Speakers

Itai Tevet

Co-founder and CEO of Intezer, Itai is on a mission to revolutionize how SOC teams investigate and respond to cybersecurity incidents. He previously led the cyber incident response team for one of the world's most targeted organizations. Itai combines his expertise in AI and security to advise security leaders at Fortune 500 companies on how to defend against threat actors in the AI era.

Lital Asher-Dotan

Lital Asher-Dotan is a four-time Chief Marketing Officer with extensive experience leading global marketing organizations for high-growth cybersecurity and enterprise technology companies. As CMO of Intezer, she drives the company’s global brand, demand generation, and go-to-market strategy, bringing a proven track record of scaling revenue, building high-performing teams, and positioning innovative security solutions for market leadership.

This 7th session of AI SOC Live "Where does Claude fit in the SOC?" was recorded live on August 19, 2026. Here is some of what was covered during that live session.

Where frontier AI agents fit inside the SOC

Security teams now have two very different ways to put AI to work. One is an autonomous AI SOC platform that triages every alert without a human in the loop. The other is an AI workspace like Claude, Codex or Cursor that an analyst drives one case at a time. In this session from AI SOC Live, Intezer CEO Itai Tevet and CMO Lital Asher-Dotan explain which jobs belong to each, using numbers from real deployments.

What actually matters when choosing an AI agent

The gap between Claude, Codex, Cursor and Windsurf turns out to be mostly negligible for security operations work. The variables that change outcomes are the context you feed the model, the tools it can reach, the guardrails around its actions, and how you control cost at volume.

The four stages of AI adoption in security teams

Itai walks through the four stages security organizations move through as AI moves from experiment to production. Most enterprises are still somewhere between stage one and stage two, running pilots and one-off investigations rather than continuous automated work.

Why triaging every alert through an LLM does not add up

An average organization generates roughly 450,000 alerts per year across EDR, SIEM and identity tools. Pushing all of them through Claude Sonnet for triage can reach about $2.5 million annually, and that figure is before correlation logic or analyst time. The session covers the tokenomics problem in detail and why model routing and cost control are engineering requirements rather than optimizations.

The two brain model for security operations

One brain runs autonomously and always on, handling triage, containment, response and detection engineering across the full alert volume. The second brain sits with the analyst and makes each escalated decision roughly 10x faster. In Intezer deployments, 98% of alerts are auto closed and 2% reach a human.

What to build yourself and what to buy

Build for the things only your organization has, meaning your custom alerts, your response actions and your business context. Rebuilding CrowdStrike or SentinelOne alert triage from scratch is wasted engineering. The session also explains why filtering alerts through a SOAR before they reach an LLM creates false negative risk and strips away the correlation context the model needs.

How MCP and the Org Brain tie the two sides together

MCP is the connective layer between an autonomous AI SOC platform and the AI workspace your analysts use. Lital demonstrates the Org Brain pulling live context from Workday, calendar, email and Slack to close out cases like impossible travel alerts that a pure telemetry view cannot resolve.

What happens to tier 1 analysts

The tier 1 function as traditionally defined is disappearing from most teams. The people are not. The role shifts toward supervision, tuning and risk reduction instead of ticket throughput.

Questions answered in this session

Should you connect Claude directly to your SIEM or EDR for triage?
Generally no. AI workspaces are strongest on a single case with a human driving. Continuous triage across tens of thousands of alerts per week needs production engineering for error handling, recovery, model routing and cost control.

- What is the right split between the two?
An autonomous AI SOC platform for always on triage, containment, response and detection engineering. An AI workspace for escalated cases that need business context and human judgment.

- Are tier 1 analysts going away?
The traditional tier 1 function is, on most teams. The job moves toward supervising automation, tuning detections and reducing risk.

- Do the differences between Claude, Codex and Cursor matter for SOC work?
Very little. Context, tool access, guardrails and cost control drive results far more than model choice.

Keep going

Read the CISO playbook to using Claude in the SOC for the implementation detail behind the session.

More webinars

webinar

AI SOC Live Episode 7: Where does Claude fit in the SOC?

Watch the recording — Itai Tevet and Lital Asher-Dotan on where AI platforms like Claude fit in the SOC.

webinar

AI SOC LIVE Episode 6: Fix the detection gap

Episode 6 — AI SOC LIVE Episode 6: Fix the detection gap with Darwin Salazar and Mitchem Boles.

webinar

AI SOC Live Episode 4: MDR vs AI SOC. Lessons from a CISO

Episode 4 — MDR vs AI SOC: lessons from a CISO, with Cecil Pineda, Mitchem Boles, and Sarah Breathnach.

Contact us

See Intezer in Action

Discover how AI-powered endpoint triage can eliminate alert fatigue and supercharge your SOC's efficiency.