I'm evaluating Cortex's AI SOC platform for my team. The marketing claims their AI assistant cuts alert fatigue by "up to 80%." I'm skeptical of that figure without concrete breakdowns.
I need specifics from anyone with hands-on experience, particularly on:
* **Triage accuracy:** What's the actual false positive reduction rate in a complex environment? Does it just group similar alerts, or does it genuinely contextualize them with asset criticality and user risk scores from my existing data?
* **Workflow integration:** Does the AI simply suggest next steps, or can it execute approved, mundane tasks within our SOAR playbooks? For example, can it autonomously quarantine a host based on a high-confidence verdict, or does it still require a human click?
* **Hidden costs:** Is the AI assistant a separate SKU? Does usage (number of alerts analyzed, automated actions taken) impact licensing costs in a way that would scale unpredictably?
* **Exit considerations:** If we train it on our data and procedures, how portable is that model? What's the data lock-in risk?
Our main pain point is analysts drowning in medium-priority alerts that require manual lookup across ten tools. Does this actually solve that, or is it just a fancy chat interface on top of the same old correlation engine?