Webinar

Webinar: Demystifying the Use of AI Agents in Security Operations

In the rapidly evolving landscape of cybersecurity, the integration of Artificial Intelligence (AI) offers significant transformative potential. AI’s capabilities in the realm of security operations can be fully realized by applying a structured approach that combines deterministic automation, AI assistance, and agentic AI. These approaches collectively enhance the efficacy of security operations. Moving beyond conceptual discussions, this webinar focuses on several tangible security recommendations for utilizing AI effectively.

Deterministic Automation: Strengthening Known Defenses

Deterministic automation, the oldest form of automation, is fast and efficient for handling predetermined scenarios. By implementing rules-based systems, security teams can quickly respond to known threats and looping alert patterns. Here are some practical steps to enhance security with deterministic automation:

  1. Rule-based Alert Management Configure your systems to automatically manage alerts based on pre-defined criteria such as checking IP reputation or device risk scores.
  2. Regular Updates and Tuning Ensure that rules are regularly updated to cover new threat patterns. This keeps the automation system effective against known attacks.

Utilization of AI Assistants for Enhanced Triage

AI assistance tools, like Microsoft Security Copilot, can perform tasks that often bog down human analysts, such as summarizing incidents and writing hunting queries. Here’s how to integrate AI assistance into your cybersecurity strategy:

  1. Incident Summarization and Response Suggestions Use AI to distill incident data into actionable insights and suggest subsequent steps, reducing manual workloads for analysts.
  2. Query Optimization Deploy AI tools to automatically formulate and optimize queries for specific threat investigations, enhancing the efficiency of the analysis process.

Agentic AI: Augmenting Analytical Capabilities

Agentic AI represents a revolutionary shift from mere rule-following to autonomous decision-making. This form of AI acts as a persistent team member for analysts, capable of reasoning and adaptation. To implement agentic AI effectively:

  1. Incident Investigation Automation Develop AI agents that autonomously investigate alerts, hypothesize potential impacts, and verify results against predefined security policies.
  2. Human-in-the-Loop Feedback Systems Establish systems where human feedback continuously improves AI responses, ensuring decisions remain accurate and transparent.
  3. Evidence Transparency and Replicability Maintain complete transparency of AI operations by allowing analysts to audit and replicate the AI’s decision-making process.

Microsoft Security Store: Made for the AI era

The Microsoft Security Store provides a convenient storefront to discover and deploy AI agents that address your organization’s security needs. All listings are built by either Microsoft or trusted partners and validated to integrate with Microsoft Security products. Deploying agents takes just a few steps, enabling fast time to value.

Since June 2025, Ontinue has been a member of the Agentic Partner Bootcamp MSSP Cohort, an exclusive group of Microsoft partners. Through this program Ontinue gets Private Preview access to Security Copilot Agent building and publishing tools.

We have since developed two Security Copilot agents which are available in the Microsoft Security Store.

  • Posture Advisor Agent: A private offering, free to install and use through the Security Store, exclusively for ION MXDR customers.

Additional Resources

  1. Cutting Through the Hype: What Agentic AI Really Means and the Future of Security Operations
  2. Webinar recording and blog post on navigating Microsoft’s new pricing changes (including the inclusion of Copilot)
  3. Join over 600 fellow MDE users in the Defender User Group on LinkedIn

Sharing