SOC Optimization

Forty five minutes of tab switching,
or one enriched alert.

Your analysts already have the alert. What they do not have is the context, so they assemble it by hand from five tools, forty times a shift.

1The alert arrives
src_iphitsownerverdict45.83.220.11142Stark Industriesevidenced104.18.32.72,910Cloudflare, Inc.clean91.242.229.488Bulletproof LLCevidencedalready populated, before anyone opens the ticket
2With its evidence
passive DNS0.34certificate reuse0.28feed: abuse.ch0.22ASN reputation0.16verdictmalicious 0.91
3So it can be cleared
CLEAREDowner: Microsoft CorporationAS8075, known goodno evidence in 190+ feedsevery field above is a queryable graph edge, not a score

Why the current stack cannot answer it.

Triage is not hard because analysts are slow. It is hard because the alert arrives with an address and nothing else, and the five things you need to know about that address live in five products that do not know about each other.

So the analyst does the join by hand, then does it thirty nine more times. The interesting one looks exactly like the boring ones until somebody happens to look closely.

Cost
TimeTens of minutes per indicator that warrants a real look
InconsistencyTwo analysts, two verdicts, no audit trail for either
False positivesNothing in the stack can clear a host, only fail to flag it
Missed pivotsRelated infrastructure never gets looked at, because looking costs too much

The context, already on the alert.

src_iphitsownerverdict45.83.220.11142Stark Industriesevidenced104.18.32.72,910Cloudflare, Inc.clean91.242.229.488Bulletproof LLCevidencedindex=firewall | whisper lookup src_ip

Enrichment in place

One search command in Splunk, or a connector in Sentinel or OpenCTI. No new tool for anyone to remember.

passive DNS0.34certificate reuse0.28feed: abuse.ch0.22ASN reputation0.16verdictmalicious 0.91

A verdict with its evidence

Sources, weights, first and last seen, and the arithmetic. Two analysts reach the same answer.

CLEAREDowner: Microsoft CorporationAS8075, on your known-good listno evidence across 190+ feedsevery field above is a queryable graph edge, not a score

Clearing, not just flagging

Known good allowlists and ownership resolution mean a host can be positively cleared. That is where false positive reduction actually comes from.

45.83.220.11shared TLS certco-hosted domainsame registrantsibling /24one query, four pivots, no tab switching

One pivot to the cluster

When it is real, one query returns shared certificates, co-hosted domains, registrant and siblings.

12,480indicators checked in one callcleanunknownevidenced

Bulk triage

Check thousands of indicators in one call. A backlog becomes a batch job rather than a rota.

Eight seconds, not forty five minutes.

Three addresses, classified with a full evidence trail, in eight seconds. The same three took forty five minutes by hand.

The second number, which is the one a SOC manager actually cares about

The real effect is not analyst hours saved. It is that pivots start happening. When expanding an indicator costs one query instead of twenty minutes, analysts expand indicators. That moves mean time to detect, and it does not show up in a time-saving calculation.

Splunk, Sentinel, OpenCTI, SOAR and XSOAR, Wazuh, n8n, any MCP client.

Put it in front
of your worst queue.