Your analysts approve. Our agents do the rest.
CyberSentinal turns manual, multi-tenant Microsoft Sentinel and Defender XDR operations into an agentic SOC. Agents triage every incident, investigate across tenants with KQL, draft the response and notify the client. Your team keeps the final say.
Incidents · All tenants
Agents active| Severity | Incident | Agent verdict |
|---|---|---|
| High | Impossible travel → MFA fatigue | True positive · approve |
| Medium | Suspicious inbox forwarding rule | Investigating |
| Low | Sign-in from new country | Benign · closed |
| High | Defender: credential dumping on SRV-04 | Contained · isolated |
| Info | Mass file download · SharePoint | Benign · closed |
Multi-tenant Sentinel doesn't scale on analyst hours.
Each new tenant adds more alerts, more runbooks and more client emails. Most of that work is the same every time: pull sign-in logs, check the IP, check the device, close it or escalate it, then write it up.
Today Manual SOC
- Analysts switch between tenants one incident at a time
- The same enrichment KQL is rewritten for every alert
- Benign noise buries the incidents that matter
- Client notifications and SLA reports are written by hand
- Headcount grows in step with every tenant you sign
With CyberSentinal Agentic SOC
- One queue across every tenant, already triaged
- Agents run the investigation and attach their evidence
- Proven benign patterns close themselves, with a comment
- Client notifications are drafted, approved and sent through your PSA
- Analysts spend their time on decisions and threat hunting
Every tenant's Sentinel overview, in one place.
The views your analysts already know from Microsoft Sentinel, rolled up across every customer workspace, with a clear split between what the agents handled and what needed a person.
Overview
Incidents per day
Show as table
Incidents by tenant
MITRE ATT&CK tactics
Data connectors
- Microsoft Entra IDHealthy
- Microsoft Defender XDRHealthy
- Office 365Healthy
- Azure ActivityHealthy
- Syslog · ContosoDelayed 4h
A team of agents for every stage of the incident.
Each agent has one job, a narrow set of permissions and a written policy per tenant. Together they cover the incident from the first alert to the client report.
Triage agent
Picks up every new Sentinel and Defender incident, removes duplicates, links related alerts, sets the owner and ranks it by real risk.
Investigation agent
Writes and runs KQL across SigninLogs, AuditLogs, Defender tables and threat intel, then returns a verdict with the evidence attached.
Response agent
Prepares containment actions such as isolating a device, revoking sessions, disabling a user or blocking an IOC. Each action runs only if policy allows it or an analyst approves.
Communications agent
Writes the client notification in your house style and opens or updates the ticket in your PSA. It sends only after the incident is approved.
Multi-tenant control plane
Manages every customer workspace through Azure Lighthouse, with a runbook, autonomy level and SLA set per tenant.
Tuning & reporting agent
Finds analytics rules that keep producing benign alerts and proposes tuning changes. It also writes the monthly report for each client.
From alert to closed incident, step by step.
Agents do the repetitive work. Analysts step in where judgment is needed, and every step is recorded on the Sentinel incident.
Ingest
New incident in any tenant's Sentinel workspace
AgentEnrich
Entities, asset context, threat intel, history
AgentInvestigate
KQL across sign-ins, endpoints, mail and cloud
AgentVerdict
Benign, suspicious or true positive, with evidence
AgentApprove & act
Containment within policy, or sent to an analyst
Human gateNotify & learn
Client ticket, report and tuning feedback
AgentEvidence you can audit, not a black box.
Every verdict shows the queries the agent ran, what they returned and how it reached its conclusion. Analysts review the work in seconds instead of redoing it.
- Queries you can seeThe KQL is attached to the incident, ready to re-run in Sentinel.
- Your runbooksAgents follow your SOC procedures for each tenant, not a generic playbook.
- One-click decisionsApprove, edit or reject the proposed action from the incident or from Teams.
Impossible travel followed by MFA fatigue
Autonomy is earned per tenant, not switched on all at once.
Every tenant starts at level 1. The agent earns more autonomy one alert class at a time, once its accuracy has been measured on your own incidents.
Recommend
Agents investigate and suggest a verdict. Analysts make every decision.
Approve
Agents prepare the full response. One click from an analyst runs it.
Auto-close benign
Proven benign patterns close themselves with a documented comment.
Auto-respond
Pre-approved containment runs immediately, within limits you set.
Built for teams running Sentinel at scale.
MSSPs & MSPs
Take on more tenants without hiring a new analyst for each one, and give every client the same quality of response.
- One agent-triaged queue across every customer workspace
- Client-branded notifications and monthly reports
- PSA ticketing and SLA tracking per tenant
- Better margin on every tenant you manage
Enterprise SOCs
Give a small team round-the-clock coverage across subsidiaries and regions, without adding night shifts.
- 24/7 triage with escalation to on-call in Teams
- Consistent runbooks across business units
- Fewer benign alerts through continuous rule tuning
- Audit-ready evidence for every incident
Your data stays in your tenants.
An agent with access to dozens of tenants has to be locked down more tightly than any analyst. The platform is built on that assumption.
Start with a pilot. Scale by tenant.
Choose whether we run it for you or your team runs it. Pricing is per tenant, so cost follows the work.
30-day proof
- Agentic onboarding through Azure Lighthouse, no client-side deployment needed
- Agents run alongside your analysts at level 1
- Accuracy and time-saved report at day 30
Agentic MDR
- Agents plus CyberSentinal analysts on approvals
- 24/7 coverage with defined SLAs
- Client notifications and monthly reporting
- Rule tuning and detection engineering
Self-operated
- Full agent platform for your analysts
- Custom runbooks and autonomy policies
- PSA, Teams and white-label reporting
Common questions
Is CyberSentinal SOC 2 compliant?
Yes. CyberSentinal has a SOC 2 Type II report from an independent auditor covering the controls behind our platform and managed service. Ask us through the contact form and we will share the report under NDA.
How is this different from Microsoft Security Copilot?
Copilot helps one analyst understand one incident. CyberSentinal runs the whole SOC workflow across many tenants: per-client runbooks, approval gates, PSA ticketing, client notifications and SLA reporting. The two work together.
Do agents take actions without a human?
Only when you allow it. Every tenant starts at level 1 (recommend only). Auto-close and auto-respond are enabled one alert class at a time, after accuracy has been measured on your own incidents. You can drop back to level 1 at any time.
What access do you need?
A scoped Azure Lighthouse delegation to each tenant's Sentinel workspace. A pilot starts with read access plus incident comments. Response permissions are added only when a tenant moves to a higher level.
Does our log data leave our tenants?
Queries run inside each customer's own Log Analytics workspace. Only the investigation summary and the evidence needed for the verdict are attached to the incident. Client data is never used to train models.
Which ticketing systems do you support?
Zoho Desk, ConnectWise, HaloPSA and ServiceNow, plus email and Microsoft Teams. Other systems can be connected through webhooks or Logic Apps.
See it on your own incidents.
Tell us how many tenants you run and how your SOC works today. We'll reply within one business day with a pilot plan.
- 30-minute walkthroughA live demo on realistic multi-tenant Sentinel data.
- Read-only pilotAgents shadow your analysts. Nothing changes until you approve it.
- Measured resultsAccuracy, time saved and benign-closure rate, reported per tenant.
Or email info@cybersentinal.tech