Corelight’s Agentic Triage turns SOC alerts into evidence-backed investigations
ID: 1cca0bc3-8e34-552e-80d4-9f00527fe9f9
STIX ID: report--1cca0bc3-8e34-552e-80d4-9f00527fe9f9
Feed Name: Help Net Security
Corelight announced new agentic AI capabilities for SOCs that automate triage by consolidating alerts into entity-centric, explainable investigations driven by expert playbooks; expanded ML models to detect evasive post-exploitation techniques and encrypted tunneling/VPN anomalies without decryption; and integrations with Azure AD/Entra and CrowdStrike to enable one-click containment and cross-agent workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
