Telecom Security Operations Centers (SOCs) are paralyzed by alert overload from Splunk, QRadar, or Sentinel, where over 95% of alerts are false positives. This operational bottleneck wastes analyst cycles, delays true incident response, and creates security debt. A custom multi-agent workflow automates the initial triage by applying layered reasoning: one agent enriches raw events with CMDB and threat intel context, another scores entity risk based on historical behavior, and a third executes suppression logic for known benign patterns, cutting manual review volume by 70-80%.




