An incident fires in Microsoft Sentinel in one of your customer tenants. It might be an unfamiliar sign-in, a new inbox forwarding rule or a risky consent grant. SocGenie ingests it the moment Sentinel raises it, whatever the hour.
An agent starts reading. It pulls the sign-in history, device compliance state, MFA methods and mailbox rules for the accounts involved. It checks every indicator against threat intelligence sources such as VirusTotal, AbuseIPDB, GreyNoise and urlscan, and maps what it sees to MITRE ATT&CK. It looks for similar incidents across your fleet, because the same campaign rarely stops at one tenant.
The agent writes up the case in plain English: what happened, what the evidence shows and what it means. If containment is warranted, it proposes the exact actions, such as revoking sessions, disabling the account or removing the forwarding rule.
Then it stops. The proposal goes to the approval channel in Slack or Microsoft Teams and to the portal, and PagerDuty reaches whoever is on call. A Reddome analyst reviews the case, and your team can weigh in too. Someone approves, rejects or asks for more. Until a person says yes, nothing in the tenant changes.
On approval, the action runs through Microsoft Graph. The incident, every tool call, the proposal, the decision and who made it are written to the audit trail. You can watch it live, replay it later, and the outcome feeds the SOC metrics and the weekly digest.