▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

ExtraHop® Launches the Agentic SOC Alliance to Validate a Shared Operating Model for Machine-Speed Defense

The security operations center is being rebuilt around a new operating model, one designed for machine-speed threats rather than human-speed workflows. Today, ExtraHop®, the leader in real-time netwo...

Immagine

Alliance members will validate architectural requirements for the AI SOC across Context, Harness, and Model, anchored by discoverable, semantically rich context every agent can query and reason on, so enterprises can adopt autonomous, machine-speed defense

Founding members include AuthMind, Armadin, Command Zero, CrowdStrike, Dropzone AI, Exaforce, ExtraHop, Fig, Intezer, Kindo, LangChain, Prophet Security, ReversingLabs, TENEX.AI, and Torq.

SEATTLE: The security operations center is being rebuilt around a new operating model, one designed for machine-speed threats rather than human-speed workflows. Today, ExtraHop®, the leader in real-time network intelligence and modern network detection and response (NDR), launched the Agentic SOC Alliance initiative to define and standardize this new SOC operating model: a three-layer architecture of Context, Harness, and Model that gives autonomous security agents the evidence, governance, and reasoning they need to act with precision.

The queue-enrich-triage-investigate-escalate pipeline that has run every SOC for two decades was built for a threat that moved at human speed. Post-frontier-AI adversaries now find a vulnerability, weaponize it, and move laterally in minutes. That pipeline cannot be optimized fast enough to close the gap. It has to be replaced by an operating model built for autonomy from the ground up, with rich, discoverable context as its foundation.

“Post-Mythos AI has fundamentally changed cyber defense. Adversaries now operate at machine speed, yet most security operations are still built on architectures designed for a human-paced world,” said Greg Clark, CEO, ExtraHop. “The industry needs a blueprint for how autonomous security should operate that combines real-time context, intelligent orchestration, and specialized AI agents into a new operating model. The Agentic SOC Alliance is bringing that blueprint together, giving organizations a foundation to detect, decide, and respond with the speed and accuracy that modern threats demand. This is a starting point, not a finished one. We invite the rest of the industry to join the Alliance and help us refine, validate, and perfect this operating model, because outpacing a machine-speed adversary is a challenge no single company can solve alone.”

“In the modern SOC, the turning point is recognizing that real-time ingest from network and endpoint telemetry has to become the primary substrate for how AI agents operate,” said Jason Dewez, CISO, Fiserv. “Post-Mythos-level models can reason at remarkable speed, but only when they are fed live evidence from the environment instead of waiting on slower, batch-oriented pipelines. Our target state is machine speed detection, containment, response, and recovery. Our traditional SIEM model, while necessary, will not be able to keep up. Agentic assisted SOC is the only answer in our opinion.”

Founded by AuthMind, Armadin, Command Zero, CrowdStrike, Dropzone AI, Exaforce, ExtraHop, Fig, Intezer, Kindo, LangChain, Prophet Security, ReversingLabs, TENEX.AI, and Torq, this diverse coalition spans network detection, endpoint, AI-native SOC platforms, orchestration, and agent frameworks, and reflects the reality that autonomous defense cannot be delivered by any single vendor. The Agentic SOC Alliance establishes the requirements, best practices, and implementation blueprints for a SOC built for autonomy from the ground up.

Machine-Speed Attackers Demand Machine-Speed Defenders

As Mythos-class frontier models reshape the threat landscape, adversaries now automate reconnaissance, exploit development, and lateral movement at machine speed. Security teams are racing to deploy autonomous defenses of their own, but most of these AI systems flood analysts with false positives, send investigations down the wrong path, and let real threats slip through the noise.

The Agentic SOC Alliance closes that gap by uniting three foundational layers into a single post-Mythos architecture designed so autonomous agents can act with precision and be trusted to do it. Two of those layers, Context and the Harness, are durable. The third, the Model, is interchangeable by design.

Context: Not a collection of telemetry sources, but a continuously updated, highly structured representation of enterprise reality that AI reasons over directly.

Context should provide an operational knowledge graph of every device, identity, workload, connection, and behavior, discoverable and semantically detailed enough that an agent can find exactly what it needs and understand what it means. Assembled in real time, it includes insight from network, endpoint, identity, and threat intelligence. Because agents reason over this structured representation rather than raw logs, they reach more defensible conclusions while consuming far less inference: This results in lower reasoning complexity, fewer tokens, less time and cost spent inspecting raw data and faster answers. Fragmented logs force a model to reconstruct meaning on every turn. A structured, discoverable knowledge graph hands it the answer already assembled. This is the layer the rest of the architecture depends on. No model is good enough to reason its way out of missing evidence.

Harness: The AI runtime and orchestration layer that governs how agents actually operate, executing workflows, calling tools, managing state and memory, and coordinating agents across the environment, with governance, guardrails, permissions, human approval routing, and a complete audit trail as core responsibilities running throughout.

This is where autonomous work actually runs, and where it stays controllable. Because the Harness layer holds the orchestration and the guardrails, a model can be swapped without re-earning trust from a standing start.

Model: The interchangeable reasoning layer, where specialized, multi-model AI performs triage, investigation, and response.

Context and Harness are the durable layers the architecture is built on; the model is not. Customers can adopt each new generation of models, or run several at once, without re-architecting anything around them. The model is a component you upgrade, never a foundation you are locked into.

“Cybersecurity has reached the point where human-speed defense is no longer sufficient against machine-speed attacks. The Agentic SOC Alliance represents one of the industry’s first serious efforts to define an open operational architecture for autonomous security operations, bringing together trusted context, governed AI, and coordinated response so enterprises can finally begin defending at the speed of their adversaries. I am excited to see the development.” – Dr. Edward G. Amoroso, CEO, TAG Infosphere and Research Professor, NYU

By aligning the Context, Harness, and Model layers across a shared ecosystem, the Agentic SOC Alliance helps joint customers modernize the SOC around a more accurate and governable autonomous operating model.

Trustworthy Context: The Foundation the Rest of the Architecture Reasons On

The primary barrier to agentic SOC accuracy is the AI context gap. Fed fragmented logs, autonomous agents lack the evidence to reach defensible conclusions, and they burn tokens and time reconstructing meaning the data should have carried in the first place. Structuring that evidence as a continuously updated operational knowledge graph, discoverable and semantically detailed rather than raw, closes both gaps at once; network, endpoint, and identity signals become continuously findable and understandable in place, so agents reason over answers rather than reconstructing them from raw material.

Within this ecosystem, ExtraHop delivers the high-fidelity, real-time operational knowledge graph, enriched with identity and endpoint data, that autonomous agents need. Its decrypted, protocol-level visibility closes the gaps that cause AI models to falter. Because that context arrives already structured, discoverable, and richly detailed rather than raw and fragmented, agents reach conclusions with lower reasoning complexity, fewer tokens, and less time and cost spent inspecting raw data, which makes autonomous detection, investigation, and response not just more accurate but more affordable at enterprise scale.

What Agentic SOC Alliance Members are Saying

“We built Armadin to answer one question. Are we secure? This Alliance is asking that same question of the modern SOC. The only honest answer comes from testing the architecture against something that behaves like a real attacker. That is Armadin's contribution, and it's the standard the industry needs to meet.” – Kevin Mandia, CEO & Founder, Armadin

“We're excited to join the Agentic SOC Alliance. A Context, Harness and Model architecture is only as good as the data feeding it. AI SOC agents require the identity activity data to be able to operate as they can't reason precisely from identity policies alone. They need an identity access graph that shows what identities are actually doing, to have better context, relevant identity risks findings and the data needed to enable fast remediation.” – Shlomi Yanai, CEO, AuthMind

“Command Zero asks specific questions to get the full context and validates threat data to deliver the best verdicts in the SOC. The platform relies on ExtraHop’s network data to improve visibility and accuracy for every analysis. We are excited to be part of the Agentic SOC Alliance, and we see it as an impactful step towards giving defenders the upper hand against AI-powered threats.” – Alfred Huger, Co-founder and Chief Product Officer, Command Zero

“The future of the SOC is agentic, and CrowdStrike is leading that transformation with the AI-native Falcon platform. Autonomous security operations require an open ecosystem that brings together the right data to investigate and respond with speed and precision. Our participation in the Agentic SOC Alliance extends the Falcon platform with high-fidelity network telemetry, helping customers accelerate investigations, automate response, and stop breaches.” – Daniel Bernard, Chief Business Officer, CrowdStrike

“We are at a defining moment where AI analysts must scale to match the velocity of modern cyberattacks, and achieving that requires a collaborative ecosystem, not isolated solutions. The Agentic SOC Alliance is about driving that collective operational evolution forward. By combining Dropzone’s agentic SOC agents with ExtraHop’s protocol-level network context, we are proving that a truly integrated ecosystem can deliver an elite autonomous defense layer that operates flawlessly at machine scale.” – Edward Wu, Founder and CEO, Dropzone AI

“The future of security operations won’t be defined by AI alone, but by AI with complete context. Every security product sees a different part of an attack, yet defenders are still forced to stitch those signals together manually. By combining ExtraHop’s network intelligence with Exaforce’s Exabots (AI Agents) across the broader security ecosystem, we’re helping build an open ecosystem where Exabots operate with richer context and greater confidence.” – Ankur Singla, Co-founder and CEO, Exaforce

“We're proud to be a founding member of the Agentic SOC Alliance. A modern SOC is only as reliable as the data behind it. ExtraHop delivers rich, high-fidelity network detection and response, and Fig makes sure that data keeps flowing reliably through the SecOps stack, so the detections and AI agents built on top of it stay accurate as the environment changes. We're excited to help make the agentic SOC something teams can actually trust.” – Gal Shafir, Co-founder & CEO, Fig

“Most security teams never investigate the majority of their alerts. Intezer’s AI SOC changes that by pulling alerts from across the security stack, including identity, endpoint, email, and cloud tools, and autonomously investigating 100% of them at forensic depth, examining the actual code, behavior, and origin of every threat. The quality of that triage and investigation relies entirely on the accuracy of the data and context feeding it. ExtraHop fills the network visibility gap the other tools leave behind, giving Intezer the decrypted, protocol-level telemetry it needs to produce verdicts backed by evidence an analyst can stand behind.” – Mark Daggett, Vice President of Global Channels and Alliances, Intezer

“Outpacing a machine-speed adversary is not something any one vendor can do alone, and we're proud to stand with ExtraHop and the founding members to define what autonomous security should actually look like. Kindo brings the AI harness with the governed runtime where security agents act across all tools and data sources, keeping a human in the loop by policy. Kindo runs wherever you need it: from SaaS to your own private cloud to fully on-premise, and even air-gapped. The customer always decides where their data and decisions live. Kindo is AI model and data source agnostic, so you stay in control of your costs and remain agile as the fast changing AI market evolves.” – Ron Williams, CEO, Kindo

“Better models alone don't get an agent to production. The harness does. We built LangGraph to govern what an agent can do with its evidence, which context it reads, which actions it takes, when a human signs off, and LangSmith to test its trajectory before it goes live. Inside the Alliance, that becomes the layer every member agent runs in, so you can change the model underneath without re-earning trust in what the agent is allowed to do.” – Karan Singh, Head of Partnerships, LangChain

“The Agentic SOC Alliance unites leaders advancing the future of security operations with autonomous AI. Bringing ExtraHop’s high-fidelity network data into the Prophet AI SOC Platform provides critical context and ground truth for our AI agents as they investigate alerts and perform threat hunts. This integrated approach gives enterprises the transparency and confidence to trust autonomous security operations.” – Vibhav Sreekanti, CTO, Prophet Security

“Next-generation threat intelligence can’t stop at static indicators and behavioral signatures. In the AI era, that’s not enough. GenAI-era threat intelligence delivers those artifacts alongside a threat context that auto-generates a behavioral detector and the instructions to investigate and provide compensatory controls once it fires. It’s an autoimmune system: rapid inoculation, efficient response, and we look forward to powering the Alliance with it.” – Mario Vuksan, CEO & Co-Founder, ReversingLabs

“The legacy SOC framework is fundamentally unsuited for the AI era; the industry desperately needs a new architectural blueprint designed for true autonomy. Tenex joined the Agentic SOC Alliance to help lead collective transformation. When our automated deployment services are backed by the critical network context ExtraHop brings to the ecosystem, enterprise organizations can finally move past manual triage, radically collapse investigation timelines, and achieve stronger business resilience.” – Eric Foster, Founder and CEO, TENEX.AI

“The agentic SOC lives or dies on context quality. When AI agents reason on fragmented or delayed data, accuracy and outcomes suffer. ExtraHop’s network telemetry is one of the high-fidelity sources that the Torq AI SOC Platform analyzes to triage, investigate, and respond at machine speed. It’s no coincidence that Gartner® recently named Torq The Company to Beat for AI SOC Agents for Threat Investigation, and that’s why we are thrilled to be a founding member of and contributor to this alliance.” – Eldad Livni, Chief Innovation Officer and co-founder, Torq

Learn more about the Agentic SOC Alliance and why the SOC needs a new operating model.

About ExtraHop®

ExtraHop is a leader in real-time network intelligence, empowering organizations with the high-fidelity context they need to power security and IT AI automation, detect risks faster, and respond with confidence.

ExtraHop anchors AI agents with the real-time, ground-truth foundation they need to operate reliably in the SOC and NOC. For security, that means surfacing threats and providing definitive evidence to investigate and respond to novel AI attacks and unsanctioned usage at machine speed. For IT operations, it means identifying and resolving performance issues in seconds to keep critical systems running.

Engineered for unmatched scale, the ExtraHop RevealX platform delivers a complete, unified view of the network for the largest enterprises in the world. Capturing and analyzing network data across data centers, campus, branch, cloud, and AI environments, ExtraHop combines behavioral analysis with deep visibility into encrypted traffic to uncover what others miss.

To learn more, visit www.extrahop.com or follow us on LinkedIn.

© 2026 ExtraHop Networks, Inc., RevealX, RevealX 360, RevealX Enterprise, and ExtraHop are registered trademarks or trademarks of ExtraHop Networks, Inc.

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

Rapidus and Cadence Partner on Agentic AI for Advanced SoC Design

$CDNS #AIforDesign--Rapidus Corporation and Cadence (Nasdaq: CDNS) today announced a collaboration to advance agentic AI for advanced-node system-on-chip…

Nebius raises $775 million in first secured debt financing to accelerate…

Nebius Group N.V. (Nasdaq: NBIS), the AI cloud company, today announced that it has entered into its first senior secured debt facility for approximately…

OpenWorld and Blockchain.com Announce Strategic Partnership to Advance…

OpenWorld Ltd. (“OpenWorld”), a blockchain infrastructure company advancing real-world asset (RWA) tokenization across global markets, and Blockchain.com,…

Spire Global Appoints Eric (“Mell”) Mellinger as Chief Commercial Officer

Spire Global, Inc. (NYSE: SPIR) (“Spire” or “the Company”), a global provider of space-based data, analytics and space services, has appointed Eric (“Mell”)…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!