A security operations team of three, facing 4,300 alerts a day across a fourteen-country IT and OT estate, was investigating fewer than one alert in ten. Within weeks of deploying Trace8 against their existing Microsoft Sentinel environment — read-only, with no data moved — every alert was being investigated, and mean time to investigate had fallen from 4.2 hours to 6 minutes.
The organization
The client is a global energy company with roughly $1 billion in annual revenue, operating in fourteen countries. Its estate spans conventional corporate IT — endpoints, identity, email, cloud workloads — and operational technology supporting production and distribution infrastructure, where the tolerance for both missed detections and disruptive false positives is unusually low. Security monitoring was centralized on Microsoft Sentinel, fed by log sources from both sides of the IT/OT boundary.
The security operations function was small by design: three analysts, responsible for the entire detection queue, distributed across time zones that never quite covered the clock. The organization had invested seriously in detection engineering. What it could not scale was what happens after a detection fires.
The challenge
Sentinel was producing approximately 4,300 alerts per day. Three analysts, however capable, can investigate only a small fraction of that volume with any rigor — in practice, fewer than 10% of alerts received a genuine investigation. The remainder were dispositioned by severity heuristics, suppression rules, and informed guesswork. Every uninvestigated alert was an implicit risk acceptance that nobody had formally made.
The alerts that were investigated took time. Mean time to investigate stood at 4.2 hours: pivoting across workspaces, assembling entity timelines, chasing context from identity and endpoint tooling, and writing up findings. In an environment with OT exposure, a four-hour investigation window on a true positive is a material operational risk, not a reporting inconvenience.
The obvious answers were unattractive. Hiring an around-the-clock analyst bench was not economically defensible at this revenue scale. Replacing the SIEM would mean a multi-quarter migration and re-ingesting log data the organization had already paid to collect. Outsourcing to a conventional MSSP would trade the queue problem for a ticket-quality problem.
The deployment
Trace8 deployed in week one, read-only, with zero ingestion. Its federation layer connected to the existing Sentinel workspaces and queried log data in place; no collectors were installed, no pipelines were built, and no raw logs left the client's boundary. The Sentinel investment — data connectors, analytics rules, retention — remained exactly where it was.
From the first day of connection, Trace8's Frame Agents began working the live queue. The Triage agent picked up every alert as it fired and ran a full investigation: entity resolution, timeline construction, and correlation across the identity, endpoint, and network sources federated through Sentinel. The Evidence agent attached the query results and reasoning behind each conclusion, and the Challenge agent adversarially tested every proposed verdict before it was allowed to stand. Alerts the pipeline could close with confidence were closed automatically — each with a complete case file recording what was checked, what was found, and why the verdict held. Alerts that warranted human attention were escalated as evidence-backed briefs rather than raw alerts.
Only the AI-generated case files persist in Trace8. The underlying log data stays in Sentinel, under the client's existing retention and residency controls — a property that mattered given fourteen national jurisdictions and OT-adjacent data.
The results
Within the first full reporting period, the operating picture had inverted. Coverage was total, investigation was fast, and the analysts had been repositioned from queue labor to oversight.
| Dimension | Before | After |
|---|---|---|
| Alerts investigated | <10% of ~4,300/day | 100% |
| Mean time to investigate (MTTI) | 4.2 hours | 6 minutes |
| Alerts auto-closed with case files | 0% | 88% |
| Raw log egress from client boundary | N/A | Zero |
| Analyst role | Queue triage | Oversight and threat hunting |
Every one of the roughly 4,300 daily alerts is now investigated end-to-end. 88% are closed automatically, each with an evidence-backed case file available for review and audit. Mean time to investigate fell from 4.2 hours to 6 minutes — a reduction of more than 97% — and the reduction applies to the entire queue, not the fraction humans previously reached. Throughout, zero raw log data left the client's environment.
The three analysts were not displaced; they were promoted by the architecture. Their work is now reviewing escalations, sampling auto-closed case files for quality assurance, and running proactive hunts with the Hunt agent — the work they were hired to do and never had time for.
Why it worked
Three properties of the deployment carried the outcome. First, zero-ingestion federation removed the usual price of admission: there was no migration, no dual-running period, and no new data platform to secure, which is why value arrived in week one rather than quarter three. Second, investigation-by-default changed the unit of work — instead of humans deciding which alerts deserved investigation, machines investigated everything and humans decided what deserved judgment. Third, evidence discipline made automation acceptable in a conservative industry: an 88% auto-close rate is only tolerable when every closure carries a case file that a reviewer, a regulator, or an incident retrospective can interrogate.
If your alert queue outruns your analysts — whatever your SIEM — CAELION can demonstrate Trace8 against your live environment, read-only, in a private briefing.
Client identity withheld by agreement. Figures anonymized and rounded from engagement reporting.