Advanced Security Operations Center with CCTV Monitoring Wall

Intezer Launches SOC Operating Layer for AI Agents

The protocol integration provides frontier AI models with direct access to normalized forensic data to accelerate cybersecurity triage.

A new software framework aims to help enterprise organizations integrate generative artificial intelligence into their security operations centers.

Intezer announced a redesigned Model Context Protocol server developed to supply autonomous tools with structured security context. The integration provides frontier AI assistants, including Anthropic Claude, OpenAI Codex and Cursor, with direct access to forensic data gathered from the automated triage of network alerts.

Plugging generative AI platforms directly into raw security detection feeds often yields inconsistent and unreliable outcomes, while building custom data pipelines remains cost-prohibitive for many enterprises. The new operating layer is designed to act as a system of record, collecting and normalizing data across various security layers before the information reaches the AI workspace.

The system ingests alerts from endpoint detection and response, network detection and response, security information and event management, identity, cloud and email security platforms. It then executes forensic analysis to deliver automated verdicts. According to company data, the autonomous layer handles the initial volume to scale down data feeds, allowing connected AI models to inherit historical context when executing response actions or generating incident reports.

By routing data through a unified protocol layer rather than individual tool connectors, security teams can use the connected AI models to write automated tuning rules for false positives, cross-reference user login histories during anomalous travel alerts and sweep enterprise networks for newly discovered threat indicators.

The integration architecture is currently available to existing customers, allowing organizations to maintain localized ownership of case histories, triage logic and internal detection rules within their own network instances.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities