AI SOC Solution Release 26.2.0
ai soc 26 2 0 adds agentic investigation and improves analyst workflows with clearer progress feedback and regeneration options what's new in this release? this release expands ai soc investigation capabilities and adds new enrichment, case management, and playbook building improvements ai soc solution ai soc 26 2 0 introduces agentic investigation and improves analyst workflows with clearer progress feedback and regeneration options agentic investigation extends ai soc beyond analyst driven generate plan workflows on a case management record, set analysis mode to autonomous under agentic investigation data on the support tab (or on the case analysis metadata column), then click re investigate in ai alert analysis to start the analysis agent on the record the agent generates and runs investigation plan steps without requiring an analyst to initiate each phase manually for the analyst workflow and record controls, see case management (case) docid\ sdpesft6lsyz0zfrn hok teams can also scale agentic triage through signal routing rules after solution import, create a routing rule and associate the packaged playbook ai soc trigger analysis agent via routing rule , which calls the ai soc trigger analysis agent component to invoke the analysis agent when a rule matches this supports use cases such as first seen alert types, overnight ingestion, and high volume queues where manual plan generation is not practical for playbook requirements and configuration, see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi additional 26 2 0 ai soc improvements include progress detail β real time status messages during generate plan, remediation plan generation, regeneration, and agentic runs, so analysts see what the agent is working on instead of a generic wait state see case management (case) docid\ sdpesft6lsyz0zfrn hok regenerate β regenerate investigation plan, regenerate remediation plan, and recreate playbook when results need refinement without restarting the full investigation see investigation plan workflow docid\ bde8p71mmp2lbymuzuooi and creating automation docid\ wjpjto3fjno0jio1dyv3s manual path unchanged β analysts can still use manual analysis mode and step through plans interactively when review is required see getting started docid\ p7qjquayekczhpxeppwcp n+1 playbook run details β when a routing playbook runs for a subsequent alert, the ai alert analysis panel displays the playbook run details on the case management record so analysts can review the execution without permission to open playbook runs the ai soc collect playbook execution data component supplies these execution details see creating automation docid\ wjpjto3fjno0jio1dyv3s urlscan threat intelligence β added url and domain enrichment through the urlscan connector, asset, and enrich urlscan enrich observable (vic) component see configure threat intelligence enrichment docid wafaim1sg 7z1uzmvr p actionable invalid observable notifications β notifications now identify the case management record that received an invalid observable and link back to that case see case management (case) docid\ sdpesft6lsyz0zfrn hok mitre att\&ck links β tactic and technique names and ids in mitre att\&ck references now link to their corresponding mitre pages see case management (case) docid\ sdpesft6lsyz0zfrn hok linked cases β relate case management records with parent case and child cases , then use sync from parent case or sync to child cases to synchronize classification, manual verdict, status, and owner see case management (case) docid\ sdpesft6lsyz0zfrn hok action required when upgrading existing investigation playbooks if you created an investigation playbook with ai soc content earlier than 26 2 0 and retain that playbook after upgrading the content, add ai soc collect playbook outputs immediately before the verdict component set playbook run id to $run id this component collects outputs from successful actions in the current playbook run without it, a playbook that calls multiple components inside a loop may pass only the last component output to hero ai, resulting in an incomplete or incorrect verdict new playbooks created from ai soc 26 2 0 content already include this component for configuration and troubleshooting, see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi , understanding verdict generation docid\ bnyc263ysl2bmajhbaiob , and troubleshooting docid\ cknuxqv85k9lu0ocqv218 in the ai soc solution user guide addressed issues ai soc generate plan returned inconsistent plans for the same input β fixed an issue where ai soc generate plan produced different investigation plans for the same alert details and payload on repeated runs generate plan now returns more consistent plans for equivalent inputs