
Agentic AI use cases are the specific jobs security and IT teams assign to AI agents. These use cases include alert triage, phishing analysis, audit evidence collection, and the resolution of routine service desk tickets. Teams can assign that work to a single agent using a few tools, or split it among several specialists, each owning one piece.
Orchestration is how teams split tasks across multiple AI agents. A coordinator agent breaks the task into pieces and assigns each piece to a specialist agent. Each specialist completes its piece and returns the result to the coordinator.
Once the specialists return their results, the coordinator combines them into a single case. If the next step could change a system, such as isolating an endpoint, a person has to approve it first. Strike48 builds our agents for security operations, MSSP delivery, and IT operations on this model.
The team that builds a specialist agent limits it in three ways. Each specialist gets one job, one knowledge graph to retrieve from, and a fixed set of tools it can call through Model Context Protocol (MCP). Developers use MCP to define which tools, data sources, and capabilities an agent can access while reasoning.
Microsoft's Azure Architecture Center ranks this multi-agent pattern above a direct model call and above a single agent with tools. Microsoft recommends it when a single agent can't reliably handle a task due to prompt complexity, tool overload, or security scoping requirements. For a simple, repeatable job, Microsoft recommends a single agent with tools.
To limit hallucinations, Strike48 narrows the scope of what each agent can retrieve. It uses GraphRAG to organize each agent's knowledge as a graph of entities and relationships. It then assigns each agent a persona that sets which parts of the graph the agent can reach.
For example, a phishing specialist can retrieve email headers, URL reputation, and message metadata, and nothing else. The agent only ever gets questions inside that job. Someone on your team has to update the knowledge graph as your infrastructure changes.
Every workflow step belongs to one of two classes, and the platform sets the class before the workflow runs. A deterministic step follows fixed logic and returns the same result every time. A cognitive step reasons through evidence that no rule covers. Strike48 explains how the two classes combine in its post on agentic log intelligence.
Strike48 places approval gates in front of actions that change a system, meaning endpoint isolation, remediation, account lockout, and firewall changes. Agents run investigation, correlation, and documentation without a gate. Agents record every step in an audit trail that reviewers can verify.
When an endpoint alert comes in, the SOC Level 1 Agent first runs its deterministic steps. It pulls the process tree, the parent binary, and the originating user from the logs. It then decides whether the pattern warrants enrichment. If it does, the agent passes the case to the SOC Level 2 Agent and attaches the indicators.
The Level 2 Agent queries threat intelligence and adjacent log sources. It then interprets the file hash and the network destination together to decide whether an active campaign is underway.
The SOC Manager Agent compares the case against other open alerts that share IP addresses, user accounts, or process hashes and merges four related signals into a single incident. Each agent writes its findings to the shared case as it finishes. At the approval gate, the analyst sees the assembled case, the evidence behind each conclusion, and one proposed action: isolate the host.
Strike48's SOC Level 1 Agent performs initial alert triage, separating real threats from false positives before any alert reaches an analyst's queue. Strike48 lists available SOC agents on our security solutions page, and each agent at around Level 1 handles a single bounded job.
Teams build custom threat-hunting agents themselves in Prospector Studio, as covered below. Every SOC agent depends on access to logs. An agent can only reason over logs it can query, so if your team leaves a source unconnected, the agent never sees the activity in it.
In our early deployments, mean time to detection dropped below eight minutes. We also found that agents in those deployments uncovered active phishing campaigns that legacy SIEM tooling had missed.
Pick a bounded, high-volume job with a before-state you already measure and a low cost if the agent gets the first pass wrong. Level 1 triage meets all three conditions. You already know your false-positive rate, and your analysts catch a wrong triage verdict downstream.
Response automation fails the third condition because a wrong isolation or lockout disrupts the business before anyone catches it. Before you commit, check what share of your log sources the agent can reach and whether you can trace each conclusion it returns to log data you can inspect.
Each time you onboard a client, your analysts take on its alerts, and each client keeps its log data in its own environment under its own retention terms. You can't hire analysts at the same rate, so each analyst covers more tenants as your client book grows.
Strike48 runs the same SOC tier agents in every tenant environment, so a Tier 1 verdict means the same thing for your newest client as for your oldest. We also rank alerts by severity across tenants, so your analysts work the highest-severity alert first, regardless of which tenant it came from.
Our search-in-place connectors for S3, Splunk, and Elastic allow agents to query each tenant's logs where they are stored. You don't have to run a migration project for a client whose logs can't leave its environment. Agents produce a separate audit trail for each tenant, and you can use those trails in renewal reporting. Strike48 documents the tier structure on our MSSP solutions page.
Strike48 states that agent assistance shortens analyst onboarding from a six-to-nine-month ramp to two to three weeks. Strike48 reports this figure from our own deployments, and no independent source has confirmed it. To test it, run one tier for one tenant against a previously measured before state. Hold the test for a quarter, then decide whether to extend it across your client book.
Strike48's Cloud Cost Optimization Agent finds unused resources and rightsizing opportunities across cloud infrastructure. It queries the same log data the security agents use. Three other named agents handle adjacent operations work.
Your engineers can also ask these agents plain-language questions about infrastructure state. Suppose you ask why latency spiked in the payment service last night. The agent can answer only if it can reach that service's logs in the application tier, the load balancer, and the cloud provider's telemetry.
When a source has no parser, Strike48 generates one, or the agent reads the semi-structured log directly. Your team doesn't have to write a schema before the agent can query a new source.
An AI assistant returns suggestions and summaries. An agent carries out the step. If your analysts read AI-drafted summaries and then work every alert by hand, their workload hasn't changed.
Rule-based automation runs the same way every time, but it fails on any alert pattern for which no rule was written. A general-purpose model can reason through a novel pattern, but it returns different output from one run to the next. Strike48's agents use both methods. They run deterministic steps where auditors need repeatable results and reason through the evidence where no rule applies.
Prospector Studio is our no-code environment for building, testing, and managing custom agents.
In Prospector Studio, your team works with an agent creation assistant and writes queries in natural language. You can also run gap analysis across domain tables to find where detection coverage is missing. The environment includes playbook and report generation, as well as case management integration.
Teams turn to Prospector Studio when a workflow falls outside the pre-built packages, when their data sources are specific to their environment, or when they want to own and extend the agent logic. Custom threat hunting is the clearest case, because your team writes the hypothesis for each hunt. Teams also build agents for collecting SOC 2, PCI, or HIPAA evidence.
Choose a job with a before-state you already measure, such as SOC Level 1 alert triage or routine service desk requests.
Deploy a Strike48 pre-built agent package against that job, then compare the agent's results with your before-state.
Before you add a second job, trace a sample of conclusions in the audit trail back to specific log data. Confirm that every consequential action stopped at the approval gate you set. When the next workflow falls outside the pre-built packages, build it in Prospector Studio.
An AI assistant suggests and summarizes. An autonomous agent runs the investigation and the subsequent workflow steps. To tell them apart, check whether the system takes the action or proposes an action for a person to take. If your analysts still perform every step after they read the output, you have an assistant.
Choose a bounded, high-volume job with a before-state you already measure, such as SOC Level 1 alert triage or common service desk requests. Deploy a pre-built agent package when the workflow is standard, and you need coverage right away. Build a custom agent when the workflow or data sources are specific to your environment, or when you want to extend the logic without depending on the vendor.
A scoped agent reports that the request falls outside its scope and stops. To add a new log source, your team onboards it through Strike48's auto-generated parsers or semi-structured log reading. Onboarding a source takes real work, and the agent never does it silently in the middle of an investigation.
In Strike48's workflows, a person approves actions with real-world consequences, such as endpoint isolation, remediation, account lockout, and firewall changes. Agents run investigations, correlations, enrichments, and documentation without approval. Agents log every deterministic and cognitive step in the audit trail, including every tool they call through MCP. A reviewer can trace what the agents did before the action reached the gate.
No. Strike48 works as a unified log intelligence layer on top of your existing log stores. Its agents query those stores in place through search-in-place connectors, so your data stays where it is. You still need centralized ingestion when you want long retention in a single system of record, when downstream tools require normalization at ingest, or when a compliance regime specifies a particular store.