Agentic SOC
What is Agentic SOC
Limited Availability
Agentic SOC is available to a limited set of US-based customers as part of a Limited Availability release. If you don’t see the Signals or Alerts pages described in this documentation, your organization hasn’t yet been migrated to Agentic SOC. Your existing Alerts and Investigations experience remains unchanged until migration.
Agentic SOC is Rapid7’s autonomous security operations center capability within SIEM (InsightIDR). It introduces an AI-driven investigation layer that works alongside your Managed Detection and Response (MDR) team to accelerate threat investigation, reduce manual effort, and surface clearer answers faster.
When Agentic SOC is enabled for your organization, it changes how detection outputs are structured and how investigation work is organized:
- Detection rules now produce Signals: atomic, static records of each detection event.
- AI automatically groups Signals into Alerts, which are consolidated work objects that represent a coherent security incident or investigation unit.
- For supported integrations, the AI agent autonomously investigates each Alert end-to-end, running a playbook, compiling evidence, and issuing a determination before a human analyst ever touches it.
- For all other integrations, the engine still groups Signals into Alerts and extracts key entities, giving your team correlated context in a single place, even without full AI investigation.
The new object model
Agentic SOC introduces a clearer hierarchy for how security data flows through SIEM (InsightIDR):
Logs → Detection Rules → Signals → Alerts
Each stage represents:
- Logs - Raw security data collected from endpoints, cloud, identity, network, and third-party sources.
- Detection Rules - Evaluate logs and, when a match is found, produce a Signal.
- Signals - The output of a detection rule: a static, immutable record of what fired and why. Signals were previously called Alerts in SIEM (InsightIDR).
- Alerts - One or more related Signals that the AI clustering engine groups together into a single investigation unit. Alerts are the primary object your team triages.
Autonomous investigation
For three supported integration sources, the Agentic SOC agent conducts a full autonomous investigation on every Alert it receives:
- Microsoft Cloud
- CrowdStrike Falcon
- SentinelOne
For these sources, the AI agent runs a dynamically generated investigation playbook, querying telemetry, identifying key entities, assessing impact, and producing an Investigation Summary and determination. The agent can close Alerts autonomously when the evidence is conclusive.
The engine still groups Signals from all other sources into Alerts with entity extraction and contextual data, but these Alerts don’t receive a full AI investigation. Your MDR team reviews these Alerts using the evidence and clustering context provided.
Key capabilities at a glance
Agentic SOC includes these key capabilities:
- Signals page - View and search all Signals generated by detection rules in your environment.
- Alerts page - Your primary triage queue. Each Alert is a cluster of one or more related Signals.
- AI Investigation Summary - A human-readable narrative of the investigation findings and determination.
- Playbook - The complete list of investigation queries the AI ran, including the results of each query.
- Ask AI - A conversational AI assistant scoped to the current investigation. Ask a question and get a context-aware answer.
- Human and AI determination - Both an AI determination and a human analyst determination can coexist on an Alert, supporting human-in-the-loop review.
- Response actions - Run containment actions (quarantine host, suspend user) directly from the Alert for supported integrations.
Organizations not on Agentic SOC
If your organization hasn’t been migrated to Agentic SOC, your experience is unchanged — Alerts and Investigations work exactly as they did before. The Signals page and the new Alerts experience described in this documentation are visible only to organizations enabled for Agentic SOC.