Intezer Workflows. The AI SOC is now complete

August 19, 2026

Written by

Zev Schonberg

Over the past year we shipped the pieces of a complete AI SOC one by one. Forensic-depth triage and investigation across 100% of alerts. Cases that correlate related alerts instead of leaving them as isolated tickets. Custom Agents that automate the reporting, tuning, and handoff work that exists in every investigation. Closed-loop detection engineering that turns triage verdicts into better coverage.

While Intezer always provided auto-closing of false positives and full response capabilities (whether via our solution engineers building response actions or through a SOAR integration), our customer wanted self-serve, custom response capabilities, native to our AI SOC platform.

Today we have delivered that with Intezer Workflows, the automation and response builder native to the Intezer AI SOC. You can now build custom workflows directly in the platform, instead of owning a separate SOAR system. Early access is available for selected customers, with general availability later this quarter.

Custom response, built inside the platform

The Intezer operating model is simple. AI executes, humans supervise. The platform triages and investigates every alert at forensic depth, resolves 98% of them autonomously, and escalates fewer than 2% for human review.

Workflows puts what happens next in your hands and they behave the way you'd expect from a mature automation layer, with one difference that matters. They are wired directly into the investigation itself. A forensic verdict, a case event, a schedule, or a webhook can fire a workflow the moment it lands, with the full context of the investigation behind it, no API glue or polling required. Actions run across your stack, closing the alert in the source, isolating the host, updating the ticket, pinging the owning analyst, with conditional routing wherever your logic branches. And because the workflow lives where the investigation lives, its actions surface back into the case and alert it touched, with every run logged step by step for audit and troubleshooting.

The shift from the standalone SOAR version to Intezer’s end-to-end triage to response, is context. Your automation no longer starts from a webhook payload it has to re-enrich. It starts from a verdict that already carries the evidence, data and organizational context.

The response logic that used to justify a standalone SOAR now lives where your investigations already happen, and it is yours to build and modify.

Building a workflow is a conversation

You do not need to build workflows by hand. Describe what you want in plain language and it is built for you through Intezer's MCP. You can then review and refine it visually in the platform. For example you can tell it to close false positives back in your SIEM and notify the relevant analyst in Slack, and the workflow appears in the builder, ready to test and turn on. 

Workflow building was an engineering project in the SOAR era. It is a conversation now.

What you can build on day one

Here are some common examples our customers are using.

Containment workflow

Response is where it gets interesting. Take a common containment scenario. An alert for exposed credentials escalates, and the workflow kicks in immediately. It notifies the team on Slack, opens a Jira ticket for the dev team, rotates the compromised secret, and then verifies the rotation actually took effect before closing the loop. Similar workflows can be used to drive host isolation, IOC blocking, disabling an account, and other forms of remediation.

Case escalation workflow

When a case is created, an escalation workflow evaluates its disposition immediately. False positives are closed straight back in the source console with no analyst time spent. Anything escalated pages the on-call through PagerDuty and reaches out to the affected user to verify the activity. If the user confirms it was them, the case closes as a false positive; if they don't respond or deny it, the workflow blocks the account on the spot. Either way, it finishes by generating an incident report with timeline, scope, and root cause, attached to the case for the record.

Beyond these examples, MSSPs using Intezer can now run customer communication and per-tenant routing as workflows instead of manual process.

Every one of these previously required a separate SOAR, an engineering project, or a request to our team. Now they take minutes to build, and they run where your investigations already live.

Full coverage makes AI-speed response meaningful

Attackers are already operating at AI speed. As organizations prepare for the next generation of autonomous attacks and "Mythos-ready" adversaries, the challenge is responding at the same machine scale and machine speed.

That is only possible when automation is built on complete visibility.

Data from the AI SOC Report 2026, based on 25 million alerts across our customer base, shows why coverage has to come before automation. Nearly 1% of real incidents traced back to alerts classified at the lowest severity levels. At average enterprise volume, that's roughly 54 genuine threats per year, hidden where most teams never look. More than 60% of alerts are never reviewed by SOC or MDR teams, and more than half of the endpoints we confirmed as compromised through live memory forensics had already been marked as mitigated by the EDR.

Automation built on partial coverage simply accelerates existing blind spots. Automation built on complete coverage eliminates them. When every alert is investigated with forensic depth, the low-severity signal that would otherwise be ignored becomes a verified finding and the appropriate response can execute automatically.

This is why response automation is becoming a foundational requirement for AI-ready security operations. As attackers scale with AI, human-driven response cannot keep pace. Organizations investing in AI-readiness or preparing for the era of autonomous, AI-powered attacks, need security operations that can investigate every alert and execute every response at machine speed. Full coverage combined with automated response closes the loop, allowing defenders to match AI-scale attacks with AI-scale defense across the entire incident lifecycle.

Workflows and Custom Agents

For Intezer customers already using Custom Agents, a natural question comes up. When do you use a workflow and when do you use a Custom Agent?

Workflows are deterministic by design. Give one the same input and you get the same output, every time. That is the point. When you know exactly what should happen after a verdict, you should not need an AI to improvise it. Custom Agents are generative. They reason, and they handle open-ended jobs like summarizing an incident or hunting through historical data or even triggering a workflow. 

Some jobs need step-by-step precision, some need judgment, and many need both, which is why the two work together. Between them they cover everything post-triage, from reporting and tuning to closure and containment.

Your logic, your control

Every security team has logic that belongs to it alone. Escalation rules shaped by the org chart, response thresholds shaped by risk appetite, reporting formats shaped by who reads them. That’s why Workflows and Custom Agents exist so that logic stays yours to define, with full visibility into every run and full control on anything you build.

On the other hand, the deep investigation of a CrowdStrike or Sentinel alert, works at forensic depth out-of-the-box and keeps improving across millions of alerts. Your team's time goes to the automation only your organization can design, on top of an investigation engine that is constantly being optimized by Intezer.

Availability

Workflows is in early access today for existing customers, with general availability later this quarter. Like Custom Agents, it is part of the AI SOC platform rather than a separate product, because response belongs inside the loop that produced the verdict. Our customer success team will help teams migrate existing SOAR playbooks.

The AI SOC is complete. Every alert investigated at forensic depth, every verdict feeding detection, and now every response running in the same place. AI executes. Humans supervise. If you want to see the full loop live, join the early access program or book a demo.

Zev Schonberg

Zev Schonberg is a product marketing manager with years of experience in deep tech.

As a lead contributor at Intezer, Zev authors research-driven analysis and thought leadership that explores how modern security operations centers can better detect, investigate, and respond to threats at scale.

In this article

Share article

Related Articles

AI SOC

3 min

Analyst firm SACR recognizes Intezer in the AI SOC category

What makes an AI SOC trustworthy? SACR's 2026 research points to evidence, context and verified action. See how Intezer was evaluated.

Company News

4 min

Intezer Workflows. The AI SOC is now complete

Detect, triage, investigate, respond. The entire SOC lifecycle now runs in one platform with AI executing and humans supervising. 

CISO

CISO Playbook: Putting Claude to work in security operations

This playbook is for security leaders who know AI belongs in the SOC, but need a practical model for where it actually fits. It’s written for CISOs, SOC leaders, detection engineers, and security teams dealing with alert volume, manual triage, reporting drag, and pressure to justify AI investment.