SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Exabeam adds AI tools for agentic security operations

Exabeam adds AI tools for agentic security operations

Fri, 2nd Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Exabeam has introduced new artificial intelligence features for its security operations products across cloud and on-premises environments.

The update adds tools for automated investigation, visibility into AI agent activity, and reporting for business and board-level audiences.

The changes are intended to support what Exabeam calls an Agentic SOC, a security operations model in which AI agents handle parts of investigation and execution while analysts retain decision-making control.

Among the new capabilities is an expanded role for Exabeam Nova AI, which now operates across the platform as a persistent investigator. As incidents develop, it can gather context, run secondary searches, and retrieve entity profiles.

Exabeam has also added a Related Cases feature that groups connected incidents to give analysts a broader view of linked events. Its internal security operations team found Nova AI triaged an average case in about 10 minutes, compared with five hours for a human analyst.

AI investigation

Another addition is the Exabeam Agentic SOC Plugin for Anthropic Claude Code and OpenAI Codex. The plugin brings guided investigation workflows into AI coding assistants and is designed to help analysts triage alerts, prioritise cases, and investigate through natural-language commands.

Exabeam described it as the first in a planned series of tools from its Agent Skills Marketplace. The company has also extended its integration with Claude Enterprise to give security teams a unified timeline of prompts, tool calls, and actions.

According to Exabeam, the integration uses event-time analysis and behaviour-based correlation to detect rogue agents and behavioural drift. The aim is to address visibility gaps as organisations increase their use of autonomous AI systems.

Exabeam has also added Executive Digest and Outcomes Navigator Overrides, two reporting and measurement tools. Executive Digest is designed to present security metrics to senior executives, while Outcomes Navigator Overrides lets teams adjust risk scoring and separate compliance metrics across business units.

Steve Wilson, Chief AI and Product Officer at Exabeam, said the company sees AI and human analysts working together rather than replacing one another.

"The next generation of the SOC won't be defined by more alerts or more automation. It will be defined by how effectively people and AI agents work together," Wilson said.

"The Agentic SOC gives security teams the speed and scale of AI without giving up human judgment, context, or control. That's how defenders keep pace with threats that increasingly operate at machine speed."

Michelle Abraham, Research Vice President for Security and Trust at IDC, said the broader industry shift is changing how analysts spend their time.

"The evolution toward an agentic SOC is less about removing analysts from the process and more about changing where their time and judgment are applied," Abraham said. "As AI agents take on more investigation, context gathering, and repetitive execution, security teams can focus human expertise on the decisions that matter most. Exabeam's latest capabilities illustrate how that model is beginning to take shape across modern security operations."

On-premises push

Exabeam has also updated the LogRhythm SIEM Platform for organisations that keep infrastructure, data, or AI workloads on-premises. The changes bring AI-assisted security operations into local environments without moving sensitive data outside them, according to the company.

New generative AI collectors for ChatGPT, Google Gemini, and GitHub Copilot provide centralised visibility into enterprise AI activity through LogRhythm Intelligence Analytics. A new community Model Context Protocol server allows teams to query, investigate, and triage security data using local generative AI models.

The updated platform is based on an in-place migration from Elasticsearch to OpenSearch. Exabeam said the change supports improvements in speed and scale, as well as a self-service reporting engine with AI governance and compliance reporting.

The announcement adds to Exabeam's broader push into AI-led security operations. Its Open Agent and AI Security Community, which the company founded, has recorded more than 10,000 downloads since launching in June 2026, according to Exabeam.

A customer using the technology pointed to gains in case prioritisation and investigation speed.

"Exabeam Nova AI has helped us prioritise cases more effectively, giving our analysts faster access to the context they need to make confident decisions. We've seen how AI can materially improve the speed and efficiency of security investigations without removing human judgment from the process. Extending that intelligence across the platform is the kind of evolution security teams need to address machine-speed threats," said Eduardo Sulvarán Velázquez, Subdirector of Cyber Risk Management at E-Global.