Omniquad Agentic SOC
by Omniquad.com
AI agents that triage incidents, hunt threats, and tune Sentinel ingestion in your tenant
Omniquad Agentic SOC adds scheduled LLM-driven agents to your Microsoft Sentinel workspace. They triage incidents, hunt threats, audit your detection coverage, and tune ingestion costs — all running inside a managed application deployed to your own Azure tenant. Your Sentinel data never leaves your subscription.
What the agents do
- Incident Triage — every six hours, investigates new Sentinel incidents with rule and entity context, flags likely false positives, and surfaces actionable verdicts.
- Threat Hunting — weekly KQL-driven hunts tailored to your connectors, telemetry, and threat landscape.
- Analytics Coverage — weekly review of detection rules against deployed data sources and the MITRE ATT&CK matrix, with concrete coverage gaps and recommendations.
- Log Anomaly Detection — daily statistical baselining of ingestion volumes; alerts when a table goes silent or surges.
- Log Trimmer — daily noise audit of your most expensive tables, with deployable DCR transforms and projected monthly savings.
- Security Report — weekly executive roll-up of incidents, coverage, and ingestion health.
- Synthesist — every 30 minutes, aggregates findings from every other agent into a single posture view for your dashboard.
- On-demand Ask — a chat surface inside the UI for ad-hoc questions across your Sentinel data.
How it deploys
The offer installs a single managed resource group in your subscription. Inside, two Azure Container Apps host the web UI and read-only API; Container Apps Jobs run the scheduled agents on cron and enforce the audit-policy lifecycle. State persists in a dedicated per-customer Storage account with a WORM-locked audit container. A per-customer Azure OpenAI (Microsoft Foundry) resource is provisioned for LLM inference; you pay Azure consumption directly.
What stays under your control
- Per-tenant isolation. Storage, Key Vault, managed identity, and Foundry are deployed once per customer — no shared runtime state with any other Omniquad customer.
- Read-only on Sentinel. The user-assigned managed identity gets Sentinel Reader and Log Analytics Reader; no write access until you opt into Responder mode in a future release.
- Tamper-evident audit. Every agent run, every notification, and every administrative action is HMAC-signed and appended to an immutable WORM blob with configurable retention.
- Publisher zero-access. Omniquad has no RBAC into the deployed managed resource group. The managed-app authorizations array is empty by design.
What you need
- A Microsoft Sentinel workspace and the underlying Log Analytics workspace, in one of the supported regions.
- Permission in the target subscription to create resources. After install, the deployed managed identity needs Sentinel Reader and Log Analytics Reader on your workspace — the managed-app Overview blade surfaces a one-command Cloud Shell helper that binds both roles in a single paste.