Agentic SOC: Exabeam Advances AI-Powered Security Operations

0
Exabeam unveiled new capabilities designed to bring the Agentic SOC to both cloud and on-premises environments, combining AI-powered investigation, automated execution, and governance. As threats move at machine speed and AI-driven agents and autonomous workflows become more complex, traditional analyst-led processes are increasingly challenged. Exabeam says the future of security operations is agentic.

For more than a decade, Exabeam has built applied machine learning into security operations, beginning with its pioneering work in user and entity behavior analytics (UEBA). Over the past two years, that foundation has fueled continued investment in generative AI and agentic security, including Exabeam Nova AI, the Exabeam MCP Server, and the expansion of Agent Behavior Analytics (ABA) to monitor AI agents alongside human users.

“The next generation of the SOC won’t be defined by more alerts or more automation. It will be defined by how effectively people and AI agents work together,” said Steve Wilson, Chief AI and Product Officer at Exabeam. “The Agentic SOC gives security teams the speed and scale of AI without giving up human judgment, context, or control. That’s how defenders keep pace with threats that increasingly operate at machine speed.”

New Agentic SOC Capabilities Accelerate Investigation and Improve AI Visibility

The latest Exabeam New-Scale capabilities help security teams investigate faster, gain visibility into autonomous AI activity, and demonstrate program value to the business without adding headcount. Each is designed to move analysts from alert to resolution faster while keeping human judgment and response in control.

  • Investigate faster with autonomous Nova AI. Nova AI now works across the platform as a persistent investigator across the platform, gathering context, running secondary searches, and retrieving entity profiles as incidents unfold. Related Cases automatically groups connected incidents, so analysts see the broader picture immediately.
  • Bring guided investigation to AI CLI Agents. The new Guided Investigation Skills Pack for Anthropic Claude brings expert-guided workflows into analysts’ AI tools, helping them triage alerts, prioritize cases, and investigate through natural-language commands. It is the first in a planned series of skills from the Exabeam Agent Skills Marketplace.
  • Close AI visibility gaps with Claude Enterprise. Deeper Claude Enterprise integration normalizes prompts, tool calls, and actions into a single timeline and uses event-time analysis and behavior-based correlation to detect rogue agents and behavioral drift.
  • Prove Business Outcomes with Executive Digest and Outcomes Navigator. Executive Digest delivers boardroom-ready security metrics, while Outcomes Navigator Overrides lets teams tailor risk scoring and separate compliance metrics across business units.

“Exabeam Nova AI has helped us prioritize cases more effectively, giving our analysts faster access to the context they need to make confident decisions. We’ve seen how AI can materially improve the speed and efficiency of security investigations without removing human judgment from the process. Extending that intelligence across the platform is the kind of evolution security teams need to address machine-speed threats,” said Eduardo Sulvarán Velázquez, Subdirector Cyber Risk Management at E-Global.

New LogRhythm SIEM Platform Brings Agentic Security Operations On-Premises

The Agentic SOC has to work wherever security data resides. For organizations that keep infrastructure, data, or AI workloads on-premises, the modernized LogRhythm SIEM Platform brings AI-assisted security operations into the local environment while preserving control over sensitive data.

New out-of-the-box generative AI collectors for ChatGPT, Google Gemini, and GitHub Copilot give security teams centralized visibility into enterprise AI activity through LogRhythm Intelligence Analytics. A new community Model Context Protocol (MCP) server lets teams query, investigate, and triage security data using local generative AI models without moving data outside their environment.

These capabilities run on a modernized foundation, based on an in-place migration from Elasticsearch to OpenSearch. The update improves speed and scale and supports a new self-service reporting engine with AI governance and audit-ready compliance reporting.

Together, these updates bring AI-assisted security operations to organizations that need to keep security data, AI workloads, and compliance reporting on-premises.

Continued Open Source Momentum Advances Agentic Security

The Open Agent and AI Security Community, founded by Exabeam, continues to expand with new tools and updates for the agentic SOC:

  • Agentic SOC Skill Suite. Open-source skills for Exabeam New-Scale are now available for Claude Code and OpenAI Codex.
  • Praxen updates. New Thinking Modes and evidence-committed scoring tie findings and scores more directly to supporting evidence.
  • Community plugin marketplace. A single marketplace now supports both Claude Code and OpenAI Codex plugins, simplifying installation with one command. Security practitioners, researchers, and engineers are invited to join the Open Agent and AI Security Community and contribute.

Learn more about the agentic SOC and how AI-powered capabilities are transforming modern security operations at the website here.

Related News:

Google Security Operations: Exabeam Named Recommended Partner

Exabeam Extends AI Security Analytics to Google Security Operations

Share.

About Author

Taylor Graham, marketing grad with an inner nature to be a perpetual researchist, currently all things IT. Personally and professionally, Taylor is one to know with her tenacity and encouraging spirit. When not working you can find her spending time with friends and family.