How to Fix Your Alert Backlog with Intezer and Microsoft

May 1, 2025

Written by

Shaul Holtzman

Security teams today are grappling with an increasingly unsustainable challenge: there are too many alerts generated by modern detection tools, resulting in backlogs, burnout, and missed threats. In our recent webinar, "Fixing the Alert Backlog with Intezer and Microsoft," we showcased how Intezer's Autonomous SOC Platform, in deep partnership with Microsoft, helps security teams tackle this problem head-on.

👉 You can watch the full webinar on demand here.

Why Alert Triage Is Broken and How to Fix It

Detection and response have evolved. With tools like Microsoft Defender and Defender XDR, identifying suspicious activity is extensively automated. Response, too, has become easier to trigger through integrated SOAR platforms. But how can we bridge the gap between detection and response? That's where the bottleneck truly lies—the investigation phase—and has for some time.

Most security teams only have time to investigate a fraction of detections. They have to brutally prioritize, focusing on the high-severity alerts and leaving countless low-severity ones unchecked. This isn’t because security teams are negligent. Traditional, manual triage methods simply don’t scale.

➡️ See why our CEO, Itai Tevet, says cybercriminals aren't trying to evade detection; they're aiming to be ignored.

Intezer's AI SOC solution can step in at the investigation stage, mimicking a human SOC analyst workflow—if that analyst had infinite time—to collect context, extract evidence, run deep analysis on files, command lines, memory artifacts, and more. Our platform then automatically classifies each case and recommends appropriate actions or closes it out as benign, ensuring every alert, whether low or high severity, is thoroughly investigated.

The result? About 96% of alerts are handled automatically, with only 4% of critical alerts escalated to analysts. This significantly reduces wasted time, ensures attention is reserved for truly urgent threats, and gives the team peace of mind knowing no threats are inadvertently overlooked.

Microsoft + Intezer: Your Questions Answered

Intezer can seamlessly integrate across Microsoft’s security ecosystem. Through connections with Microsoft Defender for Endpoint, Microsoft Defender XDR, and Microsoft Sentinel, Intezer can ingest a wide variety of alert types, ranging from identity-based anomalies to endpoint infections to reported phishing emails.

During the webinar, we received several great questions about how Intezer works with Microsoft's security suite, how quickly you can see results, and how we complement existing tools and workflows. Here are the top three questions we addressed:

1. How does Intezer compare to Microsoft Copilot?

Most tools today have AI assistants or copilot capabilities, which are helpful when security teams need to generate different threat-hunting queries. That's also the case with Microsoft Copilot. While it's a helpful AI assistant, it requires user prompts. It doesn't automate triage, but it can help security teams out as they conduct investigations themselves.

Intezer, on the other hand, is built to take actions autonomously. It doesn’t require prompts, handling routine investigations, and only involves humans when absolutely necessary. This can provide security teams with a powerful combination in which they can take escalated alerts from Intezer and further investigate them using Microsoft Copilot.

2. Can Intezer work alongside my existing SOAR workflows?

Yes. Many security teams try to build investigation workflows in SOAR, but SOAR platforms simply aren’t designed to conduct deep investigations. Building and maintaining those workflows requires extensive logic, integrations, and third-party tools. This often becomes a time-consuming, fragile process, and workflows can break easily. Building anything from scratch is laborious, and the same goes for SOAR playbooks.

Intezer can connect to SOARs at the escalation or notification stage, providing a prioritized and contextualized alert with comprehensive response recommendations. We pass along structured results, full context, and response recommendations so your SOAR can take action or notify the right individuals. This approach supercharges your existing workflows with the depth, precision, and automation they were never designed to deliver.

➡️ Learn more about how Intezer can complement your SOAR.

3. How quickly can we start seeing results?

Whether ingesting alerts directly from Microsoft Defender or receiving logs through Microsoft Defender XDR, Intezer doesn't require a lengthy tuning or “learning” phase for most detection types. Some tuning and adjustments might be required for tools such as Microsoft Sentinel, but that's usually completed within a week or two. In many cases, organizations start seeing value from day one.

We also understand that every environment is different. What might be unauthorized access in one organization could be legitimate admin activity in another. That's why Intezer enables organizations to customize their results. We support adding logic and intelligence specific to your environment and use customer feedback to further tune outcomes over time. The result is a tailored experience that aligns with your team's expectations and operational context.

We often hear how simple the integration process is, with one user sharing, “Wow, it's just as easy as it says on your website.” That's music to our ears and a quick time to value for your team.

Learn More About Our Microsoft Partnership

Intezer is proud to have an Enterprise Agreement with Microsoft, making us a strategic partner with deep integrations that enhance Microsoft’s security capabilities. If you’re ready to free your team from the alert avalanche and move toward a more autonomous future, we’d love to show you how. Read more about our partnership or reach out to connect with our team.

👉 You can also watch the full on-demand webinar to see for yourself how easy it is to integrate Intezer with your Microsoft security tools.

Shaul Holtzman

Shaul is the Senior Director of Solutions Engineering at Intezer. He has over a decade of experience in cybersecurity technologies and methodologies, with background in malware analysis, forensics and incident response.

In this article

Share article

How to Fix Your Alert Backlog with Intezer and Microsoft

AI SOC

AI

Company News

5 minutes

Loop engineering comes to the SOC: Introducing the Intezer Org Brain

Organizational context in an AI SOC is table stakes. Org Brain is very different. It learns, it recalls, it fetches what it's missing, and it gets sharper with every alert it touches, all autonomously.

Detection Engineering

AI SOC

8 minutes

Detection engineering in the AI era

AI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short.

AI SOC

CISO

Company News

Introducing Custom Agents: Automate your SOC, your way

Add your own agents and automations on top of the ones Intezer runs out of the box, take more of the manual work off your analysts, and tailor AI SOC to the way your team actually operates.