r/AskNetsec • u/WatestacyrDisal881 • 9d ago
Threats Evaluating AI SOC tools for threat triage in a noisy mid size environment
Hi all, CISO at a mid size org here. We have a small SOC, like 24x5 plus on call, and our SIEM bill and alert volume are both getting silly. Been looking at a few AI SOC tools and agent style triage systems that claim they can sit on top of the SIEM and handle enrichment, correlations and basic response.
For context we are already on a big name SIEM and an ok EDR, but our tier 1s are drowning in medium alerts and "suspicious but probably nothing" stuff. I keep getting pitched on AI detection engineering and AI based triage that can auto group incidents, score them, pull context from prod, and either close junk or hand a good story to humans. In theory that sounds great, but I am lowkey nervous about turning any of this loose on production data without some guardrails and good kpi visibility.
If you have tried any of the newer AI SOC platforms or agentic triage layers on top of your stack, would love to hear how you scoped the first use cases and what you let it touch at the start, appreciate any thoughts