Agent catalog

Each agent is purpose-built for Microsoft Security Copilot. Click through for the full product page, deployment requirements, and SCU pricing.

custom_agent.build()

Don't see your stack?
We'll build the agent.

LOX Agent ships against CrowdStrike + Defender out of the box. If your environment runs different EDRs, different data feeds, or has Sentinel playbooks and datalake pipelines that need first-class hand-off, we'll customize an agent purpose-built for your SOC.

  • [ EDR_OF_CHOICE ] opt.01

    Your EDR, your way

    We rebuild the active-EDR side of LOX against the platform you actually run — CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne Singularity, Palo Alto Cortex XDR, Carbon Black, or anything with an alerts API.

    • CrowdStrike
    • Defender for Endpoint
    • SentinelOne
    • Cortex XDR
    • Carbon Black
  • [ DATA_FEED ] opt.02

    Any data feed, correlated

    Bring your own telemetry: a SIEM you already pay for, a custom datalake, a threat-intel feed, identity logs, network sensors. We map it into the agent's investigation graph so every finding cites its source.

    • Sentinel
    • Splunk
    • Snowflake
    • ADX
    • Elastic
    • MDTI
    • Recorded Future
  • [ SENTINEL_PLAYBOOK ] opt.03

    Sentinel playbook + datalake integration

    Automate agent triage straight from Sentinel incidents using the Logic Apps connector for Security Copilot agents — fire a full investigation as a step inside any playbook. Then tap into Sentinel's MCP plugin to search deeper data sets directly inside your Sentinel datalake.

    • Sentinel Playbooks
    • Logic Apps connector
    • Sentinel MCP plugin
    • Sentinel Datalake