---
title: AI SOC Solution
slug: ai-soc-solution
docTags: 
createdAt: 2026-02-03T00:00:00.000Z
---

The **AI SOC Solution** is a ready-to-use security operations workflow that demonstrates how Turbine components work together in a real-world scenario. It combines alert and phishing triage, threat intelligence enrichment, and case and incident management with **Hero AI**–powered analysis, investigation plans, and verdicts.

## Why Start with a Solution?

Solutions are pre-configured end-to-end use cases that help you:

- **Learn Turbine faster** - See how components, playbooks, and applications integrate
- **Save time** - Get productive faster with pre-built automation
- **Follow best practices** - Learn from working examples
- **Reduce errors** - Use established, tested workflows

## What AI SOC Includes

The AI SOC Solution provides:

- **Alert Triage** - Ingest and process alerts from SIEM, XDR, EDR, or other sources
- **Phishing Triage** - Process reported phishing emails
- **Threat Intelligence Enrichment** - Automatically enrich observables with threat intelligence
- **Case and Incident Management** - Central application for managing signals, cases, and incidents
- **Signal Routing Rules** - Route signals to playbooks automatically based on conditions
- **AI Ingestion** - Build connector and ingestion components from OpenAPI specs with Hero AI–assisted TEDS mapping; use the AI Ingestion application to add new alert sources
- **AI-Powered Analysis** - Hero AI generates investigation plans and verdicts

## Getting Started

To install and configure the AI SOC Solution, see the latest documentation:

- [AI SOC Solution](docId\:DDizyEIQevgzG8Ay0FCc5) — Overview, key capabilities, and next steps
- [Installing and Configuring AI SOC Solution](docId:_b7njxu5XnzYrjCnGQg5J) — Install, configure assets, Hero AI, and ingestion playbooks
- [AI SOC Ingestion](docId:0p9Qwz3o-0J5DNkPJUGmq) — Build connector and ingestion components from OpenAPI specs

## Next Steps

After trying the AI SOC Solution:

1. Complete [Installation and Configuration](https://docs.swimlane.com/solutions/installing-and-configuring-ai-soc-solution), then follow **Getting Started** for your first signal investigation
2. Use [AI SOC Applications](docId\:UOSUZRpSl6hFe9d6Br5az) to learn the record layout (Signal Triage, Case Management, routing rules, and more)
3. Use [Operations and Guidance](docId\:DsdGtAQeg95DSeAF2Iat-) for day-to-day workflows (claim, verdict, escalate, triage rules, playbooks)
4. For dashboards, reports, troubleshooting, and examples, see the [AI SOC Solution](https://docs.swimlane.com/solutions/ai-soc-solution#next-steps) next steps table
