Solution brief · 2026

Autonomous
SOC

The fifth level of SOC maturity, delivered from the Intelligent Threat Defense Centre, the facility Saint Fox built to run security operations for customers globally. AI investigates every alert. Security Analysts decide.

Managed ProtectManaged XDR Cyber Crime InvestigationManaged Risk SOC Maturity Assessment
Intelligent Threat Defense Centre · Protect Relentlessly contact@saintfox.com · saintfox.com · Customer: Public
Who you are working with

An AI-first cybersecurity firm. Principal Engineers do the work.

Saint Fox helps regulated companies govern AI usage, cut SOC noise, harden cloud platforms, and reduce identity blast radius. Every decision leaves a trail a Board, an auditor, and the engineer on call can all follow.

01

AI Governance

Find shadow AI. Govern every model, Agent, and prompt the business adopts.

02

Autonomous SOC

Cut the noise. AI investigates, Security Analysts decide, evidence is sealed.

03

Secure Platform Engineering

Policy as code and drift closure, from pipeline to production.

04

Secure Identity 360

Reduce blast radius across human, Machine, SaaS, and AI Agent identity.

VIGILE · the operating framework behind every engagement
ValidateIdentifyGuard ImplementLearnEnhance
Empanelled with CERT-In for information security auditing · Certified as per ISO/IEC 27001:2022 standards · A Principal Engineer answers the first call saintfox.com · Customer: Public
Why now

Most SOCs are losing the volume war

Analysts triage a fraction of the queue, leaving a growing backlog where genuine threats are buried in the noise. Adding more alerting tools increases operational load without materially improving detection fidelity.

Signals in
0
Human capacity
a fraction

Representative volumes for illustration, not a claimed result. Actual figures depend on environment size and telemetry.

Alert overload

Thousands of low signal alerts every week. Real incidents slip through while the queue grows.

Coverage gaps

The alerts nobody had time to open are exactly where a quiet intrusion sits.

Headcount does not scale

Staffing against volume means hiring against a number that only grows.

The fix is an operating model where AI does the tireless enrichment and correlation, and people spend their judgment where it counts.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
The cost of standing still

The clock is the cost

0Days to identify and contain a breach, global average, a nine year low
$0MGlobal average cost of a breach
$0MUnited States average, the highest of any region
$0MLower cost where AI and automation are used extensively in security, with roughly 80 days cut from the lifecycle

Breaches contained inside 200 days averaged $3.61M. Past 200 days, $5.49M. The gap between those two numbers is the business case for investigating everything.

Source: IBM Cost of a Data Breach Report 2025, IBM and Ponemon Institute. Figures are industry benchmarks, not Saint Fox results.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
The operating rule

AI investigates.
Security Analysts decide.

A fully autonomous SOC that contains threats on its own sounds appealing until an automated action takes down production at 3am for a false positive. Saint Fox draws a hard line through the workflow. AI never contains, isolates, or disables on its own.

Tireless

Every alert enriched, correlated, and investigated, including the ones a human team never had time for.

Named

Isolation, revocation, and account disable pass through a specific analyst who owns the decision on record.

Sealed

Inputs, reasoning, approver, and action written to a tamper evident ledger as the work happens.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
The service stack

Five pillars. 360 degree coverage of the security lifecycle.

01 · Prevent

Managed Protect

The preventive foundation. Reviews and strengthens controls, configurations, change management, and access policies across EDR, firewall, DLP, and cloud.

02 · Detect and respond

Managed XDR

Beyond traditional MDR: telemetry from SIEM, security controls, cloud, threat intelligence, and vulnerability data, with AI supported investigation, triage, and response.

03 · Investigate

Managed Cyber Crime Investigation

Deep breach investigation, threat hunting, incident response, recovery support, and root cause analysis when preventive and detection controls are bypassed.

04 · Reduce risk

Managed Risk

Finds exposure without waiting for an alert: vulnerabilities, misconfigurations, attack surface, brand exposure, and CTEM driven priorities, through to remediation.

05 · Mature

SOC Maturity Assessment

Where your operations stand across people, process, and technology, and a practical roadmap to higher maturity with cost optimization.

Together the five pillars cover the full security lifecycle: prevention, detection and response, breach investigation, continuous risk reduction, and maturity improvement. From identifying gaps to protecting assets, responding to incidents, and strengthening resilience over time.

Delivered from the Intelligent Threat Defense Centre, the facility Saint Fox built to run Autonomous SOC services for customers globally.saintfox.com · Customer: Public
Inside the iTDC

Three stages, and a named owner on every consequential call

StageWhat happensWho owns it
01 · AI investigatesEvery alert enriched with context, correlated across all telemetry, response playbook drafted, recommended action queued.AI, tireless, around the clock
02 · Human-In-Loop gateA named analyst reviews the recommendation with full context, then approves, adjusts, or rejects. The decision goes on record.Security Analyst, named owner
03 · Action takenIsolation, revocation, or account disable executes. Timeline and proof captured, packaged for audit, insurance, and review.Evidence ledger, sealed
Reviewer Agent

A second AI checks decision quality and chain of custody, so the work holds up under audit.

Calm is a deliverable

Your team reads a daily brief in sentences, not a queue of ten thousand alerts.

Authority stays yours

Escalation paths, crown jewel rules, and autonomy thresholds are set with you, in writing.

The boundary, stated plainly: AI investigates at Machine speed and assembles the case. A Security Analyst owns every consequential call, and that split is written into the gate table you sign.saintfox.com · Customer: Public
How it works

From telemetry to decision, every alert, around the clock

Telemetry in
EDR and XDRNetwork and NDRIdentity and ITDR CloudData centerEmailSIEMFirewall Threat intelSaaS auditVulnerability DLPAI activity over MCP
01Ingestclean events
02Triagescored queue
03Correlatelinked case
04Investigatecase file
05Build caserecommendation
06Decideverdict
07Human-In-Loopapproved action
Every closure explained

Auto closed alerts carry their reasoning, sampled weekly by Analysts so the Machine stays honest.

Reversible by design

Gated actions ship with rollback paths documented before they run.

Detections are code

The catalog is versioned, tested, and rolled back like any deploy, with control IDs auditors can sample.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
The maturity journey

Five levels of SOC maturity. The iTDC operates at Level 5.

LEVEL 1
Reactive
respond in ~30 days
LEVEL 2
Basic monitoring
~1 week
LEVEL 3
Managed SOC
~24 hours
LEVEL 4
Intelligence driven
4 to 5 hours
LEVEL 5 · iTDC
Autonomous SOC
minutes, Human-In-Loop

Maturity model with target response times per level. Planning targets for the operating model, not claimed results.

What Level 5 covers
Agentic investigationEvery alert investigated end to end, no sampling
Continuous huntingHypothesis driven hunts running alongside detection
Detection as codeVersioned catalog, tested, retro matched against history
AI workload telemetryAgents, MCP, and model gateways as first class sources
Cloud and data centerCloud control plane, workloads, and on-prem infrastructure in one case
Human-In-Loop responseNamed approvals on every consequential action
Sealed evidenceTamper evident ledger for audit and insurance

Most teams sit at Level 2 or 3. The jump to Level 5 is an operating model change, and it does not require replacing the stack you own.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Human-In-Loop gates

The question is never whether the SOC is autonomous. It is which actions may proceed without a person.

Action classAutonomyWhy
Enrich and correlateFully automaticReading telemetry and assembling cases has no blast radius.
Step up authenticationPolicy approvedThe real user passes in seconds. The attacker usually cannot.
Session revocationPolicy or AnalystReversible in minutes, gated tighter on crown jewel systems.
Isolation and account disableAnalyst approvedConsequential and disruptive. A Security Analyst owns the call, every time.
Crown jewel and business criticalTwo-step approvalA Saint Fox Analyst recommends. Your named executive sponsor authorizes before anything executes.

What autonomy never includes: ransom negotiation, legal notification, and anything that locks a human out of a system. Gate thresholds are reviewed quarterly against real cases, and the boundary moves only on evidence, in writing, with your sign off.

A gate, as code. The boundary is versioned, not tribal.
gate "crown-jewel-isolation" {
  trigger:  case.severity >= high
            and asset in crown_jewels
  require:  analyst_recommendation,
            sponsor_approval,     # your executive
            rollback_path_documented
  timeout:  page on-call lead at "15m"
  log:      always               # SOC-GTE-006
}

Who carries the decision. Saint Fox recommends, with the case and the evidence attached. You authorize anything that touches a crown jewel system, through a named executive sponsor on your side. Every approval is recorded with the name, the timestamp, and the reasoning, and commercial liability and remedies are set in the engagement agreement before the first alert.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Autonomy is set per action

Dialed up only as accuracy proves out

L0 to L1AI assistsAnalyst approves every action.
L2Plan approvedAnalyst approves a plan, AI runs the steps.
L3Bounded autonomyAutonomous within set boundaries. Exceptions escalate.
L4Broad auto remediationKill switch and executive sign off required.

Every consequential action requires a named analyst to approve it, at every level. Autonomy is dialed down the moment a live breach is detected.

The tuning loop

Confirmed positives raise weights, so the patterns that mattered fire earlier next time. False positives are treated as bugs: each one gets a tuning change with a control ID.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Signal coverage

The iTDC sees in every domain at once

Autonomy is only as good as the telemetry underneath it. A phish, the session it steals, and the data it reaches are one case, not three alerts.

Six telemetry domains, one case
01 · Endpoint

EDR streams

Execution, persistence, and lateral movement on devices and servers.

02 · Identity

Sign-ins, tokens, privilege

Takeovers, MFA fatigue, and dormant account activity, scored per identity.

03 · Cloud

Control plane and workload

Role assumptions, config changes, and exposure events as they happen.

04 · Data center

On-prem and infrastructure

Servers, virtualization, network gear, and the systems that never moved to cloud, monitored in the same pipeline.

05 · AI workloads

Agents, MCP, model gateways

Prompts, tool calls, and Agent actions as security telemetry, correlated with the identities behind them.

06 · Email and network

Gate verdicts, flow, DNS

Campaigns joined to the endpoints they touched. Beaconing and exfiltration paths surfaced.

Coverage discipline

Gaps become work items

Telemetry domains are scored for completeness. A silent log source is a finding, not a mystery.

History replays

New detections retro match against stored telemetry, so a fresh technique is checked against your past.

No findings is not no risk

Coverage honesty is the discipline. No findings is never allowed to stand in for no blind spots.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Autonomous detection engineering

Your SOC is only as good as your detection logic

Most SOC providers inherit whatever SIEM rules already exist. Saint Fox continuously evaluates every detection against your technology stack, MITRE ATT&CK coverage, threat exposure, and rule efficacy, so gaps surface before they become missed incidents.

Traditional SOCSaint Fox detection engineering
"2,000 use cases available"Measures how many are relevant to your environment
Rules deployed onceRules continuously validated and scored
Coverage reviewed after incidentsCoverage gaps discovered proactively
MITRE mapping done periodicallyATT&CK coverage monitored continuously
New threats require manual reviewThreat intelligence automatically highlights detection gaps
Noisy alerts remain for monthsHigh noise, low value detections identified automatically
What the AI continuously evaluates

Detection quality

Which rules are enabled, which are firing, and which produce useful alerts.

MITRE coverage

Covered techniques, missing techniques, and ATT&CK gap analysis.

Threat exposure

New threats affecting your environment, mapped against current coverage.

Rule efficacy

True positive performance, false positive rates, noisy rule identification.

Technology stack mapping

Data sources discovered automatically. Missing detections across cloud, identity, endpoint, email, network, and SaaS.

Fix gaps before they become incidents. The platform continuously discovers, evaluates, grades, and recommends improvements across the whole detection program, so weaknesses surface before a penetration test or a real attack exposes them.

Detection Engineering Grade: a continuously calculated score combining coverage, quality, efficacy, threat exposure alignment, and technology stack visibility.saintfox.com · Customer: Public
The technology core

Proprietary engineering, plus an AI layer purpose built for security operations

Built and run by Saint Fox

GlassBox and Private Sandbox

Detonation and analysis built in house, so samples never leave the boundary you approve.

Detection catalog as code

Versioned, tested, and rolled back like any deploy, with control IDs auditors can sample.

Evidence ledger

Inputs, reasoning, approver, and action, tamper evident, captured as the work happens.

Gate table as code

The autonomy boundary written down, signed, and reviewed quarterly against real cases.

Threat intelligence

60+ open source and partner native feeds, with premium sources available on request.

Runs on your stack

Bring your own SIEM license under full management, on the tooling you already own.

Digital Forensics Agent

Hosted and managed by Saint Fox, with Velociraptor based collection. A lightweight agent acquires the artifacts forensic investigation needs.

Reporting and analytics

In-house data pipeline, database, and reporting engine. Daily, weekly, and monthly executive reports with defense-in-depth visibility.

AiStrike · the AI intelligence layer inside the iTDC

Composite AI combines machine learning, knowledge graphs, and language models, so investigation carries context rather than guesswork. Alerts are correlated with identity, asset, and behavioral data, then mapped into MITRE ATT&CK attack chains with a root cause attached.

Detection engineeringTriage and investigation Threat intel operationsResponse automation Cloud investigation100+ integrations
SOC 2 Type II

Certified platform, granular role based access, zero customer data used for model training.

Multi-region residency

Deployment aligned to your data residency requirements, region by region, confirmed in scoping.

Built by the team behind Securonix

AiStrike's founding leadership built Securonix, named a Leader for the fifth consecutive time in the 2024 Gartner Magic Quadrant for SIEM. Pedigree from the platform Gartner rated at the top of the category.

AiStrike platform details published by AiStrike. Securonix recognition per Securonix announcement of the 2024 Gartner Magic Quadrant for SIEM. Saint Fox operates the iTDC around the AI layer and owns the decision model.saintfox.com · Customer: Public
The landscape

Five ways to run detection and response. One combines all of it.

In-house SIEM + SOARTraditional MSSP Product attached MDRAI-SOC point toolSaint Fox iTDC
Who investigatesYour analystsTiered offshore triageVendor analysts, strongest on their own stackAI software, your team decides and staffsAI investigates every alert, Saint Fox Security Analysts decide
AI security coverageRareRareEmergingVaries by vendorAgents, MCP, and model gateways as first class telemetry
Cloud and data centerDepends on staffingOften an add-onCloud strong, DC variesCloud firstCloud, data center, and on-prem in one case
Beyond detectionSeparate vendorsLimitedLimitedNoVAPT, red teaming, VM to CTEM, AI governance in one VIGILE program
AccountabilityYours entirelyShared and diffuseVendor SLAYours entirelyNamed Human-In-Loop approvals, sealed evidence
Cost shapeFixed headcount racePer device tiersPer endpointPer seat or alert, plus your staffingScoped to telemetry and coverage hours

The market itself validates the direction: CrowdStrike, Microsoft, and SentinelOne all ship AI SOC copilots, and a wave of AI-SOC startups sells triage software. The open question in every one of those models is who operates it, around the clock, with a name on each decision. That is the part Saint Fox sells.

Category comparison of delivery models based on published vendor positioning, July 2026. Traits vary by vendor inside each category.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Performance

Same detection outcomes. A different clock.

Traditional SOCiTDC
MTTA
5 min to 1 hour
under 1 min
MTTI
1 hour and up
under 10 min
MTTR
hours to days
minutes

Engineered targets for the operating model, not claimed results. MTTD and MTTR targets are set for your environment, measured continuously, and reported to leadership.

0%of alerts investigated. The whole queue, top to bottom, including the ones a human team never had time for.
0ungated actions. No consequential action executes without a named approval.

Published partner outcome. A named enterprise customer running the AiStrike platform reported mean time to investigate under 10 minutes and more than 90 percent fewer escalations to the in house team. Published by AiStrike, not a Saint Fox measurement.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
The economics

What autonomy takes out of the run rate

To match this coverage in house
8,760hours in a year that need covering
~1,700productive hours per analyst after leave, training, and attrition
5.2analysts required per continuously staffed seat
10 to 12analysts for a two person watch, plus a SOC lead and a detection engineer
$1.5M to $2.1Mblended fully loaded people cost per year, before SIEM, SOAR, threat intel, and training

Estimate, built from published market salary ranges and standard shift coverage math. Replace with your own rate card in the first workshop.

Lever 01 · Coverage

Round the clock without staffing for noise

Analyst headcount scales with complexity rather than with raw alert count. A predictable managed cost replaces an open ended hiring race.

Lever 02 · Labor

Tier 1 and Tier 2 triage absorbed

Enrichment, correlation, and case building run in the pipeline. Your people spend their hours on decisions, not on gathering data.

Lever 03 · Tooling

Fewer seats, no rip and replace

Case management and response orchestration sit inside the AI layer, and the iTDC runs on the SIEM and EDR you already own.

Lever 04 · Exposure

The number that dwarfs the others

IBM puts $1.9M and roughly 80 days of breach lifecycle between organizations using AI extensively in security and those that are not.

Managed cost is scoped to your telemetry volume, integrations, and coverage hours. We model it line by line against your own rate card and current tooling spend, and we show the arithmetic. Planning targets, not claimed results.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Beyond detection

Find exposure before attackers do. From VAPT to CTEM.

The exposure maturity path
Stage 1 · Scanning focus

Periodic vulnerability scans, severity based lists, manual spreadsheets.

Stage 2 · Basic prioritization

Regular scanning with early threat intelligence folded into the queue.

Stage 3 · Risk based VM

Internet exposure and business context decide what gets fixed first.

Stage 4 · CTEM

Continuous discovery, validation, and mobilization run as a program on a cadence.

Stage 5 · Agentic exposure management

AI agents continuously discover assets, validate exploitability, and draft remediation, with people approving the fixes.

VAPTRed, Blue and Purple TeamingBreach and attack simulation Vulnerability ManagementCTEMAI Red Teaming Agentic AI Red TeamingSOC assessment
1 · Scoping 2 · Discovery 3 · Prioritization 4 · Validation 5 · Mobilization
CTEM
CONTINUOUS LOOP

The five stages of Gartner's Continuous Threat Exposure Management framework, run as a Saint Fox managed program.

Every red team finding and every validated exposure becomes a new detection in the iTDC. Offense feeds defense inside the same VIGILE loop, so each exercise leaves the estate measurably harder to attack.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Autonomous reporting and defense-in-depth intelligence

Reports that improve security, and prove it

Most SOC reports are exports from SIEM and ticketing dashboards. Saint Fox builds every daily, weekly, and monthly report from a dedicated reporting intelligence platform that analyzes trends, anomalies, operational effectiveness, threat exposure, and defensive coverage. The report becomes an improvement engine.

Every report answers five questions
01

What changed?

Trends against previous weeks, automatic deviation detection, significant movements highlighted.

02

What requires attention?

Open critical cases, long pending investigations, integration failures, telemetry gaps.

03

What is increasing risk?

New threat intelligence, threat actor activity, CVE and IOC exposure, impacted assets.

04

What is breaking visibility?

Log source degradation, ingestion anomalies, asset reporting gaps, integration health.

05

What should we improve next?

MITRE ATT&CK gaps, defense-in-depth recommendations, detection engineering improvements.

Defense-in-depth as a deliverable. Beyond alerts and tickets, every report measures user activity, authentication patterns, lateral movement, privileged access usage, telemetry health, detection coverage, and threat exposure, mapped to MITRE, with what changed, why, and the next action attached.

A report should answer one question: are we more secure today than we were last week? Saint Fox reports provide that answer.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Getting live

Telemetry in week two. Live and quiet by week four.

Weeks 1 to 2

Connect

Telemetry sources connect. The gate table is drafted with your team: crown jewel rules, escalation paths, autonomy thresholds.

Weeks 2 to 3

Shadow mode

Detections tune against your live environment without paging anyone. Noise is engineered out before you feel it.

Week 4

Live operations

The iTDC takes watch, already quiet. Highest value sources go first rather than waiting for full coverage.

Month 2 onward

The Learn loop

Weekly tuning from live cases, hunts, and purple team findings. Monthly metrics pack, quarterly Board review.

What the Board sees

Alerts in, cases out

The compression the AI triage achieves, trended month over month.

True positive rate

Cases that mattered against cases that paged someone. Tuning lives here.

Time to contain

Median minutes from first signal to contained, in the Board pack.

Numbers from your telemetry, not industry averages.

Your analysts can work inside the iTDC too. Many clients keep their team on the same case queue with shared runbooks. Who decides what is part of the gate table, agreed before go live.

Saint Fox · Autonomous SOC · Intelligent Threat Defense Centresaintfox.com · Customer: Public
Next step

Pressure test your SOC workflow

A Principal Engineer walks through one of your real alerts end to end and shows you exactly where the gaps are. No slides, no sales pitch. You leave the call with a clear starting point whether or not you engage us.

Every alert investigatedNamed Human-In-Loop approval Sealed evidenceRuns on the stack you own
Innovate Fearlessly, Protect Relentlessly contact@saintfox.com · saintfox.com · Customer: Public
Arrows or scroll · F for fullscreen