Integrations
SocGenie is Microsoft-only. It reads each tenant and runs approved actions through Microsoft Graph, with app consent and nothing to install. Around that sit the tools your team already uses for approvals, tickets, intelligence and billing.
How it connects
Everything SocGenie reads, deploys or changes goes through Microsoft Graph with permissions the tenant owner has consented to.
SocGenie's app is consented once in the tenant, with delegated, least-privilege permissions. Customer data stays in the customer's tenant and is read through Microsoft Graph.
No agents on endpoints, no log shippers, no middleware. Connect a tenant in minutes and run the first scan the same day.
Reading is unlimited. Anything that changes a tenant waits for a person to approve it, and the decision is written to the audit trail with the evidence behind it.
What SocGenie connects to
Grouped by the job they do in the loop. Nothing here is a placeholder: if it is listed, it works today.
The platform SocGenie is built for. Each service below is read, hardened or watched as part of the loop.
The tenant SocGenie assesses: posture checks run against its settings, and every finding carries severity, evidence and a fix.
Free and aboveSign-in, user and role data feed the posture scan, the monthly access review report and every investigation, and Conditional Access and RBAC baselines are deployed here.
Free and aboveBaseline device policies from a curated catalogue are deployed into Intune, policy by policy, and drift against them is flagged.
ZerotouchCustom detection rules mapped to MITRE ATT&CK are deployed into Defender and kept current, and the Defender assessment shows what is switched on.
ZerotouchManaged MDR customers get a Sentinel analytics-rule baseline, and every Sentinel incident is ingested and triaged by agents around the clock.
Managed MDRThe one path SocGenie uses to read a tenant with delegated consent and to run containment a person has approved.
All tiersInvestigations query the tenant's Log Analytics data so the evidence behind a verdict is in the write-up.
Managed MDRThe deployment engine behind Zerotouch: baselines are applied as code and every run is kept in history.
ZerotouchWhere a person says yes, and where the reports and pages arrive.
Approval requests land in a channel you choose, a person approves or rejects there, and the decision is written to the audit trail.
The same approval flow for teams that live in Microsoft 365, with the decision recorded the same way.
High-severity incidents page whoever is on call, using the escalation policies you already run.
Scan reports, the weekly digest and the monthly access review report arrive as PDFs in your inbox.
Events are pushed to a URL you control, so findings and incidents can reach tooling you already run.
Remediation tracked where your engineers already work.
Create a Jira ticket from any finding, so the fix is owned, scheduled and closed in the tool your team already uses.
Zerotouch and aboveThe frameworks detections are mapped to, and the sources agents consult while they triage an incident.
Every detection is mapped to a technique, the coverage view shows what you cover, and you can export it to ATT&CK Navigator.
Countermeasures are suggested for the techniques you see, so hardening follows detection.
Known exploited vulnerabilities are matched against each client, so you know which advisories matter to whom.
File, URL and IP reputation while an incident is being triaged.
Reported abuse history for the source addresses in an incident.
What an address exposes to the internet: open ports, services and banners.
Whether an address is background internet noise or something aimed at you.
A rendered look at a suspicious URL and what it loads.
Indicators of compromise shared by the abuse.ch community, matched against an incident.
Community threat pulses matched against the indicators in an incident.
Whether a user's address appears in a known breach.
There is no self-serve checkout. Paid tiers are scoped with you and activated by Reddome.
Once a paid tier is scoped on a short call, Reddome sends you a Stripe payment link.
For teams that want SocGenie's data in their own tooling.
Programmatic access to SocGenie for your own dashboards and automation, with keys stored hashed and every request scoped to your organisation.
Microsoft-only, on purpose
SocGenie does not connect to other identity providers, endpoint platforms or SIEMs. The checks, the baselines and the detections are all written for Microsoft 365, and the agents know how the platform's data fits together. That is how it stays accurate.
Questions
Free scanner coming soon
Run the free posture scan on one Microsoft 365 tenant and see findings with evidence and fixes, plus a PDF report in your inbox. Nothing to install.