Intezer is adding native response automation to its AI security operations platform, aiming to eliminate one of the more persistent gaps in modern SOC workflows: the handoff between investigating an alert and actually doing something about it. Its new Workflows capability lets security teams create response actions inside Intezer, potentially reducing reliance on separate SOAR platforms for remediation and follow-up tasks.
Security operations platforms have spent years getting better at finding and investigating threats. The next challenge is closing the loop.
Intezer is taking a step in that direction with Workflows, a native automation and response builder that lets security teams create customized actions directly inside its AI SOC platform. The company says the capability can automate what happens after an alert reaches a verdict, including closing alerts, isolating hosts, updating tickets and notifying analysts.
The significance is less about another automation feature than where Intezer is putting it.
Traditionally, investigation and response can live in separate systems. A security information and event management (SIEM) or detection platform identifies an alert, analysts investigate it, and a separate security orchestration, automation and response (SOAR) platform executes the resulting playbook.
That architecture works, but it creates integration overhead. Context has to move between systems, playbooks have to be maintained, and teams may need custom APIs or polling mechanisms to connect investigation outcomes with response actions.
Intezer’s Workflows attempts to collapse that boundary.
The company describes Intezer as an AI SOC platform built around its ForensicAI technology. With Workflows, investigation evidence and organizational context can flow directly into the response process. Each workflow execution is logged, while actions are reflected in the relevant alert or case.
For security teams, the practical appeal is straightforward: the system that determines what happened can also initiate the next operational step.
That is becoming more important as AI agents take on larger portions of security operations.
Microsoft, for example, has expanded Microsoft Security Copilot with agents capable of handling security tasks such as incident triage, investigation, threat hunting and threat intelligence. Microsoft now provides agents across Defender, Entra, Intune and Purview, while allowing organizations to deploy agents from Microsoft and partners.
Google Cloud is taking a similar direction with its agentic SOC, where Gemini-powered agents can automate alert triage, threat hunting and detection engineering. Google says its Triage and Investigation agent can reduce a typical manual analysis process from about 30 minutes to approximately 60 seconds.
Intezer is competing in that emerging category with a narrower proposition: combine forensic-depth investigation with response automation in the same platform.
That positioning also challenges the conventional SOAR model.
SOAR remains useful when organizations have well-understood processes that can be represented as deterministic playbooks. But the more security operations move toward AI-driven investigation, the less useful a hard boundary between “investigation” and “automation” may become.
An agent might determine that an endpoint should be isolated, a ticket should be updated and a security team should be notified. Requiring the result to cross into a separate orchestration platform can add latency and another integration point.
Intezer’s Workflows instead starts with the evidence already gathered during the investigation.
Natural-language automation moves into the SOC
One of the more notable capabilities is natural-language workflow creation.
Through Intezer’s Model Context Protocol (MCP) interface, users can describe the response they want in plain language. The resulting workflow can then be reviewed, refined, tested and activated within the platform.
This reflects a broader movement in enterprise software toward using natural language as an interface for configuring automation.
Microsoft’s Security Copilot architecture similarly allows organizations to work with agents, plugins and connectors, while developers can build custom agents for internal deployment.
The important distinction is that natural-language creation does not eliminate the need for governance. A generated workflow that can isolate a production server or disable an identity has materially different consequences from one that simply produces a report.
Intezer’s inclusion of logging and review mechanisms therefore matters. Enterprise security teams will need to know what an agent or workflow did, why it did it and which evidence informed the action.
The low-severity alert problem
Intezer is also using its product announcement to make a broader argument about alert coverage.
The company’s AI SOC Report 2026 says nearly 1% of real incidents in its research were associated with alerts initially classified at the lowest severity levels. Intezer estimates that for an enterprise generating 450,000 alerts annually, this could represent approximately 54 real threats a year—roughly one per week—that might otherwise remain uninvestigated.
Those figures are company research and should be treated accordingly, but the underlying operational problem is familiar.
Security teams routinely prioritize alerts because the volume of telemetry exceeds available analyst capacity. Low-severity events can be deprioritized even when they contain useful signals. AI-driven investigation could theoretically make broader coverage economically viable by reducing the human effort required to examine each alert.
That creates an important distinction between automating response and automating investigation.
A SOAR playbook can respond quickly once an alert has been classified. But if the classification itself is wrong—or if the alert never receives meaningful investigation—the automation may simply execute the wrong decision faster.
Intezer’s pitch is that forensic-depth investigation should come first, followed by response once the system has reached a verdict.
That approach aligns with a key concern in the emerging AI SOC market. Gartner’s February 2026 research on AI SOC agents says organizations need to balance the potential for improved detection, prioritization and response with the quality of data and workflows available to AI systems.
Gartner also identifies AI-driven SOC solutions as a cybersecurity trend that is changing operational norms, including staffing requirements and the economics of security tooling.
What enterprise teams should watch
For enterprise security leaders, Intezer’s launch raises a broader procurement question: does an AI SOC need a separate SOAR platform at all?
The answer will depend on the existing security stack.
Organizations with large investments in established SOAR systems may not want to replace mature playbooks and integrations. They may instead look for AI SOC products that integrate cleanly with their existing orchestration layer.
Newer SOC environments, meanwhile, may prefer a unified platform that combines investigation, case management and response.
MSSPs are another potential beneficiary. Intezer says Workflows can automate customer communications and per-tenant routing, reducing manual processes across managed security environments.
The capability is currently available in early access to selected Intezer customers, with general availability planned for later in the quarter. The company also says its customer-success team will assist customers migrating existing SOAR playbooks.
The larger industry trend is clear even if the eventual winners are not.
AI is pushing the SOC toward a model where investigation and response increasingly happen inside the same automated loop. Platforms that can connect evidence, reasoning, action and auditability without forcing analysts to move between systems could gain an advantage.
Intezer’s Workflows is an example of that convergence. Its real test will be whether enterprises trust an AI-driven platform not only to explain what happened, but to take the next step safely.
Market Landscape
The security automation market is converging around three layers: SIEM and detection, AI-assisted investigation, and automated response.
Traditional SOAR platforms such as Splunk SOAR and Palo Alto Networks’ Cortex XSOAR remain strong in deterministic orchestration. Meanwhile, Microsoft, Google and other major security vendors are embedding AI agents directly into their security ecosystems. Microsoft Security Copilot agents can now operate across Defender, Entra, Intune and Purview, while Google’s agentic SOC combines Gemini with security operations workflows.
Intezer’s strategy is to reduce the distance between investigation and response rather than compete solely as a standalone orchestration layer.
That could appeal to organizations seeking fewer integrations and a unified investigation-to-remediation workflow. The trade-off is platform dependence: enterprises adopting a unified AI SOC need confidence in the vendor’s detection coverage, investigation accuracy, integrations, governance and ability to coexist with existing security infrastructure.
For buyers, the most important evaluation criteria are likely to be alert coverage, evidence quality, workflow governance, auditability, API access, human approval controls and interoperability with existing SIEM, SOAR and endpoint systems.
Top Insights
- Intezer Workflows brings response automation into its AI SOC, allowing investigation outcomes to trigger remediation without requiring a separate SOAR platform.
- Natural-language workflow creation lowers the technical barrier to automation, while review, testing and execution logs remain important safeguards for security teams.
- Intezer’s strategy targets a persistent SOC problem: investigation and response often occur in separate platforms, creating integration overhead and potential context loss.
- Microsoft and Google are also moving toward agentic security operations, making unified AI investigation and response an increasingly competitive category for enterprise cybersecurity buyers.
- The value of AI-driven SOC automation ultimately depends on investigation accuracy, alert coverage and governance, not simply the ability to execute response actions faster.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI




