A cyber department that builds its own agents

At Sodexo, the SOC, the VOC, the team running the security infrastructure and the security architecture team work with their Agents: alerts qualified before the analyst, an autonomous watch, platforms kept under watch and reviews prepared. Tickets are handled twice as fast, but the decision is unchanged.

50%less handling time on tickets.

In brief.

What the team handed over, with which tools, and what it changed.

Team

Cyber department: SOC, VOC, security infrastructure, security architecture.

Work handed over

Alert qualification, vulnerability and exposed-surface watch, security platform supervision, daily checks, architecture reviews, reporting.

Tools

SIEM, EDR, vulnerability scanner, SOC orchestration platform, email.

Triggered

By the security systems continuously, by Schedules every morning, on request by the teams.

The work before Ubby

In a cyber department, the decision is rare and the preparation is everywhere.

Before an alert can be judged, someone has to understand it: find the host and the account, check the domains and the hashes, rebuild the timeline. Before the vulnerability team can prioritise, someone has to have read last night's publications and crossed them with the exposed surface. Before a security platform can be called healthy, someone has to have checked its versions, its access and its coverage, machine by machine. And every week, someone has to check that the tools are running, count, document, report.

None of these tasks decides anything. All of them are essential, all of them repeat, and all of them take the time of the same people.

The work with Ubby

Four teams, each with its own Agents.

SOC — alerts qualified before the analyst.

As soon as an alert is created, the orchestration platform calls an Agent through the API. It extracts the artefacts, enriches them in the SIEM and the EDR, rebuilds the timeline, applies the classification grids written by the team, and returns a sheet into the case: proposed verdict and confidence level, evidence, what to do first.

VOC — the vulnerability watch and the exposed surface, every morning.

A scheduled Agent goes through the new vulnerabilities and zero-days, crosses them with the company's exposed surface and hands the team what concerns it before the day starts. Another checks the state of the scanner and the SIEM and emails its report: a silent outage does not stay silent.

Security infrastructure — the platforms, kept current and under control.

Security platforms have to be watched, updated and provisioned continuously, with very fine-grained access management: a protection that misbehaves leaves the whole company exposed. An Agent takes part of that work off the team — checking that the EDR is on its latest version on every machine, raising an alert as soon as a threshold is crossed, producing the reports.

Security architecture — reviews prepared, playbooks documented.

Architecture review before acceptance, documentation of the orchestration playbooks, KPI and SLA dashboard: produced by Agents, reviewed by the team. The architect walks into the meeting with the file already built.

Alert 67898 triage

Triage alert 67898 and produce an analysis note.

Thought for 18 seconds

I pulled the artefacts and enriched them against the following sources (SIEM, EDR, vulnerability scanner, CMDB, IdP, CTI): the parent process is legitimate, but the contacted domain was registered six days ago and appears on no other host on the estate. Proposed verdict: likely incident, 78% confidence. No containment was triggered — the call stays with the analyst.

alert-67898-case-note.md

18.4 KB · 1 min ago

Triage case note

Artefacts pulled, then enriched from the SIEM, the EDR, the scanner, the CMDB, the IdP and the CTI. Proposed verdict, evidence and first actions — for the analyst to confirm.

alert-67898-summary.pdf

94.7 KB · 1 min ago

Alert summary — 67898

Artefacts enriched14
Hosts affected1 / 4,820
Confidence78%

Ask Ubby anything, or mention an Agent...

SOC - Triage

Lite

Ubby is an AI and can make mistakes. Please check before use.

Pull the artefacts

Enrich from the SIEM

Enrich from the EDR

Enrich from the scanner

Enrich from the CMDB

Enrich from the IdP

Enrich from the CTI

Propose a verdict

Hand the note back

Connectors

SIEM

EDR

Skills

soc-triage-skill

alert-67898-summary.pdf

94.7 KB · Updated 1 min ago

alert-67898-case-note.md

18.4 KB · Updated 1 min ago

Status

Task

Type

Team

Agent

Credits spent

Done

Alert 67898 triage

API

SOC

🛡️

SOC - Triage

4 820

Running

Vulnerability watch

Scheduled

VOC

📡

VOC - Watch

9 240

Done

Exposed surface check

Workflow

VOC

🌐

VOC - Surface

6 015

Done

EDR coverage across the estate

Workflow

Security infra

🖥️

Infra - Estate

2 480

Failed

SIEM health check

API

Security infra

🩺

Infra - Health

310

Queued

Architecture review

Chat

Architecture

📐

ARCH - Review

1 760

Done

Playbook docs

Chat

Architecture

📘

ARCH - Docs

3 405

Done

KPI & SLA reporting

Scheduled

SOC

📊

SOC - Steering

7 120

What it changesin the job.

In most cyber departments, AI is a tool you open. Here, the orchestration platform calls the Agent through the API on every alert and collects the sheet in the case. Nobody copies and pastes, nobody launches anything. The Agent is part of the process in the same way the SIEM or the EDR is.

Which work would you like to delegate first?

Share one real task. We identify the expected outcome, the tools involved and the approval frame.

See also.