Report an Incident Become a Partner Careers Contact
Book a Demo
The platform

CYBERSHIELD AI

The agentic AI platform powering modern security operations. Fourteen specialised agents work as a coordinated SOC — triaging, investigating, hunting, managing exposure and containing threats, with senior human analysts accountable for every outcome.

app.wizardcyber.com
CYBERSHIELD AI — performance dashboard
Average L1 verdict
3m 30s

Triaged, enriched and decided, with the evidence attached.

Autonomy
You set the dial

Fully autonomous, held for approval, or autonomous above your threshold.

What is CYBERSHIELD AI

Not an AI feature bolted onto a SIEM.
A SOC team built from agents.

Most tools stop at enrichment — they add context to an alert and hand it back. CYBERSHIELD AI investigates: it gathers evidence, tests hypotheses and reaches a verdict.

It reaches a verdict

Every incident gets a structured outcome — malicious or benign, scope, root cause, impact, confidence and a recommended action. Not a longer alert.

It knows your business

Investigations run against a Threat Attack Profile built for your sector, geography, technology stack and known adversaries — not a generic playbook.

It stays accountable

Agents do the repetitive work; a senior human analyst reviews and approves every customer-facing decision. Responsibility never sits with the model.

The agent team

Fourteen agents. Fourteen jobs.
One coordinated SOC.

This is a SOC org chart, not a feature list — each agent owns one function, the way a real SOC is staffed. Colour shows the squad: blue defence, red offensive, green engineering.

Front line

2 agents

Everything arriving in the queue, plus standing cover on the accounts and systems you can least afford to lose.

L1

SOC L1 Triage Agent

The front door. Every alert passes through here first.

  • Monitors incoming alerts continuously
  • Enriches each alert with user, device and asset context
  • Filters false positives and prioritises by business impact
  • Escalates to L2 — the only route out of triage
WATCH

Watch Agent

The early warning, ahead of any alert firing.

  • Monitors high-risk users, admins and critical systems
  • Tracks behavioural drift against normal patterns
  • Maintains the standing watchlists you define

Investigation

3 agents

Turning escalations into evidenced verdicts, with real-world context attached.

L2

SOC L2 Investigation Agent

The hub. Works escalations to a verdict and directs every other agent.

  • Correlates logs, endpoint, identity and cloud telemetry
  • Reconstructs the timeline; determines scope, root cause and impact
  • Expands the investigation automatically when confidence is low
  • Tasks the specialist agents and hands to L3 for sign-off
FUSION

Fusion Agent

Joins the dots, then asks whether this is one incident or a campaign.

  • Links related alerts, assets and identities into a single incident
  • Collapses duplicate signals arriving from different tools
  • Works with the completeness gate to decide whether an incident belongs to a wider campaign
  • Maintains the register of active and closed campaigns
INTEL

Intel Analyst Agent

The context. Global intelligence, made specific to you.

  • Tracks threat actors relevant to your sector and geography
  • Maps adversary TTPs to your actual environment
  • Maintains your Threat Attack Profile as the landscape shifts

Proactive

4 agents

Finding what never alerted — and closing the gaps that let it through in the first place.

HUNT

Threat Hunter Agent

Looks for what no detection caught.

  • Generates and tests hunting hypotheses
  • Correlates weak signals that individually look benign
  • Turns findings into new detection candidates
DET

Detection Engineering Agent

Every incident makes the next one easier to catch.

  • Tunes noisy rules that generate low-value alerts
  • Writes and refines detection logic for new TTPs
  • Tracks coverage against MITRE ATT&CK
VULN

Vulnerability Management Agent

Exposure ranked by what attackers can actually reach.

  • Correlates vulnerability data with real exposure and asset criticality
  • Prioritises by exploitability and active threat, not CVSS alone
  • Tracks remediation progress across the estate
INSIDER

Insider Risk Agent

Watches the threat that already has a login.

  • Puts named users on watch, for leavers or where there is cause
  • Builds a scheduled end-of-day report with AI analysis of the day’s activity
  • Reviews data accessed, login locations and behaviour against the user’s norm
  • Runs periodic checks across the estate and flags what looks suspicious for investigation

Response

1 agent

Containment planned and executed inside the limits you set at onboarding.

RESP

Response Agent

From verdict to contained, without waiting for a ticket.

  • Builds the containment plan for a confirmed incident
  • Executes pre-authorised actions within your containment matrix
  • Verifies the action landed and reports what changed

Service Ops

4 agents

The agents that run the SOC itself — included on every package, because the service does not work without them.

COMMS

Communications Agent

Keeps people informed while an incident is still moving.

  • Drafts incident notifications for your named contacts
  • Produces technical write-ups and board-level summaries
  • Maintains status updates through the life of an incident
RPT

Reporting Agent

Turns a month of security operations into something you can act on.

  • Produces scheduled service and executive reporting
  • Tracks incident trends, SLA performance and detection coverage over time
  • Builds board-ready summaries from the underlying case data
MAINT

Maintenance Agent

Makes sure the SOC can still see.

  • Monitors telemetry sources for ingestion gaps and connector failures
  • Flags silent log-shipping failures before they become blind spots
  • Checks detection rule health across the estate
MGR

SOC Manager Agent

The coordinator. Runs the shift and holds the standard.

  • Assigns work across agents and tracks the queue
  • Enforces confidence thresholds and QA sampling
  • Monitors service performance against Mean Time to Verdict
See it in action

One platform for the whole
detection-and-response lifecycle.

What it’s built from

Agents are the roles.
Skills and tools are the how.

01 Agents

One per SOC function — triage, investigation, watch, intel, hunting, detection, exposure, response, and the three that run the service. Each owns a single job.

02 Skills

Named analyst procedures the agents execute: assess token replay, audit mailbox rules for exfiltration, reconstruct a 72-hour timeline, and more.

03 Tools

The integrations and actions those skills draw on across identity, endpoint, cloud, email and the rest of your security stack.

Watch it run

Watch an alert become
an answer.

A real AiTM (adversary-in-the-middle) case, replayed — investigated, scoped and contained end to end, holding for human approval before anything executes.

LIVE T+00:00
Buying the platform

Your own instance,
in your own region.

CYBERSHIELD AI is sold as a dedicated platform as well as delivered as a managed service. Bought as a platform it is single tenant — your own deployment, running on your data, operated by your own SOC.

Single tenant, always

A platform deployment is yours alone. Not a partition, not a namespace inside somebody else’s instance — a dedicated deployment, with no shared services and no cross-customer anything.

Fully hosted, or part hosted

Two components decide the shape of the deployment: the Azure AI Foundry the agents run on, and the database that holds your data. Each can sit on either side.

Azure AI Foundry

The model and agent runtime. Host it in your own subscription, or let us run it in the deployment we manage for you.

The database

Where your investigations, evidence and history live. The most common reason to self-host, and the easiest one to take on.

Fully hosted

We host both. The fastest route to running, and the one most teams start on.

We host FoundryDatabase
You host Nothing

You hold the data

Your database, our Foundry. The usual answer when residency or retention policy sits with you.

We host Foundry
You host Database

You hold the runtime

Your Foundry, our database. For estates with their own Azure AI governance already in place.

We host Database
You host Foundry

Fully self-hosted

Both in your subscription. Everything runs inside your tenant; we maintain the platform on it.

We host Nothing
You host FoundryDatabase
Any Azure region, in country

Deployed into the region you need, including in-country where that matters for residency or regulation.

Subject to Microsoft having a region there, and to the services the platform depends on being available in it — a Microsoft constraint rather than ours, and worth checking early for anywhere unusual.

Who runs what

Your team

You run the SOC

Your own security team operates the platform day to day — the agents work the queue, your analysts hold L3 and set the autonomy dial per agent.

Wizard Cyber

We maintain the platform

Updates, new agent capability and platform maintenance are ours, wherever it is hosted. Self-hosting does not hand you a maintenance burden.

Wizard Cyber

Tool development, on request

When an investigation needs a tool that does not exist yet for your estate, we build it. Purchased as development rather than bundled, so you pay for what you ask for.

Talk to us about a platform deployment

Questions

CYBERSHIELD AI, answered.

What is CYBERSHIELD AI?

CYBERSHIELD AI is an agentic security operations platform built and run by Wizard Cyber. Instead of one AI model bolted onto a SIEM, it runs a roster of specialised agents — each owning a single SOC function such as triage, investigation, threat hunting or containment — coordinated by an orchestration core, with senior human analysts accountable for every customer-facing decision.

How many AI agents does CYBERSHIELD AI have?

They are grouped by SOC function: front line (L1 Triage, Watch), investigation (L2 Investigation, Fusion, Intel Analyst), proactive (Threat Hunter, Insider Risk, Detection Engineering, Vulnerability Management), response (Response Agent), and service operations (SOC Manager, Communications, Reporting, Maintenance). The roster grows as we add agents.

Does CYBERSHIELD AI replace human security analysts?

No. Agents carry the repetitive analyst workload, but a senior human analyst reviews and approves every customer-facing decision before it reaches you. High-impact containment actions are held for human approval. Responsibility for an outcome never sits with the model.

How is this different from an AI feature added to a SIEM?

Most tools stop at enrichment — they add context to an alert and hand it back to you. CYBERSHIELD AI investigates: it gathers evidence, tests hypotheses and reaches a structured verdict stating whether activity is malicious or benign, along with scope, root cause, impact, a confidence score and a recommended action.

What is a Threat Attack Profile?

A Threat Attack Profile is a per-customer model of who realistically targets you, built from your sector, geography, technology stack and operations, and the threat actors active against organisations like yours. Investigations run against that profile rather than a generic playbook, and it is maintained as the threat landscape shifts.

Can I buy CYBERSHIELD AI as a platform and run it myself?

Yes. CYBERSHIELD AI is sold as a dedicated platform as well as delivered as a managed service. A platform deployment is single tenant — your own instance, operated day to day by your own security team. You can have it fully hosted by us, fully self-hosted in your own Azure subscription, or part hosted: the Azure AI Foundry the agents run on and the database holding your data can each sit on either side. We maintain the platform and ship updates wherever it is hosted, so self-hosting does not hand you a maintenance burden.

Which Azure region can CYBERSHIELD AI be deployed in?

Any Azure region, including in-country where data residency or regulation requires it. The practical limit is Microsoft’s rather than ours: there has to be an Azure region in that country, and the services the platform depends on have to be available in it, which is not true of every service in every region. It is worth checking early for anywhere unusual.

Does my data stay in my own tenant?

Yes. Your data stays in your tenant and isolation is enforced architecturally, not by policy alone. There is no cross-customer learning between tenants.

See it on your estate

See CYBERSHIELD AI run against
your own environment.

Book a demo and watch the agents work a real scenario — with our senior analysts walking you through every decision.