AN Alpesh Nakrani
SolutionsBlogBooksPraiseAbout Work with me ↗
Solutions/AI SOC alert triage agent

SOC automation you own. No meter. No renewals.

The agent triages every alert. Your analyst disposes every real one. A regression suite proves nothing true ever gets auto-closed.

46% of your alert queue is false positives, and you are paying humans to prove it, one alert at a time.

30 minutes. The price on this page is the price on the call.

Triage Desk illustrative
critlateral movement · srv-db-02→ analyst
hightoken theft pattern · idp→ analyst
low · sign-in anomaly · vpn rotation resolved benign
Documented closure · evidence attached · below floor
low · dns burst · known scannerdocumented
low · failed logins · service acctdocumented
low · geo-improbable · travel calendar matchdocumenting…
INV-2214 · lateral movement · srv-db-02 analyst disposition pending

“SMB session chain from workstation ws-114 within 4 min of phish click; service account escalation attempted…”

6 evidence sources recommended: escalate agent cannot close
SOC triage evaluation dashboard showing zero false-negative misses across 131 alerts, 94.6% triage accuracy, 44% of the queue automatically closed below the severity floor, and zero critical alerts automatically closed

Golden set: your labeled alert history · zero-FN is the contract acceptance criterion · illustrative values

Closed with documentation · audit trail entry written
Severity floor: enforced in code Criticals never auto-close
46%
of all SOC alerts are false positives
Microsoft SOC report, 2026
73%
of teams call false positives their single biggest challenge
SANS Detection & Response Survey, 2025
71%
of SOC analysts report burnout; 64% considering leaving within a year
Tines

Read those numbers together: nearly half the queue is noise, everyone knows it, and it is grinding down exactly the people you can least afford to lose. The queue is a machine’s job. Judgment is your analyst’s job. I build the system that enforces that split and proves it with evals.

The problem

What the Tier-1 queue is costing you

Every alert gets 10 to 20 minutes of a human’s attention. At 46% false positives, half of that work exists to conclude “nothing happened.” Meanwhile 75% of analysts no longer have time for threat hunting, and IBM found extensive AI and automation saved $1.9M per breach and 80 days of lifecycle. The current options:

01

Hire more Tier-1

24/7 coverage takes 4 to 5 FTEs, into a market with a documented skills shortage and a burnout pipeline.

~$400K / yr
02

Rent an AI SOC analyst

Dropzone AI’s base tier is $36,000 a year for 4,000 investigations, then the meter resets every January. Prophet, Radiant, and the enterprise platforms sit behind “request pricing.”

$36K / yr, metered
03

Buy a SOAR, build playbooks

Torq and Tines are good tools, and your engineers now own a second full-time job maintaining playbooks that encode rules, not judgment.

subscription + eng time

The fourth option: own a scoped triage agent. One year of renting one, paid once.

How it works

Fixed scope: one stack, your top 10 alert types, eight weeks

One SIEM or EDR stack per build: Splunk, Microsoft Sentinel, CrowdStrike, or Elastic.

01

Enrich

Every alert gets context pulled automatically: asset criticality, user history, threat intel, prior related incidents.

02

Triage

The agent classifies against your alert taxonomy, correlates duplicates and campaigns, and scores confidence.

03

Draft

For every alert it writes the investigation summary a Tier-1 analyst would have written: what fired, what the evidence shows, recommended disposition.

04

The gate

The agent recommends. Your analyst disposes. Alerts above the severity floor can never be auto-closed, and that constraint is code, not configuration. Every decision lands in an audit trail.

Low-severity noise below the floor gets closed with full documentation attached, which is the 46% you stop paying humans to disprove.

The differentiator

The false-negative regression is the product

Every vendor in this market claims accuracy. The only claim that matters in a SOC is the negative one: it will not close something real. So that is the eval I ship, written into the contract as the acceptance criterion.

  1. A labeled golden dataset

    Built from your historical alerts and their true dispositions, including your real incidents.

  2. A zero-tolerance false-negative regression

    On the golden set, the agent must never recommend closing a labeled true positive. One miss fails the suite.

  3. Triage-accuracy thresholds, per alert type

    Scored across every alert type in scope, per type, not averaged into a flattering blend.

  4. MTTR and MTTD tracking

    The speed claim is measured on your queue, not quoted from a benchmark.

  5. A parallel run

    The agent triages alongside your analysts until the thresholds clear on live traffic. No cutover before the score.

You keep the harness, the golden set, and the regression suite. When the model updates or your detections drift, you re-run it and read the score yourself. The machine does the work, and the human judges it, with instruments instead of trust.

The price

The price is $36,000. Here is what it buys.

One price. No per-investigation meter, no seat count, no “request pricing.”

One public price
$36,000
one-time · 8 weeks + 30-day stabilization
Schedule a call
  • Discovery and alert-taxonomy workshop: your top 10 alert types, severity floor, escalation paths
  • SIEM/EDR integration for one stack (read and annotate; disposition only through the gate)
  • Enrichment pipeline: asset context, identity context, threat intel, prior-incident lookup
  • Triage agent with drafted investigation summaries per alert
  • Analyst judgment gate with per-decision audit trail
  • Labeled golden dataset from your alert history
  • Eval harness: per-type triage accuracy, zero-tolerance false-negative regression, MTTR/MTTD dashboard
  • Guardrails in code: severity floor, confidence floors, no auto-close of criticals
  • Parallel run with published acceptance thresholds
  • Handover pack: runbook, eval documentation, team training
Outside the number, said plainly: you pay your own LLM API and hosting, typically $300 to $900 a month at mid-market alert volume, on your accounts. Optional monitoring retainer is $2,500 a month, cancel anytime. Neither is required to run what you own.
The field

Against the alternatives

This build Dropzone AI SOAR (Torq/Tines) More Tier-1 hires
Cost $36,000 once $36K/yr base, 4,000 investigations, renews forever Subscription + your engineering time ~$400K/yr for 24/7
Meter None Per investigation Per workflow complexity Per human hour
Who owns it You: code, evals, golden set Vendor Vendor platform, your playbooks n/a
Proof it won’t close real threats Zero-FN regression you can re-run Their accuracy claim Whatever your playbooks encode Analyst fatigue says otherwise at 2am
Audit trail Per decision, yours In their tenant Partial Tribal knowledge

If a metered subscription fits your volume better, buy it; the table is the honest math. What no subscription gives you is the regression suite in your own hands.

Delivery

How the eight weeks run

  1. Weeks 1–2

    Discovery

    Alert taxonomy, severity floor, escalation paths, pull and label alert history, fix acceptance thresholds in writing.

  2. Weeks 3–4

    Enrichment + integration

    Stack integration, context pipelines, audit-trail plumbing.

  3. Weeks 5–6

    Triage agent + gate

    Classification, correlation, drafted summaries, the analyst gate, guardrails in code.

  4. Weeks 7–8

    Parallel run

    The agent triages live traffic alongside your team. Per-type scores published. Cutover only when the suite clears, including the zero-FN regression.

  5. Days 1–30 after

    Stabilization

    I watch the dashboards, tune confidence floors against drift, then hand over the keys.

FAQ

Straight answers

The questions every SOC manager, vCISO, and MSSP principal asks before booking the call.

Can it auto-close alerts?

Only below the severity floor you set, and never criticals. Above the floor the agent recommends and a human disposes. The constraint is enforced in code and verified by the regression suite; it is not a settings toggle someone can flip.

How do you prove it won't miss a real incident?

The golden dataset includes your labeled true positives, and the acceptance criterion is zero tolerance: the agent must never recommend closing one. Then the parallel run tests live traffic before anything changes in production. You re-run the same suite any time, forever.

What does the $36,000 include, exactly?

Everything in the scope list: discovery, integration, enrichment, triage agent, judgment gate, golden dataset, eval harness, parallel run, audit trail, handover, and 30 days of stabilization. Your only other costs are your own API/hosting and the optional retainer.

Which stacks do you support?

One of Splunk, Microsoft Sentinel, CrowdStrike, or Elastic per build. That is what keeps the price fixed. A second stack is a follow-on with its own public price.

Does this help with DORA and NIS2 incident reporting?

The drafted investigation summaries and per-decision audit trail are exactly the evidence those reporting timelines demand. Regulatory obligations get scoped plainly in discovery; I won't hand-wave compliance.

We're an MSSP. Can we run this across clients?

This build is single-tenant by design. The multi-tenant version with client isolation and per-client eval dashboards is a separate scoped offer. Book the call and say MSSP; that conversation is different and better.

What happens when detections drift?

You own the regression suite; re-run it on a schedule. If you want me watching, the $2,500 a month retainer covers continuous eval runs and tuning, and you can cancel anytime.

Proof

What teams say

“His vast knowledge of technologies and a natural problem-solving mindset consistently lead us through complex challenges with clarity and confidence.”
AM
Adil Multani
Senior Backend Developer
Next step

Give the queue to the machine. Keep the judgment.

Half your alerts are noise, and your best people are drowning in it. Eight weeks from now the noise can be documented and closed by an agent, every real threat can carry a drafted investigation, and your analysts can do the work you hired them for.

30 minutes · the price stays $36,000 · if it’s not a fit, I’ll say so

Ask AI about AI SOC Alert Triage Agent