Loop engineering comes to the SOC: Introducing the Intezer Org Brain

Itai Tevet

Last month (June), one idea took over the AI conversation: stop prompting your agent, and start designing the loop that prompts it. Boris Cherny, the creator of Claude Code, said he doesn’t prompt Claude anymore. Loops do. Within days the industry had a name for it: loop engineering.

https://x.com/PawelHuryn/status/2069363303952818474

Coding agents got there first. But the loop that matters most for security teams doesn’t run in a code editor. It runs in your SOC, where the real question is what your AI analyst remembers after each investigation.

Think about the best analyst on your team. Three years in, they just know things. That CrowdStrike alert on the build servers fires every time DevOps pushes a release. Dave from finance logs in from Portugal, and it’s fine. None of it is written down anywhere. And the day they resign, all of it walks out the door.

We built Org Brain so it doesn’t.

Context was table stakes. This is something else.

Let’s be clear about what we’re not claiming. Organizational context in an AI SOC is table stakes. Every serious AI SOC product has some version of it, and Intezer has used org context in investigations for years. If a vendor is still pitching “we understand your environment” as the headline, that’s a 2024 announcement.

Org Brain is different in kind, not degree. It’s a memory system, not a context store. It doesn’t just hold what someone loaded into it during onboarding. It learns, it recalls, it fetches what it’s missing, and it gets sharper with every alert it touches, all autonomously. Here’s how.

Two memory systems, one brain

Today we’re releasing Org Brain, built from two main components, modeled on the two kinds of memory a real SOC team runs on: how you work, and who you are.

Muscle memory — the how (procedural knowledge)

Every SOC develops its own way of doing things, mostly without documenting it. Which query an analyst runs when an identity alert hits a domain controller. Which detections get closed on sight because they’ve been benign four hundred times in a row. What the tuning history says about that noisy DLP rule. Where an investigation goes next after a suspicious login, and where it doesn’t bother going. This knowledge lives in your analysts’ hands. For Intezer customers, it has also lived in the Tuning Center, as memory you had to create yourself. Org Brain now captures it autonomously and applies it, so an investigation at 3am runs the way your best analyst would run it at 10am.

Self-awareness — the who (declarative knowledge)

Your assets and what they’re for. Your users, their roles, what their normal login behavior looks like. The tickets they’ve opened before. And one layer deeper: your data itself. How your SIEM is structured, which fields exist, what the columns actually mean, where the truth about an entity lives. This is declarative knowledge. The facts an investigation stands on. An AI agent that doesn’t know your schema is a tourist with a phrasebook. One that does can ask your environment the right question, in your environment’s own language, mid-investigation.

Put together, this is the difference between an AI that has context and an AI that knows your organization. Context answers “what is this server?” Org Brain answers “what is this server, is that login normal for this user, and what would our team do about it?”

Engineered as a loop

Org Brain is built the way loop engineering prescribes. The agent alone isn’t the system; the loop around it is. Act, verify, learn, repeat. Org Brain runs that loop across your SOC’s past, present, and future.

It learns from your past. A brain that starts empty would take months to become useful. Org Brain doesn’t start empty. Intezer can now ingest the history your SOC already has: the cases and tickets sitting in your case management tool, years of resolutions, escalations, and quiet decisions to close without action. That history becomes muscle memory and self-awareness before the first new alert arrives.

It fetches your present. When memory isn’t enough, Org Brain doesn’t guess. It knows what it knows, and it knows where to look. Mid-investigation, it pulls live context from your environment on demand, just in time, so a verdict rests on what’s true right now, not on what was true when someone last synced a database or refreshed a graph. We’ve been investing in developing more integrations to fetch just-in-time organizational context, and customers can expect an increasingly rich context ecosystem.

It learns for your future. After every investigation, autonomous or alongside your analysts, the loop closes. Following frontier AI system design, a superior model, what AI labs call an auditor, or critic, reviews what happened. What the investigation found, what your analysts corrected, which path led to the verdict. The conclusions are written back into the brain. A tuning decision or an analyst’s feedback becomes muscle memory. A newly seen asset becomes self-awareness. The next investigation starts smarter than the last one finished.

Illustration about how Loop Engineering looks when using a superior model for auditing and planning. https://x.com/ClaudeDevs/status/2074606058128224365

What this means for Intezer customers

Org Brain is rolling out gradually, and parts of it are already working for you. Some capabilities live in the backend. You won’t see a new button immediately, but you’ll notice richer context in results and more accurate verdicts. When Org Brain appears in your menu bar, you’re officially in the rollout.

Some of it will also look familiar. Alert tuning, feedback, and custom queries are now part of Org Brain, which means every tuning decision and correction your team has made was, in effect, training it before it had a name. More capabilities will land under the Org Brain umbrella in the coming months.

A superior way to run an AI SOC

Context is critical to every investigation. That was true before AI entered the SOC, and it’s table stakes now. No AI analyst should be making verdicts blind to the environment it works in. But holding context and understanding an organization are not the same thing, and the gap between them shows up exactly where it hurts: in accuracy, in speed, in how complete an investigation really is.

Org Brain is our answer to that gap, and it reflects how we build: staying at the frontier of AI development and turning what’s proven there into outcomes for security teams. A brain that knows how your SOC works and who your organization is. One that learns from your past, fetches your present just in time, and gets smarter with every investigation.

If you want to see what your SOC looks like with a brain, book a demo.

Itai Tevet

Co-founder and CEO of Intezer, Itai is on a mission to revolutionize how SOC teams investigate and respond to cybersecurity incidents. He previously led the cyber incident response team for one of the world’s most targeted organizations. Itai combines his expertise in AI and security to advise security leaders at Fortune 500 companies on how to defend against threat actors in the AI era.

Recommended Blogs
8MIN READ

Detection engineering in the AI era

AI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short.
7MIN READ

Introducing Custom Agents: Automate your SOC, your way

Add your own agents and automations on top of the ones Intezer runs out of the box, take more of the manual work off your analysts, and tailor AI SOC to the way your team actually operates.
11MIN READ

The other half of the AI SOC: Intezer, now inside your AI workspace

Your team already lives in, Claude, Codex, Cursor, etc. Discover how to transform them into true security workspaces.