What is an agentic SOC?
Plain answers to the questions people ask about agentic SOC platforms, and how Kybit Nexus, built by Kybit s.r.o. in Prague, handles each of them.
What is an agentic SOC?
An agentic SOC is a security operations centre in which AI agents do the investigative work of first- and second-line analysts. An agent takes an alert, gathers the context an analyst would look up, reasons over it and proposes a verdict and a response. People stay responsible for what may close and for every destructive action.
Kybit Nexus is an agentic SOC platform built and operated by Kybit s.r.o., a Czech managed security service provider. It works on top of the SIEM, EDR, CMDB and identity provider an organisation already runs, and Kybit's own SOC and MDR service runs on it.
How is an agentic SOC different from SOAR?
SOAR runs playbooks that a person wrote in advance: when this alert arrives, take these steps. An agentic SOC investigates first. The agent works out what to look up for this particular alert, weighs the evidence and writes a reasoned assessment, which matters most for the alerts nobody wrote a playbook for.
Kybit Nexus keeps what SOAR does well: connectors, a library of 110 runbooks, and response actions through your firewall, EDR and identity provider. What changes is who decides. The model proposes, a deterministic policy engine decides what may close, and the agent itself cannot execute a playbook: execution sits behind role checks and approvals.
Does an agentic SOC replace the SIEM?
No. An agentic SOC reads from the SIEM rather than replacing it. Kybit Nexus pulls or receives alerts from the SIEM, EDR and NDR you already run, adds what an analyst would look up and hands back a decision. Nothing is migrated, and your detection content stays where it is.
Does an agentic SOC still need analysts?
Yes. Kybit Nexus does the repetitive first- and second-line work, gathering context, correlating it and writing the assessment, so analysts spend their time on decisions. Every destructive action waits for a person to approve it, and every investigation is recorded on a trace that cannot be rewritten.
Can an AI agent close alerts on its own?
An AI agent may close an alert only where a deterministic policy allows it, and in Kybit Nexus that policy closes nothing without a human today. The model proposes; the policy engine decides.
Automatic closing is fail-closed: it needs a positive allowlist match, no indicator hit, a severity below high and a known asset tier. A second, independent model must agree first, and agreement between samples of the same model never counts. Alert text is treated as data and checked by a detector whose hit forces escalation, and one platform setting halts every autonomous step.
Where does the AI run, and what data leaves?
In Kybit Nexus, where the AI runs and what leaves is chosen per tenant, in one of three modes. Local: the model runs on Kybit hardware and nothing leaves. Hybrid, the default: the model still runs locally, and a second model in the EU (Azure OpenAI) checks a pseudonymised summary in which hosts and addresses are tokens. Hosted: the full evidence goes to a model hosted in the EU, only after an explicit, recorded opt-in.
Pseudonymised is not anonymised: in hybrid mode, account names, group names and the incident narrative are sent as written.
Read what leaves your estate, data class by data classHow fast does an agentic SOC triage an alert?
In Kybit Nexus a full triage, from the alert to a reasoned assessment on Kybit hardware, takes about 16 seconds. The human decision comes after that, and destructive actions wait for it.
Which tools does Kybit Nexus work with?
Kybit Nexus reads alerts, context and threat intelligence from the tools below and acts through the response tools; each has a connector available today. A connector that does not exist yet is written in days, through a connector SDK.
- Alerts
- Wazuh, IBM QRadar, Microsoft Defender, CrowdStrike Falcon, Splunk, Progress Flowmon, GREYCORTEX Mendel, AlienVault OSSIM, Microsoft Entra sign-ins, Ingest API (any source)
- Vulnerabilities
- Findings API (any scanner)
- Identity
- Microsoft Entra ID, Active Directory
- Assets
- NetBox
- Threat intel
- MISP, VirusTotal, AbuseIPDB, GreyNoise, urlscan.io
- Response
- FortiGate, OPNsense, VyOS, SentinelOne, Microsoft Entra ID, Active Directory
Who is Kybit Nexus for?
Kybit Nexus is built for managed security service providers (MSSPs) and in-house SOC teams. It is multi-tenant by design: tenants are isolated by row-level security in the database, and budgets, model modes, egress policy and auto-close rules are set per tenant. It works for a single SOC too.
Kybit's own SOC and MDR service runs on Kybit Nexus.
How is Kybit Nexus deployed?
Kybit Nexus is deployed with Docker Compose, on your premises or Kybit's. Production runs a high-availability layout (Patroni, PgBouncer, keepalived, HAProxy) and a dedicated inference node running Ollama, reachable only on the local network.
Does an agentic SOC help with NIS2?
An agentic SOC helps with the evidence NIS2 asks for. Kybit Nexus records the incident timeline, decisions and approvals on an append-only trace and exports them for reporting. Kybit runs its own NIS2-scoped SOC and MDR service on the same platform.
Request a demo to see Kybit Nexus on your own SIEM and EDR.