SOC Daily Brief Agent
adaQuest · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 7 captures on record
What the publisher says
As described on Microsoft Marketplace.
SOC Daily Brief Agent helps SOC Leads, SOC Managers, and service delivery teams generate a structured daily security operations briefing for the last 24 hours. The agent is designed to reduce manual reporting effort, improve operational visibility, and provide consistent leadership-ready insights across incident lifecycle, alert patterns, queue health, automation health, Security Operations Efficiency, MITRE ATT&CK-oriented trends, and recommended SOC actions.
Input
Show the rest of the publisher’s description (34 more lines)
The agent does not require operational runtime inputs for the standard daily brief. Each scheduled or manual execution automatically analyzes the last 24 hours of available security operations data.
For the interactive Chat with agent experience, the user may provide a natural language request related to the daily brief, such as asking for more details about high-priority incidents, detection drivers, SecOps Efficiency metrics, MITRE tactics, tuning candidates, audit notes, or a concise operational summary.
Task
The agent collects and correlates connected security operations data from the configured Sentinel workspace and Defender XDR evidence when available. It uses structured queries and agent orchestration to summarize incident lifecycle activity, severity and status distribution, alert and detection drivers, recurring entities, high-priority incidents, queue and backlog indicators, automation health, closure classifications, product trends, and MITRE ATT&CK-oriented activity.
The agent calculates or reports Security Operations Efficiency metrics such as Mean Time to Triage, Mean Time to Closure, incidents by closing classification, incidents created by product over time, and incidents created by MITRE tactic over time. If the required data is unavailable, the agent explicitly states the limitation instead of estimating or fabricating metrics.
The agent is read-only. It does not close incidents, assign owners, isolate devices, disable users, modify analytics rules, run remediation actions, or execute playbooks.
Outputs
The agent produces a structured daily SOC leadership briefing that may include:
- Executive Summary
- SOC Leadership Decision Snapshot
- Service Value and Operational Evidence Highlights
- Security Operations Efficiency
- Mean Time to Triage and Mean Time to Closure
- Incidents by closing classification
- Incidents created by product over time
- Incidents created by MITRE ATT&CK tactic over time
- Incident Lifecycle and Queue Health
- Incident and Alert Overview
- Detection Drivers
- MITRE ATT&CK and Detection Trends
- Recurring Entities and Repeated Patterns
- High-Priority Items Requiring Attention
- Automation and Workflow Health
- Recommended SOC Lead Actions
- Audit, Evidence, and Data Quality Notes
The Chat with agent experience allows users to ask follow-up questions about the daily brief, request explanations of findings, review tuning candidates, clarify operational metrics, prepare audit notes, or generate concise summaries for SOC handovers and leadership discussions.
Required products and permissions
The customer requires Microsoft Security Copilot with available SCU capacity, Microsoft Sentinel with a connected Log Analytics workspace, and Microsoft Defender XDR evidence where available. Recommended least-privilege access includes Security Copilot workspace access, read access to relevant Defender XDR data, and Microsoft Sentinel Reader access to the configured workspace. Global Administrator is not required.
Estimated SCU consumption
Initial measured consumption in the pilot environment was approximately 0.4 SCU per full scheduled or manual agent execution and approximately 0.1 SCU per Chat with agent interaction. Actual consumption may vary depending on workspace size, incident volume, available telemetry, data source availability, and the complexity of chat follow-up questions.
As a planning baseline, a business-day model with 22 runs per month is estimated at approximately 8.8 SCU per month, excluding chat interactions. A daily model with 30 runs per month is estimated at approximately 12.0 SCU per month, excluding chat interactions. Chat usage should be estimated separately based on expected user interaction volume.
---------
Version history / change log
0.1.0 - Initial marketplace release. Includes daily 24-hour SOC leadership briefing, manual and scheduled execution support, Chat with agent follow-up, connected workspace incident and alert summarization, Security Operations Efficiency metrics, MITRE ATT&CK-oriented trends, automation health, high-priority item review, recommended SOC Lead actions, and audit/data quality notes.
Preview
4 imagesAgent build and provenance
Sign in to see the provenance.
The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.
Sign inCompliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
1 listedSources
Publisher resources
2 linksEvidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.





