# Andrew Jerry

## SOC Automation Lead

[Linked In](https://www.linkedin.com/in/andrewmichaeljerry/)

Andrew Jerry is a SOC Automation Lead at Dropzone AI, where he drives innovation for AI-powered security solutions tailored to SOC analysts. With a focus on aligning technology with real-world user workflows, Andrew ensures that Dropzone AI's platform empowers analysts to respond decisively and efficiently to security threats. Before joining Dropzone AI, he honed his expertise as a Senior Detection & Response Analyst at Expel, leading high-stakes investigations and mentoring security teams. Passionate about redefining modern security operations, Andrew Jerry combines technical acumen with a user-first approach to deliver impactful solutions.

### Inside the SOC

#### Legacy Auth, Real Business: The MFA Alert That Didn’t Signal Compromise

Dropzone AI's SOC analyst investigated a suspicious MFA bypass alert, revealing legitimate legacy auth behavior. Real investigation case study with analysis.

*By Andrew Jerry, June 23, 2025*

### Unmasking the Relay: Navigating Alerts Triggered by Anonymized IP Services

A suspicious login from an anonymized IP triggered an alert. See how Dropzone AI traced it to Apple Private Relay and saved analyst time.

*By Andrew Jerry, May 1, 2025*

### How Dropzone AI Cracked a Tricky VPN Logon Alert—and Why Context Matters

A suspicious VPN login alert flagged a CMO. Dropzone AI investigated the context—VPN, inflight Wi-Fi, and history—and resolved it as benign.

*By Andrew Jerry, April 30, 2025*

### Silent Threat or Software Update? Decoding a Suspicious Dell Installer Alert

A CrowdStrike alert flagged a Dell installer as suspicious. See how Dropzone AI’s autonomous investigation revealed the truth in minutes.

*By Andrew Jerry, April 16, 2025*

.webp)

### How Dropzone AI Built a Rock-Solid Quality Control Program

Learn how Dropzone AI applies quality control methodology, rolling performance metrics, and human validation to ensure every AI-generated alert is accurate and trustworthy.

*By Andrew Jerry, March 27, 2025*

### IP Address Analysis Guide: Expert Tips for SOC Analysts

Transform IPs into intelligence using enrichment tools, threat feeds, geolocation. Essential techniques for SOC investigations. Guide inside.

*By Andrew Jerry, January 2, 2025*

### How AI Eliminates Knowledge Silos in Security Operations

Learn how AI eliminates knowledge silos in security operations, enabling SOC analysts to quickly access critical context and streamline investigations with efficiency.

*By Andrew Jerry, November 14, 2024*

### Top 4 Phishing Signs Every SOC Analyst Must Know

Learn to spot the top 4 phishing signs every SOC analyst should know. From suspicious links to social engineering, master key indicators for effective threat detection.

*By Andrew Jerry, November 4, 2024*

### OSCAR Methodology: A Framework for Efficient SOC Investigations

Learn the OSCAR framework: A 5-phase investigation method reducing time from 40 to 3 minutes. See how AI implements this proven methodology.

*By Andrew Jerry, October 16, 2024*

### Mean Time to Conclusion (MTTC): The Ultimate SOC Efficiency Metric

Mean Time to Conclusion (MTTC) measures the full alert lifecycle, from detection through disposition. See what MTTD and MTTR don't capture, with examples.

*By Andrew Jerry, September 13, 2024*
