Back to the overview
Agent passport

SOC Weekly Brief Agent

adaQuest · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

SOC briefReportCybersecurity
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 7 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

SOC Weekly Brief Agent helps SOC Leads, SOC Managers, and service delivery teams generate a structured weekly security operations briefing with week-over-week comparison. The agent reduces manual reporting effort and provides leadership-ready insights across incident lifecycle, queue health, alert trends, detection drivers, recurring entities, automation health, Security Operations Efficiency, MITRE ATT&CK-oriented trends, operational projections, and recommended SOC Manager actions.

Input

Show the rest of the publisher’s description (30 more lines)

The agent does not require operational runtime inputs for the standard weekly brief. Each scheduled or manual execution analyzes the current calendar week and compares it with the previous completed week. The weekly model starts on Sunday at 00:00 UTC. If the current week is still in progress, the agent identifies it as a partial week.

For Chat with agent, users may ask natural language follow-up questions about week-over-week changes, high-priority incidents, detection drivers, SecOps Efficiency metrics, MITRE tactics, recurring entities, tuning candidates, service review notes, operational projections, or CISO-ready summaries.

Task

The agent collects and correlates available security operations data from the unified Microsoft security operations experience, using Microsoft Defender XDR signals and onboarded Microsoft Sentinel data when available through the unified portal. It summarizes and compares current-week and previous-week activity across incident lifecycle, severity, status, queue health, alert trends, detection drivers, recurring entities, high-priority incidents, backlog indicators, automation health, closure classifications, product trends, and MITRE ATT&CK-oriented activity.

The agent calculates or reports metrics such as Mean Time to Triage, Mean Time to Closure, High-severity Mean Time to Closure, incidents by closing classification, incidents by product, and incidents by MITRE tactic. If required data is unavailable, the agent states the limitation instead of estimating or fabricating metrics.

The agent is read-only. It does not close incidents, assign owners, isolate devices, disable users, modify analytics rules, configure suppressions, run remediation actions, or execute playbooks.

Outputs

The agent produces a structured weekly SOC leadership briefing that may include:

  • Executive Summary
  • Week-over-Week Decision Snapshot
  • Service Value and Operational Evidence Highlights
  • Weekly Incident Lifecycle and Queue Health
  • Security Operations Efficiency
  • Severity, Status, and Backlog
  • Incident and Alert Trends
  • Detection Drivers
  • MITRE ATT&CK and Detection Trends
  • Recurring Entities and Repeated Patterns
  • High-Priority Items Requiring Attention
  • Automation and Workflow Health
  • Operational Projections for Next Week
  • Recommended SOC Manager Actions
  • Audit, Evidence, and Data Quality Notes

The Chat with agent experience allows users to ask follow-up questions, clarify metrics, review tuning candidates, prepare service review notes, summarize findings for leadership, or identify next-week SOC priorities.

Required products and permissions

The customer requires Microsoft Security Copilot with available SCU capacity and Microsoft Defender XDR access through the unified Microsoft security operations experience. Microsoft Sentinel data is optional and used when onboarded and available through the unified portal. Recommended access includes Security Copilot workspace access, read access to relevant Defender XDR data, and appropriate Defender XDR Unified RBAC permissions. Global Administrator is not required.

Estimated SCU consumption

Initial measured consumption is approximately 0.4 SCU per full scheduled or manual execution and approximately 0.1 SCU per Chat with agent interaction. Actual consumption may vary by tenant size, incident volume, telemetry availability, and chat complexity.

Version history / change log

1.0.0 - Initial marketplace release. Includes weekly SOC leadership briefing, current-week versus previous-week comparison, manual and scheduled execution, Chat with agent follow-up, unified security operations signal analysis, SecOps Efficiency metrics, MITRE ATT&CK-oriented trends, automation health, operational projections, recommended SOC Manager actions, and audit/data quality notes.

Preview

5 images
SOC Weekly Brief Agent preview 1SOC Weekly Brief Agent preview 2SOC Weekly Brief Agent preview 3SOC Weekly Brief Agent preview 4SOC Weekly Brief Agent preview 5

Agent build and provenance

Sign in to see the provenance.

The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.

Sign in

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyadaQuestAutomated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://www.adaquest.com/

Plans and pricing as listed

1 listed
adaQuest Security Agent Offer
First month free, then $11.99/month
Paid usage-based plan for SOC Weekly Brief Agent. Customers are charged per agent execution with monthly or annual billing options. Each execution generates a structured weekly SOC leadership briefing with current-week versus previous-week comparison, including incident activity, queue health, Security Operations Efficiency metrics, MITRE-oriented insights, detection trends, recurring entities, automation health, operational projections, data quality notes, and recommended SOC Manager actions. Security Copilot SCU consumption is not included and is billed separately through the customer’s Microsoft Security Copilot capacity. Customers interested in a free trial or pilot evaluation may contact adaQuest for eligibility and onboarding details. Contact: customerupdate@adaquest.com

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource
License TermsLicense TermsSource

Publisher resources

2 links
SOC Weekly Brief Agent Web Pagewww.adaquest.comSource
Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.adaquest.com/contact-us-2/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.