Vectra AI’s Approach to AI in the SOC: AI Built by Security Experts for Security Experts

July 28, 2026
7/28/2026
Zoey Chu
Product Marketing Manager
Vectra AI’s Approach to AI in the SOC: AI Built by Security Experts for Security Experts

Security teams don’t need AI because it’s new or exciting, or because it promises some version of SOC heaven. They need it because their workflows are under strain. Analysts already spend too much time on detection, tuning and maintenance. My colleague Aakash covers that detection latency problem in his blog (https://www.vectra.ai/blog/how-vectra-ai-secures-the-ai-enterprise). Here, I want to focus on what happens next: investigation latency.

Investigation is where analysts move between tools, copy and paste data, rebuild timelines, check related activity, identify impacted accounts and systems, and figure out whether one alert is part of a larger attack path. This the work that drives up mean time to investigate (MTTI), and the delay adds up quickly. Manual stitching can take 60 to 90 minutes per incident. Manual prioritization can take minutes to hours. Cross-tool hunting can stretch from hours to days. (Source: https://www.vectra.ai/resources/why-defenders-dont-see-attacks-earlier)

That work matters because it’s how analysts make good decisions. But when it’s manual, it slows the entire detection, investigation and response workflow, forcing analysts to assemble the full picture before they can apply judgment to it. This is where I see Vectra AI’s approach to AI in the SOC standing out: understand how analysts work, then apply AI where it can reduce friction, improve context and help teams move from alert review to action faster. 

Helping analysts move from alert to context

One of the first challenges analysts face is knowing where to begin after an alert is prioritized. The signal may look important, but there is still a lot to understand. What triggered it? What else is connected? Which systems, devices, or accounts are involved? Is the activity isolated, or is it a part of a broader attack path? 

This is also where uncertainty slows response. Vectra AI research found that 69% of defenders fear missing a real threat. That fear is understandable when real attacker behavior is buried in alert noise and analysts have to decide what matters with incomplete context.

Vectra AI’s AI-assisted search function is designed to reduce that friction. Instead of manually pivoting between tools or writing queries, analysts can ask questions or issue commands in natural language to hunt for related activity or gather more context around the alert. The AI agent translates those inputs into queries, retrieves the relevant data and presents it with contextual explanations of what’s happening, including associated attack techniques and patterns backed by security research and industry intelligence. 

This supports both investigation and threat hunting workflows. Analysts can expand beyond the initial alert, explore related behaviors, and validate whether the activity is isolated or part of something larger. These workflows help summarize what happened, highlight related activity, and guide the next steps without requiring analysts to rebuild context from scratch.

My colleague walks through how to use this function in this video

The goal isn’t to replace analyst judgement; it’s to help analysts reach the point where their judgement matters faster.

In practice, this shifts the workflow from “what am I looking at?” to “what should I verify next?” And in a SOC, that time savings can make a real difference

Turning activity into an attack story

Individual detections rarely tell the full story. Analysts need to understand progression. How did the activity start? What changed? Which identities, systems, or services were involved? How are the behaviors connected? What might the attacker do next? 

Vectra AI’s AI threat incident analysis helps turn prioritized activity into a clearer attack story. It summarizes and analyzes incidents, connects related behaviors, maps activity to attacker techniques in the MITRE ATT&CK framework, and explains why the activity matters, giving teams a more direct path from detection to decision. 

This is where AI can reduce a significant amount of manual investigation work. Newer analysts do not have to start from a blank page. Experienced analysts do not have to spend as much time rebuilding context. Security leaders gain more confidence that the team is focused on real attacker behavior instead of isolated, potentially benign alerts. 

This matters because investigation is often where the SOC loses the most time. If manual stitching takes 60 to 90 minutes per incident, then every correlated incident summary, connected behavior, and contextual explanation helps compress the time between detection and decision.

AI your way

Not every organization is going to adopt AI in the same way. Heck, the ways my colleagues from the next (virtual) seat over and I use ChatGPT are completely different. Some teams want built-in, native AI assistance within their existing workflows. Others want to customize and build their own automations, connect their own tools, and experiment with agentic SOC workflows on their own terms. The goal is not a single path to AI adoption, but the ability to apply it in a way that fits how your SOC already operates. 

That’s where the Vectra AI SOC starter pack and the Vectra AI MCP server come in.

The open-sourced SOC starter pack gives teams a practical foundation for building AI-enabled workflows using Vectra AI context and telemetry. It allows teams to quickly set up use cases like triage, enrichment, and investigation acceleration without starting from scratch.

The Vectra AI MCP server extends that flexibility even further. It provides a standardized way to connect Vectra AI insights to broader ecosystems, enabling teams to integrate with their preferred tools, orchestrate workflows, and build custom AI-driven experiences across their security stack. Instead of being locked into a single interface or workflow, teams can bring Vectra AI intelligence into environments where they already operate. 

For mature SOC teams and security builders, this approach matters. They don’t want a one-size-fits-all AI solution or vague promises about autonomy. They want the ability to shape how AI is used, validate outcomes, and evolve their workflows over time. AI your means giving teams the control to build, extend, and integrate AI in a way that truly improves how they work.

The goal is better operations, not full autonomy

There’s a lot of pressure right now to frame AI in the SOC as a race toward full autonomy or some perfect SOC promise land. Personally, I think that misses the point.

No SOC is going to be fully autonomous right now. As much as we’d all love a “set it and forget it” button for security (preferably next to the snooze button on our alarms), security operations still require human judgement, context, and accountability. The real opportunity for AI isn’t full automation – it's augmentation. It’s about optimizing the talent teams already have, reducing the manual burden on analysts, and helping them operate at a higher level. 

That’s why I see Vectra AI’s approach as grounded in reality. 

  • AI-assisted search helps analysts move faster by translating natural language into actionable queries and insights.
  • AI threat incident analysis helps teams understand attack progression. 
  • An open-sourced starter pack and MCP server give teams a way to build, experiment, and use AI in a way that fits how they operate. 

Furthermore, these functionalities were built by security experts for security experts. Trust me; I’ve literally watched my colleagues build everything over the past few years. They are designed to help SOC teams reduce manual delay, improve confidence, and respond while attacks are still unfolding. 

That is the operational urgency behind AI in the SOC. When 43% of defenders want more time to respond, the answer cannot be another tool or capability that adds more work to the queue. AI has to help remove the delay between signal, understanding, and action – and it has to work with whatever already exists in the SOC.

At the end of the day, AI in the SOC will only matter if it improves the work analysts do every day. The means moving beyond hype and focusing on real operational problems. From where I sit, that’s where AI in the SOC should start – and where it can make the biggest impact. 

Want to hear more? Listen in on a podcast with me and my colleague here

FAQs