Autonomous SOC Workflow
Stellar Cyber Autonomous SOC brings together AI-driven capabilities to help you investigate security activity, analyze alerts and cases, reach triage conclusions, and determine what to investigate or do next. It uses a human-augmented approach in which AI performs portions of investigation, enrichment, summarization, and triage while you review the evidence, validate its conclusions, pursue additional investigation, and decide what response to take.
The AI analysis is designed to be transparent. When Stellar Cyber reaches a conclusion, such as assigning a verdict to an alert, you can review the findings and supporting evidence used to reach that conclusion. This lets you understand why the AI reached a particular result, verify it against the underlying security data, and make your own judgment before acting.
Note that Autonomous SOC is not a single feature or workflow. It includes six related capabilities that support different parts of security operations:
-
AI Investigator provides a built-in AI experience for investigating security data in the Stellar Cyber Platform using natural language.
-
Stellar Cyber MCP Server connects an external MCP-compatible AI client to Stellar Cyber data and case-management workflows.
-
AI Case Analysis and Summary analyzes information already associated with a case and adds AI-generated narratives, hypotheses, summaries, and response guidance to the Case Detail view.
-
Alert Auto Triage investigates alerts associated with cases, enriches the investigation with additional evidence, and assigns alert verdicts before analyst review.
-
AI Assistance lets you investigate an analyzed case interactively by asking questions in natural language about the case and the evidence assembled by Alert Auto Triage.
-
Phishing Auto Triage performs specialized analysis of user-reported phishing email and assigns a verdict.
Together, these capabilities provide two complementary ways to incorporate AI into security operations. You can interact with security data through an AI client, either within or outside the Stellar Cyber Platform, and you can use AI-driven analysis to reduce the manual work involved in investigating alerts and cases.
Before You Begin
Autonomous SOC capabilities differ in deployment availability, licensing, and enablement requirements. Review the following information to determine which capabilities are available for your deployment.
| Capability | Deployment | License | Must Be Enabled |
|---|---|---|---|
| AI Investigator | SaaS only | Included with a valid platform license | Yes |
| Stellar Cyber MCP Server | SaaS and on-premises | Included with a valid platform license | No |
| AI Case Analysis and Summary | SaaS and on-premises | Included with a valid platform license | Yes |
| Alert Auto Triage | SaaS and on-premises | Add-on license for SaaS, Early Access Program for on-premises | Per case queue |
| AI Assistance | SaaS and on-premises | Included with Alert Auto Triage | No |
| Phishing Auto Triage | SaaS only | Add-on license | No |
AI Assistance is part of Alert Auto Triage. It has the same deployment availability and licensing requirements and is not licensed separately.
Add-on licenses are available from your Stellar Cyber Partner Support representative, with trial licenses offered for evaluation.
In on-premises deployments, AI Case Analysis and Summary, Alert Auto Triage, and AI Assistance are available through the Early Access Program. To enroll, contact your Customer Success representative. Phishing Auto Triage and AI Investigator are not available in on-premises deployments. ![]()
AI-assisted capabilities send security context to an external Large Language Model provider for processing. Before you enable these capabilities, review AI Data Processing and Residency for Agentic LLM Features to see what information each capability sends, how Stellar Cyber anonymizes personal information, and which regions support AI processing. Support varies by region, and the region that stores your data is not always the region where AI processing occurs.
Connectivity Requirements for On-Premises Deployments
AI-based analysis in on-premises deployments uses Stellar Cyber cloud-hosted AI services. Your deployment must be able to reach genai.stellarcyber.cloud on TCP port 443.
AI-based analysis is not available in air-gapped deployments. Without outbound connectivity to the Stellar Cyber cloud AI services, AI Case Analysis and Summary, Alert Auto Triage, and AI Assistance cannot operate.
Raw telemetry remains in your deployment. Stellar Cyber prepares minimized, anonymized context locally and sends it over an encrypted TLS connection to the Stellar Cyber cloud AI services for processing. Your deployment does not communicate directly with the external Large Language Model. For details, see AI Processing and Data Flow.
Use AI Inside or Outside the Stellar Cyber Platform
Stellar Cyber provides two ways to use an AI client as part of an investigation. AI Investigator provides the AI experience within the Stellar Cyber Platform. The Stellar Cyber MCP Server lets you use an external MCP-compatible AI client with Stellar Cyber data and workflows.
The two capabilities are complementary rather than two interfaces to the same functionality. Use AI Investigator for open-ended investigation of security data within the Stellar Cyber Platform. Use the MCP Server when you want an external AI client to perform supported operations with Stellar Cyber data, with current capabilities focused primarily on case review and case management.
Investigate Security Data with AI Investigator
AI Investigator is the built-in AI client experience in the Stellar Cyber Platform. Enter questions and investigative requests in natural language and AI Investigator converts them into structured queries against the data lake, retrieves the relevant security records, and helps you interpret the results.
Use AI Investigator when an investigation needs to extend beyond the boundaries of an individual case. For example, you can investigate activity involving a particular user or host, look for related events elsewhere in the environment, or follow a hypothesis across the security data available to Stellar Cyber.
This approach lets you investigate large volumes of security data without first spending time to construct the underlying query manually. You can move from a natural-language question to the relevant security records more quickly while retaining access to the underlying data for further investigation and validation.
Work with Stellar Cyber from an External AI Client
The Stellar Cyber MCP Server is an integration layer between an MCP-compatible AI client and the Stellar Cyber Public API. It lets an external AI client interpret natural-language requests, select the appropriate supported operations, retrieve Stellar Cyber data, and present the results in a conversational form.
Current MCP Server capabilities focus primarily on case management. Depending on the permissions assigned to your API key, you can use an external AI client to find cases, retrieve case details, examine related alerts and observables, review investigation context, and update selected case fields such as status, severity, assignee, and tags.
This lets you incorporate Stellar Cyber case review and handling into an AI client you already use without building a separate custom integration for each supported operation. Access remains governed by the permissions and tenant scope of the Stellar Cyber API key that the AI client uses so that it operates within the access you authorize.
Use AI Investigator when you want an AI-assisted investigation within the Stellar Cyber Platform. Use the MCP Server when you want an external MCP-compatible AI client to work with supported Stellar Cyber data and workflows.
See Using the Stellar Cyber MCP Server.
Use AI to Analyze Alerts and Cases
Four Autonomous SOC capabilities apply directly to analyzing alerts and cases: AI Case Analysis and Summary, Alert Auto Triage, AI Assistance, and Phishing Auto Triage.
The first three work together as part of a human-augmented case-analysis workflow. AI Case Analysis and Summary helps you understand the information associated with a case. Alert Auto Triage performs additional investigation, presents the findings and supporting evidence, and assigns verdicts to the alerts in the case. AI Assistance lets you interactively investigate the resulting case and triage evidence.
Throughout this workflow, AI performs portions of the analysis while you retain responsibility for reviewing the evidence, validating its conclusions, pursuing additional investigation, and deciding what action to take.
Phishing Auto Triage provides a related but specialized workflow for user-reported phishing email.
AI Case Analysis and Summary
AI Case Analysis and Summary analyzes the information associated with a case and adds AI-generated content throughout the Case Detail view. Instead of requiring you to assemble the complete story from individual alerts, observables, and relationships before beginning an investigation, it gives you an interpreted starting point.
After AI Case Analysis runs:
-
The Detection tab provides a Case Summary containing a high-level narrative, key insights, potential impact, and recommended next steps.
-
The Analysis tab adds a hypothesis describing what likely occurred and AI-generated summaries that help you reconstruct the timeline and understand important entities and relationships.
-
The Response tab provides case-specific guidance for further validation, investigation, and containment.
These additions help you move more quickly from the collection of evidence in a case to an understanding of what might have happened and what deserves attention next. You can then use the underlying alerts, observables, timeline, and other case evidence to validate the AI-generated interpretation before deciding how to proceed.
See AI Case Analysis.
Alert Auto Triage
Alert Auto Triage performs a deeper investigation of the alerts associated with a case. It applies structured Verdict Signal Checks, incorporates relevant enrichment and threat intelligence, and assigns each analyzed alert a verdict such as True Positive, Benign True Positive, False Positive, or Inconclusive.
Alert Auto Triage provides more than the resulting verdict. You can review the findings and supporting evidence that led to the conclusion, including the results of the checks performed during triage. This transparency lets you understand how the verdict was reached and compare the automated analysis with your own assessment.
By performing these repetitive investigation and enrichment steps automatically, Alert Auto Triage reduces the amount of manual Tier 1 triage you need to perform and helps you focus attention on alerts that require further judgment or response.
You remain responsible for evaluating the conclusion. You can confirm or override an individual alert verdict when your analysis differs from the automated determination.
AI Case Analysis and Summary and Alert Auto Triage both add AI-generated information to case investigations, but they perform different functions.
| AI Case Analysis and Summary | Alert Auto Triage | |
|---|---|---|
| Primary purpose | Interpret and summarize the information associated with the case | Investigate alerts and determine their verdicts |
| What it provides | Case narrative, hypothesis, timeline and observable summaries, and response guidance | Alert verdicts, findings, and supporting evidence |
| External enrichment | No | Yes, from integrated endpoint, identity, and threat intelligence sources |
| Verdicts | No alert verdict assignment | Yes, using Verdict Signal Checks |
| Licensing | Included with a valid platform license | Add-on license for SaaS, EAP for on-premises, or active trial |
In practical terms, AI Case Analysis and Summary helps you understand the case that Stellar Cyber has assembled. Alert Auto Triage goes further by investigating the alerts within the case, evaluating additional evidence, and reaching a verdict that you can review against the findings that support it.
See Alert Auto Triage.
AI Assistance
AI Assistance extends Alert Auto Triage into an interactive investigation. From the Case Detail view, you can ask questions in natural language about an analyzed case and the triage context already assembled for it.
For example, you can ask why a verdict was assigned, request clarification about an alert or observable, or pursue a follow-up hypothesis without manually constructing the underlying query. Because you can continue from the evidence gathered during triage, AI Assistance lets you explore the reasoning behind a result rather than treating the initial verdict as the end of the investigation.
AI Assistance is included with Alert Auto Triage and operates on the analysis and evidence produced for the case. It does not require a separate license.
See AI Assistance.
Phishing Auto Triage
Phishing Auto Triage applies automated investigation specifically to user-reported phishing email. Stellar Cyber analyzes the reported message and its extracted artifacts, performs phishing-specific investigation and enrichment, creates security records from the report, and assigns a verdict for you to review.
You can examine the analysis, extracted observables, and supporting information behind the verdict before deciding whether the reported message requires further investigation or response. This provides the same human-augmented principle used elsewhere in Autonomous SOC: automation performs repetitive analysis and presents its conclusions, while you review the evidence and make the operational decision.
This approach gives you a consistent way to process user-reported phishing attempts without beginning every report with the same manual inspection and enrichment steps. You can then investigate the resulting alert and case through the standard Stellar Cyber interfaces alongside other security activity.
Phishing Auto Triage is available only in SaaS deployments and requires an add-on license.
Analyze Cases with Autonomous SOC
AI Case Analysis and Summary, Alert Auto Triage, and AI Assistance form a connected workflow for human-augmented case investigation. You enable AI Case Analysis globally, determine which cases receive automated analysis, review the resulting analysis and alert verdicts, examine the supporting evidence, and use AI Assistance when you want to investigate further.
The workflow uses AI to reduce repetitive investigative work without requiring you to accept its conclusions without review.
Step 1: Enable AI Case Analysis and Summary
You must enable AI Case Analysis and Summary globally before you can use it for cases.
-
Log in to the Stellar Cyber UI with Super Admin privileges.
-
Select System | ORGANIZATION MANAGEMENT | Settings.
-
Toggle on Enable AI Case Analysis & Summary and submit the change.
After you enable the global setting, the Case Summary and Analysis section appears when you configure case queues.
See Global Settings.
Step 2: Turn On Case Summary for a Queue
Case queues determine which cases receive AI-based analysis. Queue design is therefore a decision about where to spend your AI analysis, not only about how cases are displayed.
In the Case Summary and Analysis section of the queue builder, turn on Case Summary. The Stellar Cyber Platform then generates a case summary when a case enters the queue or changes while it is in the queue.
You do not have to build a queue to get started. The Stellar Cyber Platform provides a default AI Analysis Queue containing cases with a score of 75 or higher or a severity of Critical, with both Case Summary and Auto-Triage turned on. This focuses AI analysis on your most serious cases from the outset.
The other default queues, All Open Cases and All Closed Cases, have these settings turned off because they are broad by design. Keeping analysis disabled for broad queues helps reserve automated-analysis capacity for more targeted, higher-priority cases.
Step 3: Turn On Auto-Triage for a Queue
Turn on Auto-Triage in the same section to have the Stellar Cyber Platform perform Alert Auto Triage on the alerts in the cases in the queue.
The Auto-Triage setting requires the Case Summary setting to be enabled, and it appears only when you have the Alert Auto Triage add-on license installed or are in an active trial. Turning off Case Summary automatically turns off Auto-Triage.
Because automated analysis is subject to a rolling 24-hour limit, queue scope affects how that capacity is used. A broadly scoped queue with Auto-Triage enabled can consume automated-analysis capacity on lower-priority cases before more serious cases arrive. Scope queues with Auto-Triage enabled as narrowly as your operations allow; conditions based on score or severity can help focus analysis on higher-priority cases.
See Configuring Case Queues for the full queue configuration procedure.
Step 4: Configure Automated Case Analysis
You can use case-analysis settings and selection criteria to determine which cases Stellar Cyber analyzes automatically.
By default, Stellar Cyber automatically analyzes critical cases with a severity score of 75 or higher. The Platform supports up to 560 automated case analyses per rolling 24-hour period.
Use the available settings and case selection criteria to focus automated analysis on the cases where it provides the greatest operational value.
When new alerts are added to an analyzed case and its severity score increases sufficiently, Stellar Cyber can analyze the case again so that the new alerts are included in triage.
Processing time varies with alert volume and external dependencies. See Understanding Alert Auto-Triage Performance. For the current automatic-analysis behavior and configuration, see Working with Cases and Alert Auto Triage.
Run Analysis On Demand (Optional)
You can also analyze a case manually when it has not been processed automatically or when you want to reanalyze it after new information becomes available.
-
Select a case from the Cases page to open the Case Detail view.
-
Select Run Analysis at the top of the page.
-
Review the analysis usage information in the confirmation message.
-
Confirm the analysis.
The button changes to Analyzing... while processing is underway and to Case Analyzed when processing is complete.
The Stellar Cyber Platform supports up to 40 manually triggered case analyses per rolling 24-hour period.
See Running AI Analysis on a Case.
Step 5: Review the Case Analysis
After analysis is complete, begin with the AI-generated information in the Case Detail view, and then use the underlying case evidence to validate what the analysis tells you.
On the Detection tab, review the Case Summary for a concise explanation of the triggering activity, important findings, potential impact, and suggested next steps. Compare the summary with the associated alerts when you need to verify the activity behind the narrative.
Move to the Analysis tab when you need to understand how the activity unfolded. Review the hypothesis, timeline summary, observables, and relationships between entities to evaluate the proposed interpretation and determine the scope of the activity.
Use the Response tab when you are ready to evaluate next steps. AI Case Analysis provides case-specific validation, investigation, and containment guidance, while the standard Case Actions let you take supported response actions through configured connectors.
Treat the AI-generated material as an investigative starting point. You can trace its interpretation back to the alerts, observables, timeline, and other case evidence before deciding whether you agree and what action to take.
Step 6: Review Alert Auto Triage Results
Alert Auto Triage assigns verdicts to individual alerts associated with an analyzed case and provides the findings and evidence that led to each conclusion.
In the Detection tab, review the Verdict column in the Associated Alerts table. Select the additional information for an alert to open the Alert Details side panel and examine the verdict, Stellar AI Summary, Findings, and the evidence used to reach the conclusion.
This evidence-backed presentation lets you move from the automated conclusion into the reasoning behind it. Review the findings when you want to validate a verdict, understand why Stellar Cyber classified the activity a particular way, or determine whether further investigation is warranted.
Verdicts also appear in supported alert and threat-hunting tables, where you can display, sort, and filter on the Verdict column without first opening the associated case. Use the column to focus your attention on alerts that require review or further investigation.
When you first begin using Alert Auto Triage, review its verdicts closely against your own analysis. This helps you become familiar with how the feature evaluates activity in your environment and where additional investigation may be warranted. If your analysis differs from the automated determination, confirm or override the alert verdict as appropriate, and if you override it, provide a justification for the change. When alert verdicts change, Stellar Cyber reevaluates the case based on the updated alert information.
Step 7: Investigate Further with AI Assistance
When the case analysis or an alert verdict raises another question, open AI Assistance from the Case Detail view.
Ask questions in natural language to explore the case and the analysis already performed by Alert Auto Triage. You can ask why a verdict was reached, examine particular alerts or observables, request clarification about the supporting findings, and test follow-up hypotheses while remaining within the context of the case.
This lets you continue the investigation from the evidence already gathered rather than starting again from the raw case data.
AI Assistance does not impose a separate limit on the number of questions you can ask. Its available context depends on the analyses already performed for the case.
Triage User-Reported Phishing Email
Phishing Auto Triage is only available for SaaS deployments and requires an add-on license.
Phishing Auto Triage provides a separate automated workflow for email that users report as suspicious.
When a user reports a phishing message, Stellar Cyber extracts and analyzes the relevant email information and observables, applies phishing-specific investigation and enrichment, and assigns a verdict. Each report produces an alert and can be represented as a case for your review.
Review the resulting phishing alert to examine the verdict, analysis, extracted observables, and supporting information. Because these alerts originate from reported email rather than the general alert-analysis workflow, their Alert Details experience includes phishing-specific information.
Use the supporting evidence to validate the automated conclusion and determine whether further investigation or response is required.

