ExtraHop releases AI tools to automate SOC workflows
ExtraHop has revealed a set of AI tools in the RevealX platform designed to automate SOC workflows and relieve analyst fatigue.
Against the backdrop of a rapidly expanding threat landscape and alert overload, SOC analysts are increasingly overworked and under-resourced. To overcome these challenges, many are looking to AI; according to the 2024 Global Cyber Confidence Index, 38% of security decision-makers said using AI and machine learning to help manage and mitigate cyber risk is a top priority for their organization this year.
Building upon Smart Triage, which helps SOC analysts prioritize detections, these new AI capabilities extend the power of AI throughout the threat detection, investigation, and response (TDIR) lifecycle.
The new generative AI-powered search assistant from ExtraHop serves as SOC analysts’ threat hunting companion, enabling teams to search for indicators of attack through an AI-powered natural language search interface so they can detect threats faster. With AI Search Assistant, analysts can quickly gain a better understanding of their attack surface with queries like, “Which workstations are not running an endpoint agent” or “Which devices have attributes associated with a known security threat.” The search assistant also suggests relevant queries based on the analyst’s environment and what it deems potentially risky.
“As SOC analysts find themselves more resource-strapped than ever before, the generative AI search assistant from ExtraHop offers immediate value via simple, conversational searches that help quickly locate potential threats,” said Chris Kissel, Research VP, Security and Trust, IDC. “ExtraHop continues to build upon its proprietary AI and machine learning capabilities, and is driving an innovative approach to threat detection that helps organizations identify security issues before it’s too late.”
Smart Investigations utilizes ExtraHop’s industry-leading machine learning architecture to automatically generate investigations by correlating detections that map to high-risk attack patterns. Informed by real-time network insights, Smart Investigations prioritizes the most critical threats, accelerating investigation and response times so organizations can keep operations running.
“AI is inherent to ExtraHop’s DNA, having been baked into our product since day one,” said Kanaiya Vasani, CPO, ExtraHop. “SOC analysts can now apply AI to automate the more mundane and time-consuming functions often bogging them down, like threat hunting, alert correlation, and triage. Recouping the time and resources often spent on these tasks, enterprises can focus on tackling critical threats to more effectively manage their cyber risk.”