AI SOC for MSSP Release Notes
ai soc for mssp is a new ai soc offering for managed security service providers that run ai soc across multiple customer environments each client tenant keeps full ai soc workflows—ingestion, triage, investigation, and case handling a central tenant receives synchronized cases, threat intelligence artifacts, and periodic soc reporting aggregates so mssp analysts can oversee every customer in one place the offering ships as two packages that work with ai soc core in each client tenant ai soc mssp client extension runs in the client tenant ai soc mssp central solution installs in the central tenant case management records and soc reporting aggregates sync over the central ingest webhook full threat intelligence artifact cache records sync over the swimlane api client teams continue day to day work in their own tenant central visibility complements local case management; it does not replace it overall, ai soc for mssp helps mssps scale ai soc with centralized visibility while keeping customer workflows isolated in each client tenant requires ai soc core solution (26 2 0 or later) in each client tenant for more information, see getting started for mssp docid\ ivvy6gxajwc34xvmnnqc and configure ai soc for mssp docid\ azfpz c qlu3elvszkllw central oversight review cases across clients mssp analysts can review synchronized cases from every client tenant in one central case management application each central case includes the client name and a link back to the originating client tenant record you can filter by customer and open the source case when investigation or response is needed in that tenant for more information, see work with central case management https //docs swimlane com/solutions/use ai soc for mssp central#work with central case management in use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq compare threat intelligence across clients the central tenant maintains a threat intelligence artifact cache of full artifact records synced from client tenants use the cache to compare observables across customers, confirm enrichment state, and request client side re enrichment when central data is stale this comparison assumes threat intelligence vendors are the same across client tenants for more information, see work with threat intelligence artifact cache https //docs swimlane com/solutions/use ai soc for mssp central#work with threat intelligence artifact cache and request client side re enrichment https //docs swimlane com/solutions/use ai soc for mssp central#request client side re enrichment in use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq report mttd and mttr across clients the central soc reporting workspace provides cross client aggregates for cases , mttd , and mttr case aggregates are further grouped by report criteria such as severity, verdict, mitre techniques, signal source, owner, and cases closed by hero ai mttd and mttr are grouped by signal source reporting uses new (past week) and total (near full history) spans dashboards default to a current week filter, except trend lines client reporting playbooks generate aggregates in the client tenant and post them to the same central webhook used for case sync for field definitions and the sunday filter workaround, see work with central soc reporting https //docs swimlane com/solutions/use ai soc for mssp central#work with central soc reporting in use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq , and known limitations action required complete client setup after you install the client extension after you install ai soc mssp client extension, complete these client tenant steps so sync works as designed include the tia central sync fields applet on the client threat intelligence application (support tab, threat intelligence metadata) without it, central threat intelligence artifact cache create and update can fail when writing required metadata fields in the core playbook ai soc main, disable the enrich tia record (create) flow only do not disable the playbook this keeps the client from re enriching observables that already exist in the central threat intelligence artifact cache then configure the client ai soc tenant configuration asset (client pat) and the two mssp sync assets ai soc mssp client configuration and ai soc mssp central sync for procedures, see accept get application fields schema overwrite https //docs swimlane com/solutions/getting started for mssp#accept get application fields schema overwrite and install in the required order https //docs swimlane com/solutions/getting started for mssp#install in the required order in getting started for mssp docid\ ivvy6gxajwc34xvmnnqc ; include tia central sync fields https //docs swimlane com/solutions/configure ai soc for mssp#include tia central sync fields and disable enrich tia record in ai soc main https //docs swimlane com/solutions/configure ai soc for mssp#disable enrich tia record in ai soc main in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw ; and onboard a client tenant docid\ fgkw7if8vsr9 hchdexus when you add another client known limitations the following behaviors are documented constraints for this release see the linked user guide topics for workarounds and setup steps central soc reporting current week filter on sundays central soc reporting dashboards default to a current week filter (except trend lines) that filter uses the viewer's local timezone reporting timestamps are stored in utc at midnight ( 00 00 00 ) on the day the weekly job runs on sundays, the current week filter can return no results even when data exists on central soc reporting workspace dashboards, change the current week date filter to a custom range that includes the report timestamps, or check again after sunday in your timezone new is the last week of aggregates; total is near full history see work with central soc reporting https //docs swimlane com/solutions/use ai soc for mssp central#work with central soc reporting in use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq get application fields schema overwrite on client extension install when you install ai soc mssp client extension in a tenant that already has ai soc core solution, the installer may prompt to overwrite the get application fields schema component accept that overwrite do not skip or deselect this component ai soc core does not use this component for client workflows a later core package will remove it see accept get application fields schema overwrite https //docs swimlane com/solutions/getting started for mssp#accept get application fields schema overwrite in getting started for mssp docid\ ivvy6gxajwc34xvmnnqc tiac tracking id gaps when observable is unique the observable field in threat intelligence artifact cache must remain unique do not remove that uniqueness constraint when observable is unique, tracking id numbers may not be assigned sequentially some id numbers may be skipped if the system encounters duplicate observable values during record creation this does not indicate data loss; skipped ids correspond to suppressed duplicate entries see tracking id gaps when observable is unique https //docs swimlane com/solutions/use ai soc for mssp central#tracking id gaps when observable is unique in use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq