Opens in a new tab

Exabeam extends AI-assisted security investigations to on-premises data

  • Home
  • Blog
  • Exabeam extends AI-assisted security investigations to on-premises data
Security technician watching an Exabeam agentic SOC data flow inside a server rack

Security operations teams can now run AI-assisted investigations across both cloud and on-premises environments, with new capabilities from Exabeam that bring agentic workflows, AI governance, and faster triage to the LogRhythm SIEM platform and the wider Exabeam New-Scale portfolio.

The release focuses on what Exabeam calls the Agentic SOC, which uses AI to help security teams respond to threats at machine speed. It also extends the same model to organizations whose security data, AI workloads, or compliance reporting must stay on-premises.

What is new in the Exabeam Agentic SOC release

The update covers four main areas aimed at speeding alert resolution while keeping analyst judgment in the loop.

Autonomous Nova AI for faster triage

Nova AI now works across the platform as a persistent investigator. It gathers context, runs secondary searches, and retrieves entity profiles as incidents unfold. Internal measurement by Exabeam’s own security operations team found that Nova AI triaged an average case in roughly 10 minutes, a rate the company describes as 30 times faster than the five hours a human analyst would typically need. A related feature, Related Cases, automatically groups connected incidents so analysts see the broader picture at a glance.

Agentic SOC Plugin for AI CLI agents

A new Exabeam Agentic SOC Plugin for Anthropic Claude Code and OpenAI Codex brings guided investigation workflows into the AI tools analysts already use. The plugin helps teams triage alerts, prioritize cases, and investigate through natural-language commands. Exabeam describes it as the first in a planned series of skills from the Exabeam Agent Skills Marketplace.

Deeper Claude Enterprise integration for AI visibility

The release deepens integration with Claude Enterprise to close AI visibility gaps. Prompts, tool calls, and actions are normalized into a single timeline. Event-time analysis and behavior-based correlation are then used to detect rogue agents and behavioral drift in AI activity.

Executive Digest and Outcomes Navigator for business reporting

Executive Digest delivers boardroom-ready security metrics, while Outcomes Navigator Overrides lets teams tailor risk scoring and separate compliance metrics across business units. Together the tools are designed to help security programs demonstrate value to the business without adding headcount.

Bringing agentic security operations on-premises with LogRhythm

For organizations that must keep infrastructure, data, or AI workloads on-premises, the modernized LogRhythm SIEM Platform brings the same AI-assisted model into the local environment without moving data outside it.

New generative AI collectors for ChatGPT, Google Gemini, and GitHub Copilot give security teams centralized visibility into enterprise AI activity through LogRhythm Intelligence Analytics. A new community Model Context Protocol (MCP) server allows teams to query, investigate, and triage security data using local generative AI models, keeping the data on premises.

These capabilities run on a modernized foundation built on an in-place migration from Elasticsearch to OpenSearch. The update improves speed and scale and supports a self-service reporting engine with AI governance and audit-ready compliance reporting.

Why the on-premises option matters

Regulated industries, public sector bodies, and any organization handling sensitive data often need security operations to run inside their own environment. Until now, many AI-assisted SOC features have been designed primarily for cloud deployments, forcing a choice between modern AI workflows and strict data residency. The new LogRhythm capabilities aim to remove that trade-off by pairing AI-assisted triage with collectors, a local MCP server, and an on-premises reporting engine.

How it fits with Exabeam’s AI roadmap

The release builds on more than a decade of applied machine learning in security operations, starting with the company’s user and entity behavior analytics (UEBA) work. Over the past two years, that foundation has supported continued investment in generative AI and agentic security, including Exabeam Nova AI, the Exabeam MCP Server, and the expansion of Agent Behavior Analytics to monitor AI agents alongside human users. The latest update extends that roadmap to organizations that need to keep data on-premises.

FAQ

What is the Exabeam Agentic SOC?

The Exabeam Agentic SOC is the company’s model for security operations, using AI to investigate, execute, and apply governance so security teams can respond quickly to threats without losing human judgment and control.

How fast is Nova AI at triaging cases?

According to Exabeam, internal measurement by its security operations team found that Nova AI triaged an average case in roughly 10 minutes, compared with about five hours for a human analyst.

Can the new Exabeam capabilities run on-premises?

Yes. The modernized LogRhythm SIEM Platform adds AI-assisted security operations for organizations that need to keep data, AI workloads, and compliance reporting on-premises, including a community MCP server and generative AI collectors for ChatGPT, Google Gemini, and GitHub Copilot.

SEOScanPro

SEOScanPro, which includes the AI visibility report

SEOScanPro has the AI visibility report runs a full technical audit of a site and shows the measured result behind every check. Open the AI visibility report.


This article summarizes reporting from helpnetsecurity.com.

← All Articles