Exabeam 推出了一系列新功能,将“代理式安全运营中心(Agentic SOC)”的理念在云端和本地环境中变为现实,融合了由人工智能驱动的调查、执行和治理。仅靠分析师的工作流程已无法跟上机器速度的威胁步伐,也无法应对目标驱动的人工智能代理和自主工作流日益增长的复杂性。安全运营中心的未来属于代理式架构。
十多年来,Exabeam 将应用机器学习融入安全运营,其开创性工作始于用户和实体行为分析(UEBA)。在过去两年中,这一基础推动了在生成式人工智能和代理式安全领域的持续投资,包括 Exabeam Nova AI、Exabeam MCP Server,以及将代理行为分析(ABA)扩展至监控人工智能代理与人类用户。
“下一代安全运营中心不会由更多的警报或更多的自动化来定义,而是由人与人工智能代理协作的有效性来定义。”Exabeam 首席人工智能和产品官 Steve Wilson 表示。“代理式安全运营中心赋予安全团队人工智能的速度和规模,同时不牺牲人类的判断力、上下文理解力和控制权。这就是防御者能够跟上日益以机器速度运行的威胁的方法。”
“向代理式安全运营中心的演变,与其说是将分析师从流程中移除,不如说是改变他们的时间和判断力所应用的领域。”IDC 安全与信任研究副总裁 Michelle Abraham 表示。“随着人工智能代理承担更多的调查、上下文收集和重复性执行任务,安全团队可以将人类专业知识集中在最重要的决策上。Exabeam 的最新功能展示了这一模式如何在现代安全运营中开始成型。”
新的代理式安全运营中心功能加速调查并提升人工智能可见性
最新的 Exabeam New-Scale 功能帮助安全团队更快地进行调查,获得对自主人工智能活动的可见性,并在不增加人员编制的情况下向业务部门证明项目价值。每项功能都旨在让分析师从警报到解决的速度更快,同时保持人类判断和响应的控制权。
通过自主 Nova AI 加速调查。Nova AI 现在作为平台上的持续调查员工作,随着事件的发展收集上下文、运行次要搜索并检索实体档案。据我们自己的安全运营团队测量,Nova AI 平均在约 10 分钟内完成了一个案例的分诊——比人类分析师通常需要的五小时快了 30 倍。“相关案例”功能自动将关联的事件分组,使分析师能够立即看到更全面的画面。
为 AI CLI 代理引入引导式调查。新的 Exabeam Agentic SOC Plugin for Anthropic Claude Code and OpenAI Codex 将专家引导的工作流带入分析师的人工智能工具中,帮助他们通过自然语言命令对警报进行分诊、优先处理案例并进行调查。这是 Exabeam Agent Skills Marketplace 计划中的一系列技能中的第一个。
通过 Claude Enterprise 填补人工智能可见性空白。更深层次的 Claude Enterprise 集成将提示词、工具调用和操作标准化为单一时间线,并利用事件时间分析和基于行为的相关性来检测流氓代理和行为漂移。
通过 Executive Digest 和 Outcomes Navigator 证明业务成果。Executive Digest 提供适合董事会汇报的安全指标,而 Outcomes Navigator Overrides 允许团队定制风险评分,并在不同业务部门之间分离合规指标。
“Exabeam Nova AI 帮助我们更有效地对案件进行优先级排序,使我们的分析师能够更快地获取做出自信决策所需的背景信息。我们见证了人工智能如何实质性地提升安全调查的速度和效率,同时并未将人类判断从流程中移除。将这种智能扩展到整个平台,正是安全团队应对机器速度威胁所需的那种演进,”E-Global 网络安全风险管理副主管 Eduardo Sulvarán Velázquez 表示。
新的 LogRhythm SIEM 平台将代理式安全运营带入本地环境
代理式 SOC(安全运营中心)必须在安全数据所在之处发挥作用。对于将基础设施、数据或 AI 工作负载保留在本地环境中的组织而言,现代化后的 LogRhythm SIEM 平台将人工智能辅助的安全运营引入本地环境,同时保持对敏感数据的控制。
针对 ChatGPT、Google Gemini 和 GitHub Copilot 的新增生成式 AI 收集器,通过 LogRhythm Intelligence Analytics 让安全团队能够集中查看企业 AI 活动情况。新增的社区版 Model Context Protocol (MCP) 服务器使团队能够使用本地生成式 AI 模型查询、调查和分流安全数据,而无需将数据移出其环境。
这些功能运行在一个现代化基础之上,该基础基于从 Elasticsearch 到 OpenSearch 的原位迁移。此次更新提升了速度和扩展性,并支持新的自助服务报告引擎,具备 AI 治理功能和可供审计的合规报告能力。
这些更新为那些需要将安全数据、AI 工作负载和合规报告保留在本地环境中的组织带来了人工智能辅助的安全运营。
Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and governance. Analyst workflows alone can’t keep pace with machine-speed threats or the growing complexity of goal-driven AI agents and autonomous workflows. The future of the SOC is agentic.
For more than a decade, Exabeam has built applied machine learning into security operations, beginning with its pioneering work in user and entity behavior analytics (UEBA). Over the past two years, that foundation has fueled continued investment in generative AI and agentic security, including Exabeam Nova AI, the Exabeam MCP Server, and the expansion of Agent Behavior Analytics (ABA) to monitor AI agents alongside human users.
“The next generation of the SOC won’t be defined by more alerts or more automation. It will be defined by how effectively people and AI agents work together,” said Steve Wilson , Chief AI and Product Officer at Exabeam. “The Agentic SOC gives security teams the speed and scale of AI without giving up human judgment, context, or control. That’s how defenders keep pace with threats that increasingly operate at machine speed.”
“The evolution toward an agentic SOC is less about removing analysts from the process and more about changing where their time and judgment are applied,” said Michelle Abraham , Research Vice President, Security and Trust, IDC. “As AI agents take on more investigation, context gathering, and repetitive execution, security teams can focus human expertise on the decisions that matter most. Exabeam’s latest capabilities illustrate how that model is beginning to take shape across modern security operations.”
New Agentic SOC capabilities accelerate investigation and improve AI visibility
The latest Exabeam New-Scale capabilities help security teams investigate faster, gain visibility into autonomous AI activity, and demonstrate program value to the business without adding headcount. Each is designed to move analysts from alert to resolution faster while keeping human judgment and response in control.
Investigate faster with autonomous Nova AI. Nova AI now works across the platform as a persistent investigator, gathering context, running secondary searches, and retrieving entity profiles as incidents unfold. As measured by our own security operations team, Nova AI triaged an average case in approximately 10 minutes — 30 times faster than the five hours a human analyst would typically require. Related Cases automatically groups connected incidents, so analysts see the broader picture immediately.
Bring guided investigation to AI CLI Agents. The new Exabeam Agentic SOC Plugin for Anthropic Claude Code and OpenAI Codex brings expert-guided workflows into analysts’ AI tools, helping them triage alerts, prioritize cases, and investigate through natural-language commands. It is the first in a planned series of skills from the Exabeam Agent Skills Marketplace.
Close AI visibility gaps with Claude Enterprise. Deeper Claude Enterprise integration normalizes prompts, tool calls, and actions into a single timeline and uses event-time analysis and behavior-based correlation to detect rogue agents and behavioral drift.
Prove business outcomes with Executive Digest and Outcomes Navigator. Executive Digest delivers boardroom-ready security metrics, while Outcomes Navigator Overrides lets teams tailor risk scoring and separate compliance metrics across business units.
“Exabeam Nova AI has helped us prioritize cases more effectively, giving our analysts faster access to the context they need to make confident decisions. We’ve seen how AI can materially improve the speed and efficiency of security investigations without removing human judgment from the process. Extending that intelligence across the platform is the kind of evolution security teams need to address machine-speed threats,” said Eduardo Sulvarán Velázquez , Subdirector Cyber Risk Management at E-Global.
New LogRhythm SIEM platform brings agentic security operations on-premises
The Agentic SOC has to work wherever security data resides. For organizations that keep infrastructure, data, or AI workloads on-premises, the modernized LogRhythm SIEM Platform brings AI-assisted security operations into the local environment while preserving control over sensitive data.
New generative AI collectors for ChatGPT, Google Gemini, and GitHub Copilot give security teams centralized visibility into enterprise AI activity through LogRhythm Intelligence Analytics. A new community Model Context Protocol (MCP) server lets teams query, investigate, and triage security data using local generative AI models without moving data outside their environment.
These capabilities run on a modernized foundation, based on an in-place migration from Elasticsearch to OpenSearch. The update improves speed and scale and supports a new self-service reporting engine with AI governance and audit-ready compliance reporting.
These updates bring AI-assisted security operations to organizations that need to keep security data, AI workloads, and compliance reporting on-premises.
首次收录 · 2026-10-02 · 7.54 分