FOMO in the SOC: Where AI Platforms like Claude Actually Fit

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Intezer outlines a three-layer SOC architecture, positioning Claude, Cursor, and Codex at the top as analyst collaboration tools rather than 24/7 alert investigators sitting beneath existing SIEM, EDR, identity, and cloud security tools.
- The tokenomics problem — investigating every alert with an LLM requires feeding it endpoint telemetry, process trees, authentication logs, email history, threat intelligence, prior investigations, and detection rules, making high-volume alert triage cost-prohibitive compared with deterministic workflows plus selective AI reasoning.
- Intezer cites analysis of more than 25 million security alerts processed during 2025, finding that nearly 1% of confirmed incidents originated from low-severity or informational alerts — a gap severity-based prioritization misses.
- MDR-reliant organizations face a structural barrier: the MDR typically owns the case management system, investigation history, and enriched telemetry, so AI platforms like Claude lack the raw artifacts needed to independently investigate alerts.
- Intezer pitches its autonomous AI SOC as the always-on investigation layer — using forensic analysis, organizational memory, and cached context to escalate only the cases that need human judgment while keeping LLM usage selective and costs predictable.
- Itai Tevet (Co-Founder and CEO) and Lital Asher-Dotan (CMO) are hosting a session arguing that analysts should use Claude to question completed investigations, draft Sigma rules, hunt threats, and generate reports — after the autonomous SOC has done the investigative grind.
- Intezer frames the takeaway as 'both, not either': an autonomous AI SOC that continuously investigates every alert alongside an AI platform that helps humans think, create, and decide.
Why it matters: For security teams buried under thousands of daily alerts, the argument reframes Claude adoption around architectural fit — pairing always-on autonomous investigation with on-demand LLM assistance rather than overloading Claude with full alert triage. Intezer's 25-million-alert figure, showing nearly 1% of confirmed incidents originate from low-severity alerts, makes the case that alert coverage breadth — not just severity prioritization — is what surfaces real threats.




