Collect
Multi-protocol ingestion from endpoints, cloud, network, apps, and APIs — agents, Syslog, webhooks, and connectors.
Built-in native SIEM with Agent XDR real-time telemetry, Sigma rules, file sandbox in the web panel, and SPF/DKIM/DMARC monitoring. Multi-agent AI detects threats and responds via SOAR — with GDPR, RGPD, and LGPD compliance built in.
More than a platform — a complete security operations service, run 24/7 by SOC AI Agent.
The agent analyzes logs, correlates threats, and identifies incidents in real time, without downtime.
Built-in decision power: detects, classifies, and responds via SOAR — block, isolate, and remediate in seconds.
DolutechAI runs the service for you: ingestion, monitoring, analysis, and response — no internal SOC required.
SOC AI Agent operates autonomously, but knows when to escalate. In critical environments or high-risk situations, it requests human analyst validation before executing sensitive actions.
It is not the operator who asks for help — the autonomous agent itself, after analyzing severity, context, and impact, determines that human validation improves response safety.
Event identified and classified
Orchestrator + specialists assess risk and impact
Immediate response or human-in-the-loop escalation
Analyst reviews context, confirms or adjusts proposed action
Action executed via SOAR with full audit trail
High-impact incidents that require human confirmation before remediation
Assets, segments, or systems classified as sensitive or mission-critical
Wide isolation, mass blocking, or invasive remediation
When analysis does not reach sufficient confidence, the agent prefers human validation
Human-in-the-loop with DolutechAI human analysts is available on selected plans. Full agent autonomy is included on all plans.
Intuitive dashboard with real-time visibility into metrics, incidents, and alerts across your infrastructure.
SOC AI Agent is a complete security data platform — native collection, storage, and correlation — while operating as an intelligent layer on top of Splunk, Wazuh, and enterprise SIEMs you already run.
Built-in SIEM capabilities mean you can centralize telemetry without assembling a separate stack first.
Multi-protocol ingestion from endpoints, cloud, network, apps, and APIs — agents, Syslog, webhooks, and connectors.
Searchable log retention with configurable policies, audit trails, and evidence ready for compliance reviews.
Cross-source correlation rules enriched by the AI orchestrator and eight specialist agents for context-aware incidents.
Forward events from your existing SIEM — SOC AI Agent analyzes, correlates with AI, and responds via SOAR without a rip-and-replace project.
Whether logs land natively or arrive from a third-party SIEM, the same orchestrator, specialist agents, incidents, and SOAR playbooks power your operations.
Start with your current SIEM and add AI-driven MDR, or deploy the full native stack — your choice.
Unified incidents, IOCs, and response actions regardless of where events originated.
Immutable audit trails and configurable retention for GDPR, RGPD, and LGPD from day one.
Deploy Dolutech's native endpoint agent, run Sigma detection in the panel, and route confirmed threats into the same orchestrator, incidents, and SOAR playbooks — no third-party XDR required.
Lightweight agents for Windows and Linux stream real-time process, file, registry, and network telemetry directly into SOC AI Agent.
Continuously updated Sigma rules — import, enable, and tune from the web console, versioned and mapped to your environment.
Detections trigger real-time SOAR response — isolation, blocking, and incident enrichment without leaving the platform.
Manage rules, review detections, and trace every alert from endpoint telemetry to incident context.

Analysts securely submit malicious file evidence from the browser — the sandbox analyzes samples in isolation, returns a verdict, and feeds context back to the AI engine and incident queue without risking production endpoints.
Upload files or paste hashes directly in the web console — no local tools or separate appliance required.
Malicious evidence runs in a controlled sandbox environment — never on production endpoints — with full behavioral capture.
Malicious, suspicious, or clean verdicts attach to incidents with IOC extraction and specialist agent enrichment.

Triage phishing attachments, unknown executables, and suspicious archives with audit-ready results.
From log ingestion to automated response — all in one console.
Executive and operational real-time view.
Native XDR agent inventory with real-time process, file, registry, and network telemetry for Windows and Linux.
CVE discovery across endpoints with CVSS scoring, severity filters, and on-demand scans tied to your asset inventory.
Search, filters, and event correlation.
Triage, severity, assignment, and resolution.
Playbooks, executions, and response integrations.
Import, manage, and run continuously updated Sigma rules — mapped to real-time endpoint telemetry and correlated into incidents with instant SOAR response.
Securely analyze malicious file evidence from the web panel — isolated sandbox, verdicts, and AI-enriched triage without touching production endpoints.
Contextual assistant for your environment.
Analyst-guided investigation.
View, add, and manage blocks for IPs, domains, and malicious actions with full audit trails.
Behavioral analytics with machine learning to detect anomalies, insider threats, and baseline deviations.
Threat context enrichment.
Attack geolocation and origin.
Real-time indicators.
Query and match history.
Proprietary collaborative network — share and receive community-validated IOCs with automatic enrichment.
Validates, corrects, and enriches indicators and threat context with continuous correlation against logs and incidents.
Continuous SPF, DKIM, and DMARC DNS monitoring, authentication failure alerts, and correlation with phishing and spoofing incidents.
Configurable ingestion and output sources.
Controlled exceptions to reduce false positives.
Users, roles, and permissions.
Policies, retention, and preferences.
Personal account and session preferences.
Secure MFA (TOTP) for analysts and administrators, with role-based policies and protected sessions.
Each log type is analyzed by the right specialist — maximum accuracy, minimal false positives.
Classifies the event, selects the specialist, aggregates conclusions, and proposes SOAR actions.
Full queue with severity, status, assignment, and Investigate / Resolve actions.

Automation with triggers, conditions, and automatic or manual approval mode.

Continuous exposure visibility with CVSS prioritization across your endpoint fleet.

Connect SIEM, endpoints, cloud, and applications without rebuilding your stack.
Any structured event via API.
Wazuh SIEM / XDR integration.
HTTP Event Collector compatible.
ArcSight Common Event Format.
RFC 5424 and RFC 3164.
Generic HTTP endpoint.
SOC Collector plugin and IP blocking.
Native SDK for Lovable apps — send events, errors, and security signals from your AI-built applications.
Native SDK for Replit — stream logs, runtime events, and security telemetry from your apps and services.
Perimeter protection and CDN events.
Windows and Linux — native telemetry.
Feeds and continuous matches.
Centralized management in the Connectors module.
Deploy logs, function invocations, and edge events for real-time analysis and response.
Outbound events, alerts, and SOAR callbacks for real-time ecosystem integrations.
Collective intelligence across SOC AI instances — confirmed real threats only.
Data control, auditing, and evidence for regulators and data subjects.
Every log, incident, and SOAR action recorded.
Configurable policies per source and type.
Export and evidence for DSAR requests.
Data under customer and regional control.
Documented incidents and playbooks.
Reports for GDPR Art. 33 and LGPD equivalents.
Every alert arrives with context — source, severity and a suggested next step. Full history stays available for your team and auditors.
Active alerts, monitored endpoints and threat intelligence in a single operational view.
The work queue reflects severity and event correlation, so analysts focus on what matters first.
Playbooks, manual approvals and containment actions stay linked to each incident with a full audit trail.
Searchable incident timelines ready for internal review or compliance requests.
Orchestrator and 8 specialists analyze every log with event-type context.
Real-time XDR detections trigger SOAR playbooks — isolate, block, and quarantine in seconds, automatically or with approval.
Immutable audit, configurable retention, and evidence for subjects and regulators.
Selective sharing of confirmed IOCs across SOC AI community instances.
Feeds, TI history, and continuous incident enrichment.
JSON/REST, Wazuh, Splunk HEC, CEF, Syslog, Webhook, WordPress, Cloudflare, and Go agents.
Ingest via API, Syslog, SIEM, webhooks, WordPress plugin, Cloudflare, and Go agents.
The orchestrator routes each event to the right specialist among 8 agents by log type.
Dynamic severity, TI enrichment, and real-time feed matching.
Playbooks trigger real-time containment via XDR and SOAR — automatic response or manual approval.
Reports, exports, and trails for GDPR, RGPD, and LGPD.
Multi-protocol ingestion and endpoint agents.
LLM orchestrator + 8 specialists by log domain.
SOAR, Cloudflare, blocking, and notifications.
The orchestrator classifies each event by log type and context, delegates to one of eight specialists, and consolidates analysis before creating or updating an incident.
JSON/REST API, Wazuh SIEM/XDR, Splunk HEC, CEF (ArcSight), Syslog (RFC 5424/3164), webhooks, WordPress SOC Collector plugin, Cloudflare, Go agents for Windows/Linux, and custom connectors.
Playbooks define triggers (category, score, severity), conditions, and actions. Run fully automatic or require manual approval before remediation.
A proprietary network sharing only real threats — IOCs with SOC hits and confirmed incidents. Public feed data is not shared.
Immutable audit trails, retention policies, exports for data subjects, and breach notification reporting (e.g. GDPR Art. 33).
Indicators are correlated with logs and incidents. IOC Feed and TI History show matches; Threat Network reinforces community-validated IOCs.
Yes. Go agents for Windows and Linux, plus the WordPress SOC Collector plugin with IP blocking.
Perimeter and CDN events correlate web attacks with internal incidents and can trigger blocking playbooks.
Automatic playbooks can respond in under one second. Specialist-per-log-type analysis drastically reduces false positives in tuned environments.
Yes. Send events via Syslog, CEF, Splunk HEC, JSON API, or Wazuh. SOC AI Agent correlates, analyzes with AI, and responds via SOAR without replacing your SIEM.
Yes. Configure thresholds, playbooks, whitelist, connectors, retention, and auto/manual modes per environment.
MDR (Managed Detection and Response) is the managed detection and response service we deliver with SOC AI Agent. We monitor your environment 24/7, detect threats, and respond autonomously — no internal SOC team required.
Human-in-the-loop is the mechanism by which the autonomous agent, upon identifying a critical context or sensitive action, automatically escalates to a human analyst to validate the decision before execution. It ensures day-to-day autonomy and reinforced safety when risk demands it.
The agent escalates when severity, critical environment, potential action impact, or analysis confidence indicate that human validation improves safety — for example, critical incidents, sensitive assets, or invasive remediation. Human analyst availability depends on your chosen plan.
The agent operates autonomously on all plans. Some plans include human analysts who participate in the human-in-the-loop flow when the agent escalates. Availability depends on your plan — contact us to find the right fit for your environment.
Agent XDR is Dolutech's native endpoint detection layer: lightweight agents on Windows and Linux stream real-time telemetry (processes, files, registry, network), a Sigma rules engine continuously updated and managed in the web panel, and detections that trigger real-time SOAR response — isolation, blocking, and incident correlation. It is built into SOC AI Agent — not a separate third-party XDR product.
Analysts submit suspicious files or malicious evidence from the SOC AI Agent web console. The sandbox runs samples in an isolated environment — never on production endpoints — returns a malicious/suspicious/clean verdict with behavioral detail, and links results to incidents, IOCs, and AI enrichment.
SOC AI Agent continuously monitors SPF, DKIM, and DMARC DNS records for your domains, alerts on misconfigurations or spoofing risk in the web panel, and correlates authentication failures with phishing and incident workflows.
Traditional stacks charge for software — then for the MSSP that operates it, and again for analysts who triage alerts. SOC AI Agent is an autopilot: one platform that detects, investigates, and responds 24/7. No MSSP middleman. No seven-figure SOC team.
Figures are illustrative of industry patterns. Final pricing depends on log volume, sources, and plan. Contact us for a tailored proposal.
Deploy SOC AI Agent in minutes. Multi-agent AI, SOAR, and compliance built in.
Request a Demo No credit card required · Full access · Dedicated support Non-profit organization? Learn about our free licensing program →