Exabeam Unveils AI-Powered Security Tools to Accelerate Investigations and Monitor AI Agents
Exabeam has introduced a new set of AI-powered capabilities designed to accelerate security investigations, improve threat response and strengthen oversight of autonomous AI agents across cloud and on-premises environments.
The cybersecurity company said the new capabilities are aimed at supporting the development of agentic Security Operations Centers (SOCs), enabling security teams to conduct investigations, gather intelligence and complete tasks more efficiently as cyber threats increasingly operate at machine speed.
The company’s approach builds on more than a decade of experience applying machine learning to cybersecurity. In recent years, Exabeam has expanded its focus on generative AI and agentic security through technologies including Exabeam Nova AI and the Exabeam MCP Server, while extending behavioral analytics to monitor AI agents alongside human users.
Steve Wilson, Chief AI and Product Officer at Exabeam, said the next generation of SOCs will depend less on simply increasing alerts or automation and more on effective collaboration between security professionals and AI agents. The objective, he explained, is to combine AI’s speed and scalability with human judgment, context and control.
Michelle Abraham, Vice President of Research for Security and Trust at IDC, said the shift toward agent-driven SOCs does not mean removing analysts from the security process. Instead, AI agents can handle information gathering, initial investigations and repetitive tasks, allowing analysts to focus their expertise on activities requiring human judgment.
Nova AI Accelerates Security Investigations
As part of the latest updates to its New-Scale platform, Exabeam has enhanced Nova AI to operate as a continuous investigator. The system can collect incident-related information and context, conduct additional searches and retrieve entity profiles as security incidents develop, helping teams move more quickly from alert detection to investigation and remediation.
According to Exabeam’s internal security operations measurements, Nova AI was able to triage a medium-severity security case in approximately 10 minutes, compared with around five hours for a human analyst performing the same task. The platform’s Related Cases capability can also automatically connect related incidents, giving analysts a broader view of security events rather than requiring them to assess individual alerts separately.
Exabeam has also introduced its Agentic SOC Plugin for Anthropic Claude Code and OpenAI Codex. The plugin provides investigation workflows within AI tools used by security analysts, allowing them to triage alerts, prioritize cases and conduct investigations through natural-language commands.
The company said the plugin is the first in a planned series of capabilities available through the Exabeam Agent Skills Marketplace.
Monitoring Enterprise AI Activity
Exabeam has further expanded its integration with Claude Enterprise to provide greater visibility into AI-agent activity. The integration brings prompts, tool calls and actions together within a unified timeline while using event timing and behavioral correlation to identify unauthorized agents and unusual system activity.
The company has also introduced tools to help organizations communicate cybersecurity outcomes to executives. Executive Digest provides security metrics designed for board-level reporting, while Outcomes Navigator Overrides allows security teams to customize risk assessments and separate compliance indicators across different business units.
Eduardo Solvaran Velasquez, Deputy Director of Cybersecurity Risk Management at E-Global, said Nova AI has helped improve the prioritization of security cases and provided analysts with faster access to the information and context needed to make informed decisions.
LogRhythm Adds AI Capabilities for On-Premises Environments
Alongside its cloud-focused developments, Exabeam has updated LogRhythm SIEM to support AI-assisted security operations within organizations’ on-premises environments.
The updated platform is designed for organizations that need to keep sensitive data, infrastructure or AI workloads within their own facilities while maintaining control over data and compliance requirements.
New AI-powered data collection capabilities support tools including ChatGPT, Google Gemini and GitHub Copilot, allowing security teams to monitor enterprise AI activity through LogRhythm Intelligence Analytics and maintain centralized visibility.
Exabeam has also introduced a community server based on the Model Context Protocol, allowing security teams to query protection data, investigate incidents and triage cases using local generative AI models without moving sensitive information outside the organization’s environment.
The updates also include a technology architecture that moves directly from Elasticsearch to OpenSearch, supporting scalability and performance improvements, alongside a new self-service reporting engine and additional AI governance and auditable compliance capabilities.
Open Community for AI Agent Security
Exabeam also highlighted continued growth in its Open Agent and AI Security Community, which it launched to encourage collaboration around the security of AI agents and autonomous systems.
The company said resources from the community have been downloaded more than 10,000 times since its launch in June 2026. The initiative brings together cybersecurity professionals, researchers and engineers to share knowledge and develop tools addressing emerging risks associated with the growing use of autonomous AI systems.
