Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialKey Takeaways
If you walked the show floor at Black Hat this year, you couldn’t go 10 feet without tripping over the word "agentic." Just about every booth promised an AI agent that will detect, triage, investigate, isolate, remediate, or all of the above, and do it faster than any human analyst ever could.
If you're cynical, the cybersecurity industry's rapid embrace of AI looks like the latest in a long line of hot technologies that cybersecurity firms use to dress up their products. Think "big data," "virtualization," "SaaS," and "cloud."
But AI is much more than that: a powerful and highly adaptable technology ecosystem that has already transformed the threat landscape by enabling highly automated and sophisticated attacks. On the flip side, agentic AI also holds the potential for security teams to get a leg up on malign actors for the first time. A key to that is the development of what is being termed the "agentic SOC," or agentic security operations center.
But how will that work? And what, if anything, will agentic SOCs carry over from existing enterprise SOCs? To get answers, I caught up with Kanaiya Vasani, CPO and CMO at ExtraHop, on the sidelines of Black Hat to talk about the transformation agentic AI is prompting in the infosec industry and the urgent need for agentic SOCs to address AI-powered cyber threats.
ExtraHop built its name as a leader in network detection and response (NDR). But as Vasani tells it, the company's role is shifting as AI pushes security firms to increase the speed and accuracy of their technologies to counter AI-powered threats. (ExtraHop just unveiled RevealX™ an NDR platform capable of 400 Gbps "line rate" analysis of enterprise data center traffic.) AI is also prompting a larger shift from a siloed, point-product vendor ecosystem to one that is far more collaborative, with shared architecture built to maximize the security effectiveness of agentic AI.
At the foundation of that architecture is what Vasani and others refer to as the "context layer": a wealth of data from leading vendors on software threats, networks, endpoint detection, identity, and more. Unlike the human analysts who have powered traditional SOCs, AI agents can rapidly digest massive volumes of that data and reason on its contents as they work out what is actually happening inside an enterprise environment.
In this conversation, Vasani and I talk about the Agentic SOC Alliance, an initiative that ExtraHop launched in July with more than a dozen partners, including ReversingLabs, CrowdStrike, and LangChain. The Alliance seeks to define a common architecture the industry can rally around instead of every vendor building its own walled garden. That architecture will include a shared context layer, a governance "harness" for agents, and an open ecosystem of models and agents.
We also dig into why structured, token-efficient context matters as much as raw model horsepower, and why customers, not just vendors, are the ones now asking for a seat at the table as this architecture takes shape.
Here's our conversation.
[ See webinar: Autonomy, Not Autopilot: Get Real About the Agentic SOC ]
Kanaiya Vasani, ExtraHop: My name is Kanaiya Vasani. I run products and marketing here at ExtraHop, so CPO and CMO at ExtraHop. ExtraHop is a leader in modern network detection and response solutions. Our positioning in the market is evolving as the SOC goes agentic, and it's really starting to rotate more around us being the context layer for the agentic SOC.
Because of the amount of intelligence we can extract from the network, that becomes the ground truth these agents are going to need in the SOC as it evolves to a more autonomous, agentic operation. That's a transition we are going through right now, as we speak.
Paul Roberts, ReversingLabs (RL): The notion of a security operations center goes back a long time. Is it simple enough to say the agentic SOC is just an automated SOC powered by artificial intelligence, or is that overly simplistic?
Kanaiya Vasani, ExtraHop: I think that's overly simplistic, because it's not just taking the human analyst you had and replacing them with a bot. That would be easy to do if that was all we needed. In the post-Mythos threat landscape, the entire workflow for detection, investigation, and response needs to be rethought.
The traditional model is very batch-processing oriented. You have alerts coming in from your detection and response systems in the form of logs. The logs get triaged. Your level one analyst grinds through the barrage of logs, prioritizes them, creates cases out of them, and passes those on to a level two analyst, who may pass them on to a level three analyst for further investigation. There might be some proactive threat hunting going on. That entire process takes hours, sometimes even days. In the post-Mythos landscape, where you have AI-assisted attackers who can find a vulnerability and exploit it in seconds, that model is just not going to work.
So when we talk about the agentic SOC, we are talking about a paradigm shift from that batch-processing approach to a real-time operation, where telemetry is ingested in real time and behavioral detections are real time in nature. Those detections fire, and when they fire, you wrap them with relevant context. Agents bolt onto that detection pipeline, and those agents have knowledge graphs and context they are connected to, so they can finish the investigation and drive the response in near real time, with a human in the loop or completely autonomously.
We're talking about that entire pipeline and workflow executing in a matter of minutes, not hours and days. That's the difference.
Paul Roberts, RL: In some ways, that's part of a larger conversation that's been happening for a while about the practice of ranking vulnerabilities by severity and patching the most severe ones first. With things like the Known Exploited Vulnerabilities catalog, there's been a growing recognition that severity isn't the only thing that matters. Does it affect your infrastructure? Is it on systems that hold valuable data? Is it actively being exploited?
Kanaiya Vasani, ExtraHop: Yes. We've talked about a risk-based approach to vulnerability management: don't just go and try to patch every vulnerability you have. But the other interesting thing, Paul, is that you are not going to be able to patch all the vulnerabilities these systems find and throw up. You can't patch your way out of this. That's just not going to work.
The other thing is that you're going to see a lot of zero days now, because you're going to find something and exploit it in minutes. So the traditional approach of patching vulnerabilities, or signature-based detection, or the indicator of compromise (IoC)-based detection we used to rely on, is important but no longer sufficient. Behavioral anomalies are really where you're going to catch the bad guys, because you're going to see subtle changes in behavior and traffic patterns. That's where you're going to have to catch them. Real-time behavioral detections will become a lot more important.
Paul Roberts, RL: At ReversingLabs, this is one of the things we've been talking about for a long time, and our Spectra Core technology makes fine-grained detection of these types of threats possible. I know ExtraHop and RL have been on a road tour talking to people about this. Talk about the intersection between what ExtraHop does and what ReversingLabs does.
Kanaiya Vasani, ExtraHop: ReversingLabs has been a great partner in terms of providing us a lot of the threat intelligence and threat context we can use to drive our detection engines at ExtraHop. It's a very synergistic partnership between the two companies.
One of the things we are really looking at right now is opening up our detection APIs, including detection customization and detection creation APIs. So if ReversingLabs finds something new in the wild and knows there is a set of IoCs associated with it, they can write a detector directly into ExtraHop.
That closes the gap between finding a threat in the wild and inoculating your customers with the right set of detectors in an NDR platform. There's an opportunity to really speed up this cycle of understanding the threat landscape, identifying behaviors, IoCs, and signatures, and pushing detectors in real time that ExtraHop can then use to inoculate the enterprise.
Paul Roberts, RL: One of the things ExtraHop announced recently is the Agentic SOC Alliance, which RL is part of, along with companies like CrowdStrike. Talk about the Alliance, what its purpose is, and what companies you're looking to bring into it.
Kanaiya Vasani, ExtraHop: This whole Agentic SOC Alliance initiative really emerged out of a lot of strategic conversations we've had on the roadshow that ExtraHop and ReversingLabs have been on across 12 cities. We have talked to more than 100 decision-makers at the highest levels in security.
As we went through that process, it became very clear that this is not just a vendor providing a solution for behavioral detections or for understanding the threat landscape. The industry needs a framework, an architecture, and an operating model that like-minded vendors can organize around and that customers can embrace.
Three things emerged out of that. The context layer is super critical, and we don't own all the context. CrowdStrike owns some of it, so they have a lot of endpoint context. You might have another vendor with cloud context. You have ReversingLabs with the threat context. You have identity vendors providing identity context.
You need to bring these context engines together into more of a pre-correlated, unified knowledge graph, so we want to partner with these folks and build that out. Then you need a harness layer that provides the governance and the middleware, if you will, between the agents and the context layer, because we are hearing stories about agents breaking out of sandboxes and all of that.
You want to provide the right set of controls on agents, on the tool calls they can make, and full observability on the data going back and forth between agents and your context layer. That's where the harness layer came in. And then you have the agentic layer, which is powered by a variety of different models. It could be open-weight models, frontier models, or tier-two models. The agents can come from large vendors like Palo Alto or CrowdStrike. They may come from a lot of the innovative startups you see here at Black Hat. And at the high end of town, the agents are going to be written by customers.
So there's going to be a full, rich ecosystem of agents. That's another reason the harness is important: agent orchestration can happen in the harness, and tool access to the context layer can be controlled there as well.
Paul Roberts, RL: This concept of the harness is really important. Looking at it from the industry perspective, is it the cybersecurity companies themselves who will create the harnesses? Is it the customers?
Kanaiya Vasani, ExtraHop: There are many very broad-based horizontal players working on harnesses: LangChain, Kindo, and some of the other players out there. We think those are the folks who are going to own the harness layer. In some cases, at the higher end of the market, customers will pick one of these third-party harnesses.
They're going to pick security tools, whether from the large vendors or the new innovators, and agents from those tools, and they're going to build their SOC around this new context-and-harness architecture. As you go lower in the market, into the mid-market, they may go to a single vendor and say, "Look, just give me the harness with your agents bolted onto it, and here's the context layer I want to plug into it."
This entire architecture hinges on context. Agents are only going to be as smart as the context they can reason on. If you don't have good context, the whole thing falls apart.
Paul Roberts, RL: It has to do with accuracy, and it also has to do with efficiency and cost, right?
Kanaiya Vasani, ExtraHop: Absolutely.
Paul Roberts, RL: That's a problem people are increasingly starting to talk about: if you don't have enough context, the number of tokens you're going to expend to complete tasks really goes up.
Kanaiya Vasani, ExtraHop: Correct, and that's one of the things ExtraHop does really well. The context layer from ExtraHop is hierarchical and structured, available through a single API endpoint, and delivered as JSON objects that these agents are really good at chewing on. But you're spot on. I could have an agent go grind on raw packet captures (PCAPs). It'll try to do its best, but the token meter is just going to keep spinning.
If instead you take those PCAPs and create what we call records out of them, you have a record of all the transactions that happened on your network over the last 30, 60, or 90 days. Then you add some time series aggregations and some higher-level abstractions in terms of identities, the assets in your infrastructure, and the behaviors associated with them, and you add things like activity maps and blast radius information. Then you go one step higher and talk about detections and correlated detections. If you can do all of that in real time, now your agent is getting real-time context that is highly structured. It can start to operate at the highest level of abstraction, very token-efficiently, and go deeper as it needs more detailed information from the lower layers of the context.
How the context is structured, and how that context is presented to the agents, is going to be equally important.
Paul Roberts, RL: On the Agentic SOC Alliance, what's the timeline? What's the plan? It just stood up, but what should we be looking for in terms of how it evolves in the coming months?
Kanaiya Vasani, ExtraHop: This is almost like a movement that is just gathering a lot of steam. We got the announcement out a week or 10 days ago, and we already have vendors coming from every corner of the industry asking whether they can join. You can expect another round of member additions very shortly.
We're getting a tremendous amount of positive feedback from customers. A lot of them have said they want to come in and have a seat at the table and drive how this architecture evolves, so we are thinking about a voice-of-the-customer advisory panel as part of the Alliance. There is also a lot of interest from system integrators, infrastructure providers, value-added resellers, and others, because they see an opportunity to play the role of providing the integration services that make it real for customers.
You're going to see some of those vendors roped into the Alliance as well, so stay tuned. In the next couple of weeks, a lot of the expansion ideas associated with the Alliance will start to emerge. The operating model and framework for the Alliance is coming together as well, and the founding members are having a lot of conversations about how we want to drive this going forward. Those things will emerge in the next couple of weeks.
Paul Roberts, RL: You talked about the roadshow and hearing from so many different decision-makers about where they were, what their concerns were, and what their hopes and vision were. Now you're here at Black Hat. Do those two things line up? Are you hearing the same things here that you were hearing out on the roadshow?
Kanaiya Vasani, ExtraHop: They do line up. OpenAI had a presentation yesterday. They talked about how that GPD 5, 6 thing broke out and breached Hugging Face. Those are the kinds of threat landscape examples we have been talking about with customers. This is something they are taking very seriously.
Paul Roberts, RL: That was the case in the UK as well, where the AI model was trying to social engineer an open-source maintainer into committing malicious code.
Kanaiya Vasani, ExtraHop: That's right. And then Meta came out this morning and said their agents breached their sandboxes as well.
Paul Roberts, RL: It's almost like a marketing thing now.
Kanaiya Vasani, ExtraHop: Yeah. "Oh, my agent is smart enough to break out, too. I can do it, too."
Paul Roberts, RL: It also robbed a bank. How about that?
Kanaiya Vasani, ExtraHop: Everyone wants to claim how smart their agents are. But that's a five-alarm fire in customer cybersecurity organizations, so it is resonating very strongly.
You just walk around, and everything you see here at Black Hat is agentic this and agentic that. Autonomous security operations are a top priority for customers, and they are voting with their budget dollars. I have talked to several very large customers who have come and said, "Look, we are reprioritizing our budgets because this is a critical priority for us."
So you see that alignment between what the industry is talking about and what customers are prioritizing. What I found was that they were struggling with how to pull it all together, because they were fending for themselves. Should I just take my context layer and feed it into agents? And then what about governance?
What changed is that when we put this out there, the reason we saw such a groundswell of interest and excitement was that they finally said, "Okay, we found a framework we can organize the entire industry around." This is not a one-vendor fix. The defense community has to come together. If capabilities like that get into the wrong hands, you will need a coordinated effort from the industry to counter them. That's one of the reasons the Agentic SOC Alliance is getting so much customer interest.
Usually these alliances are very vendor-centric. This is the first time I'm seeing customers leaning forward and saying, "Guys, we want a seat at the table. We like what you're doing. We love the framework, and we want to be very much a part of how this evolves in the industry."
Paul Roberts, RL: As an industry, we have tended to be pretty siloed over the last 20 to 30 years, with lots of vertical solutions that aren't particularly integrated. It seems like AI is really changing the ground rules of this industry.
Kanaiya Vasani, ExtraHop: Absolutely, it is changing that. Look at the SOC model today: it's very siloed. Feed threat intel into the SOC. Feed identity in. Feed endpoint in. Feed NDR, or network detections, in. And then there's this massive data lake where you sit and index all this stuff and clean up the data, and then you put a human in front of it and say, "Okay, now find the needle in this haystack."
What the Agentic SOC Alliance is pushing for is a more horizontal view of the architecture: take the entire context layer and pre-correlate it, use a harness to bind the agents to that context layer, and let the agents work on that aggregate context.
Paul Roberts, RL: Mario [Vuksan, CEO of ReversingLabs], was saying that too: one of the problems has always been noise. All of the vulnerabilities, all of the potential threat detections. With AI, in some ways it becomes that you want the noise. You want all of the data, because AI is going to be able to parse through it much more effectively than a human.
Kanaiya Vasani, ExtraHop: That is spot on, because a lot of our customers would say, "Too many detections, so I'm going to tune the detections out, because the humans in the SOC just aren't able to handle it." But that's the reason we have had so many breaches: the needle is in the haystack, and unless you turn over every blade of grass, you aren't going to find it. Now you have a really smart analyst who can turn over every blade of grass until they find the needle. AI has changed that equation.
Paul Roberts, RL: That level 5 CVE, when you pair it with this and with this, results in the breach.
Kanaiya Vasani, ExtraHop: It is amazing how quickly it can correlate information across what used to be siloed pieces of information coming in. That's really changed the dynamic in this battle of AI versus AI. If we can leverage AI, for the first time in the history of cybersecurity we may be on par with, or maybe even slightly ahead of, where the bad guys are. That's the optimistic view of where we are right now.
Paul Roberts, RL: It's a good point to end on.
Kanaiya Vasani, ExtraHop: It's a great point to end on.
Paul Roberts, RL: Thank you for taking the time to do this conversation.
Kanaiya Vasani, ExtraHop: My pleasure.



Organizations don’t realize how pervasive shadow AI has become. And as AI's capability grows, shadow use is harder to manage.

The Life and Times of Cybersecurity Professionals study highlights a trend that has accelerated as cyber has become more complex.

SecOps leaders must tackle cost and risk to deliver autonomous vulnerability operations. But with frontier AI, it's critical.
Agentic AI will disrupt how SOC teams are built — and the way CISOs hire. Here’s how to embrace AI.


We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how our free tier works.