AI & DETECTION · 8 MIN
Building the Agentic SOC: Why We Stopped Waiting
What QMasters is building for the agentic era, the AI agent already running in our SOC today, and why nobody sells software for the seat we sit in.
What is an agentic SOC and why would an MSSP build its own agentic tools?
An agentic SOC is a security operations model where AI agents carry out research, investigation and response work continuously alongside human analysts, guided by defined objectives and evidence standards rather than fixed automation scripts. An MSSP builds its own agentic tooling because the gap is not in the security platforms it operates, it is in the layer that runs one managed service across many customers and many vendors at once. No vendor sells that layer, because no vendor builds first class support for its competitors.

Building the Agentic SOC: Why We Stopped Waiting
The most boring sentence in security marketing is that AI is here to stay.
It is boring because it is settled.
It will change shape, it will improve, and plenty of what feels essential today will look naive in two years.
But it is not going back, and saying so out loud costs nothing.
The unsettled question is what a security operator actually changed because of it.
So rather than another vision, here is our build log.
The short version
An agentic SOC is a security operations model where AI agents do research, investigation and response work alongside human analysts, guided by objectives and evidence standards rather than fixed scripts.
Why we build it ourselves.
We are a CrowdStrike Elite Partner and we run IBM QRadar, Fortinet, Palo Alto and Okta in production every day.
Those platforms are excellent and we are not reinventing any of them.
The gap is not product quality, it is market structure.
Every vendor is building an agentic layer for its own platform, which is exactly what they should do.
But our seat is multi vendor and multi tenant by definition, and no vendor is ever going to build first class support for its competitors' consoles.
The layer that runs one managed service across many customers and many vendors, with one evidence standard and one memory of what came before, can only be built by whoever sits across all of them.
Nobody sells software for that seat.
So we buy the best platforms in the world and we build the layer between them, and everything we build makes those platforms work harder.
What we are planning.
A layered agentic SOC where agents triage and investigate under evidence contracts, humans stay on criticals and high impact approvals, and customers watch the work rather than receive a summary of it.
An investigation agent for our own analysts, which ships only after it survives a blind grade against our senior people on real historical cases.
Onboarding and gap analysis that measures what is covered instead of offering an opinion about it.
Safer movement of data between us and you, treated as a design constraint rather than a footnote.
What already runs.
A two tier agentic CTI pipeline researching clear and dark web per customer.
Tier one finds what is plausibly relevant, tier two evaluates what it actually means, and when it matters the agent raises an alert straight into MCSS operations for a human analyst.
DailyIOC, pushing verified malicious IPs inline every three hours with no analyst touch.
One operations console covering every managed customer, because no vendor console sees the whole estate.
Playbooks, not workflows.
This is the idea underneath all of it.
A workflow encodes the route, a fixed graph drawn in advance that dead ends the moment reality steps off it.
A playbook encodes the destination and the rules of the road: the objective, the evidence that must exist before a verdict is allowed, and the boundaries the agent may not cross.
A workflow asks what steps do I run.
A playbook asks what must I prove.
The discipline is not the freedom, it is the contract, and unlike an analyst's judgement that contract is checkable by machine.
The rest of this post is the detail, starting with where we are going.

*Figure 1.
The live operations view our analysts work from.
Customer identifiers masked.*
The part of "AI is here to stay" that nobody finishes
We have been building and running security operations centres since 2015, first as teams we stood up and operated, later as our own managed service.
StrongHold MCSS has carried that work since 2020.
Today it means 240 plus enterprise customers, roughly 4 TB of telemetry a day, 16 SOC analysts and a 25 person operations team covering the clock.
That arithmetic has exactly one solution, and it is not hiring faster.
Here is the consequence nobody puts at the end of the sentence.
AI did not change our shopping list.
It changed what kind of company a security operator has to be.
A managed security provider used to be a service business that bought tools.
It now has to be an engineering business that happens to sell a service.
That is a much bigger change than adding a chatbot to a portal, and it is why this post exists.
What we are building
The layered agentic SOC.
Agents that triage and investigate under evidence contracts, humans on criticals and high impact approvals, and a portal where customers can watch the work rather than receive a summary of it.
This is the destination, and today it is a blueprint.
It is not a guess, though, and that distinction matters.
The CTI agent further down this post is the same pattern already running in one domain: tiered agents, a real judgement, work filed into a queue a person owns.
We are extending something that works rather than betting on something we hope will.
An investigation agent for our own analysts.
An internal chat with real capability behind it, able to query the platforms we already operate, assemble a timeline and cite the evidence it used.
It has one gate to pass before it touches production, which is a blind grade against our senior analysts on real historical cases.
It ships when it survives that, and not before.
Onboarding and gap analysis.
The first weeks with a new customer decide the next three years.
We are building tooling that reads an environment, maps what is covered and says plainly what is not.
Gap analysis should be a measurement, not an opinion.
Safer data movement between us and you.
More AI in the loop means more places customer data could end up somewhere it should not.
We are treating that as a design constraint rather than a footnote.
One distinction worth drawing, because these two get muddled constantly.
This post is about operating with AI.
Securing the AI your own business is adopting is a different problem with a different answer, and we wrote that one up in AIDR explained for CISOs.
The architecture: how the investigation agent works
When a new offense arrives, our AI Investigation Manager does not hand it straight to a human. It runs four parallel tracks simultaneously — evidence collection, threat enrichment, case correlation, and an organisation-wide hunt — then assembles everything into a draft incident report before a quality check decides whether the case is ready or needs one additional round of agent work.

*Figure 2.
The AI Investigation Manager architecture.
Four agent tracks run in parallel. Human analyst oversight is required at the quality check and final report stages.*
This is the playbook model in practice.
The agent does not declare a verdict until every evidence checklist item is satisfied.
Humans remain in the loop at the two critical decision points: the quality check and the final report sign-off.
What already runs
Now the receipts, because a roadmap with nothing behind it is just a wish.
The intelligence agent
This one is not a dashboard.
It is an agent, and it is the reason the section above is credible.
Our CTI capability is a full agentic pipeline running against the clear web and the dark web, scoped per customer.
Public code repositories, paste sites, Telegram channels, ransomware leak sites, dark web forums, expired domain activity.
It runs in two tiers, deliberately, because it mirrors how the human side of a SOC already works.
Tier one does the research and the first pass.
It sweeps the sources against every organization we protect and decides what is plausibly relevant to that specific customer.
Volume is the entire problem here.
On a representative day that is around 945 items surfaced and 20 that survive as relevant.
Tier two takes what tier one found and evaluates it properly.
It reads the finding, works out what it means for that customer, and decides whether it rises to something that needs action.
Then it closes the loop.
When the answer is yes, the agent raises an alert directly into MCSS operations, where a human analyst picks it up like any other piece of work.
That last step is the part that matters.
Plenty of tools can classify.
This one researches, reaches a judgement, and files work into a live operations queue that people are accountable for.
We say we provide context, not just alerts.
An agent that hands an analyst a finding, the reasoning behind it, and why it concerns that particular customer is what that phrase has to mean in practice.

*Figure 3.
The CTI agent workspace — 945 raw items surfaced across clear and dark web sources; 18 survive as actionable findings for today.*
DailyIOC
DailyIOC is our oldest receipt and the least glamorous thing we operate.
A curated blacklist of verified malicious IPs, cross referenced across more than twenty direct feeds, refreshed every three hours, pushed inline into FortiGate, Palo Alto and Check Point.
No appliance.
No ingestion script.
No analyst time.
It belongs in this post because it predates the current AI cycle by years.
We did not pivot to building.
We have always built.
AI raised the stakes.

*Figure 4.
DailyIOC — from feed to firewall in three steps.
20+ direct feeds, validated and verified, pushed inline with no analyst touch.*
The operations layer
Our SOC works from a console we built rather than a vendor dashboard.
Every managed customer in one view.
Open incidents, mean time to resolve, quick close rate, severity mix, which rules fire most, which log sources carry the load, and which analyst is holding what.
The point is not the charts.
It is that a managed service needs one operational truth across every tenant at once, and no vendor console can provide that, because no vendor sees the whole estate.
This is what Full Visibility. Full Transparency. has to mean on the inside before we can promise it on the outside.

*Figure 5.
One operational truth across every managed customer.
Customer names, log-source prefixes and rule identifiers masked.*
Why we build when we could buy
We need to be precise here, because this is where companies usually say something dishonest.
We are a CrowdStrike Elite Partner.
We run IBM QRadar, Fortinet, Palo Alto, Okta and Proofpoint in production every day.
Those are excellent platforms built by excellent engineering teams.
When we need endpoint protection we do not write an EDR.
The gap is not product quality.
It is market structure.
Every vendor is building an agentic layer for its own platform, and that is the correct thing for them to build.
But our seat is multi vendor and multi tenant by definition, and no vendor will ever build first class support for its competitors' consoles.
The layer that runs one managed service across many customers and many vendors, with one evidence standard and one memory of what happened before, can only be built by whoever sits across all of them.
Nobody sells software for our seat.
That is not a criticism of anyone's product.
It is an observation about who is in a position to build what.
So we buy the best platforms in the world, and we build the layer only we can build.
Everything we build makes the platforms we operate work harder.
Playbooks, not workflows
If you take one technical idea from this post, take this one.
A workflow encodes the route.
A fixed graph an engineer drew in advance, which handles exactly the incidents its author imagined and dead ends the moment reality steps off the graph.
Most security automation is workflows, which is why most security automation escalates to a human the second something is unusual.
A playbook encodes the destination and the rules of the road.
The objective, the evidence that must exist before a verdict is allowed, and the boundaries the agent may not cross.
The agent chooses its path at runtime based on what it actually finds.
A workflow asks what steps do I run.
A playbook asks what must I prove.
The discipline is not the freedom, it is the contract.
An agent may take any path, but it cannot declare a verdict until every item on the evidence checklist is satisfied.
Unlike an analyst's judgement, that contract is checkable by machine.
To be clear, workflows are still correct where determinism is the feature.
DailyIOC is a workflow and proudly so.
The same feeds, the same validation, every three hours, forever.
Investigation is simply not that kind of problem.
What this means if you are our customer
We have called ourselves Your Extended Security Team since long before any of this.
The agentic work is not a departure from that idea.
It is what lets the extension keep up.
Three things in plain terms.
- Your analysts get their attention back. The repetitive research, collection and correlation work moves to agents that do it continuously and never get bored. People spend their time on judgement.
- You see more, not less. Enriched incidents with evidence attached. Guided response instead of a ticket that says investigate. Answers you can check.
- Humans still own the outcome. Agents do the work. People make the calls that carry consequences and sign their names to the result. That is the design, not a temporary arrangement until the technology matures.
Which is the whole point of the promise we put on the front page.
Less Drama. More Detection.
Hold us to it
We have believed one thing since day one.
The job is to see where this is going and get our customers ready, rather than wait for the market to tell us what to think.
That belief has a cost.
It means building things nobody has validated yet, being wrong sometimes, and rebuilding.
We think that beats discovering in eighteen months that the operating model everyone relied on quietly stopped working.
So do not trust us.
Verify us.
Come and see the floor.
A thirty minute walkthrough of the systems in this post, on live data, with your questions.
Not a slide deck.
Talk to a security expert and we will show you what is running, what is not, and where the honest edges are.
---
Author · Gregori Nazarovsky, CTO, QMasters
Last updated · 2026-08-07
Reading time · 8 min
FAQ
Frequently asked questions.
An agentic SOC is a security operations model in which AI agents perform research, investigation, enrichment and response work alongside human analysts. Unlike scripted automation, agents are given an objective and an evidence standard, and they choose the steps needed to satisfy it.
A workflow encodes the route: a fixed if this then that graph drawn in advance, which dead ends when reality steps off the graph. A playbook encodes the destination: the objective, the evidence required before a verdict is allowed, and the boundaries the agent may not cross. A workflow asks what steps to run. A playbook asks what must be proven.
No. Agents do the repetitive research, collection and correlation work continuously. People make the judgement calls, approve high impact actions and own the outcome. That is the design, not a transitional arrangement.
Yes. QMasters is a CrowdStrike Elite Partner and operates IBM QRadar, Fortinet, Palo Alto, Okta and others in production daily. We buy the platforms and build the operating layer between them, which is a different job that no vendor sells.
A two tier agentic CTI pipeline that researches clear and dark web sources per customer, evaluates what it finds, and raises alerts directly into MCSS operations for a human analyst. Alongside it, DailyIOC pushes verified malicious IPs inline every three hours, and an internal operations console covers every managed customer in one view.
ABOUT THE AUTHOR
Practitioners from the QMasters Security Operations Center. We run 24/7 monitoring, detection engineering, and incident response for organisations across regulated industries — and write here from the offense and defense work in front of us.