The fifth level of SOC maturity, delivered from the Intelligent Threat Defense Centre, the facility Saint Fox built to run security operations for customers globally. AI investigates every alert. Security Analysts decide.
Saint Fox helps regulated companies govern AI usage, cut SOC noise, harden cloud platforms, and reduce identity blast radius. Every decision leaves a trail a Board, an auditor, and the engineer on call can all follow.
Find shadow AI. Govern every model, Agent, and prompt the business adopts.
Cut the noise. AI investigates, Security Analysts decide, evidence is sealed.
Policy as code and drift closure, from pipeline to production.
Reduce blast radius across human, Machine, SaaS, and AI Agent identity.
Analysts triage a fraction of the queue, leaving a growing backlog where genuine threats are buried in the noise. Adding more alerting tools increases operational load without materially improving detection fidelity.
Representative volumes for illustration, not a claimed result. Actual figures depend on environment size and telemetry.
Thousands of low signal alerts every week. Real incidents slip through while the queue grows.
The alerts nobody had time to open are exactly where a quiet intrusion sits.
Staffing against volume means hiring against a number that only grows.
The fix is an operating model where AI does the tireless enrichment and correlation, and people spend their judgment where it counts.
Breaches contained inside 200 days averaged $3.61M. Past 200 days, $5.49M. The gap between those two numbers is the business case for investigating everything.
Source: IBM Cost of a Data Breach Report 2025, IBM and Ponemon Institute. Figures are industry benchmarks, not Saint Fox results.
A fully autonomous SOC that contains threats on its own sounds appealing until an automated action takes down production at 3am for a false positive. Saint Fox draws a hard line through the workflow. AI never contains, isolates, or disables on its own.
Every alert enriched, correlated, and investigated, including the ones a human team never had time for.
Isolation, revocation, and account disable pass through a specific analyst who owns the decision on record.
Inputs, reasoning, approver, and action written to a tamper evident ledger as the work happens.
The preventive foundation. Reviews and strengthens controls, configurations, change management, and access policies across EDR, firewall, DLP, and cloud.
Beyond traditional MDR: telemetry from SIEM, security controls, cloud, threat intelligence, and vulnerability data, with AI supported investigation, triage, and response.
Deep breach investigation, threat hunting, incident response, recovery support, and root cause analysis when preventive and detection controls are bypassed.
Finds exposure without waiting for an alert: vulnerabilities, misconfigurations, attack surface, brand exposure, and CTEM driven priorities, through to remediation.
Where your operations stand across people, process, and technology, and a practical roadmap to higher maturity with cost optimization.
Together the five pillars cover the full security lifecycle: prevention, detection and response, breach investigation, continuous risk reduction, and maturity improvement. From identifying gaps to protecting assets, responding to incidents, and strengthening resilience over time.
| Stage | What happens | Who owns it |
|---|---|---|
| 01 · AI investigates | Every alert enriched with context, correlated across all telemetry, response playbook drafted, recommended action queued. | AI, tireless, around the clock |
| 02 · Human-In-Loop gate | A named analyst reviews the recommendation with full context, then approves, adjusts, or rejects. The decision goes on record. | Security Analyst, named owner |
| 03 · Action taken | Isolation, revocation, or account disable executes. Timeline and proof captured, packaged for audit, insurance, and review. | Evidence ledger, sealed |
A second AI checks decision quality and chain of custody, so the work holds up under audit.
Your team reads a daily brief in sentences, not a queue of ten thousand alerts.
Escalation paths, crown jewel rules, and autonomy thresholds are set with you, in writing.
Auto closed alerts carry their reasoning, sampled weekly by Analysts so the Machine stays honest.
Gated actions ship with rollback paths documented before they run.
The catalog is versioned, tested, and rolled back like any deploy, with control IDs auditors can sample.
Maturity model with target response times per level. Planning targets for the operating model, not claimed results.
| Agentic investigation | Every alert investigated end to end, no sampling |
| Continuous hunting | Hypothesis driven hunts running alongside detection |
| Detection as code | Versioned catalog, tested, retro matched against history |
| AI workload telemetry | Agents, MCP, and model gateways as first class sources |
| Cloud and data center | Cloud control plane, workloads, and on-prem infrastructure in one case |
| Human-In-Loop response | Named approvals on every consequential action |
| Sealed evidence | Tamper evident ledger for audit and insurance |
Most teams sit at Level 2 or 3. The jump to Level 5 is an operating model change, and it does not require replacing the stack you own.
| Action class | Autonomy | Why |
|---|---|---|
| Enrich and correlate | Fully automatic | Reading telemetry and assembling cases has no blast radius. |
| Step up authentication | Policy approved | The real user passes in seconds. The attacker usually cannot. |
| Session revocation | Policy or Analyst | Reversible in minutes, gated tighter on crown jewel systems. |
| Isolation and account disable | Analyst approved | Consequential and disruptive. A Security Analyst owns the call, every time. |
| Crown jewel and business critical | Two-step approval | A Saint Fox Analyst recommends. Your named executive sponsor authorizes before anything executes. |
What autonomy never includes: ransom negotiation, legal notification, and anything that locks a human out of a system. Gate thresholds are reviewed quarterly against real cases, and the boundary moves only on evidence, in writing, with your sign off.
gate "crown-jewel-isolation" { trigger: case.severity >= high and asset in crown_jewels require: analyst_recommendation, sponsor_approval, # your executive rollback_path_documented timeout: page on-call lead at "15m" log: always # SOC-GTE-006 }
Who carries the decision. Saint Fox recommends, with the case and the evidence attached. You authorize anything that touches a crown jewel system, through a named executive sponsor on your side. Every approval is recorded with the name, the timestamp, and the reasoning, and commercial liability and remedies are set in the engagement agreement before the first alert.
Every consequential action requires a named analyst to approve it, at every level. Autonomy is dialed down the moment a live breach is detected.
Confirmed positives raise weights, so the patterns that mattered fire earlier next time. False positives are treated as bugs: each one gets a tuning change with a control ID.
Autonomy is only as good as the telemetry underneath it. A phish, the session it steals, and the data it reaches are one case, not three alerts.
Six telemetry domains, one caseExecution, persistence, and lateral movement on devices and servers.
Takeovers, MFA fatigue, and dormant account activity, scored per identity.
Role assumptions, config changes, and exposure events as they happen.
Servers, virtualization, network gear, and the systems that never moved to cloud, monitored in the same pipeline.
Prompts, tool calls, and Agent actions as security telemetry, correlated with the identities behind them.
Campaigns joined to the endpoints they touched. Beaconing and exfiltration paths surfaced.
Telemetry domains are scored for completeness. A silent log source is a finding, not a mystery.
New detections retro match against stored telemetry, so a fresh technique is checked against your past.
Coverage honesty is the discipline. No findings is never allowed to stand in for no blind spots.
Most SOC providers inherit whatever SIEM rules already exist. Saint Fox continuously evaluates every detection against your technology stack, MITRE ATT&CK coverage, threat exposure, and rule efficacy, so gaps surface before they become missed incidents.
| Traditional SOC | Saint Fox detection engineering |
|---|---|
| "2,000 use cases available" | Measures how many are relevant to your environment |
| Rules deployed once | Rules continuously validated and scored |
| Coverage reviewed after incidents | Coverage gaps discovered proactively |
| MITRE mapping done periodically | ATT&CK coverage monitored continuously |
| New threats require manual review | Threat intelligence automatically highlights detection gaps |
| Noisy alerts remain for months | High noise, low value detections identified automatically |
Which rules are enabled, which are firing, and which produce useful alerts.
Covered techniques, missing techniques, and ATT&CK gap analysis.
New threats affecting your environment, mapped against current coverage.
True positive performance, false positive rates, noisy rule identification.
Data sources discovered automatically. Missing detections across cloud, identity, endpoint, email, network, and SaaS.
Fix gaps before they become incidents. The platform continuously discovers, evaluates, grades, and recommends improvements across the whole detection program, so weaknesses surface before a penetration test or a real attack exposes them.
Detonation and analysis built in house, so samples never leave the boundary you approve.
Versioned, tested, and rolled back like any deploy, with control IDs auditors can sample.
Inputs, reasoning, approver, and action, tamper evident, captured as the work happens.
The autonomy boundary written down, signed, and reviewed quarterly against real cases.
60+ open source and partner native feeds, with premium sources available on request.
Bring your own SIEM license under full management, on the tooling you already own.
Hosted and managed by Saint Fox, with Velociraptor based collection. A lightweight agent acquires the artifacts forensic investigation needs.
In-house data pipeline, database, and reporting engine. Daily, weekly, and monthly executive reports with defense-in-depth visibility.
Composite AI combines machine learning, knowledge graphs, and language models, so investigation carries context rather than guesswork. Alerts are correlated with identity, asset, and behavioral data, then mapped into MITRE ATT&CK attack chains with a root cause attached.
Certified platform, granular role based access, zero customer data used for model training.
Deployment aligned to your data residency requirements, region by region, confirmed in scoping.
AiStrike's founding leadership built Securonix, named a Leader for the fifth consecutive time in the 2024 Gartner Magic Quadrant for SIEM. Pedigree from the platform Gartner rated at the top of the category.
| In-house SIEM + SOAR | Traditional MSSP | Product attached MDR | AI-SOC point tool | Saint Fox iTDC | |
|---|---|---|---|---|---|
| Who investigates | Your analysts | Tiered offshore triage | Vendor analysts, strongest on their own stack | AI software, your team decides and staffs | AI investigates every alert, Saint Fox Security Analysts decide |
| AI security coverage | Rare | Rare | Emerging | Varies by vendor | Agents, MCP, and model gateways as first class telemetry |
| Cloud and data center | Depends on staffing | Often an add-on | Cloud strong, DC varies | Cloud first | Cloud, data center, and on-prem in one case |
| Beyond detection | Separate vendors | Limited | Limited | No | VAPT, red teaming, VM to CTEM, AI governance in one VIGILE program |
| Accountability | Yours entirely | Shared and diffuse | Vendor SLA | Yours entirely | Named Human-In-Loop approvals, sealed evidence |
| Cost shape | Fixed headcount race | Per device tiers | Per endpoint | Per seat or alert, plus your staffing | Scoped to telemetry and coverage hours |
The market itself validates the direction: CrowdStrike, Microsoft, and SentinelOne all ship AI SOC copilots, and a wave of AI-SOC startups sells triage software. The open question in every one of those models is who operates it, around the clock, with a name on each decision. That is the part Saint Fox sells.
Category comparison of delivery models based on published vendor positioning, July 2026. Traits vary by vendor inside each category.
Engineered targets for the operating model, not claimed results. MTTD and MTTR targets are set for your environment, measured continuously, and reported to leadership.
Published partner outcome. A named enterprise customer running the AiStrike platform reported mean time to investigate under 10 minutes and more than 90 percent fewer escalations to the in house team. Published by AiStrike, not a Saint Fox measurement.
| 8,760 | hours in a year that need covering |
| ~1,700 | productive hours per analyst after leave, training, and attrition |
| 5.2 | analysts required per continuously staffed seat |
| 10 to 12 | analysts for a two person watch, plus a SOC lead and a detection engineer |
| $1.5M to $2.1M | blended fully loaded people cost per year, before SIEM, SOAR, threat intel, and training |
Estimate, built from published market salary ranges and standard shift coverage math. Replace with your own rate card in the first workshop.
Analyst headcount scales with complexity rather than with raw alert count. A predictable managed cost replaces an open ended hiring race.
Enrichment, correlation, and case building run in the pipeline. Your people spend their hours on decisions, not on gathering data.
Case management and response orchestration sit inside the AI layer, and the iTDC runs on the SIEM and EDR you already own.
IBM puts $1.9M and roughly 80 days of breach lifecycle between organizations using AI extensively in security and those that are not.
Managed cost is scoped to your telemetry volume, integrations, and coverage hours. We model it line by line against your own rate card and current tooling spend, and we show the arithmetic. Planning targets, not claimed results.
Periodic vulnerability scans, severity based lists, manual spreadsheets.
Regular scanning with early threat intelligence folded into the queue.
Internet exposure and business context decide what gets fixed first.
Continuous discovery, validation, and mobilization run as a program on a cadence.
AI agents continuously discover assets, validate exploitability, and draft remediation, with people approving the fixes.
The five stages of Gartner's Continuous Threat Exposure Management framework, run as a Saint Fox managed program.
Every red team finding and every validated exposure becomes a new detection in the iTDC. Offense feeds defense inside the same VIGILE loop, so each exercise leaves the estate measurably harder to attack.
Most SOC reports are exports from SIEM and ticketing dashboards. Saint Fox builds every daily, weekly, and monthly report from a dedicated reporting intelligence platform that analyzes trends, anomalies, operational effectiveness, threat exposure, and defensive coverage. The report becomes an improvement engine.
Every report answers five questionsTrends against previous weeks, automatic deviation detection, significant movements highlighted.
Open critical cases, long pending investigations, integration failures, telemetry gaps.
New threat intelligence, threat actor activity, CVE and IOC exposure, impacted assets.
Log source degradation, ingestion anomalies, asset reporting gaps, integration health.
MITRE ATT&CK gaps, defense-in-depth recommendations, detection engineering improvements.
Defense-in-depth as a deliverable. Beyond alerts and tickets, every report measures user activity, authentication patterns, lateral movement, privileged access usage, telemetry health, detection coverage, and threat exposure, mapped to MITRE, with what changed, why, and the next action attached.
A report should answer one question: are we more secure today than we were last week? Saint Fox reports provide that answer.
Telemetry sources connect. The gate table is drafted with your team: crown jewel rules, escalation paths, autonomy thresholds.
Detections tune against your live environment without paging anyone. Noise is engineered out before you feel it.
The iTDC takes watch, already quiet. Highest value sources go first rather than waiting for full coverage.
Weekly tuning from live cases, hunts, and purple team findings. Monthly metrics pack, quarterly Board review.
The compression the AI triage achieves, trended month over month.
Cases that mattered against cases that paged someone. Tuning lives here.
Median minutes from first signal to contained, in the Board pack.
Numbers from your telemetry, not industry averages.
Your analysts can work inside the iTDC too. Many clients keep their team on the same case queue with shared runbooks. Who decides what is part of the gate table, agreed before go live.
A Principal Engineer walks through one of your real alerts end to end and shows you exactly where the gaps are. No slides, no sales pitch. You leave the call with a clear starting point whether or not you engage us.