, SecOps Efficiency (MTTT/MTTC/High-severity MTTC), MITRE ATT&CK trends, backlog evolution, recurring entities, automation health, service value evidence, and a prioritized improvement plan—formatted in Markdown for monthly governance, service reviews, and CISO inputs.

Customer value

  • Saves 2–4 hours per cycle by replacing manual consolidation across queues, workbooks, dashboards, and service review notes.
  • Surfaces month-over-month trends across MTTT/MTTC, closure quality, product, MITRE tactics, and backlog—not just raw counts.
  • Executive-ready output with CISO summary, service value evidence, decision snapshot, and audit/data-quality notes.
  • Continuous improvement plan with prioritized actions for SOC Manager, Detection Engineering, Automation, and Service Delivery—read-only boundary preserved.

At a glance

Lookback

Fixed current month-to-date vs. previous completed calendar month.

Trigger

MonthlyRun schedule, manual run, or Chat with agent.

Output

Markdown review designed for monthly governance, service reviews, and CISO inputs.

30
Schedule trigger
Monthly cadence
Execution
MonthlyRun trigger, manual run, or Chat with agent
Output
Markdown

Monthly review workflow

1) Define monthly windows

Sets current month-to-date (1st day at 00:00 UTC to execution time) and previous completed calendar month for month-over-month comparison.

2) Collect & normalize

Defender XDR / Unified portal: incidents, alerts, entities, evidence

Sentinel (when onboarded): incident, alert, automation telemetry

Operational: backlog, aging, assignment, closure quality, service value indicators

3) Compare & analyze

Calculates deltas, identifies trends, evaluates SecOps Efficiency, MITRE coverage, recurring entities, and operational maturity.

4) Generate executive review

Produces a Markdown monthly review with service value evidence, decision snapshot, CISO summary, and prioritized improvement plan.

Enablement & how to run

Required skillsets

M365 (Defender XDR / Unified security operations)

Sentinel data when onboarded in the unified portal (optional)

Generic

Agent package skillset (orchestrator, chat, report generator + KQL skills)

Prerequisites

Security Copilot workspace access with Security Reader (or equivalent) and appropriate Defender XDR Unified RBAC.

Read access to incidents, alerts, entities, and automation health data.

Deployment steps

1) Set up SOC Monthly Brief Agent in the Microsoft Security Store.

2) Enable required skillsets and validate data access.

3) Run manually during current month and at month close (1–2 cycles).

4) Enable MonthlyRun aligned with the customer service review cadence.

Want executive-ready monthly SOC governance with zero manual effort?
Contact us to enable SOC Monthly Brief Agent and generate automated monthly leadership reviews with month-over-month trends, service value evidence, MITRE visibility, and a prioritized improvement plan. Monthly-driven. Evidence-based. Markdown-only output suitable for executive governance, service reviews, and CISO reporting.

Request contact