---
title: "How the SOC Analyst Agent cuts investigation time from four hours to fourteen minutes"
page_name: "How the SOC Analyst Agent cuts investigation time from four hours to fourteen minutes"
type: "blog"
slug: "soc-analyst-agent-cuts-investigation-time"
published_at: "2026-09-03"
modified_at: "2026-09-03"
url: "https://www.sumologic.com/blog/soc-analyst-agent-cuts-investigation-time"
canonical: "https://www.sumologic.com/blog/soc-analyst-agent-cuts-investigation-time"
markdown_url: "https://www.sumologic.com/blog/soc-analyst-agent-cuts-investigation-time.md"
lang: "en"
excerpt: "From automatic verdict to incident report with the SOC Analyst Agent and Mobot."
taxonomy_blog_category:
  - "AI"
  - "SecOps &amp; Security"
  - "SIEM"
---

[ All blogs ](https://www.sumologic.com/blog "blog")[AI](https://www.sumologic.com/blog/ai), [SecOps &amp; Security](https://www.sumologic.com/blog/secops-security), [SIEM](https://www.sumologic.com/blog/siem)

# How the SOC Analyst Agent cuts investigation time from four hours to fourteen minutes

[Oren Shevach](#blog-author-block-375)

September 3, 2026

5 min read 

[AI](https://www.sumologic.com/blog/ai), [SecOps &amp; Security](https://www.sumologic.com/blog/secops-security), [SIEM](https://www.sumologic.com/blog/siem)

##### Table of contents

 

 

 

4:37 a.m. Someone tried logging into Sarah Chen’s account for the sixth time in ninety seconds.

MFA fatigue campaigns work on a simple bet: eventually, someone taps “approve” just to make the notifications stop. It paid off. The attacker was in.

The first move was quiet — deactivate SMS authentication, a small settings change easy to miss on a busy queue, and exactly the kind of thing that buys room to work without tripping an alarm. Then came the real work: AWS credentials pulled from one system, SSH keys from another, and a slow and methodical pull of internal source code.

All of it happened while Sarah slept, while the overnight shift watched a queue that didn’t yet know to flag this one as urgent, while nobody with the context to connect “SMS deactivated” to “credentials pulled” to “source code accessed” was awake to see it happen in real time.

By the time the sun was up, it was over. The attacker had what they came for.

Let’s take a look at two ways this could go.

## **The old way: Four hours of queues, handoffs, and browser tabs**

**4:39 a.m.** [Sumo Logic SIEM](https://www.sumologic.com/solutions/siem) correlated those events into a single insight.

**5:00 a.m.** The SOC team picks up the queue that includes this alert and dozens of others.

**5:21 a.m.** Edwin, a tier-one analyst, opens the alert and checks the basics: Has this account logged in from here before? Has MFA fired like this before? Nothing rules it out, so it goes into the “look closer” pile while the analyst moves to the next alert.

**7:08 a.m.** By mid-morning, it’s finally up for a closer look. Investigating means toggling between tools that don’t talk to each other: the identity provider for MFA history, the SIEM for correlated events, a chat tool to check what a file name actually said, and a separate lookup for the IPs involved. The analyst is the integration layer. You copy values from one screen, paste them into another, tracking what matched by hand. Ruling out “the user just forgot their password” alone can eat the better part of an hour.

If the SMS-authentication change gets caught, and on a busy queue, a settings change is exactly what slips through, it’s usually what bumps the ticket to tier two. A hand-off, a wait for queue room, then confirming the exfiltration, tracing which credentials were exposed, and writing the incident report by hand, mostly from memory of what got checked and in what order.

**8:48 a.m.** Several hours, multiple handoffs, and many browser tabs later, the investigation is complete. The job, done properly, takes that long. Which is exactly why triage existed: to make sure only the alerts that could survive that much attention got it.

## **AI moves us directly to full investigation**

Detect, triage, investigate. That pipeline has run security operations for a quarter century, for one simple reason: deep investigation was expensive, and analysts were scarce. So the industry built a fast filter to protect the expensive step. This made sense at the time. Triage is skilled work, and the tiers and queues built around it got real value out of the attention available.

But agents don’t get tired at four in the morning, and they don’t run out at the end of a shift. The scarcity that made rationing necessary is gone. So when Sumo Logic built its first AI agent for the SOC, the [SOC Analyst Agent](https://www.sumologic.com/blog/soc-analyst-agent-for-soc-team), we weren’t aiming to accelerate triage. We sought to eliminate the need for it.

## **The Dojo AI way: Four minutes to verdict, fourteen minutes to deep understanding and a report**

**4:39 a.m.** Sumo Logic SIEM correlated those events into a single insight, and the SOC Analyst Agent automatically began its investigation.

It works the way an experienced analyst does: starting with a hypothesis, deciding which explanation to test first, then looking for the evidence that would rule it out. Every test gets measured against your data and against what normal looks like for that account. Explanations that fail get dropped, and the agent tells you which ones failed and why. The verdict isn’t the first story that fits the facts, it’s the one still standing once the others were eliminated.

Every key finding carries its evidence, so the claim about MFA deactivation links straight back to the deactivation event itself. What happened regenerates whenever signals are added or removed, so the story moves when the evidence moves.

**4:43 a.m.** In less than five minutes, the [SOC Analyst Agent](https://www.sumologic.com/demo/soc-analyst-agent) reached a verdict: the activity was malicious.

Edwin could close the investigation now, but instead, he decides to take a few extra minutes to verify the agent’s findings, dig a little deeper, and generate a report.

**4:45 a.m.** First things first: understand the blast radius.

Edwin, the assigned analyst, clicks through to [Mobot](https://www.sumologic.com/blog/mobot-your-log-analysis-partner) to dig deeper. The context is already loaded, so he starts where the agent left off, not at the beginning.

Before he asks anything, Edwin looks at what the agent already did, skimming the queries run and the data behind them. He could edit or run them again, but instead decides to start a new search.

### Prompt one: Look for related insights

**4:47 a.m.** “Search for related insights”

Trying to figure out if this has happened before, he can pivot easily: same entity, same attack name, same signal rules, same [MITRE](https://www.sumologic.com/glossary/mitre-attack) tactics, or insights active in the same window. The same entity shows what the attacker did next. Same tactics shows whether anyone else is getting the same treatment.

With every decision Edwin makes, his agent teammate surfaces more moves worth exploring.

### Prompt two: Check every indicator at once

**4:49 a.m.** “Check every indicator in this insight against threat intelligence and tell me what matched, what didn’t, and why it matters”

Instead of pivoting through search results one indicator at a time, Edwin asks the high-level question and runs all of them at once. [Mobot](https://www.sumologic.com/demo/mobot-walkthrough) breaks it down: which artifacts in this insight count as indicators, and which feeds, such as Sumo Logic’s out of the box, plus any custom additions, can actually speak to them. Then it reports back on every one, including the ones nobody can check.

### Prompt three: Chase the credentials

**4:52 a.m.** “Show me any authentication attempts using the AWS service credentials in those files.”

Mobot doesn’t fake an answer to the literal question. Slack logged the file names, not the credentials inside them, so no log can actually tie a login back to that file. Instead of guessing, it says so, then offers what it can test: AWS activity on the account after the exfiltration, sign-ins from unfamiliar addresses, console logins from the proxy.

At every step, Edwin also gets a recommendation. Here, it’s to treat the credentials as compromised regardless, and rotate them today.

### Prompt four: Generate a report

**4:53 a.m.** “Generate a report of the investigation.”

What Mobot returns is an executive summary, a timeline with a MITRE technique on every row, and every signal that fires. This is a report Edwin can hand to an IR lead or an auditor.

It tracks dead ends, recording the ruled-out indicators, so a reader six months from now sees what was dismissed, not only what was concluded. It cites its sources too, separating what Okta’s own security context told it from what a threat feed told it, so nothing shows up looking corroborated when it isn’t. And it closes with a priority-ranked action list: suspend the account, rotate every credential in those files, notify legal and compliance — a customer database export happened, and that carries a notification obligation.

## **Accelerate MTTR with AI you can trust**

The above example is hypothetical, but it’s indicative of what Sumo Logic customers ([and our own SOC](https://www.sumologic.com/blog/building-ai-first-soc-customer-zero)) experience every day.

With the SOC Analyst Agent, trust and transparency are built in because it operates on the SIEM data you already trust:

- **Every step is auditable.** Tool calls land in the audit event index, findings link back to their source signals, and any query Mobot runs opens straight in Log Search. Verdicts and findings are also available through the [Sumo Logic SIEM API](https://www.sumologic.com/help/docs/api/cloud-siem-enterprise/).

- **It reasons over more than one insight in front of it.** Normalized records and signals, the entities correlated across your sources, your threat intel feeds plus ours, and enrichment like geolocation, user behavior, and asset details.
- **It never acts on its own**, on purpose. Suspending an account, rotating a key, isolating a host — those decisions stay with you.
- **You control what it investigates automatically**, and there’s a policy for what happens once you hit your committed volume.

## **See for yourself**

Ready to give the SOC Analyst Agent a try? [Sign up for our free trial](https://www.sumologic.com/sign-up/).

### Article Tags

- [AI](https://www.sumologic.com/blog/ai)
- [SecOps &amp; Security](https://www.sumologic.com/blog/secops-security)
- [SIEM](https://www.sumologic.com/blog/siem)

Oren Shevach

Senior Director of Product Management

Oren Shevach is a Senior Director of Product Management at Sumo Logic, bringing over 15 years of experience. He previously served as a Product Leader at IBM Security and Trustwave, where he defined vision and strategy for security solutions and services. He is passionate about helping clients optimize and advance the maturity of their SecOps processes.

[](https://www.sumologic.com/feed "RSS Feed")[](https://twitter.com/intent/tweet?text=How%20the%20SOC%20Analyst%20Agent%20cuts%20investigation%20time%20from%20four%20hours%20to%20fourteen%20minutes&url=https%3A%2F%2Fwww.sumologic.com%2Fblog%2Fsoc-analyst-agent-cuts-investigation-time "X")[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.sumologic.com%2Fblog%2Fsoc-analyst-agent-cuts-investigation-time "Facebook")[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.sumologic.com%2Fblog%2Fsoc-analyst-agent-cuts-investigation-time "Linkedin")

[Previous blog

The six pillars of AI-ready telemetry](https://www.sumologic.com/blog/six-pillars-ai-ready-telemetry)

People who read this also enjoyed

[  

The six pillars of AI-ready telemetry

September 2, 2026

 

 ](https://www.sumologic.com/blog/six-pillars-ai-ready-telemetry)[  

Mobot levels up: Build incident response playbooks with natural language

August 27, 2026

 

 ](https://www.sumologic.com/blog/mobot-incident-response-playbooks)[  

The AI SOC explained: Intelligent security for modern threats

August 26, 2026

 

 ](https://www.sumologic.com/blog/ai-soc-intelligent-security-for-modern-threats)[  

Mobot levels up: create smarter alerts in minutes

August 19, 2026

 ](https://www.sumologic.com/blog/mobot-conversational-monitors)

[AI Instructions](https://www.sumologic.com/ai-instructions.md)
