# AI SOC Agent

## AI built to act, not just advise

Panther's AI SOC Agent runs on a schedule, responds to natural language queries, and takes action with complete context.

Complete Context

## Every investigation starts with evidence, not assumptions

When an alert fires, Panther automatically gathers evidence across your data lake, detection logic, alert history, and connected tools, delivering a complete investigation with a definitive risk classification before an analyst has to pull a single thread.

## Proactive Coverage

## Scheduled threat hunts that expand coverage without expanding headcount

Panther runs scheduled threat hunts across your full data lake on a cadence you configure, surfacing patterns and coverage gaps that no pre-written detection rule would have caught.

## Compounding Intelligence

## Detections that improve without an engineering backlog

Panther generates new detection rules from natural language, identifies recurring false positives, and submits tuning changes as reviewable Python code through your existing GitHub workflow.

## On-Demand Analysis

## Senior-level investigation depth, available on demand

Panther responds to natural language queries across alerts, detections, and log data, pulling live context from your connected tools via MCP so every analyst gets a complete answer regardless of experience level or time of day.

## The AI SOC Agent in action

###### AI Alert Triage

###### Recommended Actions

###### Auto-Resolve

###### Investigate Anything in Natural Language

###### Panther MCP Server

###### Automated Detection Tuning

###### Scheduled Prompts

#### AI Alert Triage

Panther AI queries your data lake, reviews detection logic, and pulls enrichment from connected tools, delivering a definitive risk classification with transparent reasoning before an analyst pulls a single thread.

## HealthEquity triages alerts in 5 minutes or less. That's Panther’s AI SOC Agent in production.

## Proof from teams who’ve been there.

- # 5 min

Faster Tier 1/2 triage

- # 85%

Reduction in total alert volume

- # 70%

Reduction in time spent on investigations

## Learn more about Panther

## Frequently asked questions

#### Can junior analysts use the AI SOC Agent effectively without deep query knowledge?

Yes. Any analyst can investigate through a natural language interface without writing SQL, PantherFlow, or any other query syntax. The agent handles the data retrieval and correlation, and returns a complete investigation with its reasoning visible.

#### How is this different from AI triage tools that layer on top of an existing SIEM?

Panther's agent runs inside the platform with native access to your data lake, detection logic, and alert history. This allows for improved detection over time rather than just speeding up how quickly an analyst reviews an alert.

#### How does the agent improve detections over time?

When the agent identifies a pattern that's generating false positives, it traces the issue back to the specific Python rule responsible and proposes an edit as reviewable code through your existing GitHub workflow.

#### What tools can Panther's AI SOC Agent connect to through MCP?

The agent connects to GitHub, PagerDuty, Atlassian, Notion, Okta, Slack, and other tools your team already uses.

#### How does Auto-Resolve work, and what controls does my team have over it?

When the agent's risk classification falls below a configured threshold, the alert closes automatically with a full audit trail.

#### What is Panther's AI SOC Agent, and how is it different from an AI triage feature?

The AI SOC Agent investigates alerts rather than accelerating review processes, facilitating a complete risk classification with context.
