A cyber department that builds its own agents
At Sodexo, the SOC, the VOC, the team running the security infrastructure and the security architecture team work with their Agents: alerts qualified before the analyst, an autonomous watch, platforms kept under watch and reviews prepared. Tickets are handled twice as fast, but the decision is unchanged.
50%less handling time on tickets.
In brief.
What the team handed over, with which tools, and what it changed.
Team
Cyber department: SOC, VOC, security infrastructure, security architecture.
Work handed over
Alert qualification, vulnerability and exposed-surface watch, security platform supervision, daily checks, architecture reviews, reporting.
Tools
SIEM, EDR, vulnerability scanner, SOC orchestration platform, email.
Triggered
By the security systems continuously, by Schedules every morning, on request by the teams.
The work before Ubby
In a cyber department, the decision is rare and the preparation is everywhere.
Before an alert can be judged, someone has to understand it: find the host and the account, check the domains and the hashes, rebuild the timeline. Before the vulnerability team can prioritise, someone has to have read last night's publications and crossed them with the exposed surface. Before a security platform can be called healthy, someone has to have checked its versions, its access and its coverage, machine by machine. And every week, someone has to check that the tools are running, count, document, report.
None of these tasks decides anything. All of them are essential, all of them repeat, and all of them take the time of the same people.
The work with Ubby
Four teams, each with its own Agents.
SOC — alerts qualified before the analyst.
As soon as an alert is created, the orchestration platform calls an Agent through the API. It extracts the artefacts, enriches them in the SIEM and the EDR, rebuilds the timeline, applies the classification grids written by the team, and returns a sheet into the case: proposed verdict and confidence level, evidence, what to do first.
VOC — the vulnerability watch and the exposed surface, every morning.
A scheduled Agent goes through the new vulnerabilities and zero-days, crosses them with the company's exposed surface and hands the team what concerns it before the day starts. Another checks the state of the scanner and the SIEM and emails its report: a silent outage does not stay silent.
Security infrastructure — the platforms, kept current and under control.
Security platforms have to be watched, updated and provisioned continuously, with very fine-grained access management: a protection that misbehaves leaves the whole company exposed. An Agent takes part of that work off the team — checking that the EDR is on its latest version on every machine, raising an alert as soon as a threshold is crossed, producing the reports.
Security architecture — reviews prepared, playbooks documented.
Architecture review before acceptance, documentation of the orchestration playbooks, KPI and SLA dashboard: produced by Agents, reviewed by the team. The architect walks into the meeting with the file already built.
Alert 67898 triage
Triage alert 67898 and produce an analysis note.
Thought for 18 seconds
I pulled the artefacts and enriched them against the following sources (SIEM, EDR, vulnerability scanner, CMDB, IdP, CTI): the parent process is legitimate, but the contacted domain was registered six days ago and appears on no other host on the estate. Proposed verdict: likely incident, 78% confidence. No containment was triggered — the call stays with the analyst.
alert-67898-case-note.md
18.4 KB · 1 min ago
Triage case note
Artefacts pulled, then enriched from the SIEM, the EDR, the scanner, the CMDB, the IdP and the CTI. Proposed verdict, evidence and first actions — for the analyst to confirm.
alert-67898-summary.pdf
94.7 KB · 1 min ago
Alert summary — 67898
Ask Ubby anything, or mention an Agent...
SOC - Triage
Lite
Ubby is an AI and can make mistakes. Please check before use.
Connectors
SIEM
EDR
Skills
soc-triage-skill
alert-67898-summary.pdf
94.7 KB · Updated 1 min ago
alert-67898-case-note.md
18.4 KB · Updated 1 min ago
What it changesin the job.
In most cyber departments, AI is a tool you open. Here, the orchestration platform calls the Agent through the API on every alert and collects the sheet in the case. Nobody copies and pastes, nobody launches anything. The Agent is part of the process in the same way the SIEM or the EDR is.
Which work would you like to delegate first?
Share one real task. We identify the expected outcome, the tools involved and the approval frame.






