SOC Monthly Review Agent
by adaQuest
Monthly SOC review with trends, service value, SecOps metrics, MITRE insights, and actions.
SOC Monthly Review Agent helps SOC Managers, SOC Leads, service delivery teams, and security leadership generate a monthly security operations review. The agent reduces manual reporting effort, improves executive visibility, and provides leadership-ready insights across incident lifecycle, queue health, Security Operations Efficiency, MITRE ATT&CK-oriented trends, detection drivers, recurring entities, automation health, service value evidence, maturity notes, and recommended improvement actions.
Input
The agent does not require operational runtime inputs for the standard monthly review. Each scheduled or manual execution analyzes the current month-to-date and compares it with the previous completed month.
The monthly model starts on the first day of the current month at 00:00 UTC and runs until execution time. The previous month is treated as the last completed calendar month. If the current month is still in progress, the agent identifies it as month-to-date.
For Chat with agent, users may ask follow-up questions about month-over-month changes, CISO-ready summaries, service review notes, SOC improvement actions, SecOps Efficiency metrics, MITRE trends, recurring entities, tuning candidates, automation health, or maturity observations.
Task
The agent collects and correlates available security operations data from the unified Microsoft security operations experience, using Microsoft Defender XDR signals and onboarded Microsoft Sentinel data when available through the unified portal. It uses structured queries and agent orchestration to summarize and compare month-to-date activity with the previous completed month across incident lifecycle, severity and status distribution, queue health, alert and detection drivers, recurring entities, high-priority items, backlog indicators, automation health, closure classifications, product trends, and MITRE ATT&CK-oriented activity.
The agent calculates or reports Security Operations Efficiency metrics such as Mean Time to Triage, Mean Time to Closure, High-severity Mean Time to Closure, incidents by closing classification, incidents created by product, incidents created by MITRE tactic, created versus closed activity, and backlog indicators. If required data is unavailable, the agent states the limitation instead of estimating or fabricating metrics.
The agent is read-only. It does not close incidents, assign owners, isolate devices, disable users, modify analytics rules, configure suppressions, run remediation actions, or execute playbooks.
Outputs
The agent produces a structured monthly SOC leadership review that may include:
- Executive Summary for SOC and Security Leadership
- Month-over-Month Decision Snapshot
- Service Value and Operational Evidence Highlights
- Monthly Incident Lifecycle and Queue Health
- Security Operations Efficiency
- Mean Time to Triage and Mean Time to Closure
- Incidents by closing classification
- Incidents created by product
- Incidents created by MITRE ATT&CK tactic
- Monthly Incident and Alert Trends
- Detection Drivers
- MITRE ATT&CK and Detection Trends
- Recurring Entities and Repeated Patterns
- High-Priority Items Requiring Attention
- Automation and Workflow Health
- Detection Engineering and Tuning Opportunities
- Monthly Operational Risk and Maturity Notes
- Recommended SOC Improvement Plan
- CISO and Service Review Summary
- Audit, Evidence, and Data Quality Notes
The Chat with agent experience allows users to ask follow-up questions about the monthly review, request explanations of findings, review improvement opportunities, clarify operational metrics, prepare service review notes, summarize findings for CISO-level reporting, or identify SOC priorities for the next month.
Required products and permissions
The customer requires Microsoft Security Copilot with available SCU capacity and Microsoft Defender XDR access through the unified Microsoft security operations experience. Microsoft Sentinel data is optional and used when onboarded and available through the unified portal experience. Recommended access includes Security Copilot workspace access, read access to relevant Defender XDR data, and appropriate Defender XDR Unified RBAC permissions. If onboarded Sentinel data is used, read access to the relevant Sentinel incident and alert data is also required. Global Administrator is not required.
Estimated SCU consumption
Initial measured consumption in the pilot environment was approximately 0.4 SCU per full scheduled or manual execution and approximately 0.1 SCU per Chat with agent interaction. Actual consumption may vary depending on tenant size, incident volume, telemetry availability, and chat complexity.