SOC Monthly Review Agent
adaQuest · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
SOC Monthly Review Agent helps SOC Managers, SOC Leads, service delivery teams, and security leadership generate a monthly security operations review. The agent reduces manual reporting effort, improves executive visibility, and provides leadership-ready insights across incident lifecycle, queue health, Security Operations Efficiency, MITRE ATT&CK-oriented trends, detection drivers, recurring entities, automation health, service value evidence, maturity notes, and recommended improvement actions.
Input
Show the rest of the publisher’s description (34 more lines)
The agent does not require operational runtime inputs for the standard monthly review. Each scheduled or manual execution analyzes the current month-to-date and compares it with the previous completed month.
The monthly model starts on the first day of the current month at 00:00 UTC and runs until execution time. The previous month is treated as the last completed calendar month. If the current month is still in progress, the agent identifies it as month-to-date.
For Chat with agent, users may ask follow-up questions about month-over-month changes, CISO-ready summaries, service review notes, SOC improvement actions, SecOps Efficiency metrics, MITRE trends, recurring entities, tuning candidates, automation health, or maturity observations.
Task
The agent collects and correlates available security operations data from the unified Microsoft security operations experience, using Microsoft Defender XDR signals and onboarded Microsoft Sentinel data when available through the unified portal. It uses structured queries and agent orchestration to summarize and compare month-to-date activity with the previous completed month across incident lifecycle, severity and status distribution, queue health, alert and detection drivers, recurring entities, high-priority items, backlog indicators, automation health, closure classifications, product trends, and MITRE ATT&CK-oriented activity.
The agent calculates or reports Security Operations Efficiency metrics such as Mean Time to Triage, Mean Time to Closure, High-severity Mean Time to Closure, incidents by closing classification, incidents created by product, incidents created by MITRE tactic, created versus closed activity, and backlog indicators. If required data is unavailable, the agent states the limitation instead of estimating or fabricating metrics.
The agent is read-only. It does not close incidents, assign owners, isolate devices, disable users, modify analytics rules, configure suppressions, run remediation actions, or execute playbooks.
Outputs
The agent produces a structured monthly SOC leadership review that may include:
- Executive Summary for SOC and Security Leadership
- Month-over-Month Decision Snapshot
- Service Value and Operational Evidence Highlights
- Monthly Incident Lifecycle and Queue Health
- Security Operations Efficiency
- Mean Time to Triage and Mean Time to Closure
- Incidents by closing classification
- Incidents created by product
- Incidents created by MITRE ATT&CK tactic
- Monthly Incident and Alert Trends
- Detection Drivers
- MITRE ATT&CK and Detection Trends
- Recurring Entities and Repeated Patterns
- High-Priority Items Requiring Attention
- Automation and Workflow Health
- Detection Engineering and Tuning Opportunities
- Monthly Operational Risk and Maturity Notes
- Recommended SOC Improvement Plan
- CISO and Service Review Summary
- Audit, Evidence, and Data Quality Notes
The Chat with agent experience allows users to ask follow-up questions about the monthly review, request explanations of findings, review improvement opportunities, clarify operational metrics, prepare service review notes, summarize findings for CISO-level reporting, or identify SOC priorities for the next month.
Required products and permissions
The customer requires Microsoft Security Copilot with available SCU capacity and Microsoft Defender XDR access through the unified Microsoft security operations experience. Microsoft Sentinel data is optional and used when onboarded and available through the unified portal experience. Recommended access includes Security Copilot workspace access, read access to relevant Defender XDR data, and appropriate Defender XDR Unified RBAC permissions. If onboarded Sentinel data is used, read access to the relevant Sentinel incident and alert data is also required. Global Administrator is not required.
Estimated SCU consumption
Initial measured consumption in the pilot environment was approximately 0.4 SCU per full scheduled or manual execution and approximately 0.1 SCU per Chat with agent interaction. Actual consumption may vary depending on tenant size, incident volume, telemetry availability, and chat complexity.
Preview
5 imagesAgent build and provenance
Sign in to see the provenance.
The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.
Sign inCompliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
1 listedSources
Publisher resources
2 linksEvidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






