◆ Cyber Security Operations · Enterprise Platform

Agentic Security Operations Platform

An identity-first, fully-audited automation platform that detects, investigates and responds across the Microsoft security estate — every action authenticated by Microsoft Entra, every action recorded before it runs, with no shared secrets anywhere in the system.

🛡️ Entra-gated — every call carries a verified identity token
🧾 Audit-first — logged before execution, aborts on failure
🔑 Zero shared secrets — access governed by group & role
🎯 Least privilege — scoped managed identity & network isolation
🎛️
✦ Meet the AI SOC Operations Manager

This team is powered by Artificial Intelligence

The Security Operations team is driven by an autonomous AI Operations Manager. It orchestrates the entire platform through on-demand model picking from Microsoft AI Foundry — selecting the right reasoning model for each task — using opencode as its agentic harness, and runs continuously across both a local operator workstation and a dedicated operations server for 24/7 unattended operation.

🧠 Microsoft AI Foundry · on-demand model picking
⚙️ opencode agentic harness
💻 Runs on localhost + dedicated ops server
🤖 Specialised subagents & MCP tools

Capability Building Blocks

The business value the platform delivers — each block is a self-contained capability backed by automated services.

🚨

Threat Detection & Response

Detect · Investigate · Respond
Turns raw Sentinel alerts into investigated, documented incidents — automatically and within minutes.
Automated alert triage & entity extraction True/false-positive verdict with 90-day recurrence check Advanced hunting across the Defender estate Threat-intelligence context on every IOC
SentinelDefender XDRThreat Intel
🛠️

Vulnerability & Reporting

Find · Prioritise · Track
Continuous visibility of weaknesses, with SLA-aware lifecycle tracking and reporting.
Daily CVE inventory per device + delta Severity, CVSS & remediation aging SLA & lifecycle KPI reporting Per-device & per-CVE remediation tracking OT vulnerabilities Pending
Defender VMKPIs & SLA
👤

Identity & Access Governance

Know · Monitor · Control
A daily, queryable picture of who has access to what — and who holds the keys to the kingdom.
Full identity inventory & manager hierarchy Privileged-role monitoring (permanent & PIM) Sign-in & risk event analysis Group-membership change detection CyberArk managed identities Pending
Entra IDPIMSign-in Logs
🗂️

Asset & Estate Visibility

Inventory · Health · Risk
An always-current map of endpoints, devices and cloud resources and their security health.
Endpoint inventory with health & risk Entra device inventory & ownership Cloud resource inventory (15+ types) MDE sensor coverage & estate governance Email phishing / malware analysis OT, AWS, legacy domains Pending
Defender for EndpointAzure / Arc
🎫

SecOps Automation & ITSM

Orchestrate · Document · Close
Removes manual ticket toil — incidents are created, enriched and tracked end-to-end.
Automated ServiceNow incident lifecycle Work-note documentation & closure codes CMDB CI search & asset tagging Dual-tenant ITSM support
ServiceNow ITSMCMDB
📊

Reporting & Executive Insight

Summarise · Publish · Inform
Translates operational telemetry into board-ready dashboards and analyst notifications.
Weekly security posture dashboard Identity-gated private reports portal Azure subscription cost analysis & reports On-demand investigation reports
Reports PortalOutlook 365
📚

Knowledge & Compliance

Document · Govern · Evidence
Keeps the SOC's knowledge base in sync and produces an immutable evidence trail.
SharePoint SOP & playbook sync ISMS & assurance documentation Tamper-evident audit log of every action Saved query & detection library
SharePointAudit Trail

TISAX & Audit Assurance

Assess · Evidence · Attest
An on-demand TISAX expert grounded in the organisation's live evidence set and the ENX ISA catalogue.
TISAX control-point Q&A (domains 1, 4, 5, 8) Audit-evidence lookup from synced HQ pack Central vs Site-Level responsibility mapping ENX ISA framework & control-requirement guidance
TISAX / ENX ISAEvidence Pack
🔭

Recon & Exposure Testing

Probe · Validate · Verify
Active and passive reconnaissance to validate exposure and investigate phishing.
Port & service scanning Web / TLS / email fingerprinting Domain & IP reputation checks Phishing domain investigation
Scan EngineDNSBL / TI
🌐

Attack Surface Management

Discover · Monitor · Reduce
A continuously-mapped view of everything the organisation exposes to the internet.
EASM external attack-surface discovery & monitoring Domain & IP reputation tracking DNS health & dangling-record detection Internet-facing port & service management
Defender EASMExternal DNSReputation
Pending
🧱

Network Security

Inspect · Segment · Enforce
Unified visibility and control across the secure-edge and firewall estate.
Zscaler ZIA / ZPA traffic & policy visibility Palo Alto firewall log & rule analysis Egress / web-proxy & URL category insight Segmentation & policy drift detection
ZscalerPalo Alto
Pending
⚔️

Incident Management

Respond · Contain · Eradicate
Active response actions that move beyond investigation into containment and remediation.
Always Human-in-the-Loop approach Automated response & containment actions Blocking of IPs, domains & file hashes File acquisition & removal from endpoints Email quarantine & device isolation
Defender XDRResponse

Operating Scale & Outcomes

What the platform governs and produces, every day, without manual effort.

~10.4K
Identities inventoried & governed daily
~1.6K
Endpoints with health & vuln tracking
18
High-risk privileged roles monitored
~3.2K
Entra devices inventoried
100%
Operations authenticated & audited
24/7
Autonomous detection & response

From Alert to Resolution — Automated

A representative end-to-end flow the platform runs on its own, real-time.

1
🚨
Alert Fires
Sentinel analytics rule raises an alert / incident
2
🔍
Auto-Investigate
Entities extracted; context queried from the workspace
3
🧩
Enrich
Identity, device risk, hunting, reputation & WHOIS
4
🎫
Enrich Incident
SIEM incident enriched and suggested action shown
5
📝
Document
Builds an environment knowledge over time
6
📧
Notify
Analyst is empowered by AI automatic analysis and remediation
1

Identity & Access Plane

Microsoft Entra is the single authorization plane. Callers present a token; app roles decide what they can invoke.

Who can act
👥

AS2 Operators

Interactive · az login
  • SOC operators group grants the Function.Invoke app role
  • Entra SSO, MFA, Conditional Access & Azure RBAC on the session
  • Access is revoked by removing group membership
🤖

Automation Identity

Managed Identity
  • Scoped user-assigned managed identity
  • Holds the Function.Invoke app role
  • Attached to compute & the operations host
📊

Reports Readers

Portal SSO
  • Report readers group grants the Report.Read app role
  • Private storage is served only through the reports Function
  • No public containers, SAS links or shareable tokens
🛡️

Microsoft Entra — Easy Auth Gates

AS2 audience + reports audience
  • AS2 requires the Function invocation app role
  • Reports require the portal read app role
  • Disable the Enterprise App to cut access at the audience
authenticated request
2

Intelligent Automation Core

The reasoning engine and tooling that decides what to do and calls the platform services.

The brain
🧠
Agentic Reasoning Engine
Operator laptop + ops VM · goal-driven AI agents · specialised subagents · MCP tools + typed Python wrappers · shared endpoint resolver + token broker
Resolves endpoints centrally Acquires Entra bearer per call Audits before every action Plain endpoint map, no secret URLs
🧾 MANDATORY AUDIT GATE — every audited operation writes a server-side audit record before execution · aborts on failure
invoke
3

Secure Function Gateway

A Python function app — the Entra-gated front door. Every capability is an HTTP endpoint or a scheduled job.

Compute · Easy Auth
Linux Elastic-Premium function app · VNet-integrated with a fixed corporate egress IP · one identity, one audience, one role. Server-side audit gate on every audited route.
/api/auditMandatory audit gate → log table
/api/la-queryLog Analytics KQL workspace query
/api/defender-queryDefender Advanced Hunting
/api/threat-intelGraph threat-intel articles
/api/entra-identityLive identity lookups
/api/entra-deviceLive device lookups
/api/privroles-queryPrivileged-role queries
/api/mde-machinesEndpoint machine inventory
/api/az-queryAzure Resource Graph / ARM
/api/az-vmruncommandGoverned VM command execution
/api/sentinel-incidentsSentinel incident ops
/api/sn-*ServiceNow incident & CMDB ops
timer functionsDaily inventory, exposure & vulnerability ingestion
/api/connector/{op}Entra-gated proxy → the network-isolated managed-connector flows (SharePoint & Outlook). The connector URLs & signatures live only in Key Vault and are read server-side; callers never see them.
proxied · from corporate egress only
4

Network-Isolated Connector Flows

Managed-connector integrations (SharePoint, Outlook) kept for their authenticate-once experience — but locked down.

Managed connectors
SP
List Folder
SP
Download
SP
Upload
SP
Create Folder
SP
Delete File
SP
Delete Folder
🔒 Dual gate — AS2 authorises the caller with the Function invocation app role, then the connector trigger accepts only the platform's fixed corporate egress IPs plus the server-held signature. A leaked signature is useless from anywhere else.
query & act on
5

Connected Microsoft & External Systems

The sources of truth the platform reads from and acts upon.

◈ Microsoft Sentinel
Log Analytics workspace
KQL · curated telemetry · DCR ingestion
Incidents & alerts
SLA tracking · entities · comments
Saved detection library
Reusable hunting & reporting queries
🛡 Microsoft Defender
Defender for Endpoint
Machine inventory · health · risk
Vulnerability & EASM
CVE dump + delta · external attack surface
Advanced hunting & XDR
All Defender tables · email threats
👤 Entra ID & Graph
Identity, device & Intune
Users · managers · groups · devices · policy reach
Privileged access
Permanent · PIM-active · eligible
Sign-in & risk telemetry
Sign-in / audit logs · risk events
☁ Azure Platform
Resource Manager / Graph
VMs · Arc · DBs · edge origins · public IPs · IAM
Key Vault & Cost Mgmt
Secrets / signatures · subscription spend
Scan host
Port / web / TLS recon engine
🌐 External Systems
AWS commercial estate
Accounts · compute · storage · DNS · ingress
ServiceNow ITSM
Dual-tenant · incidents · CMDB
SharePoint & Outlook 365
Knowledge base · TISAX evidence · email
DNS & threat-intel feeds
External DNS · reputation sources
ingested into the data platform
6

Security Data Platform

Project-owned ingestion endpoint feeding curated telemetry streams — the analytical backbone.

Curated telemetry
Server-side audit trail
Caller identity · action · route · curated arguments
every action
Endpoint posture
Device OS, health, onboarding, risk & exposure
daily
Vulnerability baseline
All device-CVE findings with severity, CVSS & remediation metadata
daily
Vulnerability movement
New, fixed and changed findings for lifecycle and SLA tracking
daily
Identity inventory
Users, accounts, groups, manager hierarchy and ownership context
daily
Entra device registry
Registered devices with ownership and transitive group membership
daily
Privileged access
Permanent, active and eligible assignments across high-risk roles
daily
Azure exposure posture
Normalized resource inventory with ownership, type and exposure attributes
daily
Azure raw resource graph
Full-fidelity cloud-resource snapshot for deep dives and reprocessing
daily
Azure compute estate
Virtual machines and scale sets with power state, OS and identity links
daily
Arc-connected estate
Hybrid machines with connectivity, extension and onboarding context
daily
Front Door origins
Internet-facing application origins behind first-party edge services
daily
External attack surface
Discovered assets, ports, services, TLS and policy observations
daily
Authoritative external DNS
Public zone records and day-over-day DNS change tracking
daily
Dangling DNS exposure
Potential orphaned cloud targets and takeover-risk candidates
daily
AWS raw inventory
Full commercial cloud snapshot for traceability and replay
daily
AWS account map
Account identity, ownership and organizational metadata
daily
AWS compute
Instances, state, platform, networking and exposure attributes
daily
AWS storage
Object-storage buckets, region, policy and public-access posture
daily
AWS load balancing
Ingress endpoints, schemes, listeners and target relationships
daily
AWS databases
Managed data services with engine, encryption and exposure posture
daily
AWS CDN
Edge distributions, aliases, origins and viewer security settings
daily
AWS API gateways
Published API front doors, stages, endpoints and public reachability
daily
AWS network controls
Security-group rules and internet exposure paths
daily
AWS hosted zones
Public DNS zones, ownership and delegation metadata
daily
AWS DNS records
Cloud-hosted public records for attack-surface correlation
daily
Intune device state
Managed-device compliance, ownership and platform posture
daily
Intune policy reach
Which devices are reached by configuration-policy assignments
daily
Intune policy settings
Flattened configuration settings for policy drift and control review
daily
ServiceNow CMDB
Configuration items, class coverage and operational ownership context
daily
consumed by
7

Experience & Outputs

Where analysts and management consume the results — all identity-gated, none publicly exposed.

🔐 Private Reports Portal
Single-sign-on web portal serving dashboards & investigation reports from private storage over the corporate private backbone. Unguessable per-report links; no public access, no shareable tokens.
📊 Dashboards & Cost Reports
Auto-generated weekly posture dashboard (alerts, incidents, ITSM, vulnerabilities, exposure, platform usage) plus Azure subscription cost-analysis reports — published to the portal.
📧 Email Reports & Alerts
HTML triage notifications & digests via Outlook 365. Restricted to corporate-domain recipients only.
🎫 ServiceNow, KB & TISAX
Enriched incidents & CMDB updates in ServiceNow, a continuously synced SharePoint SOP / playbook / ISMS library, and a TISAX audit-evidence assistant grounded in the live HQ evidence pack.
Agentic Security Operations Platform · Azure subscription · region redacted · updated June 2026