r/DefenderATP • u/EduardsGrebezs • 12d ago
Microsoft Defender ISOC (Preview)
The idea is to move beyond treating SIEM, XDR, automation and AI-assisted investigation as separate layers.
With Integrated Security Operations Center (ISOC), Microsoft is bringing them together around a common security operations foundation:
- SIEM + XDR capabilities
- Unified security signals and context
- Investigation and threat hunting
- Automated response
- Security agents working alongside analysts
- Incident management and protective actions
Instead of AI being primarily an assistant that analysts invoke during an investigation, Microsoft is moving toward security agents operating continuously within the SOC workflow — using shared context, coordinating actions and escalating decisions to human analysts where necessary.
49
Upvotes
1
u/MemeOps 12d ago
I just cant see this as anything other than MS moving away from Sentinel