AI-Driven SOC Triage Automation
Built intelligent L1 alert triage workflow reducing manual investigation by ~50% through AI and automation.
Challenge
High volume of L1 security alerts (200+ daily) leading to analyst fatigue, delayed response times, and inconsistent triage quality.
Solution
Designed and implemented an automated workflow integrating CrowdStrike EDR alerts with AI (ChatGPT) for context enrichment, VirusTotal for IOC analysis, and Power Automate for orchestration with Jira ticketing.
Key Accomplishments
- ~50% reduction in manual investigation time
- Improved Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
- Standardized alert handling with consistent documentation
- Automated IOC enrichment and threat context gathering
- Better analyst focus on high-severity and novel threats