← All Netgraph solutions
Agentic AI SOCDetect & Respond

Eight agents. One graph. Humans stay in command.

Netgraph ships a full agentic SOC bench — L1 Triage, L2 Investigator, L3, RCA, Threat Analyst, Threat Hunter, Forensic and SOC Manager — plus Phish-Triage, a SOAR agent for response reasoning, and Frontal, the app-wide assistant. Every agent reasons over the security knowledge graph, so answers are anchored in real edges — not model imagination — and every risky action stops at a durable human-in-the-loop approval gate before anything touches your estate.

8 specialised SOC agents75-skill libraryL1 autopilot — 60s loopDurable HITL approvalsGraph-grounded answersBring your own LLM

What is an Agentic AI SOC?

An agentic AI SOC replaces the chatbot-on-a-console pattern with a bench of specialised AI agents that actually work the queue: L1 triages every alert autonomously, L2 investigates with a full entity subgraph, RCA finds root cause and drafts the detections that should have fired, and hunter, forensic, and manager agents cover the rest of the workflow. Netgraph's agents are graph-grounded — every answer cites real nodes and edges, not hallucinated entities — and every consequential action waits for durable human-in-the-loop approval.

What ships in the module

A SOC bench that works the queue, not a chatbot.

01

L1 autopilot triage

Autonomous near-real-time triage of every new alert on every active tenant — a 60-second loop reads the queue, reasons over the graph, and disposes. Malicious and suspicious verdicts escalate to the L2 queue and open a case; benign auto-closes with a full audit trail.

02

The eight-agent bench

L1 Triage, L2 Investigator, L3, RCA — which drafts detections from root cause — Threat Analyst, Threat Hunter, Forensic and SOC Manager. Each is catalogued, each surfaces its reasoning trace in the Agent Console.

03

Phish-Triage & SOAR agents

A dedicated Phish-Triage agent works reported messages, and a SOAR agent reasons through response — choosing actions, sequencing playbook steps and explaining why, on the same graph the analysts read.

04

75-skill library

EDR / AV / forensics / posture / self-heal endpoint skills — including shadow-AI inventory and prompt-injection detection — plus Detect / Respond / Analyze ADR suites, IOC reputation, phishing identification, enrichment, UEBA, vulnerability and MITRE skills.

05

Honest integration gating

Skills act only through integrations you have configured and enabled. When none is available, the skill runs in a clearly-labelled simulation fallback — the platform never pretends an action happened that didn't.

06

Durable HITL approvals

Every WRITE or DESTRUCTIVE skill hits a persisted human-in-the-loop approval gate. Approve re-invokes the exact tool with the exact arguments — nothing is re-interpreted — and every disposition is audited.

07

Graph-grounded retrieval

Agent answers are anchored in real edges of the security knowledge graph, and the full prompt and tool trace of every run is logged to the AI LLM Observability console — inspectable, replayable, accountable.

08

Frontal — the universal assistant

App-wide assistant with cross-functional tools: NQL generation, summarize, detection generate / test / deploy, dashboard build / deploy — rendered inline where you work, with approve-&-deploy on every artefact it drafts.

09

PICERL & BAS in the loop

PICERL incident checklists auto-progress as agent investigations advance, and attack-simulation tools let agents run deterministic BAS scenarios and read the resulting coverage gaps. LLM provider is configurable — bring your own.

Autonomy with receipts

Every verdict shows its work. Every action waits for a human where it should.

The L1 autopilot doesn't just close alerts — it records the graph evidence behind each verdict. Escalations arrive in the L2 queue with a case already open and a reasoning trace attached. And when any agent reaches for a skill that changes the world, the request lands in the HITL queue — persisted, reviewable, and executed exactly as approved.

  • Verdicts cite graph edges — the alert, the entity, the history that justified the call.
  • Malicious / suspicious → L2 queue + case; benign → auto-close with audit.
  • Approvals are durable — they survive restarts and re-invoke the exact tool call.
  • Full prompt & tool traces in the AI LLM Observability console.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Agent ConsoleWatch agents work — reasoning traces, tool calls, verdicts, case write-backsOperations ▸ Agentic SOC ▸ Agent Console
Agent CatalogThe full bench — 8 SOC agents plus Phish-Triage and the SOAR agent, with roles and skillsOperations ▸ Agentic SOC ▸ Agent Catalog
Escalation & HITL QueueL2 escalations and pending human approvals in one working queueOperations ▸ Agentic SOC ▸ Escalation & HITL Queue
HITL Approvals RunnerApprove or reject persisted actions — approve re-invokes the exact tool, fully auditedOperations ▸ Agentic SOC ▸ HITL Approvals Runner
Skills LibraryAll 75 skills with side-effect class and integration gating statusOperations ▸ Agentic SOC ▸ Skills Library
Frontal assistantNQL generation, summaries, detection and dashboard generate / test / deploy — inline, everywhereApp-wide assistant
LLM observabilityFull prompt & tool trace for every agent run; configurable LLM providerAI LLM Observability console
Agentic AI dashboardAutopilot throughput, verdict mix and agent activity at a glanceDashboards ▸ Agentic AI

Common questions

Agentic AI SOC — asked and answered

How does Netgraph prevent AI hallucination in investigations?+

Graph-grounded retrieval: agents can only assert facts anchored to actual nodes and edges on the security knowledge graph, and every verdict cites the alert, entity, and history that justified it. Full prompt and tool traces land in the LLM Observability console for review.

Which LLMs does the agentic SOC use?+

Bring your own provider — the platform is LLM-agnostic, and a heuristic fallback keeps L1 triage functioning even with no LLM configured, which matters for air-gapped deployments.

Do the agents take actions autonomously?+

Triage and investigation, yes; consequences, no. The 75-skill library is policy-gated with single, dual, or auto approval per skill class, and approvals persist in a durable queue that survives restarts and re-invokes the exact reviewed action.

See it live

Give the autopilot your alert queue. Keep your hand on the approvals.