Full investigation report
The complete case on every incident: evidence gathered, hypotheses tested, scope, root cause, impact and confidence.
A fully managed security operations centre where the analyst workload is carried by fourteen specialised AI agents — triage, investigation, hunting, exposure and containment — backed by a 24/7 manned SOC where named senior analysts sign off every customer-facing decision.
CYBERSHIELD AI is our own agentic security operations platform, built and run in-house by the SOC that uses it. 14 agent personas draw on 250+ agent skills and 300+ AI tools to work an incident all the way to a verdict, not just to a ticket.
Every one of those skills is a procedure our analysts wrote while running Microsoft Sentinel for customers since 2019. Nothing here is a model trained on public threat data.
A managed security operations service where the analyst workload — triage, investigation, hunting, intelligence and detection — is carried by AI agents, with senior humans accountable. A traditional MSSP scales by hiring; a managed AI SOC scales by adding agents.
Every investigation produces the same complete set of documents — not a summary line in a portal, and not only on the incidents someone had time for.
The complete case on every incident: evidence gathered, hypotheses tested, scope, root cause, impact and confidence.
Produced whenever an incident is escalated, so your team inherits the reasoning rather than a ticket number.
A plain-English account of what happened and how it was resolved, written for the record.
A ready-to-send notification for your stakeholders, drafted while the incident is still moving.
The honest answer to the question every buyer asks: no, it does not act on its own. Here is exactly where the line sits, and who draws it.
One place where every agent reports, and where our analysts watch and approve what they do. Nothing runs unobserved.
You decide which agents may act, on what, and where the line sits. Your configuration is yours — it is not a shared platform default.
Set the bar. Below it, the action waits for a human. Above it, the agent proceeds and the decision is still recorded.
Senior analysts and responders remain in the loop for the decisions that carry real consequence. That is deliberate, not a limitation.
The orchestration agent tracks queue, confidence and service performance, and escalates to a human when the standard is not met.
Your incidents, verdicts, reports and service performance — live, not a monthly PDF.
Approve, review and stay across live incidents from anywhere, including out of hours.
A team you can reach by name, with defined escalation paths to human experts.
These aren’t upsells. They’re the conditions that make the service defensible — so they apply from the entry tier upwards.
Agents run continuously and our SOC is staffed by security professionals around the clock, every day of the year.
We measure the whole chain — signal received to signed-off outcome — not just how fast a machine acknowledged an alert.
Every customer-facing decision is reviewed and approved by an experienced human analyst before it reaches you.
Every incident closes with a structured outcome: malicious or benign, scope, root cause, impact, a confidence score and a recommended action.
Your data stays in your tenant. No cross-customer learning, enforced architecturally.
A named team you can reach, with defined escalation paths to human experts.
Per agent: fully autonomous, held for your approval, or autonomous above a threshold you set. High-impact containment is held for a human either way.
Microsoft Sentinel is the only hard requirement. Connectors, parsers, analytical rules and playbooks for what you already run are built during onboarding, as part of the service.
Start where you are and move up when the estate does. Every tier includes the 24/7 manned SOC, senior analyst sign-off and a structured verdict on every incident; the package decides how much of the agent roster is on duty for you.
For teams that need alert volume handled properly, with the option to grow into a full SOC.
Per incidentYou pay for what your estate actually produces.
A full SOC. Every agent on duty, with threat hunting running continuously as part of the service.
Per userYour bill moves with headcount, never with incident volume.
For regulated and high-risk organisations that need deeper hunting and responders already on standby.
Per userYour bill moves with headcount, never with incident volume.
The Response Agent handles automated containment within your agreed limits.
| Agent | Core01 | Complete02 | Command03 |
|---|---|---|---|
| Front line | |||
| SOC L1 Triage Agent | ✓Included | ✓Included | ✓Included |
| Watch Agent | –Not included | ✓Included | ✓Included |
| Investigation | |||
| SOC L2 Investigation Agent | ✓Included | ✓Included | ✓Included |
| Intel Analyst Agent | –Not included | ✓Included | ✓Included |
| Fusion Agent | –Not included | ✓Included | ✓Included |
| Proactive security | |||
| Threat Hunter Agent | –Not included | ✓Included | Extended |
| Detection Engineering Agent | –Not included | ✓Included | ✓Included |
| Vulnerability Management Agent | –Not included | ✓Included | ✓Included |
| Response | |||
| Response Agent (automated containment) | –Not included | ✓Included | ✓Included |
| Service operations | |||
| SOC Manager Agent | –Not included | ✓Included | ✓Included |
| Communications Agent | –Not included | ✓Included | ✓Included |
| Reporting Agent | –Not included | ✓Included | ✓Included |
| Maintenance Agent | –Not included | ✓Included | ✓Included |
A managed AI SOC is a managed security operations service where the analyst workload — triage, investigation, threat hunting, intelligence and detection engineering — is carried by AI agents, with senior human analysts accountable for the outcomes. A traditional MSSP scales by hiring more analysts; a managed AI SOC scales by adding agents, so capacity grows without a proportional increase in cost.
A managed AI SOC differs from a traditional MSSP in depth and consistency. A traditional MSSP triages thousands of alerts a day by hand, closing low-value alerts quickly to keep the queue moving, and investigation depth depends on who is on shift. an AI SOC investigates every escalation end to end at machine speed, applies the same depth at 3am as at 3pm, records the reasoning behind filtered noise rather than discarding it, and plans and executes containment instead of handing you back a ticket.
No. Your data stays in your own tenant and isolation is enforced architecturally rather than by policy. There is no cross-customer learning: nothing we run for another customer touches your detections, and your telemetry does not improve the service any other customer receives.
Yes. Agents run continuously and the SOC is staffed by security professionals around the clock, every day of the year, with named contacts and defined escalation paths to human experts.
Every tier includes a 24/7 manned SOC, senior analyst sign-off on every customer-facing decision, a structured verdict on every incident, tenant isolation, named contacts, Mean Time to Verdict measured across the whole chain, the autonomy dial on whichever agents are on duty for you, and the connectors and tooling your estate needs, built during onboarding. Which agents are on duty — and whether you have a Threat Attack Profile — is what the package decides.
Continuous threat hunting is included in the Complete package and extended in Command, and additional allocation can be purchased on top of either. It is not included on Core, which is the front-line agents only — hunting arrives with the rest of the roster at Complete.
Yes, within limits you set. The Response Agent builds a containment plan for a confirmed incident and executes pre-authorised actions inside the containment matrix agreed at onboarding, then verifies the action landed and reports what changed. Anything beyond those pre-authorised limits is held for human approval.
Mean Time to Verdict measures the whole chain — from the moment a signal reaches CYBERSHIELD AI to a signed-off outcome — rather than how quickly a machine acknowledged an alert. The clock starts at the same point on every measure.
Book a demo and we’ll walk you through the agents, the sign-off process and the package that fits.