Advanced Security Operations Center with CCTV Monitoring Wall

Intezer Launches SOC Operating Layer for AI Agents

The protocol integration provides frontier AI models with direct access to normalized forensic data to accelerate cybersecurity triage.

A new software framework aims to help enterprise organizations integrate generative artificial intelligence into their security operations centers.

Intezer announced a redesigned Model Context Protocol server developed to supply autonomous tools with structured security context. The integration provides frontier AI assistants, including Anthropic Claude, OpenAI Codex and Cursor, with direct access to forensic data gathered from the automated triage of network alerts.

Plugging generative AI platforms directly into raw security detection feeds often yields inconsistent and unreliable outcomes, while building custom data pipelines remains cost-prohibitive for many enterprises. The new operating layer is designed to act as a system of record, collecting and normalizing data across various security layers before the information reaches the AI workspace.

The system ingests alerts from endpoint detection and response, network detection and response, security information and event management, identity, cloud and email security platforms. It then executes forensic analysis to deliver automated verdicts. According to company data, the autonomous layer handles the initial volume to scale down data feeds, allowing connected AI models to inherit historical context when executing response actions or generating incident reports.

By routing data through a unified protocol layer rather than individual tool connectors, security teams can use the connected AI models to write automated tuning rules for false positives, cross-reference user login histories during anomalous travel alerts and sweep enterprise networks for newly discovered threat indicators.

The integration architecture is currently available to existing customers, allowing organizations to maintain localized ownership of case histories, triage logic and internal detection rules within their own network instances.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.