Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI SOC investigations: what changes when context is in the tool?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security teams still lose 20 to 30 minutes per routine alert assembling context across Okta, CloudTrail, GitHub, PagerDuty, and runbooks, according to Panther, which argues that investigation quality improves when the system surfaces live cross-tool context inside the workflow. The governance issue is not analyst effort but whether identity and incident context is encoded in the platform or trapped in people’s heads.

NHIMG editorial — based on content published by Panther: Investigating Alerts Without Switching Tools

By the numbers:

Questions worth separating out

Q: How should security teams reduce context switching in AI SOC investigations?

A: Security teams should expose the systems analysts already use for identity, incident, and code context inside the investigation workflow.

Q: Why do identity signals matter so much in alert triage?

A: Identity signals often determine whether an alert is ordinary or dangerous.

Q: What breaks when investigation knowledge lives only in analysts' heads?

A: The same alert can receive different treatment depending on who is on shift, how familiar they are with the environment, and whether they know which sources to check.

Practitioner guidance

  • Map investigation-critical identity sources Identify which systems provide decision-grade context for alert triage, including authentication logs, group membership, incident records, and runbooks.
  • Codify alert-specific runbooks and profiles Convert environment knowledge into detection runbooks and organization profiles that define normal behaviour, sensitive assets, and escalation criteria.
  • Limit MCP access to approved investigative queries Restrict which systems the AI can query and document the purpose of each integration.

What's in the full article

Panther's full blog post covers the operational detail this post intentionally leaves for the source:

  • Live examples of how Panther queries Okta, PagerDuty, GitHub, and documentation systems during a single investigation
  • Customer-reported workflow outcomes and implementation context behind faster triage and broader log-source coverage
  • How natural language investigation behaves inside open alerts, threat hunts, and detection-building workflows
  • Examples of scheduled runs for IAM checks, false-positive analysis, and post-termination monitoring

👉 Read Panther's analysis of AI SOC investigations with full context →

AI SOC investigations: what changes when context is in the tool?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Context-aware SOC automation is becoming an identity governance problem as much as an operations problem. Once an investigation engine can query authentication history, group membership, incident state, and code activity in one workflow, the question is no longer just speed. The real issue is whether identity evidence is trusted, current, and sufficiently scoped for machine-led decision support. Practitioners should treat AI investigation design as a control plane for evidence, not a convenience layer.

A question worth separating out:

Q: How should teams govern AI systems that query identity and incident tools?

A: Teams should treat those integrations as part of the control surface, not just a convenience feature. Access should be least-privilege, auditable, and limited to approved investigative queries. Governance also needs to cover what the AI can see, what it can do, and how its reasoning is preserved for review.

👉 Read our full editorial: AI SOC investigations need full context, not more tab switching



   
ReplyQuote
Share: