Effective triage requires analysts to quickly assess the severity, credibility, and context of each incoming alert. It is the first and highest-volume step in the SOC workflow, and is where the most time is wasted in manual operations. Automating triage, with sufficient accuracy and explainability, is one of the most impactful ways to increase SOC capacity and reduce analyst workload.