惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
月光博客
月光博客
博客园 - 司徒正美
爱范儿
爱范儿
aimingoo的专栏
aimingoo的专栏
量子位
Recent Announcements
Recent Announcements
V
V2EX
P
Proofpoint News Feed
小众软件
小众软件
云风的 BLOG
云风的 BLOG
腾讯CDC
宝玉的分享
宝玉的分享
Microsoft Azure Blog
Microsoft Azure Blog
大猫的无限游戏
大猫的无限游戏
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
B
Blog
博客园_首页
GbyAI
GbyAI
博客园 - Franky

SentinelOne

The Good, the Bad and the Ugly in Cybersecurity – Week 35 Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who's Exploiting Your Perimeter The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity The Good, the Bad and the Ugly in Cybersecurity – Week 34 The Good, the Bad and the Ugly in Cybersecurity – Week 33 The Good, the Bad and the Ugly in Cybersecurity – Week 32 From Input to Impact: Secure AI Where It Runs The Good, the Bad and the Ugly in Cybersecurity – Week 31 The Good, the Bad and the Ugly in Cybersecurity – Week 30 Your Best Analyst Shouldn't Be a Person. It Should Be a Capability Everyone Can Summon. Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage The Agentic SOC: Transforming Data into Defensive Velocity The Good, the Bad and the Ugly in Cybersecurity – Week 29 The Good, the Bad and the Ugly in Cybersecurity – Week 28 The Good, the Bad and the Ugly in Cybersecurity – Week 24 The Good, the Bad and the Ugly in Cybersecurity – Week 23 SentinelOne + Claude: Integrations for AI Visibility, Governance, and Defense The Good, the Bad and the Ugly in Cybersecurity – Week 22 The Good, the Bad and the Ugly in Cybersecurity – Week 21 Sentinels League 2026: Live Rankings for the Threat Hunting World Championship Turn Blind Trust into Verified Control with Prompt Security for Agentic AI SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain Breaking the Black Box: A Case Study in Red-Teaming a Government Education AI Living Off the Pipeline: Defending Against CI/CD Subversion The Good, the Bad and the Ugly in Cybersecurity – Week 20 The Good, the Bad and the Ugly in Cybersecurity – Week 15 Edge Decay: How a Failing Perimeter Is Fueling Modern Intrusions The Good, the Bad and the Ugly in Cybersecurity – Week 14 Securing the Supply Chain: How SentinelOne®’s AI EDR Stops the Axios Attack Autonomously The Identity Paradox: The Hidden Risks in Your Valid Credentials
From Triage Grind to Strategic Operator: The New AI SOC C...
SentinelOne · 2026-07-22 · via SentinelOne

AI is absorbing the volume work that makes up the fundamental architecture of the Security Operations Center (SOC) tier system. While the tiers and the work aren’t going away, a junior and senior analyst’s day-to-day is changing fast.

At some point in the last week, every analyst on your team made the same call. Close an alert uninvestigated, because the queue was too long and triage ate the time real investigation and deep analysis was needed. Most of those calls were right, but odds are that at least one critical threat will eventually be overlooked.

The root cause here is the mathematical disparity. Nearly half of SOC teams lack the capacity to investigate more than fifty percent of the alerts they generate daily. Analyst capacity grows linearly while data volume compounds exponentially.

According to findings from SentinelOne®’s Annual Threat Report, what’s worse is that the math leans heavily towards the adversaries. Automated exploits have been recorded escalating privileges within a target environment in approximately 30 milliseconds. Similarly, malicious attack chains can progress from initial network access to establishing persistent footholds in under 50 seconds. No manual workflow currently matches these kinds of machine speed tempos.

As a result, the traditional tier structure of the SOC is transforming in real time. AI is already absorbing the triage and correlation work that that structure was originally built to manage. The critical call-out here is understanding that these tiers are not dissolving; rather, they are evolving. Junior and senior analysts still exist and hold their titles, and continue to have a clear career path ahead of them. What’s changing is the nature of the tasks that fills their day.

Analyst Tiers, Redefined by Depth

Historically, the distinctions between Level 1, Level 2, and Level 3 analysts were established primarily to manage high-volume workloads. Those distinctions were built to manage volume: Alerts routed to the right skill level, junior analysts escalating what they couldn’t resolve, senior time reserved for what actually needed it. AI now handles the triage and correlation volume those tiers existed to manage. Volume stops being the variable that defines the role. As a result, analyst tiers are being redefined by depth of expertise rather than the ability to process large queues.

That evolution isn’t limited to junior and senior analysts:

  • Threat intel analysts move from manual feed correlation to directing AI-correlated intelligence
  • Security engineers move from manual rule-writing to guiding AI-generated detection logic
  • SOC managers move from tactical management to strategic leadership and AI governance

Depth of expertise replaces volume as the key differentiator: cloud architecture, identity, adversarial tradecraft. The kind of judgment that only comes from watching an environment long enough to know what normal looks like. AI can’t replicate nuanced, environment-specific skills that the legacy, volume-driven tiered system was never able to encourage or reward.

A Day in the Life, Before and After

In the legacy model, an analyst’s day typically begins by facing a queue containing hundreds of unvetted overnight alerts. Three or four hours go to manual triage, pivoting between tools to reconstruct what happened. The vast majority of the queue closes as false positives. The real threat, if there is one, surfaces hours later, pieced together across five or more disconnected consoles.

Adding in the administrative paperwork widens the gap even further. The legacy model requires analysts to spend upwards of an hour writing an incident report that adds nothing to the actual technical investigation. The new model allows the analyst to review and approve an AI-generated summary, adds environment-specific context, and closes the case in minutes.

In a modern model, the day starts with a prioritized queue instead of a noise wall: evidence-backed verdicts already assembled, ready for review. Thirty minutes go towards confirming the highest-priority case. That confirmation triggers a pre-approved response workflow within defined policy. Critical hours that were parcelled off to triage are used for proactive threat hunting instead.

Teams operating this way report the difference in hard numbers, according to two IDC research studies commissioned by SentinelOne.

  • Teams using AI-powered investigation report 63% faster threat identification and 41% more efficient investigation. (IDC Business Value of Purple AI®, July 2025)
  • AI SIEM customers on the Singularity™ Platform report 55% more efficient security operations and 4x more threats handled, at 55% lower solution costs. (IDC Business Value of Singularity AI SIEM, May 2026)

That time moves to where the judgment actually matters.

Governance is the New Core Skill

Recovered time only pays off if real judgment fills it. The most important judgment now is knowing when to distrust the AI.

The analyst who knows exactly where their AI is unreliable is more operationally effective than the one who trusts it uniformly. That skepticism is a skill and it has to be built on purpose, case by case.

Four capabilities define the analyst role going forward:

  • Validating AI output instead of accepting it by default
  • Designing the automation workflows that execute at machine speed
  • Forming hypotheses worth hunting instead of only answering tickets
  • Translating what the AI found into what it means for the business

Escalation frameworks must be designed to reflect that same judgment. Teams building trust in a new workflow route more cases to a human by default. Mature teams narrow that escalation path as their confidence in specific alert types grows. Either way, the analyst decides where the line sits, not the AI.

On top of this, analysts must govern the response earlier, setting the policy before events are triggered instead of reacting to it. Every automated action is scoped to a policy an analyst defined in advance. This keeps all of the details of the logged and fully auditable after the fact. The quality of what fires automatically traces back to the quality of that workflow.

The Career Path Forward

The evolution we are seeing in SecOps is directly addressing systemic issues of burnout and attrition, both significant risks to retaining talent within the cybersecurity industry. Under an AI-augmented model, every rung on the SOC career ladder gets more strategic:

  • Junior analysts move from manual triage to verdict review
  • Senior analysts move from reactive response to strategic hunting
  • Managers move from daily firefighting to designing the system everyone else works inside

None of this happens in one leap. Adoption works crawl-walk-run, workflow by workflow. ‘Crawl’ starts with AI-assisted triage, validated against your own judgment, alert by alert. ‘Walk’ enables automated responses for well-understood, lower-risk cases, with human approval required for anything novel. ‘Run’ hands full workflows to AI for established threat patterns, with analyst time going to verdict review and hunting. Different parts of a SOC can sit at different stages of that maturity at the same time.

Start with the First 90 Days in the AI SOC checklist, a concrete plan for the next ninety days. For the full argument behind it, check out the Analyst’s Guide to the Autonomous SOC and see how SentinelOne is building toward this model.

Third-Party Trademark Disclaimer:

All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third-party.