SOC automation you own. No meter. No renewals.
The agent triages every alert. Your analyst disposes every real one. A regression suite proves nothing true ever gets auto-closed.
30 minutes. The price on this page is the price on the call.
“SMB session chain from workstation ws-114 within 4 min of phish click; service account escalation attempted…”
Golden set: your labeled alert history · zero-FN is the contract acceptance criterion · illustrative values
Read those numbers together: nearly half the queue is noise, everyone knows it, and it is grinding down exactly the people you can least afford to lose. The queue is a machine’s job. Judgment is your analyst’s job. I build the system that enforces that split and proves it with evals.
What the Tier-1 queue is costing you
Every alert gets 10 to 20 minutes of a human’s attention. At 46% false positives, half of that work exists to conclude “nothing happened.” Meanwhile 75% of analysts no longer have time for threat hunting, and IBM found extensive AI and automation saved $1.9M per breach and 80 days of lifecycle. The current options:
Hire more Tier-1
24/7 coverage takes 4 to 5 FTEs, into a market with a documented skills shortage and a burnout pipeline.
Rent an AI SOC analyst
Dropzone AI’s base tier is $36,000 a year for 4,000 investigations, then the meter resets every January. Prophet, Radiant, and the enterprise platforms sit behind “request pricing.”
Buy a SOAR, build playbooks
Torq and Tines are good tools, and your engineers now own a second full-time job maintaining playbooks that encode rules, not judgment.
The fourth option: own a scoped triage agent. One year of renting one, paid once.
Fixed scope: one stack, your top 10 alert types, eight weeks
One SIEM or EDR stack per build: Splunk, Microsoft Sentinel, CrowdStrike, or Elastic.
Enrich
Every alert gets context pulled automatically: asset criticality, user history, threat intel, prior related incidents.
Triage
The agent classifies against your alert taxonomy, correlates duplicates and campaigns, and scores confidence.
Draft
For every alert it writes the investigation summary a Tier-1 analyst would have written: what fired, what the evidence shows, recommended disposition.
The gate
The agent recommends. Your analyst disposes. Alerts above the severity floor can never be auto-closed, and that constraint is code, not configuration. Every decision lands in an audit trail.
Low-severity noise below the floor gets closed with full documentation attached, which is the 46% you stop paying humans to disprove.
The false-negative regression is the product
Every vendor in this market claims accuracy. The only claim that matters in a SOC is the negative one: it will not close something real. So that is the eval I ship, written into the contract as the acceptance criterion.
-
A labeled golden dataset
Built from your historical alerts and their true dispositions, including your real incidents.
-
A zero-tolerance false-negative regression
On the golden set, the agent must never recommend closing a labeled true positive. One miss fails the suite.
-
Triage-accuracy thresholds, per alert type
Scored across every alert type in scope, per type, not averaged into a flattering blend.
-
MTTR and MTTD tracking
The speed claim is measured on your queue, not quoted from a benchmark.
-
A parallel run
The agent triages alongside your analysts until the thresholds clear on live traffic. No cutover before the score.
You keep the harness, the golden set, and the regression suite. When the model updates or your detections drift, you re-run it and read the score yourself. The machine does the work, and the human judges it, with instruments instead of trust.
The price is $36,000. Here is what it buys.
One price. No per-investigation meter, no seat count, no “request pricing.”
- Discovery and alert-taxonomy workshop: your top 10 alert types, severity floor, escalation paths
- SIEM/EDR integration for one stack (read and annotate; disposition only through the gate)
- Enrichment pipeline: asset context, identity context, threat intel, prior-incident lookup
- Triage agent with drafted investigation summaries per alert
- Analyst judgment gate with per-decision audit trail
- Labeled golden dataset from your alert history
- Eval harness: per-type triage accuracy, zero-tolerance false-negative regression, MTTR/MTTD dashboard
- Guardrails in code: severity floor, confidence floors, no auto-close of criticals
- Parallel run with published acceptance thresholds
- Handover pack: runbook, eval documentation, team training
Against the alternatives
| This build | Dropzone AI | SOAR (Torq/Tines) | More Tier-1 hires | |
|---|---|---|---|---|
| Cost | $36,000 once | $36K/yr base, 4,000 investigations, renews forever | Subscription + your engineering time | ~$400K/yr for 24/7 |
| Meter | None | Per investigation | Per workflow complexity | Per human hour |
| Who owns it | You: code, evals, golden set | Vendor | Vendor platform, your playbooks | n/a |
| Proof it won’t close real threats | Zero-FN regression you can re-run | Their accuracy claim | Whatever your playbooks encode | Analyst fatigue says otherwise at 2am |
| Audit trail | Per decision, yours | In their tenant | Partial | Tribal knowledge |
If a metered subscription fits your volume better, buy it; the table is the honest math. What no subscription gives you is the regression suite in your own hands.
How the eight weeks run
- Weeks 1–2
Discovery
Alert taxonomy, severity floor, escalation paths, pull and label alert history, fix acceptance thresholds in writing.
- Weeks 3–4
Enrichment + integration
Stack integration, context pipelines, audit-trail plumbing.
- Weeks 5–6
Triage agent + gate
Classification, correlation, drafted summaries, the analyst gate, guardrails in code.
- Weeks 7–8
Parallel run
The agent triages live traffic alongside your team. Per-type scores published. Cutover only when the suite clears, including the zero-FN regression.
- Days 1–30 after
Stabilization
I watch the dashboards, tune confidence floors against drift, then hand over the keys.
Straight answers
The questions every SOC manager, vCISO, and MSSP principal asks before booking the call.
Can it auto-close alerts?
Only below the severity floor you set, and never criticals. Above the floor the agent recommends and a human disposes. The constraint is enforced in code and verified by the regression suite; it is not a settings toggle someone can flip.
How do you prove it won't miss a real incident?
The golden dataset includes your labeled true positives, and the acceptance criterion is zero tolerance: the agent must never recommend closing one. Then the parallel run tests live traffic before anything changes in production. You re-run the same suite any time, forever.
What does the $36,000 include, exactly?
Everything in the scope list: discovery, integration, enrichment, triage agent, judgment gate, golden dataset, eval harness, parallel run, audit trail, handover, and 30 days of stabilization. Your only other costs are your own API/hosting and the optional retainer.
Which stacks do you support?
One of Splunk, Microsoft Sentinel, CrowdStrike, or Elastic per build. That is what keeps the price fixed. A second stack is a follow-on with its own public price.
Does this help with DORA and NIS2 incident reporting?
The drafted investigation summaries and per-decision audit trail are exactly the evidence those reporting timelines demand. Regulatory obligations get scoped plainly in discovery; I won't hand-wave compliance.
We're an MSSP. Can we run this across clients?
This build is single-tenant by design. The multi-tenant version with client isolation and per-client eval dashboards is a separate scoped offer. Book the call and say MSSP; that conversation is different and better.
What happens when detections drift?
You own the regression suite; re-run it on a schedule. If you want me watching, the $2,500 a month retainer covers continuous eval runs and tuning, and you can cancel anytime.
What teams say
“His vast knowledge of technologies and a natural problem-solving mindset consistently lead us through complex challenges with clarity and confidence.”
Give the queue to the machine. Keep the judgment.
Half your alerts are noise, and your best people are drowning in it. Eight weeks from now the noise can be documented and closed by an agent, every real threat can carry a drafted investigation, and your analysts can do the work you hired them for.
30 minutes · the price stays $36,000 · if it’s not a fit, I’ll say so