Corelight outlines an agentic SOC model beyond alert queues

Corelight has outlined an agentic security operations centre model intended to move investigation ahead of human alert triage. Rather than allowing detections to wait in an alert queue, AI agents would begin examining a signal as it appears and escalate it to an analyst only when network evidence supports that decision.
The proposed shift changes both the pace and order of security operations. Corelight says agents can conduct investigations in seconds or minutes instead of hours, while working asynchronously on multiple cases. The model is built around agentic AI, deep network telemetry and structured investigative playbooks.
From alert priority to evidence-backed escalation
In a conventional SOC, an alert receives a severity score and waits for a human to determine whether it merits investigation. High volumes of telemetry make that queue unavoidable when analysts are the investigative layer, and teams must prioritise signals before they fully understand what those signals represent.
Corelight’s alternative is an agentic alert-validation flow: alert, queue, machine investigation, evidence and human judgment. An agent can validate a detection, examine underlying network activity, profile the affected entity, consider historical behaviour, correlate related events and gather further evidence from available data.
That work can proceed without competing for analyst attention. The intended result is not simply faster triage, but a broader examination of signals before a human is asked to make a disposition. Cases that require escalation should arrive with context and evidence attached, while investigations without supporting evidence can end without human involvement.
Threat hunting begins with a hypothesis
The same approach can be applied before or beyond an alert. Traditional threat hunting starts with a hypothesis about attacker behaviour, searches the available evidence and then attempts to prove or disprove it. Corelight argues that agents can perform this cycle at machine scale because they can test many hypotheses in parallel.
Examples include an attacker using an unusual command-and-control protocol, moving laterally through remote administration services, staging data for exfiltration, communicating with systems that have no legitimate reason to interact, or operating below existing detection thresholds. Each proposition implies observable behaviour in network traffic.
AI-powered hypothesis-driven hunting does not replace detection in this model. It uses network evidence to test and extend verifiable detections, asking what is unusual, which relationships deserve examination, what supports or contradicts a hypothesis and what evidence could reduce uncertainty.
A different role for analysts
Corelight presents this as an added investigative layer between network activity, detection and confirmed threats. It says the model can provide more investigative coverage without a proportional increase in analyst capacity, lower the cost per investigation and make more use of security telemetry as actionable evidence.
The business implication is practical: security leaders considering machine-led triage need reliable network telemetry and clear investigative playbooks, while retaining human responsibility for response, decisions and complex cases.

