Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
← All resources Release

Soarcery 2.2: the SOC gets a Familiar

The Familiar as a luminous companion commanding three color-spined orders of watchers along orange, teal, and purple beams Release

There have been two honest answers to the question of how a SOC gets faster, and both of them quietly kept a human at the keyboard. Legacy SOAR made you pre-author every branch in advance: if this, then that, drawn out across a drag-and-drop canvas that broke the first time reality did something your flowchart did not predict. The newer AI SOC analyst tools went the other way, investigating an alert at machine speed and reasoning like a seasoned hand, then handing the verdict right back to the same queue your team was already drowning in. One asked you to imagine every future. The other did the thinking and left you the work.

Soarcery 2.2 inverts both. You talk to one companion, autonomous agents do the work, and a deterministic gate decides what gets to happen next.

We have written before that the difference is what happens after the verdict. The verdict is the midpoint, not the finish line, and a tool that stops there has sold you faster reading, not a smaller queue. 2.2 is the release where the after-the-verdict half stops being a person clicking through consoles and becomes machine work with human checkpoints, organized the way an actual security team is organized.

The Familiar: ask, do not click

The first thing you meet in 2.2 is the Familiar, and it is the cornerstone of the whole product. One plain-English console replaces the dashboard sprawl. You do not hunt for the right view, build a query, or remember which tool holds which fact. You ask. Show me everything that touched that host since Tuesday. Quarantine the phishing wave in finance and tell me who clicked. The Familiar is not a chatbot bolted onto a SIEM; it is the surface through which the entire agent society is commanded.

Three orders of Watchers

Behind the Familiar is an agent society with a real org chart, and the chart is the point. We split the work into three Watcher orders, each with a job, a doctrine, and a color spine that runs from the surface down to the receipt so you always know which order acted.

The Attack order detects. These are the agents that read the signal, correlate it, and decide whether something is actually happening. Their doctrine is MITRE ATT&CK: every finding maps to a technique, so a verdict is never a vibe, it is a citation. The Attack spine is orange.

The Defend order responds. When the Attack order confirms, the Defend order proposes the moves that contain it, the Spells that quarantine a message, isolate a host, or disable an account. Their doctrine is MITRE D3FEND, the countermeasure side of the same map, so response is described in the same shared language as the attack it answers. The Defend spine is teal.

The Scholar order documents. The work nobody volunteers for and every audit demands. The Scholar order writes the case up as it happens and keeps your ticketing system in two-way sync, so the record in Soarcery and the record in your ITSM tool are the same record, not two drifting copies someone reconciles on Friday. The Scholar spine is purple.

Three orders, one Familiar over them. The color spine is not decoration: it is how an analyst reads, at a glance, who detected, who proposed, and who wrote it down.

Seals: the AI is never above the law

None of this matters if the agents can act unsupervised on anything that touches a user or a host. So every consequential move in 2.2 passes through a Seal. A Seal is the propose-and-dispose gate: the agents propose an action with the evidence, the blast radius, and an expiry attached, and a named human disposes by approving or rejecting it. The agents are autonomous right up to the moment a decision has consequences, and there they wait.

Agents propose. A human disposes. The AI is never above the law, and the law is a Seal.

Where you set the Seal is a dial, not a switch. As trust accrues in a given use case, you can let more run unattended; until then, the destructive moves wait with their case file in front of you. And because every Seal records who approved what, the gate is auditable rather than advertised. This is the same discipline we described in deterministic verdicts on top of non-deterministic agents: let the agent be creative about finding the truth, never about what happens next.

Also new in 2.2

The Familiar and the orders ride on top of three more changes worth naming.

The Library. Your reusable building blocks now live in one place: Omens, the detections that tell the Attack order what to watch for; Spells, the response actions the Defend order casts; and Scrolls, the saved investigations and runbooks your team can reach for instead of rebuilding. Borrow, fork, and curate rather than author from scratch.

The redesigned navigation. With the Familiar as the cornerstone, the whole left rail was rebuilt around asking rather than clicking. Fewer places to get lost, and a straight line from a question to the order that answers it.

The Lake. Underneath everything, one queryable store of your security telemetry that the agents reason over, so investigation is not bottlenecked by which tool happened to hold the log. The orders read from the Lake; you read the receipt.

Come see it run

2.2 is the release where the three honest answers finally converge: machine-speed investigation, machine-speed response, and a human holding the one decision that genuinely needs judgment. We built a three-minute interactive tour that follows a real case from signal to Seal, through the Attack order to the Defend order to the Scholar order, with no signup, because evaluation should not cost you a meeting. If the after-the-verdict half of your queue is the half that hurts, that is the part worth watching.

See it live

Meet the Familiar and watch a case run.