CyberSecurity SEE

Exabeam Advances the Agentic SOC for Cloud and On-Premises Deployments While Keeping Analysts Informed

Security operations centers (SOCs) are grappling with a dual crisis. On one side, attackers are ramping up automation in their campaigns, creating increasingly sophisticated threats. On the other, organizations are witnessing a surge in the deployment of AI agents and autonomous workflows, often outpacing the capacity of security teams to monitor and manage these complexities. In response to this growing challenge, Exabeam has introduced a comprehensive suite of updates aimed at enabling AI to undertake a larger share of investigative work while ensuring that human analysts remain pivotal in decision-making processes that truly matter.

Headquartered in Broomfield, Colorado, Exabeam has carved a niche for itself as a trailblazer in user and entity behavior analytics (UEBA). Over the past two years, the company has been broadening its capabilities to encapsulate aspects of generative and agentic AI. Key components of its latest offering include Exabeam Nova AI, the Exabeam MCP Server, and Agent Behavior Analytics (ABA), which monitors the activities of both AI agents and human users. This robust foundation sets the stage for the recent innovations aimed at redefining SOC operations.

Steve Wilson, the Chief AI and Product Officer at Exabeam, posits that the evolution of SOCs will not merely be gauged by the number of alerts or the extent of automation. Instead, he argues that the effectiveness of collaboration between human analysts and AI agents will dictate success. “The Agentic SOC gives security teams the speed and scale of AI without relinquishing human judgment, context, or control,” Wilson remarked, emphasizing the importance of a blended approach.

Industry analysts echo this sentiment, observing a shift in focus. Michelle Abraham, Research Vice President of Security and Trust at IDC, notes that the transition towards an agentic SOC is not about sidelining analysts; rather, it is about recalibrating where their expertise and judgment are applied. With AI agents taking on the burden of investigation, context gathering, and repetitive tasks, humans can dedicate their attention to more critical, high-stakes decisions.

At the heart of these updates lies Nova AI, which now functions as a persistent investigator across the Exabeam New-Scale platform. It collects context, executes follow-up searches, and compiles entity profiles as incidents unfold. A notable enhancement is its Related Cases feature, which automatically clusters linked incidents, providing analysts with a broader view of attack patterns rather than a series of isolated alerts. This holistic perspective enables quicker and more informed responses.

Exabeam is also capitalizing on the AI tools that analysts are increasingly utilizing. The introduction of a new Guided Investigation Skills Pack for Anthropic’s Claude aims to streamline structured triage and investigation workflows within command-line AI agents, driven by natural language instructions. This release marks the inaugural offering from Exabeam’s forthcoming Agent Skills Marketplace.

Moreover, a deeper integration with Claude Enterprise serves a dual purpose: not only does it bolster the effective use of AI, but it also enhances visibility into the actions performed by AI agents. Through event-time analysis and behavior-based correlation, security teams can monitor prompts, tool calls, and actions on a unified timeline, allowing them to identify irregular activities and behavioral deviations.

For security leaders grappling with budget constraints and accountability pressures, Exabeam has introduced tools that generate metrics tailored for board presentations. Outcomes Navigator Overrides allow teams to refine risk assessments and segregate compliance reporting based on different business units, thus enhancing operational transparency.

Organizations that have begun employing these innovations are already witnessing tangible improvements. Eduardo Sulvarán Velázquez, Subdirector Cyber Risk Management at E-Global, reported that Nova AI has significantly enhanced case prioritization and granted analysts faster access to context. This, he noted, has hastened investigation processes while preserving the integral role of human judgment.

Recognizing that not all organizations are ready or willing to transition their security data to the cloud, Exabeam has modernized its LogRhythm SIEM Platform. This upgrade includes an in-place migration from Elasticsearch to OpenSearch, thereby boosting speed and scalability. Additionally, it supports a new self-service reporting engine equipped with AI governance and compliance reporting features.

The rollout also introduces new out-of-the-box collectors for tools like ChatGPT, Google Gemini, and GitHub Copilot, allowing security teams to manage enterprise AI use centrally. Furthermore, the community Model Context Protocol server permits analysts to query and address security data using local generative AI models, all while keeping data securely within their environment.

Exabeam’s commitment to open-source development continues with the expansion of its Open Agent and AI Security Community. New additions include an Agentic SOC Skill Suite for Claude Code and OpenAI Codex, along with enhanced thinking modes and evidence-committed scoring linked to its ongoing Praxen project. These initiatives strive to solidify connections between findings and supporting evidence, and Exabeam is actively inviting contributions from practitioners, researchers, and engineers to further this collective effort.

In summary, Exabeam’s recent offerings signify a pivotal moment in the evolution of security operations, acknowledging the exponential rise of both attacks and AI capabilities while ensuring that human analysts remain pivotal in navigating the complexities of cybersecurity.

Source link

Exit mobile version