SOC, AI/ML, MSSP

Torq SOC Brain trains on analyst decisions to improve AI SOC accuracy

Torq has introduced SOC Brain, a new layer of its AI SOC Platform that learns from past investigations and analyst decisions. The system uses resolved incidents, analyst corrections, and each organization’s security practices to guide future investigations. Torq says that the process can improve consistency and reduce the number of routine cases analysts have to review.

Torq draws a line between memory and learning

AI SOC vendors are increasingly describing their platforms as self-learning. Most often, that means retrieving similar incidents and adding them to the context of an AI-led investigation.

Torq says SOC Brain takes a different approach by training a machine learning model on each organization’s operational data and analyst decisions.

That claim puts Torq into a more crowded conversation. Intezer recently launched Org Brain, which it describes as an autonomous learning loop that updates procedural and organizational knowledge after each investigation.

Torq says the main difference is the way SOC Brain trains and applies its models.

Leonid Belkind, CTO and co-founder of Torq, told MSSP Alert, “What Torq SOC Brain does is unique to the industry. It trains an actual encoder model with a classifier head neural network in a deliberately opinionated way, using techniques like weighted cross entropy to ensure the model treats signals with the seriousness they deserve. The result is that Torq SOC Brain accurately classifies signals as malicious or benign, and that distinction matters. Misclassify a malicious signal, and you miss a real threat. Misclassify a benign one, and you waste someone's valuable time.”

SOC Brain is built around three capabilities: Torq Recall, Torq Reflex, and Torq Retrospect.

Torq Recall uses earlier cases as precedent

Torq Recall searches past investigations for matching indicators, including IP addresses, file hashes, URLs, and hostnames. It ranks relevant cases and reviews how analysts handled them. The system can also read analyst notes, identify conflicting decisions, and adjust confidence based on the strength of the evidence. Torq says analysts do not have to create new tags, rules, or workflows for the system to use that history.

Recall uses retrieval-augmented generation, or RAG, and structured RAG to bring historical and operational data into an investigation. Belkind said those methods support the process, but the final classifications come from models trained on the organization’s own operating patterns.

“What’s fundamentally different is we don’t just deliver in-context learning, which is what the vast majority of AI security operations solutions do. What Torq SOC Brain does is more than just take information about one environment, including history, analyst guidance, previously processed information, and conclusions about previous cases, and put them in the context of agent execution. Torq SOC Brain uses mechanisms such as RAG and structured RAG to dramatically enhance in-context learning as a part of the process. What’s important is that classifications and decisions are based on opinionated analysis, driven by a model trained on the operational data with all its dimensions. The model training process is the one that identifies dimensions/parameters that reflect the operational practices specific for the organization, and not just the data added to the context in an opinionated fashion. This true machine learning is what makes the outcome fundamentally deeper.”

Torq Reflex learns from analyst verdicts

Torq Reflex learns from confirmed verdicts and analyst corrections. Over time, it adapts to how each organization evaluates evidence and classifies risk. Torq initially said Reflex matched analyst-corrected verdicts 85% of the time. Belkind said recent deployments have reached higher accuracy following changes to the model and its training process.

“Torq Reflex is now more than 91% accurate in recent deployments, which is the result of improvements to our AI model’s architecture, as well as training process enhancements. We’ve seen a number of organizations dramatically improving accuracy after just a few dozen verified or disputed analyst verdicts, which only increases in accuracy after a few hundred verdicts.”

Torq Retrospect brings in existing SOC history

Torq Retrospect allows customers to import resolved cases from tools they used before deploying Torq. Those cases then become available to Recall and Reflex. This gives SOC Brain access to an organization’s previous decisions from the start, rather than forcing the system to build a history after deployment.

That history may also come with problems. Older cases can include incomplete notes, inconsistent verdicts or decisions based on policies that no longer apply. Torq says the training process is designed to identify the factors that reflect how the organization operates.

Each customer gets its own model

Torq says every customer receives a private SOC Brain trained on its own incidents, policies, analysts, and operational history. The company says it does not pool customer data, share model parameters, or train one customer’s system on another customer’s experience.

SOC Brain currently trains encoder models for each environment. Torq is also considering separate models for different event families, which could allow the platform to learn different decision patterns for identity, endpoint, cloud, or other types of alerts.

“Torq SOC Brain trains encoder models for each environment. We’re even considering training separate encoder models for different event families. That means we’re capturing the learning context and operational decisions, so analysts don’t have to. This learning process is what truly captures the operational intent. It infers what’s important without someone needing to think about it ahead of time, and it’s what contributes to the high-quality outcomes Torq SOC Brain delivers.”

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds