Andrew Jerry
Andrew Jerry
SOC Automation Lead
Andrew Jerry is a SOC Automation Lead at Dropzone AI, where he drives innovation for AI-powered security solutions tailored to SOC analysts. With a focus on aligning technology with real-world user workflows, Andrew ensures that Dropzone AI's platform empowers analysts to respond decisively and efficiently to security threats. Before joining Dropzone AI, he honed his expertise as a Senior Detection & Response Analyst at Expel, leading high-stakes investigations and mentoring security teams. Passionate about redefining modern security operations, Andrew Jerry combines technical acumen with a user-first approach to deliver impactful solutions.
Inside the SOC
Legacy Auth, Real Business: The MFA Alert That Didn’t Signal Compromise
Dropzone AI's SOC analyst investigated a suspicious MFA bypass alert, revealing legitimate legacy auth behavior. Real investigation case study with analysis.
By Andrew Jerry, June 23, 2025
Unmasking the Relay: Navigating Alerts Triggered by Anonymized IP Services
A suspicious login from an anonymized IP triggered an alert. See how Dropzone AI traced it to Apple Private Relay and saved analyst time.
By Andrew Jerry, May 1, 2025
How Dropzone AI Cracked a Tricky VPN Logon Alert—and Why Context Matters
A suspicious VPN login alert flagged a CMO. Dropzone AI investigated the context—VPN, inflight Wi-Fi, and history—and resolved it as benign.
By Andrew Jerry, April 30, 2025
Silent Threat or Software Update? Decoding a Suspicious Dell Installer Alert
A CrowdStrike alert flagged a Dell installer as suspicious. See how Dropzone AI’s autonomous investigation revealed the truth in minutes.
By Andrew Jerry, April 16, 2025
.webp)
How Dropzone AI Built a Rock-Solid Quality Control Program
Learn how Dropzone AI applies quality control methodology, rolling performance metrics, and human validation to ensure every AI-generated alert is accurate and trustworthy.
By Andrew Jerry, March 27, 2025
IP Address Analysis Guide: Expert Tips for SOC Analysts
Transform IPs into intelligence using enrichment tools, threat feeds, geolocation. Essential techniques for SOC investigations. Guide inside.
By Andrew Jerry, January 2, 2025
How AI Eliminates Knowledge Silos in Security Operations
Learn how AI eliminates knowledge silos in security operations, enabling SOC analysts to quickly access critical context and streamline investigations with efficiency.
By Andrew Jerry, November 14, 2024
Top 4 Phishing Signs Every SOC Analyst Must Know
Learn to spot the top 4 phishing signs every SOC analyst should know. From suspicious links to social engineering, master key indicators for effective threat detection.
By Andrew Jerry, November 4, 2024
OSCAR Methodology: A Framework for Efficient SOC Investigations
Learn the OSCAR framework: A 5-phase investigation method reducing time from 40 to 3 minutes. See how AI implements this proven methodology.
By Andrew Jerry, October 16, 2024
Mean Time to Conclusion (MTTC): The Ultimate SOC Efficiency Metric
Mean Time to Conclusion (MTTC) measures the full alert lifecycle, from detection through disposition. See what MTTD and MTTR don't capture, with examples.
By Andrew Jerry, September 13, 2024