Success Story

Scaling Security Investigations for a Cloud-First Team with Prophet AI

Industry
Real Estate Technology / Residential Brokerage
Size
Multi-billion-dollar revenue; tens of thousands of affiliated agents nationwide
Integration
Crowdstrike
Google Workspace
Okta
Wiz
Sublime Security
Sumo Logic
Slack
Opsgenie

Key highlights

2-minute

mean time to investigate

95%

reduction in investigation time vs. manual analyst baseline (19x productivity increase)

91.9%

of investigations completed automatically with no analyst involvement

The problem

The customer is a large tech-enabled real estate services company operating one of the highest-volume residential brokerage businesses in the United States. Its end-to-end platform is built on an integrated suite of cloud-based software, powering everything from customer relationship management to marketing and brokerage services for tens of thousands of agents nationwide. With a modern, cloud-first security stack, the company operates with a small security team on an on-call rotation and no dedicated 24/7 SOC.

The team faced three compounding challenges. First, a high volume of alerts that looked suspicious on the surface but were ultimately benign. Distinguishing the benign from the dangerous required tribal knowledge that was difficult to scale and impossible to transfer to junior staff quickly. Second, complex investigations that required manually stitching together signals from the SIEM, EDR, identity provider, and cloud infrastructure to build a coherent timeline — a process that could take hours per incident and pulled senior engineers away from higher-value work. And third, the reality that many alerts were simply ignored because the team lacked the bandwidth to chase down likely false positives.

A recent security incident underscored the risk: a virtual assistant working overseas had malware on their workstation, followed by suspicious login activity from unexpected geographies. The team needed better detection and investigation of impossible-travel-style patterns, but couldn't staff their way to the coverage they needed.

The company was already evaluating AI-powered solutions, but was wary of tools that were inconsistent, opaque in their reasoning, or vulnerable to prompt-injection-style failures. They needed a solution that could reason across their full stack, not just summarize single-source alerts.

The solution

An Agentic AI SOC Platform that reasons across the full cloud stack

The company deployed Prophet AI to act as an autonomous investigation layer across their existing tooling. For each alert, Prophet asked a deterministic set of investigative questions, pulled evidence from multiple tools, and reached a conclusion: benign, malicious, or inconclusive. High-confidence benign findings were resolved automatically. Malicious and inconclusive investigations were escalated into a review queue with full evidence, reasoning, and recommended next steps.

During the deployment, Prophet Security's engineering team built a bi-directional sync with the customer's cloud SIEM, allowing Prophet to write investigation notes and dispositions back into the SIEM and automatically close benign investigations. This meant the security team could continue working from their existing console without adding another dashboard to their rotation.

The team used Prophet AI’s Guidance system to encode their organizational context, teaching the platform how to interpret activity specific to their environment. Prophet AI applied those corrections immediately and carried them forward into all future investigations. For example, when investigating suspicious global authentication and MFA denial activity, Prophet AI was able to correlate IPs, MFA results, geo-locations, and login sequences across the identity provider and EDR into an integrated investigative storyline — a process that would have previously required an analyst to manually pivot across multiple consoles.

The results

95% reduction in investigation time (19x productivity increase)

Based on the company's alert volume and industry-standard benchmarks by severity level, manual investigation effort averaged roughly 37 minutes per alert. Prophet completed the same investigations at an average of 2 minutes each — a 95% reduction in total investigation time and a 19x productivity increase over the manual baseline.

91.9% of investigations resolved automatically

Prophet AI autonomously completed nearly 92% of all investigations without requiring human review. Previously, these same alerts would have either consumed analyst time or, more likely, been deprioritized and ignored due to bandwidth constraints. By handling the volume automatically, Prophet ensured every alert was investigated while freeing the team to focus on the subset that required expert judgment.

99.6% alert type coverage from day one

Prophet AI supported over 99.6% of the customer's SIEM alert types during the initial deployment, demonstrating broad compatibility with their detection engineering without requiring extensive custom configuration.

2 minutes from alert to investigated

Prophet AI's mean time to investigate was 2 minutes — 24x faster than the average attacker's 48-minute breakout time. For a team operating on an on-call rotation without 24/7 SOC coverage, this speed ensures that threats are investigated in near-real-time even when no analyst is actively monitoring.

We have a small team with an on-call rotation and a lot of alerts that look bad but are actually benign. We needed to bubble up only the actionable alerts, and Prophet has felt like having another analyst on the team.

Senior Manager,

Incident Response & Forensics, multi-billion-dollar real estate technology company