EasySOC — the autonomous investigation engine MSPs resell. White-label 24×7 security monitoring that runs on the Microsoft 365 tenants you already manage. New recurring revenue, zero added headcount.
Hi Product Hunt 👋
I'm Ivan. I built EasySOC for one specific person: the MSP owner who manages 30 M365 Business Premium tenants and has nobody on the team who can read a Defender alert.
You know the pattern. Microsoft is already generating the alerts — you pay for them in the Business Premium licence. Nobody can interpret them. So they sit unwatched, or get a glance on Friday afternoon. And you still carry the risk when a client gets breached.
The usual answers don't fit a generalist shop. Hire an analyst — can't find one, can't bill one. Refer to an MSSP — they end up owning the relationship. Buy Security Copilot — a good tool, if you already have an analyst who knows what to ask it.
EasySOC is the fourth option: an autonomous investigation engine that runs **inside your client's tenant**.
- It picks up each Sentinel incident, search telemetry, checks IPs and hashes, forms hypotheses, and produces a verdict a generalist tech can read.
- When it can't decide, it asks the customer a plain-language question in Teams — "is this admin normally signing in from Malaysia?" — and keeps the answer as a permanent fact for that tenant. Month 6 is far quieter than month 1.
- White-label. Your brand, your invoice, your customer. We never contact the end client.
- Customer data never leaves their tenant. It runs on their Azure, bring-your-own-model.
What it does **not** do, so nobody wastes a demo:
- **No automated response.** It investigates and recommends. Blocking, isolating, resetting stays with you — you already have tenant admin.
- **M365 only.** No on-prem AD, no OT, no non-Microsoft stacks.
- **No production track record yet.** 50+ logged runs on a live Sentinel tenant, median investigation ~3.5 minutes, under $1 of model spend for a batch of 8 incidents. That's where it is. I'd rather say it here than on a call.
So the ask isn't "buy it". I want 3 design partners: run it in shadow mode on one tenant, free, for 90 days. It writes to incident comments only, and you compare what it concluded against what you'd have concluded. 30 minutes with me every two weeks. If it turns out to be noise, tell me and I'll say so publicly.
MSPs — what would stop you putting this on a client tenant next week? I'm answering every comment today.