Coming soon to the Microsoft Security Store

LEX Agent

Lockbase EXposure Agent — executive exposure intelligence across the Microsoft security stack

Synthesize XSPM exposure, Defender vulnerability management, Entra identity risk, and behavioral signals into ranked, executive-ready exposure briefings — without manual correlation.

[ DESIGNED FOR ]

Designed for CISOs and security leaders who need cross-domain exposure visibility across Microsoft Defender XDR, Entra ID, Intune, and Microsoft Threat Intelligence — without manual correlation between consoles. LEX Agent converts fragmented Microsoft security telemetry into executive-grade exposure judgment.

live // LEX_AGENT.describe()

What it
actually does

> Three-paragraph technical brief. No marketing fluff. Read top to bottom — it walks the agent's job from input to output.

  1. [ OVERVIEW ] 01 / 03

    LEX Agent (Lockbase EXposure Agent) provides executive-level exposure intelligence by synthesizing four Microsoft data layers — Enterprise Exposure Graph (XSPM), Defender Threat & Vulnerability Management, Microsoft Secure Score, and behavioral activity patterns — into clear business-risk briefings. Its unified job is to convert fragmented Microsoft security telemetry into executive judgment a CISO can act on the same hour.

  2. [ INVESTIGATION ] 02 / 03

    The agent operates across five operating modes: Executive Risk Ranking (top exposures by exploitability and business impact), Focus Validation (compare exposures to active incidents for SOC alignment), Finding Consolidation (identify compound risk from overlapping findings on the same asset), Patch Tuesday Triage (campaign exposure and deployment tracking), and Behavioral Risk Assessment (jump-box compliance, lateral movement, service-account misuse, credential attacks, local-admin overuse).

  3. [ DELIVERABLE ] 03 / 03

    LEX Agent outputs executive briefings with ranked P1–P4 exposure tiers, affected hostnames, CVSS and EPSS scores, exploit status, recommended owners, and — when an analyst confirms — Microsoft Intune remediation tasks created and tracked through resolution. Every claim is source-labeled so the security leader can trace any exposure statement back to ExposureGraph, TVM, Entra, or Defender for Identity.

// end.report | sections: 3 | chars: 1,327 v1.0.0 — phase 1

Capabilities

LEX_AGENT.skills[]

35 hunting & enrichment skills,
organized by tradecraft.

A built-in library of investigation skills, categorized by attacker phase. Each category is a set of named capabilities the agent invokes inline — analysts never write the underlying queries by hand.

cat 01
[ XSPM ]

XSPM Exposure Graph & posture

Critical-asset risk profiles, identity blast radius, permission graphs, and finding consolidation across the fleet.

e.g.

Critical-asset risk ranking

Ranks your most important assets by real-world exploitability — not just raw CVE counts.

skills 09
cat 02
[ TVM ]

Vulnerability management & patching

Defender TVM, Patch Tuesday triage, Office and SQL exposure, and update-deployment tracking.

e.g.

Patch Tuesday triage

Turns a fresh batch of CVEs into a ranked list of what actually needs patching first in your fleet.

skills 09
cat 03
[ BEHAVIORAL ]

Behavioral risk detection

Tier 0 access, lateral movement, service-account misuse, brute force, and local-admin overuse.

e.g.

Tier 0 exposure check

Shows which devices are reaching your most critical identity infrastructure outside sanctioned admin paths.

skills 06
cat 04
[ INCIDENT-CORRELATION ]

Defender XDR & identity correlation

Active incidents, identity risk, sign-in anomalies, and Entra context joined with posture data.

e.g.

Posture-to-incident join

Connects live incidents and risky users to the posture findings that explain how they got there.

skills 08
cat 05
[ REMEDIATION ]

Remediation & device management

Intune compliance, remediation-task creation, and write-capable hand-off.

e.g.

Remediation hand-off

Turns a confirmed finding into a prioritized Intune remediation task — with user confirmation before anything is written.

skills 03

Want the full skill list?

We walk through the complete catalog — every skill, live, against real telemetry — in a demo.

Book a demo
// catalog.summary categories: 5 total: 35 skills Full skill catalog available in a live demo.

Requirements

To deploy LEX Agent into your Microsoft Security Copilot workspace you'll need:

  • Microsoft Security Copilot license
  • Microsoft Defender XDR with Advanced Hunting access (ExposureGraph + TVM tables)
  • Microsoft Entra ID with SecurityReader role minimum (queries) or Security Admin for remediation task creation
  • Microsoft Defender for Identity (recommended for behavioral risk skills)
  • Microsoft Intune (recommended for remediation task creation)