LOX Agent Investigation Coach
Lockbase Cyber · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
LOX Agent (Lockbase Open XDR) is a cross-EDR investigation coach that unifies Microsoft Defender XDR, CrowdStrike Falcon, and Microsoft Threat Intelligence inside Security Copilot, helping L1/L2 SOC analysts triage alerts faster and with higher confidence than working each console separately.
Inputs: Microsoft Defender XDR alerts and Advanced Hunting telemetry, CrowdStrike Falcon alert and device records, Microsoft Threat Intelligence indicator context, and analyst natural-language prompts (alert IDs, hostnames, UPNs, file hashes, IPs, CVEs).
Show the rest of the publisher’s description (8 more lines)
Tasks: Correlates Defender XDR alerts with CrowdStrike Falcon detections for the same host or user, enriches every indicator (IP, domain, URL, file hash, CVE) through Microsoft Threat Intelligence, runs 145+ KQL hunting skills spanning endpoint, identity, email, and cloud-app telemetry, assesses CrowdStrike prevention status via bitmask and sensor , and coaches the analyst through structured investigation with explicit next-step skill invocations.
Outputs: Prioritized (P1–P4) triage narrative with MITRE ATT&CK tactic and technique mapping, cross-EDR correlation showing where Defender and CrowdStrike agree or disagree for each finding, source-labeled data blocks, and concrete containment and remediation recommendations.
LOX Agent consumes approximately 0.3–1.5 SCU per triage run, depending on investigation depth:
- A single-alert cross-EDR correlation (one CrowdStrike alert + Defender hostname lookup + one MDTI enrichment) runs at ~0.3–0.5 SCU.
- A standard triage flow that enriches 3–5 indicators and executes 10–15 KQL hunting skills averages ~0.6–1.0 SCU.
- A full investigation spanning 20+ hunting skills across endpoint, identity, email, and cloud-app telemetry reaches ~1.0–1.5 SCU.
- Extended hunts over large time windows may add ~0.2 SCU per additional 1 GB of Defender Advanced Hunting log data queried beyond the default 24-hour window.
SCU consumption scales with the number of cross-EDR API calls, Microsoft Threat Intelligence enrichments, and KQL hunting skills invoked during each run.
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
1 listedSources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






