ExtraHop Launches 400 Gbps NDR Sensor for Agentic SOC

0
ExtraHop has introduced a new 400 Gbps sensor for ExtraHop RevealXâ„¢, enabling full analysis of enterprise data center traffic at line rate. The sensor provides high-fidelity, real-time network context for advanced threat detection while creating an open, extensible foundation for agentic security operations. By delivering evidence at data center speeds, RevealX helps autonomous security agents detect and respond to machine-speed threats faster.

“AI is compounding the volume of data moving across our infrastructure every day, and our security tooling has not kept pace with our data center,” said Chris Konrad, Vice President Global Cyber, World Wide Technology (WWT). “Complete visibility at this scale is no longer optional post-Mythos. AI-powered attacks move at record speed, and the AI-powered systems need to be able to tell the difference between a quiet network and a network they are only partially seeing.”

Autonomous defenses fail when an agent bases decisions on incomplete evidence. An agent fed partial telemetry can reach the wrong conclusion about an attack yet take action confidently at machine speed, across thousands of cases. The resulting audit trail might appear sound yet a breach no one can explain still occurs.

When enterprise data centers and neoclouds moved to 400 Gbps, most detection and response tools remained at 100 Gbps, sampling traffic rather than analyzing it in full, leaving significant security gaps or creating costly clustering overhead. Accelerated AI adoption has made full visibility even more challenging: GPU clusters, Kubernetes workloads, model training and inference pipelines, and agent-to-agent traffic generate dense, encrypted east-west traffic in volumes that make sampling untenable.

The result is blind spots where lateral movement, living-off-the-land techniques, and identity compromise go undetected. These gaps compound as the attack window collapses: mean time to exploit has fallen from 23.2 days in 2025 to roughly 1.6 days in 2026, leaving no margin for a defense that sees only part of the wire.

ExtraHop RevealX analyzes full data center traffic at 400 Gbps and structures it into a live, continuously updated semantic map of every device, identity, workload, and conversation on the network, the instant it happens. Instead of querying the raw feed, SOC agents query discoverable, structured context through APIs and MCP— including the relationship structure of the environment.

From there, agents can drill into the underlying evidence on demand: real-time behavioral detections, assets and entities, protocol metrics and activity maps, L7 transaction records across more than 90 protocols, and full-fidelity packet capture. To keep reasoning both accurate and affordable as volume grows, agents start at the highest-signal layer and examine the full details only when an investigation demands more.

“The reflex across the industry has been to bolt AI onto the SOC we already have, and the harder problem is the context substrate underneath,” said Kanaiya Vasani, Chief Product Officer, ExtraHop. “SIEMs, forensic data lakes, and security warehouses are built to look backward. They are valuable as depth and memory, but they cannot be the first and only source of truth for an agent that has to decide something right now. RevealX is the prevention side of that equation: structured, queryable evidence whose latency budget matches the attack. At 400 Gbps, the busiest networks in the world can hand their agents complete evidence instead of a sample, which is the difference between autonomy a CISO can defend to a regulator and autonomy that is confidently wrong at scale.”

In the recently launched Agentic SOC Alliance’s three-layer architecture — Context, Harness, and Model — the 400 Gbps sensor is the Context layer delivered at data center scale. What 400 Gbps delivers to the Context layer:

  • Complete evidence, not a sample – Full analysis at line rate means an agent’s conclusions rest on what actually happened on the wire, including the encrypted east-west traffic where modern intrusions live.
  • Real-time evidence rather than retrospective – Storage-first tools describe what already happened. ExtraHop produces evidence while the attack is still unfolding, leaving the SIEM and data lake to provide depth and history.
  • Structured and queryable context on arrival – Context arrives structured and addressable, with relationships intact, ready for agents to query through API and MCP, not as raw logs a model has to reconstruct meaning from on every turn, which lowers reasoning complexity, token consumption, latency, and cost per investigation.
  • Open context, verifiably – Evidence semantics that are published, discoverable, and addressable. Customers and third-party agents query the same surfaces ExtraHop’s own tooling uses, with no proprietary runtime required.
  • A live AI asset inventory – Continuous discovery of LLM usage, MCP servers, tool endpoints, and agent-to-agent communication paths as they appear.
  • Fewer sensors for lower total cost – 400 Gbps coverage reduces sensor count, cost, and operational complexity on high-speed networks.
  • One ground truth across SOC and NOC – Security teams, IT teams, and every agent in the environment reason over the same real-time view, with nothing to reconcile across tools.

For more information, visit: https://www.extrahop.com/

Related News:

Talkdesk Report Reveals Agentic AI Execution Gap in Customer Experience

Parallels Desktop 27 Adds AI Acceleration and OpenGL 4.3 Support

Share.

About Author

Leigh Porter's first love is to love people. Beginning her career as a neonatal RN was an obvious choice until life threw the curve ball to embark on a new IT endeavor. Pursuing this fresh career was a piece of cake with her resilient and steadfast character. Outside of the office, Leigh also diligently gives much of her time faithfully as a nationally awarded volunteer leader to a very dear to her heart organization.