Create a ~10-minute presentation slide deck introducing the Security Threat Management Center (STMC) platform, focusing on how automated workflows and AI agents handle enterprise security alerts. Slide Outline & Requirements 1. Overview of the STMC Platform & Workflow Evolution 1.1 Key Metrics & Telemetry - High-level statistics on security alert volume and handling capacity Over the 12-month period, the SOC intake ~2,000,000 total alerts, ~130000 escalated as cases for further investigation effort. daily 356 cases to handle 1.2 Paradigm Shift / Evolution - Automation + Tier 1 Analysts - automation + AI Agents + Tier 1 Analysts 1.3 Workflow Visualizations - Automation:(should use a more graphic display, not a straight-line flow) - alert ingestion - alert triage - static rules - directory fuzzing patterns - threat intel reputation - known legit business software name - Close -> (Respond) / Escalate as Case - case investigation - enrichment flows - alert details retrival - run templated log query - tier 1 analysis - Automation + Agentic:(should use a more graphic display, not a straight-line flow, the agent is the focus, it should be centered and larger) - alert ingestion - alert triage - static rules - directory fuzzing patterns - threat intel reputation - known legit business software name - Close -> (Respond) / Escalate as Case - case investigation - agent analysis - dynamic enrichment - contextual verdict - dynamic respond - tier 1 analysis (if agent dont have enough evidence) 2. AI Agent Architecture & Module Deep-Dive (not generic, but highlight what we put into each of these modules, maybe create a graphic display of the entire ai agent system with different modules, multiple slides, with each slide focus and expanding on a particular module for focus) 2.1 Core Capabilities & Technical Stack - Tools & Connectivity: Model Context Protocol (MCP) and tool integrations - threat intel MCP: virustotal, threatbook, cve feeds - SIEM MCP: clickhouse, splunk - security product MCP: titan, crowdstrike, impervaWAF, PAFW - Skills System: - company security stack - reliable query practice - threat intel lookup practice - available responding actions - Self-Learning Engine: - Learns from manual handled cases, - e.g. legitimate business software, critical asset context (e.g., Domain Controllers, Load Balancers) 2.2 Multi-Agent Architecture (Sub-Agents vs. Master Agent Diagram) - Breakdown of complex investigation tasks into targeted sub-agent execution - Example Case (HTTP Alert Investigation): - Master Agent: Task orchestration & final verdict compilation - Sub-Agent 1: Request Analysis - Sub-Agent 2: Response Analysis - Sub-Agent 3: Threat Intelligence Lookup - Sub-Agent 4: Historical Correlation Lookup 3. Impact & Performance Metrics 3.1 Agent analyst Performance first half stats vs second half stats