Natively integrated Google Gemini Artificial Intelligence

Translate the complexity of
Defender threats with Google Gemini AI.

The main adversary of a SOC analyst is not always the hacker, it is the volume of data. Akuity SOC natively embeds Gemini AI to instantly translate complex JSON payloads, reduce mental fatigue and eliminate false positives.

Partenaire Pure Player Microsoft depuis 1990 NIS 2 Conformité Cyber Munich, Bavière (Allemagne)
Operational asymmetry

Manual analysis of Defender logs destroys the productivity of your analysts

Sans Akuity SOC
Avec Akuity SOC
Comprehensive manual decoding

Tedious reading of raw JSON filescontaining thousands of lines. Manual decryption of obfuscated PowerShell scripts.

Instant summary: technical summary generated by AI as soon as the ticket is opened, in less than 3 seconds.

Time-consuming reporting

Manual report writingfor management taking hours for each critical incident.

Gemini Double Speech: raw engineer report + clear COMEX summary, generated simultaneously and automatically.

Alert overload

Humane processing of countless false positives: up to 80% of alert volume is unqualified background noise.

Out-of-band AI: automatic qualification of probable false positives with contextualized dangerousness score.

3 AI pillars

How Gemini AI is revolutionizing Defender log analysis

The Gemini Double Discourse (Tech & COMEX)

The analysis tab generates a summary atDouble Speech: a detailed technical description (attack vectors, processes involved) for the engineer, AND a popularized recommendation ready to be shared with the COMEX.

Contextual Chat Analyst & AI

The Ticket Panel includes achat powered by Geminiwho knows the full context of the ticket. Ask it to explain an obfuscated Base64 script, or generate a typical warning email to send to the compromised user.

Intelligent Reputation Analysis

When the AI ​​encounters an IOC (SHA256 Hash, IP), it generates acontextual analyst notewith weighted dangerousness score. Bonus if the IP belongs to Azure/AWS, penalty if the domain is recent (< 100 days) with malware signature.

Concrete case

Qualification of an obfuscation attack in 3 steps

01

Detection — Unreadable CMD command on financial server

Pupil

Microsoft Defender reports the execution of aObfuscated CMD commandon a financial server. The alert is classified as suspicious without being qualified.

02

AI Translation — Instant Deobfuscation

Gemini AI Active

The analyst opens the alert. Gemini has already deobfuscated the order, revealing aattempt to download payloadfrom a C2 domain. The COMEX summary is already ready.

03

Validation — The analyst confirms and isolates

True Positive

The analyst uses theAI catto check the dangerousness of the IP via AlienVault OTX. Confident, he declares the alert as True Positive and initiates server isolation.

FAQ

Frequently Asked Questions about Gemini AI in Akuity SOC