Back to the overview
Agent passport

L1 SOC Triage Agent

adaQuest · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

SOCAgentMonitoring
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 9 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

L1 SOC Triage Agent is a Security Copilot agent built to help SOC Level 1 analysts investigate incidents in the unified security operations experience with the judgment, structure, and consistency expected from a senior analyst.

The agent is designed for evidence-driven triage, not simple incident summarization. It investigates the incident, enriches relevant entities, validates supporting signals, identifies gaps, and recommends a clear analyst action: close, remediate, or escalate.

Show the rest of the publisher’s description (30 more lines)

Inputs:

  • IncidentId: required. The incident identifier provided by the analyst.
  • LookbackDays: optional. Analysis window used for supporting investigation and enrichment. Default: 30 days.

Tasks:

  • Resolve and investigate the incident from the unified Defender portal experience.
  • Correlate and enrich with Microsoft Sentinel workspace evidence through configured KQL queries.
  • Review incident metadata, related alerts, evidence, timeline, severity, status, and classification context.
  • Extract and enrich users, identities, devices, IP addresses, URLs, domains, files, and hashes.
  • Investigate identity and login context using Microsoft Entra and Defender identity signals, including sign-in patterns, risky users, audit activity, and suspicious authentication indicators.
  • Enrich indicators with Microsoft Defender Threat Intelligence, including reputation, DNS, WHOIS, hosting, and related threat intelligence where available.
  • Use Microsoft Purview enrichment when the incident suggests DLP, data exposure, insider risk, file activity, sensitive data movement, or possible exfiltration.
  • Separate confirmed evidence from weak signals, assumptions, and unavailable data.
  • Generate follow-up KQL suggestions so analysts can manually corroborate important findings when needed.

Outputs:

  • Structured Level 1 triage report.
  • Final verdict with confidence level and evidence rationale.
  • Recommended analyst action: Close, Remediate, or Escalate.
  • Closure reason and ready-to-use closure comment when the incident can be closed.
  • Escalation reason, target team, and ready-to-use escalation comment when Level 2 or a specialized team should take over.
  • Entity enrichment summary covering users, devices, indicators, files, hashes, and relevant data risk signals.
  • Threat intelligence findings for IPs, URLs, domains, and hashes when present.
  • Login and identity investigation summary.
  • Purview/data risk summary when applicable.
  • Investigation coverage checklist and data gaps.
  • Suggested analyst follow-up KQL queries for validation.

Required integrations may include Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra, Microsoft Defender Threat Intelligence, Microsoft Purview, and Security Copilot. The agent operates in read-only investigation mode and does not automatically close, isolate, remediate, or modify incidents.

Version history / change log: v2.6.19

  • Refining the stable L1 SOC Triage Agent execution model with stronger runtime controls, improved investigation quality, reduced risk of loops or unnecessary tool execution, and graceful handling for empty device enrichment results.

Estimated SCU consumption:

Typical runs are expected to consume approximately 0.8 to 2.0 SCUs depending on incident complexity, number of entities, enabled plugins, available evidence, and lookback window. Larger incidents with many entities, extensive threat intelligence enrichment, Purview context, or broad Sentinel correlation may consume more.

Preview

3 images
L1 SOC Triage Agent preview 1L1 SOC Triage Agent preview 2L1 SOC Triage Agent preview 3

Agent build and provenance

Sign in to see the provenance.

The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.

Sign in

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyadaQuestAutomated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://www.adaquest.com/

Plans and pricing as listed

1 listed
Free Plan Offer - Default
First month free, then $0.00/month
1-month subscription

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

3 links
Document requirement Scenario templatecatalogartifact.azureedge.netSource
L1 SOC Triage Agent Landing Pagewww.adaquest.comSource
Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.adaquest.com/contact-us-2/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.