Securonix, Inc. introduced Securonix Advanced Behavioral Analytics (ABA), a new capability that helps security teams identify at machine speed, activity that is technically permitted but operationally abnormal. ABA features Agent and Entity Behavior Analytics (AEBA), which identifies when an enterprise AI agent uses an unexpected tool, accesses data outside its purpose or changes its operating pattern. It connects those changes with identity, authority, data use, asset sensitivity, timing and threat context, helping analysts understand what changed, why it matters and what to do next.
Compromised accounts, insider activity and AI agents can resemble legitimate behavior when events are reviewed in isolation. Advanced Behavioral Analytics combines AEBA with User and Entity Behavior Analytics (UEBA), which connects unusual login times, rising data access and contact with sensitive assets across systems and time. Together, AEBA and UEBA help analysts investigate developing risk instead of isolated alerts and carry context through detection, investigation, case management and governed response. Policies, approvals and audit records remain visible and enforceable throughout the process.
“AI is compressing the time between initial access and business impact, while security leaders remain accountable for the decisions made under that pressure,” said Toby Weiss, Chief Executive Officer of Securonix. “Securonix Advanced Behavioral Analytics helps analysts identify meaningful behavioral change earlier and gives them clear control over how AI supports the response. Consequential response actions remain subject to human approval.”
Detect AI-Accelerated Attacks and Govern the Response
Traditional SIEM platforms were built to collect and correlate human and machine activity before enterprise AI agents became part of the attack surface. Securonix extends behavioral baselines and risk detection across users, identities, assets, applications, cloud environments and AI agents. It correlates signals across systems and time to surface compromised identities, unusual access, privilege misuse, sensitive data exposure and abnormal agent activity. An expanding catalog of AI-threat policies helps teams detect established attack techniques such as AI compresses reconnaissance, exploit development, privilege escalation and data movement.
Sam, the AI SOC Analyst, executes repeatable Tier 1 and Tier 2 work across triage, investigation, evidence collection and case creation. The Agentic Mesh coordinates AI-supported workflows, while Agentic Guardrails keep actions policy-bound, visible and auditable. Analysts review and approve consequential response actions. By completing repeatable work, Sam helps security teams absorb growing alert volumes and expand SOC capacity without requiring linear growth in headcount.
For authorized insider-risk investigations, the Securonix Insider Intent Agent adds contextual and corroborating evidence while preserving competing explanations. Analysts review each signal as part of the broader evidence rather than treating a message, search or behavioral deviation as proof of intent.
“In a managed SOC, the hardest part isn’t writing detection rules. It’s understanding each customer’s environment well enough to separate real threats from normal activity. That becomes even harder in cloud and Infrastructure-as-Code environments, where workloads appear and disappear and identities constantly change.” said Darren Humphries, Group CISO, Acora. “Securonix Threat Analytics builds that behavioral baseline automatically, then uses risk scoring and evidence boards to show our analysts what matters and why. For Acora’s customers, that means fewer false positives, faster investigations and quicker containment, without losing the customer context that makes detection effective.”
New Research Supports Critical Need For AI Governance Pressure
Securonix research found increased AI investment alongside continued questions about governance, trust and human accountability. For The Evolution of Cybersecurity Automation: Towards the AI-Governed SOC, Securonix surveyed 1,000 global cybersecurity professionals during summer 2026.
Survey findings show that cybersecurity teams want automation and AI to advance work inside clear approval boundaries. In the survey, 96.6% of respondents said cybersecurity automation is important to their organization, 49% said they use AI in behavioral analytics with human approval and 99.6% said their organization had increased its budget for AI in cybersecurity automation during the past year.
Investment has moved past experimentation. Security teams want AI to advance the work inside clear approval boundaries, with evidence they can explain and outcomes they can defend. The full report and methodology will be available in November.





