Episode 434: Reading the Spec Sheet on Microsoft’s Agentic SOC
Aug 13, 2026 · 47m
Summary
Ben and Scott analyze Microsoft’s Project Perception, an AI-driven security workforce featuring red, blue, and green agents for threat simulation, investigation, and remediation. They detail the high licensing prerequisites, such as Defender XDR and E5, alongside the Security Compute Unit pricing model. The hosts critique the current "human-in-the-loop" design, noting that agents are largely read-only and manually triggered, raising questions about their true agentic value versus existing tools.
Topics discussed
Episode 434 Intro: Project Perception Overview
Passkeys Correction, Agents, and Puppy Distractions
Project Perception: Tenant Security Service
Licensing, Defender Portal, and ERBAC Requirements
Red, Blue, and Green Team Agent Categories
Human-in-the-Loop and Manual Triggering
Red Team Recon Agent and Attack Path Mapping
Blue Team Agents: Triage and Investigation
Sponsor Message: Nasuni Global File System
Value for IT Generalists vs. Dedicated SOC Teams
Incident Verdicts and KQL Query Generation
Detection Authoring and Secure Score Comparison
Playbooks as Orchestrators for Agents
Future Automation and Permission Boundaries
Underlying AI Models and Cyber One Flash
Pricing Concerns and TechCon 365 Promo Code
Outro and Call to Action
Listen ad-free on Castria