TL;DR

Alert triage is how a SOC decides which alerts are real and which aren't. An analyst groups related signals, gathers context on the user and host, judges risk, follows the evidence, and records a disposition. Dropzone AI builds AI agents that do the first pass under the agentic SOC model, handing analysts a verdict with evidence and a guided recommendation for what to do next.

Every SOC runs triage, and it has always been this way. Alerting and triage are run by close to 100% of the SOCs surveyed (SANS SOC Survey 2026). It is also where the shift gets spent.

What is alert triage?

Alert triage is the first pass over the alert queue: deciding which signals are real, which matter, and which need a full investigation. It exists because alerts have always outnumbered the hours available to work them.

In practice it means five things:

  • Grouping related alerts so you're looking at one story instead of nine signals
  • Gathering context on the affected systems, the user, and what changed recently
  • Scoring risk against business impact and what the attacker could reach next
  • Following the evidence far enough to separate malicious from benign
  • Recording the reasoning, and whether the alert was closed or escalated

The record is what an auditor reads a year later.

Why alert triage is the bottleneck

Detection works. It finds more than a team can get to, and that is the problem because the queue is longer than the hours available to work it. Investigation is where the time still goes, because that is the part where human hours go in and nothing scales them.

The staffing picture is the constraint. 88% of respondents say their organization experienced at least one significant cybersecurity consequence because of a skills deficiency, and 48% report feeling exhausted from trying to stay current with threats and emerging technologies (ISC2 Cybersecurity Workforce Study 2025).

Institutional knowledge walks out regularly too, with typical SOC tenure running three to five years (SANS SOC Survey 2025). Every departure takes with it the sense of what's normal in your environment, which is the thing triage depends on most.

Tooling hasn't closed the gap. 79% of respondents now use AI or machine learning tools, but only 36% have built them into a defined workflow (SANS SOC Survey 2026). The capability arrived faster than the operating model for it.

What a tier 1 analyst actually does on one alert

A tier 1 analyst picks up an impossible-travel alert. The first question is whether anyone got in: did the authentication succeed, and how was multi-factor authentication (MFA) satisfied. A fresh challenge the user answered, or a claim carried in on a token that had already been issued. A failed sign-in from an impossible location is a non-event. A success where nobody was actually challenged is the case worth the afternoon.

Then the benign explanation, which is usually that the location is simply wrong. A corporate virtual private network (VPN) egress, a consumer VPN on a phone, iCloud Private Relay, a carrier gateway three states from the user, a stale geolocation record. Most of the time it's one of those, and the alert ends there.

When it isn't, the checks fan out. The device, and whether it's managed. The IP reputation, which is a second tool, and which comes back clean when the address belongs to a residential proxy network. Knowing to discount that answer is its own skill. Then what the session did after authenticating: new inbox rules, mail forwarding, an OAuth app consent grant, a newly registered MFA method, files pulled in bulk. That's the audit log in the mail platform, which may or may not be in the security information and event management (SIEM) system. Somewhere in here the analyst messages the user to ask whether they were in Madrid on Tuesday. If anything looks wrong, they check whether the same pattern touched anyone else.

That's four or five tools and a direct message for one alert, and most of the time the answer is that the geolocation was wrong. The analyst writes it up, closes it, and picks up the next one.

Knowing which of those checks matters for this alert type, and knowing when an answer that came back clean isn't, is judgment that takes years to build. Repeating the lookups themselves requires none of that. The work is repetitive and context-switching heavy, and that is where the shift goes.

How an AI SOC analyst works the same alert

An AI SOC analyst is an AI agent that runs that first pass end to end. Take the same impossible-travel alert:

It gathers the context all at once. The agent queries the identity provider, the endpoint tool, the IP reputation source and the SIEM at once, through the integrations already in place. Dropzone AI's agents connect through 90+ integrations, which means the data stays where it lives and nothing gets shipped out to be normalized first.

It reasons about a scenario nobody wrote down. A playbook branches too, and it works well when you already know the scenario. What it cannot do is handle the one nobody anticipated, because every branch in it had to be written in advance.

An AI agent reasons about the alert in front of it. If the login succeeded and MFA was satisfied from a known device, that is one path. If the device is unknown and the session immediately enumerated mailbox rules, that is another, and the agent takes it without anyone having scripted it first. That is the line between an agent and a security orchestration, automation and response (SOAR) playbook.

It reaches a verdict and shows its work. The output is a determination with the evidence chain that produced it, and a guided recommendation for what to do next, rather than a score. The analyst is going to want to see how the agent reached that verdict, so they can decide whether they agree with it.

On this alert that reads roughly as follows. Benign, with the evidence attached. The second location resolves to the corporate VPN egress in Frankfurt. The login succeeded with MFA satisfied from the user's enrolled laptop.

The session made no mailbox rule changes and touched no new hosts, and no other account authenticated from that address in the window. An analyst can open any one of those lines, check it in the source tool, and disagree.

It stops where you told it to stop. Analysts set the bounds on which response actions the agent may take on its own, and widen them as the agent earns trust. Where those bounds sit is a decision each SOC makes for itself, and anything outside them comes to a person.

The result customers report is coverage rather than speed alone. Assala Energy reports 100% of alerts investigated and 70% fewer false positives. Indiana Farm Bureau Insurance reports 75% less manual investigative work, with verdicts in under 10 minutes from alert to determination. Across deployments the average reduction in manual alert investigation is 95%.

The comparison worth making is against the alerts that weren't getting investigated at all, not against a hypothetical analyst working every alert carefully.

Where the analyst still decides

Analysts own the verdict, and that is a design constraint rather than a courtesy.

Analysts decide which response actions the agent may take alone, and revisit that as evidence comes in. They own the determination, and the evidence chain is what lets them check the agent's reasoning before they agree with it. And they teach the environment, because the business context that makes an alert routine in your organization and serious in another is knowledge the agent has to be given.

What changes for a tier 1 analyst is that the queue arrives investigated. What's left is the work where a person's judgment changes the outcome: the ambiguous case, the exception, the call that carries consequences. The job doesn't disappear. It gets elevated.

How do you measure whether alert triage got better?

Pick metrics that can't be satisfied by closing tickets faster.

Mean time to investigate (MTTI) is the one triage owns. The clock starts when an analyst or an agent picks the alert up, and stops when a defensible verdict is recorded, true positive escalated or false positive ruled out, with the evidence and a response plan ready. It reads analyst throughput cleanly, and it's the part of the workflow agents change most.

Mean time to conclusion (MTTC) is worth measuring alongside it. It covers the full clock, from the first observable malicious event through to a verdict with a response plan attached, so it tells you what the whole pipeline did rather than what triage alone did.

One caution on the acronym: MTTC has two expansions in active use, mean time to conclusion and mean time to contain, and they measure different things, so name which one you mean before you report it. Our guide to mean time to conclusion works through the full clock model.

‍Mean time to acknowledge (MTTA) is the earliest queue signal and one of the easiest metrics to game. Track it, but never as the headline.

‍Investigation coverage is the share of alerts that got a real investigation with a record behind it. It's the number that exposes the problem triage is meant to solve, and it's also the one most SOCs can't currently answer, which is itself the finding. Its companion is alerts closed without an investigation record, worth counting directly. If that number is large, the other metrics are measuring the wrong thing.

Whichever clock you report, report it three ways. Dropzone AI's own dashboards carry the mean, the median and the 95th percentile for each metric. The 95th percentile is the one worth watching, because it shows the slowest investigations rather than the typical ones, and those are the cases where an attacker had the most time.

Key takeaways

  • Triage is universal and it's where the shift goes. Nearly every SOC surveyed runs alerting and triage (SANS SOC Survey 2026).
  • Investigation is the constraint, not detection. Detection finds more than a team has the hours to work.
  • A tier 1 analyst crosses four or five tools on a single alert, and most of the time the answer is benign.
  • An AI SOC analyst runs that first pass end to end. It gathers context all at once, reasons about scenarios nobody scripted, and hands over a verdict with evidence and a guided recommendation.
  • Analysts set the bounds and own every verdict. Which response actions the agent takes on its own is a decision each SOC makes for itself.
  • Measure MTTI, MTTC and investigation coverage. Treat MTTA carefully, and say which MTTC you mean.

See it on your own alerts

Dropzone AI's AI SOC Analyst investigates every alert end to end and delivers a verdict with the evidence chain and the recommendation already attached, across the tools your SOC already runs.

Try the self-guided demo, or read the AI SOC Team Playbook for how the agent roles divide the work.

‍

Sources: SANS SOC Survey 2025; SANS SOC Survey 2026; ISC2 Cybersecurity Workforce Study 2025. All linked in full above.

FAQ

Who does alert triage, and at what tier?

Tier 1 analysts carry most of it, escalating to tier 2 when an alert needs deeper work. That split is why triage dominates a SOC's hours. It's the highest-volume task assigned to the least experienced analysts, and the checks are the same every time. It's also why the first pass is the part an agent can take without touching the judgment calls above it.

How long should triaging an alert take?

It depends entirely on the alert type and how many tools the analyst has to cross to answer it. The elapsed time is mostly context-switching rather than analysis. Indiana Farm Bureau Insurance reports verdicts in under 10 minutes from alert to determination using Dropzone AI's agents.

Can alert triage be automated?

The first pass can. An AI SOC analyst gathers context all at once, then follows the evidence where it leads and produces a verdict with the evidence chain attached. What doesn't automate is ownership. The determination is signed by an analyst, and the bounds the agent works inside are theirs to set.

What's the difference between an AI SOC analyst and a SOAR playbook?

A SOAR playbook runs a sequence somebody wrote in advance. It branches, and it works well for the scenarios you anticipated, which is a job worth keeping. What it can't do is work a scenario nobody wrote down. An AI SOC analyst reasons about the alert in front of it, including one nobody anticipated, and can explain the path it took.

Which metric best shows that triage improved?

Mean time to investigate, the span from an analyst or agent picking the alert up to a defensible verdict with a response plan ready, paired with investigation coverage. Treat mean time to acknowledge carefully, because the metric is easy to game. If you use mean time to conclusion, say whether you mean conclusion or containment.

Self-Guided Demo

Test drive our hands-on interactive environment. Experience our AI SOC analyst autonomously investigate security alerts in real-time, just as it would in your SOC.
Self-Guided Demo
A screenshot of a dashboard with a purple background and the words "Dropzone AI" in the top left corner.