Securonix Unveils AI-Powered Agent Detection in Unified Defense SIEM to Cut Data Costs
Securonix has unveiled new features aimed at reducing cybersecurity expenditures, enhancing threat detection across Microsoft Sentinel, and introducing governance mechanisms for AI agent activities.
Modern security operations face mounting challenges
Modern security operations face mounting challenges as telemetry volumes and SIEM costs increase, threats expand across identity, cloud, endpoint, application, and third-party ecosystems, and enterprises adopt AI-driven tools that interact with critical systems. Security teams must balance these pressures while maintaining visibility, supporting existing infrastructure, and improving outcomes without increasing staff or operational complexity.
Three key innovations
The latest Securonix updates address these concerns through three key innovations: Governed AI Agent Detection and Response, expanded Data Pipeline Manager licensing, and enhanced Threat Analytics for Microsoft Sentinel.
Securonix Data Pipeline Manager (DPM) agent
The platform now offers enhanced control over security data economics via the Securonix Data Pipeline Manager (DPM) agent, allowing enterprises and service providers to optimize telemetry collection, routing, retention, and analysis. This capability enables organizations to align data handling with operational and security value, prioritizing real-time analytics for critical data while maintaining cost-effective pipelines for investigation and compliance needs. By focusing only on security-relevant data for immediate analysis, organizations can reduce SIEM costs by 30–50% while retaining access to telemetry for long-term use.
Threat Analytics for Microsoft Sentinel
Threat Analytics for Microsoft Sentinel provides a cloud-native analytics layer that strengthens detection quality without requiring replacement of the existing platform. This solution applies behavior-driven analytics, user and entity behavior analytics (UEBA), advanced correlation, entity context, dynamic risk scoring, and continuously updated detection content to telemetry already ingested by Sentinel. The enriched detections are returned directly to Sentinel for triage and response, allowing analysts to work within their established workflows. Enterprises gain broader coverage and contextual insights without deploying additional agents, duplicating telemetry pipelines, or re-platforming their security operations.
Governed AI Agent Detection and Response
The Governed AI Agent Detection and Response feature addresses risks posed by enterprise AI assistants, autonomous workflows, and digital workers. These tools interact with users, identities, applications, and sensitive data, creating new attack surfaces. The solution uses behavioral analytics to monitor both human and non-human identities, identifying anomalies in agent activity, suspicious interactions, risky tool usage, and policy violations. This capability supports monitoring across AI environments, including Microsoft Copilot and other widely used tools, ensuring investigations remain explainable and response actions auditable.
Securonix emphasizes that AI agent behavior must be integrated into security operations when these tools access critical systems such as mailboxes, APIs, or business processes. Analysts require visibility into what agents access, why they act, and whether their activities align with organizational policies. The platform integrates this context into existing investigation and response workflows.
The updated features are available through the Unified Defense SIEM platform, with expanded DPM licensing for eligible SIEM environments and the Securonix DPM agent now in general availability. Threat Analytics for Microsoft Sentinel targets enterprise SOCs, managed security service providers (MSSPs), and managed detection and response (MDR) providers, while Governed AI Agent Detection and Response is included in the Unified Defense SIEM offering. Organizations adopting these capabilities can strengthen their security posture without disrupting existing workflows, reducing costs, and addressing emerging risks from AI adoption. The updates reflect a strategic focus on balancing scalability, cost control, and comprehensive threat detection in evolving cybersecurity landscapes.
