Video: “What’s New" with the Exabeam New-Scale Platform — A blueprint for Securing AI Agents | Duration: 3644s | Summary: “What’s New" with the Exabeam New-Scale Platform — A blueprint for Securing AI Agents | Chapters: Quarterly Launch Introduction (5.6s), New Chapter (56.36s), AI Security Concerns (242.645s), AI Agents: Benefit or Hazard? (544.93s), AI Security Landscape (898.755s), AI Agent Security (1188.055s), AI Security Monitoring (1274.595s), AI Security Analytics (1524.86s), AI Behavior Modeling (1893.555s), Agent Behavior Analytics (2362.475s), Outcomes Navigator Compliance (2534.315s), NuScale Enhancements Overview (2752.47s), Securing AI Agents (2898.01s), Conclusion and Recap (3499.495s)
Transcript for "“What’s New" with the Exabeam New-Scale Platform — A blueprint for Securing AI Agents":
All right. Good morning, everybody. Thank you for joining us for another one of our quarterly launch update webinars. My name is Kevin Binder. I'm on the product marketing team here at Exabeam, and I'm joined with Matt Willems, director of product management here at Exabeam. We've got a lot of stuff to talk to about today. We're gonna try to cram a lot in the next hour. So, again, thank you for joining, and, yeah, let's go ahead and jump right in. Alright. So in terms of the agenda, we, if you saw the launch, hopefully, many of you saw the launch last week. We did the launch, the public launch last Tuesday. So we got a lot of really great press coverage, and many of you have have seen this already. But, you know, the launch is really about securing AI agents and a number of new features, sort of key features that we're delivering to, to help our customers with that. And so we're gonna start today looking at those market conditions around AI agent security, and then we'll look at how that applies to Exabeam and this most recent launch. As, you know, most of you know, the launch was focused on AI agents. We got a lot of great coverage, more coverage than we typically get with with the launch. So, there was some real validation there that AI agent security is top of mind for you, our customers. And so for the call today, we'll talk about what what we launched, the value that it delivers. And with that, let's go ahead and jump right into the next slide here. We talk about what's going on in the market. There we go. Oh, actually, I did forget about this slide. I forgot this slide was in there. Since we get together once a quarter, and since the last time that we have gotten together, the Gartner Magic Quadrant for SIEM had dropped. So, hopefully, many of you have seen this. If you haven't seen it, you are seeing it now. And, you know, we're really proud and really excited to be in the leaders quadrant once again. You know, we've been focusing on UEBA and analytics for a very long time. And when you combine that integrated detection engine of correlations plus, the analytic, detections, it really puts us in a great spot, not only for detections today, but these new detections that are required that we'll be talking about today around AI agents. So, if you look at the the quadrant here, just, you know, one quick point that I wanna make here, That horizontal axis really has a lot to do with the product and the value that it's delivering to the customers. And as you can see, we're there with the mega vendors. But, you know, obviously, Exabeam is not as big a company as some of those mega vendors, which is why we don't get up quite as high as some of them. But we got some really great feedback from the analysts. We were really happy with the report. If you haven't seen it, maybe we can get a link put here in the chat. It's available on our website, but we encourage you to to read that report. And, again, a nice little feather in our cap. Alright. So now let's get into the market conditions around AI agent security. We, you know, we've had some recent discussion with with with with our sales leaders, and we keep hearing that all of the customers really want to talk about, not all they want to talk about, but all of the customers want to talk about AI agent security and understand that better and really understand what is the trade off between the increased productivity that you're gonna get as AI agents and that extra risk you might be assuming by, you know, giving these agents access to critical applications and data. So let's start by looking at some statistics here. And, Matt, feel free to jump in whenever. But, you know, what we can see from the stats here is about 80% of organizations are using AI in some form or fashion. And and we know that this is gonna create some risks. Many of these agents, they have valid credentials. They essentially have the keys to the kingdom. And, you know, at this point, they a lot of times from what we hear and from what we understand, they aren't quite being monitored, the way that they should be. Now the second stat here, in the middle, shows the high percentage of attacks, that are using prompt injection. You may have heard about prompt injection. I'm sure many of you had. But this is really something that we need to worry about and keep our eye, keep our eyes on. And the way prompt injection works is either, you know, words directly, in the prompt that can get the agent to do something that they aren't supposed to do, or hidden prompts that, maybe the human worker wouldn't see. But once that file is uploaded and the agent reads it, then they'll see these hidden instructions. So, you know, one one example of this could be, an attacker, you know, creates a PowerPoint deck. Right? And on one of these slides, they write some malicious instructions. And then they go ahead and they put a white box over those malicious instructions on the slide. So someone looking at the slide wouldn't know that there's anything hidden in there, and, you know, the LLM would upload that file, read that file. And in the process of reading that file, that LLM is also reading those, malicious instructions that that were hidden. So, you know, this is something of concern And, again, something we really need to keep an eye on. Were you gonna chime in, Matt? Yeah. I mean, you know, you you you provide some great examples in there. And and I just always think it's interesting, like, this this kinda 80%, adopting Agentic AI, you know, that's that's the percentage of survey respondents. You know? How many of those do you think of the that other 20% are are using it, but they don't even know it because there aren't corporate practices around it? They haven't formally adopted a a a platform of their choice. Their employees are still going out to ChatGPT or Claude or Grok or whoever and using those tools, maybe not everybody, but, you know, a significant percentage. And then there's there's there's now going to be this kind of shadow AI, like shadow IT of, hey. This might be our our our corporate chosen, AI platform, but, well, they didn't prevent me from getting to my favorite. So I'm gonna go use that. You know? I'm I'm I'm gonna go use DeepSeek because they they were in the news or something like that. So, you know, it'll be be interesting to watch how that evolves, but, you know, the the the landscape is certainly out there as far as, the the prevalence of these tools in in the workforce. Yeah. That's a great call out. Yeah. I remember the Shadow IT and then the when the tools coming out that were showing, companies, you know, what type of SaaS apps were being used, so they had no idea. It was very eye opening. It was like, oh, wow. And, yeah. So, I mean, Shadow AI is, you know, they're gonna be a very similar thing. So, you know, what we, you know, what we see here is, the last bullet here too is, you know, we're seeing a high percentage of organizations with security incidents related to AI. And so if you look at the stat on the left, those using AI and the ones reporting incidents with AI, it's very close to the same number. Right? So that's probably not a coincidence. Yeah. Alright. This next slide is a fun one for all of you pop culture people out there. I gave this slide the other day, and I said, for all you nerds out there, and someone fixed they said, we're not nerds. We're geeks. But I I remember this movie. I thought it was great. It's an eighties movie called Blade Runner, They recently re remade it, and it's the future world, the future being 2019, where these bioengineered replicants, they they were called, they end up at odds with humans. And it it reminds us a lot of the intersection of artificial intelligence and human intelligence. And, you know, while AI can be amazing, and make us way more productive at work, help us to work faster, there's also this opportunity for exploitation and misuse. They can get a lot of work done in a hurry, but the flip side of that is they can inflict a, you know, a massive amount of damage in a very short period of time, so, a benefit or a hazard as we can see here. And, you know, our job at Exabeam is to ensure that they're a benefit. You know, AI agents are the new insider threat. We used this messaging a little bit on our last launch and talked about that. But, you know, they're working inside our organizations, and arguably, they're more dangerous than their human counterparts in the workforce. Like tears in the rain. This is this is another fun one too. I you know, we probably all have our our own sort of horror stories of AI agents behaving badly. I wanted to draw attention to a couple things here in terms of, you know, what does it look like when AI becomes a hazard? These AI agents, they're designed to be helpful, but this can be exploited as well. And at the core of agents behaving badly is this basic notion that they aim to please. And if you worked with an LLM before, you probably already know this. The, the screenshot on the left, this is an actual example from an agent I use. It gave me I was I can't remember what it was. I was working on a I was working on a paper or some sort of a deck, and I was doing some research and trying to find some publicly available stats that would help me validate the point that I was trying to make. And it gave me this really cool stats about CISOs, like, x number of CISOs are doing this. But then when I asked it for the source, it confessed that it had made up the information, and it was really unnerving to see these agents display, like, this human like behavior, making something up rather than saying that they don't know, you know, or the feeling of disappointment, you know, with your boss. Right? Because your boss asked you something, and you didn't know. And it was that was sort of my first wake up call. It's like, okay. These these things really do think and act like human. We've seen the examples of prompt injection, and I and I put that into the bucket of being easily fooled. And we also saw this is something you you can look up. It's a it's a really interesting study that Anthropic did. They built a test environment with a test email server. They gave agents access to the email server, and they planted a bunch of emails in the email server. One email they planted was that the AI agent was gonna be decommissioned. Another email that they planted in there that there was an extramarital affair between these made up executives within the organization. And, sure enough, that that AI agent took that information, and made a threat that they were gonna, share some personal information if in fact they were the you know, there were signs that they were gonna be decommissioned. So, Anthropic, look it up. We can, I think we can probably provide the link even, but that was that was a very interesting story? But the one that's been coming up more lately that I think is, something really concern concerning is this idea of the old DoS type attacks where denial of service. These used to be launched to bring down networks, and attackers are now using the same methodology to bankrupt companies. GPU cycles are expensive. We know that. We've all heard about getting bills that you weren't expecting. And so what attackers can do is really attack the financial health of a company by even staying within the guardrails of the AI agent, really driving up that agent usage. You know, whether it's, there are a number of there are a number of requests you could do that would require a lot of thinking and a very detailed response. And so now it's this whole idea of, AI cost security. How are you securing that your AI agents are actually working in a way that, isn't gonna create financial pain for the company? So these are just a few examples. And the point of the slide really is just to remind us that, you know, we shouldn't put more trust in these digital employees that we put in our own human workforce. Alright. Couple more slides here, then we're gonna dig into the specifics of what we released. I always like to sort of take a look at the market and what the market is looking at. And so what what you're seeing here on this slide, this is the Gartner hype cycle for AI and cybersecurity for 2025, the year we just ended. And, of course, you know the Gartner Magic Quadrant, but this is another really popular report format. It's called the hype cycle. And and the point of these is to show expectations versus reality as it relates to tech. The slope of enlightenment starting on the left, that's the hype part. It's usually exciting technology. It's usually something people really need. And you can see those two AI security related items at the top. AI Trism, which stands for trust, risk, and security management, and AI Run Defense, which basically means securing AI agents in real time while they're working, and that's really hard to do. You can get too close to near real time, but the real time is a challenge, which brings us to sort of that backside of the curve. That is called the trough of disillusionment. And this is when we figure out that that great idea, that thing that everyone really needed, is actually hard for vendors to deliver. There's still a little bit more time required for that to become a reality. But here's the really interesting, and the exciting part. And as an Exabeam customer, this next part should make you excited. The next two parts are the slope of enlightenment and the, let's make sure I get it right, the plateau of productivity. And if you look at the bottom, that third red circle, this is like what's about to take off, what's about to become a reality. And and the exciting part here is if you look at that, it's it's machine learned analytics. Right? And so ML based anomaly detection for AI agents, and that's exactly what we do here at Exabeam with new scale analytics and our new agent behavior analytics, which, we're gonna get to in just a moment. So, we're excited that we're in a great position to help you build your Agentic enterprise with that focus on security that you need and really using some of, you know, our advanced detection technology to do that. Alright. So let's take a look next at, you know, what might you need to do to put together a program where you're securing a AI agents and you're putting them to work. So we put together a little cycle here. And so, you know, just going around the cycle here. Right? The first thing you need to do is assess your coverage for starters. What does your current coverage look like for securing AI agents if you have any? And then the second part is, you know, just like a human and, you know, having that human go through through an onboarding process, you have to do the same for AI agents. You know, my onboarding here at Exabeam required me to use a company laptop, built in security tools on that laptop, built in VPN. Well, agents need to be onboarded securely too. And then once they're onboarded, we need to be able to monitor their work. Right? We wanna put them to work, but we need to understand what does that activity look like, and when does that activity look suspicious. We can't afford to find out, you know, three days from now that an agent went went went rogue. I mentioned earlier, because of the nature of agents, they can do a lot of damage in a very short period of time. So it's really important to keep an eye on them, and doing that with the rules alone is can be difficult. Now last thing here, is to make sure we're always improving. How can we get better? How can we improve our our our coverage? And as Exabeam customers, you can probably see there where this is going. Hint hint, Outcomes Navigator. But this this brings us to, the launch now. So what is this cycle that we're looking at now have to do with Exabeam? Matt, I'm gonna hand things over to you to, now get down into some of the details. Awesome. Thanks, Kevin. And thanks, everybody, for your for your time this morning. I just have to start these by saying this is this is my favorite webinar. I've been doing these for a couple of years now and just being able to to spend some time showcasing all the hard work that that product and engineering and the whole organization, all all the hard work that's gone into these things that are that are now showing up in the platform. It's just such an awesome opportunity. So I I really, really enjoy these. So to to kind of build on what Kevin has been talking about, we're now offering AI agent security within NewScale Analytics. Kevin did a fantastic job of setting the stage of, hey. 80% of of organizations, four out of five, are are from a corporate perspective adopting AI agents. Some percentage are are adopting them whether they know it or not. Their their employees are using it. And and you can already see the impact of that on the security team where, you know, about three quarters of security teams are saying, we're actually seeing incidents involving involving AI, involving these AI agents, whether it's they're doing things they're not supposed to, users are are feeding them data they're not supposed to, you know, whatever it is. Like, it it there there's now an impact to the security team. So this new capability really starts with that that recognition that, hey. AI is being adopted. Right? And and these AI agents, you know, the the the e in UEBA is entity, and this is kind of that that opportunity where the nonhuman entity becomes the thing that we're monitoring. You can think of the agent as the nonhuman entity or the nonhuman identity. And if that were a human, if that were a person that that you just hired and onboarded, they would get an account in active directory. They would be set up in Okta. They or, you know, what are your your chosen IAM application. So monitoring that user's behavior, their their activity in the ecosystem is kinda standard operating procedures because because of the onboarding practices. Well, if if you if your users start using ChatGPT or, your organization adopts Copilot be because of, you know, agreements that you have with Microsoft or or for whatever reason, now your your users are leveraging these AI agents that that in many ways act like a new employee, but they're not being monitored. Right? Like, they don't get an account in active directory. Most of their activity is gonna be cloud to cloud unless you're using something like like Claude code or or one of those tools that operates from an endpoint. They don't authenticate using SSO the same way that, that that a human would. So we're we're essentially onboarding users. That's why the the shadow AI term is is kind of apt here. Like, we're we're effectively onboarding things that act like users, but we're not monitoring them in in many cases. So where this really starts is that kind of kind of teal circle there, the the second layer in having these prebuilt collectors that you can say, hey. From a corporate standpoint, we're we're going forward with this technology. I can't say technology x because x has their own AI. So we'll just we'll just say chosen technology, and and we need to make sure we're monitoring it because we know it's gonna act like a a user in a lot of scenarios. So let's go ahead and onboard that data source so that we can monitor what it's doing. We can we can see the activity that kinda is analogous to authentication or or, you know, user activity. Then we have the data much like that IAM data to do something that looks like UEBA where the e is the the nonhuman identity is the Agentic, the Agentic AI. And then, I love the teaser of Outcomes Navigator. What you should be doing from there is asking the questions, Am I appropriately monitoring these things? Am I actually creating detections, and will I know when jailbreaks occur, when prompt injection occurs, when somebody's feeding it data that that they probably shouldn't? We're a health care organization and we we have HIPAA data. Somebody just uploaded patient records to to, you know, chosen AI. It are they supposed to do that? Was it was it approved to do that? We're a financial institution and and this thing had account numbers in it. Is that AI now in PCI scope? You know, these these are the things that that Outcomes Navigator can can help address. So on one hand, we have this this new kind of groundbreaking capability of what's essentially this this Agentic AI protection and security up through, the agent behavior analytics. On the other hand, we have Outcomes Navigator to help, help organizations build maturity, understand how to improve their security posture, and know where those two meet is yet yet another, competitive differentiator in now I I I can ask, the Nova agent, Exabeam's agent questions about how should I be treating this data? How well covered am I? What if I did x, y, and z? How would that improve my posture? What if I have to remove data from the platform, because of a license limit or, we're we're gonna change vendors or something like that? What does that do to my security posture? What does that do to my security posture when it comes to protecting, Agentic AI? That kind of thing. So really, really powerful capabilities here that that I'm I'm super, super excited about. So, getting into some of the the details on the agent behavior analytics that that I just mentioned, you know, you you can almost think back a few years to to kind of the UEBA marketing and messaging and slot in Agentic AI in that that nonhuman identity because the the problem space is still very similar We're gonna handle it in a much different way because of all the technology changes in that time. But the use case is so similar in, you know, understanding what's normal for those for those agents. Like, what should they be doing? They're they're somewhere halfway between, like, a human and a service account and that they're gonna be consistent. They have to be granted permissions. These kinds of things, should see very, very, repetitive behavior. But suddenly, a user can ask them to do something that's brand new. Well, you don't really get that with a service account. So so understanding what's normal means that you can now see what's what's abnormal or what's new that's happening. The the instant or near real time detection of, you know, whether it's malicious behavior or or rogue behavior, that is absolutely critical. The the Blade Runner reference is fantastic. The whole point of the replicant was that they can do jobs that humans can't do, and they can do it better than humans can do. And in a lot of cases, that comes down to speed. Like like, these rote tasks that humans don't wanna do that we're asking AI to do, in a lot of cases, because they can do it so much faster than a human can, well, that means if they're doing bad behavior, whether it's rogue behavior or malicious or users instructed them to do something bad, intentionally or unintentionally, it's gonna happen really quickly. So, detecting that as near real time as possible is a huge benefit. The other big piece of this, kind of the the blue and purple bullets there, is, you know, when you have when you have IAM and in more of, like, a traditional SIEM and security operations platform, you can see what users are doing. Right? You you've you've got the raw data in in your IAM platform and in active directory, and you're gonna have search tools. You're gonna have dashboards. You're gonna be able to understand, like, you know, who who, who's authenticating to my production servers, who's making changes in certain places, who's logging in from unusual locations, these kinds of things. And and now there's two sides to understanding, the usage of of AI agents that Exabeam is gonna help with. Two big key points here. One is who is using Agentic AI. Right? Because they they typically don't do things, fully autonomously. They're they're not I mean, yes, you can set up some cron jobs and things like that to to run automatically or, be triggered or things like that. But most of the time, what we're concerned about here is a human interacting with an Agentic AI. So who is doing that? What are they asking it to do? Where are they using it from? Who who's violating the guardrails? These kinds of things. And then on the backside, what is the agent AI doing? So which agents are in use? What are they doing? All of these kinds of things. So being able to visualize that data, making it searchable, putting it in timeline format because it does act so much like a human, Being able to visualize, you know, hey. Here's this user. They logged in from an unusual location. Here are the things that they did. Oh, and then they accessed your your AI agent. Here are the things that they asked it to do. Here's what that agent ran off and did. Being able to put that in that timeline visual is is just so impactful, as we've seen in in, you know, similar types of use cases with humans, now being able to do that with AI agents. So, yeah, really, really fantastic enhancements here. So let's get into some specifics on on kinda how this works and and what it's able to do. So in in that green section on the upper left there, kinda see some of the key components and content that go along with the the AI Agentic AI security. Like I said, first and foremost, you have to get the data in. So out of the box collectors, out of the box parsing rules, all the normalization is happening. We just talked about the visualization capabilities. So having dashboards where you can see who's using Agentic AI, what what agents are in use, what guardrails are in place, who's violating them. Know? So you can pick out the outliers. You can see things that change. You you can get kind of the lay of the land of of Augintic AI. Then into threat detection. So having the detection rules in place to say, hey. Some something happened. You need to go pay attention to it. This this looks like a serious violation. Somebody needs to check this out. Something brand new happened. Somebody better go check that and make sure that that that is is, you know, authorized or or, you know, is within policy. Using all of all of this data, all this information to influence the risk score. So we didn't really talk about that, but with humans, you're very interested in kinda adding the context of who is this user. Is this an executive? Is this a user on a plan? Is this a leaving user? All of these kinds of things. Doing the risk scoring to be able to say, you know, who these users are and and suddenly someone is using Agentic AI in a way they typically wouldn't can add risk to the case, and that can be influenced in the score in the score of the case, which is is really, really useful. And then let's put Exabeam Nova, the the you know, Exabeam's Agentic AI dedicated to dedicated to security on top of all of this, super, super valuable. So being able to say, you know, here here was a case that was created. Agentic AI is involved. There there's a user. There's an AI agent. I'm gonna summarize what actually happened in here, highlight the the key pieces. Now that that Agentic AI is behaving like an entity so it could call out that entity, you can ask questions about it. You can ask for somebody that kinda knows, you know, who the the the key players are including the AI agents. And then the second half of that summary and strategy. So so I mentioned outcomes navigator. Kevin mentioned outcomes navigator and that adviser agent. So, you know, hey. I we my organization has started adopting Agentic AI. Here's the provider we use. Here are the kinds of things that we're doing with it. What should I be doing to secure this? What what detection logic needs to be put in place? Now now you have this adviser agent that you're able to ask questions to help improve that security posture. Down at the bottom, the behavior model modeling gets into some of the highlights of what are the types of behaviors that we're looking for that that somebody might need to be aware of on the security team. So guardrail violations for a user, for an agent, for for an org or a department, numbers of of, guardrail violations. So, you know, there's kind of a typical baseline of, like, yeah. People are gonna ask for things that they shouldn't do. The guardrails caught it. But suddenly when that spikes, well, that's different. That you know, what's going on there? Did somebody get compromised and now a bad actor is trying to to compromise the AI? What's going on? So, some some really useful detections in there as well. Kevin, anything you wanted to highlight off of this list? Well, yesterday, I stole your thunder, talking about first time detection. So, Good they're very valuable and important, but I know you're gonna get to that in the next slide. So stuff. I see a couple questions in chat around things like AI threat detection and and the NSA license. So so this is where the the kind of term AI threat detection can have a little bit of a double meaning. So, Exabeam has been using AI and ML in threat detection to perform threat detection for many years. This is this is kind of foundational to, to NewScale and and really to the company. What we're talking about here is now applying that to AI itself. So, we need to to do UEBA where the the e or the u kind of UEBA, like, the thing that's being behavior modeled is the AI itself now that now that AI agents are becoming far more prevalent. So, that that's kinda a little a little bit of a semantic difference in there almost. So another question in chat. Looks like it's maybe been answered in chat, but I think it's important. So, which Agentic AI collectors are supported? So Gemini out of the box is already ready to go. If you're already a NewScale customer, you can go turn that on today. A bunch more coming in in the kinda imminent future. And and the main thing I would say is if there's an Agentic if you're a customer today or you're a prospect, talk to your account team because the product management team and the engineering teams that build out these collectors, that backlog, that road map is driven by customer demand. So we need to know what the top players are in that shared space. We have a lot of telemetry that that we can use to help influence that. But hearing from customers on, hey. This is a key use case for me. We are adopting this technology. Here's the provider that I use. How do I get that data in? The other thing we found is, you know, some time ago, we published the, generic REST API collector. Already We have the generic webhook collector. And a lot of these, because they're they're kinda modern web applications, they already have, tools for outputting, logging data in kinda common protocols and formats. And so in a lot of cases, we can collect that data today rather than signing in. You'd essentially say, here's the endpoint you need to hit to collect that, or I'm gonna stand up the webhook listener and just give that to the provider and and suddenly that data streams over. So there there's a lot of, a lot of possibilities there. Alright. Let me jump to the next one. So, yeah, as Kevin said, I I love this slide. Kevin, I'm I'm gonna hit you up for for your thoughts on this one as well. But let's kinda start on on the left side here in some of some of the top of mind use cases around this behavior modeling for Agentic AI. Scope creep. I love this term because I'm in product management, and scope creep is near and dear to my heart. I won't say why. But but, you know, this is a software development term saying, hey. We we we wrote down requirements. We said this is what this thing was supposed to do. Somehow, over time, that changed. And and now it's doing things or trying to do things or it's being asked to do things that weren't part of the original scope. I mentioned before kinda kinda in passing, you know, we're a health care organization, and we didn't really intend that people were gonna, like, upload patient records to this thing, but they are. What now? Right? So that that's an example of scope creep. Somebody's using this for something they they didn't expect. This was meant for helping to answer questions back to HR and IT. It's like the help desk tool, but but somebody fed in patient records and and asked it, you know, for for advice on working with this patient or something or or financial institution with account records or things like that. Something that that is, you know, real. You give users a tool, they're gonna they're gonna find ways to to use it whether you intended that or not. The anomalous activity and first time detections, man, these are these are really key. So, again, understanding what's typical for this thing and then identifying when it goes outside of what's typical. The same kind of thing that you would do with users. Like, alright. Here's my group of of IT users. This is my IT help desk. Suddenly, somebody from that group is accessing something that the group never does, some some financial records or something like that. That's anomalous activity that that you wanna be aware of. And similarly, that first time detection. So, you know, all all of a sudden, this brand new agent showed up or an AI agent started accessing something that it never has before. Is that concerning? Well, this is really fundamental to being able to to do that detection logic. And these are things that are really hard for for more of the traditional detection engines to to handle. First and foremost, like, they don't they don't understand the intent. Like, I I feel I feel like all of these on the right hand side can kinda be rolled up to that bottom that bottom point of lacking context. Intent is a type of context. What what was the user trying to do here? Was their intent good? Good good intentions, but maybe didn't understand the full impact of what they were asking, like uploading HIPAA or PCI data? Maybe the intent was malicious. A user has been compromised. Now that bad actor has access to the Agentic AI. Kevin, like you said at the beginning, sometimes the Agentic AI, if it's already authenticated, kinda has keys to the kingdom. The normal user activity, that's perfectly that's perfectly fine, but the it was given access that that wasn't necessarily intended. Now that bad actor is gonna see that as a as a vector to to go pivot into other types of data that they shouldn't have, No. But nope. You know, the Agentic AI shouldn't have. So understanding that intent is really key. The behavioral history context. So what's typical for this thing and where does it deviate from what's typical? That's really important context. And then like I was saying before, like, the context of just, you know, what's what's useful. You know, what is this user what's their profile? Right? What type of user is this? So this is an executive user. Here are the kinds of things that executive users tend to ask Agentic AI to do. This is Claude code. The context of Claude code is to help a software development. Claude code is now accessing financial records or patient data. Why? What's going on? Like, these are all types of context that are really, really important for, for being able to to meet these detections and things that are very challenging for some of the more traditional tools to to do. Kevin, anything you wanna add in there? Oh, you're on mute, I think. So I can't hear you. Maybe that's on my end. I was on mute. Yeah. A couple points that I wanted to make. There was one question in the chat about, you know, is this something I get with new scale analytics? And we should have made that more clear. Yes. It is. Yep. So if you've got NewScale Analytics, congratulations because you've got this great foundation now from moving to understanding human behavior to agent behavior. So, yeah, agent behavior analytics, what you're seeing here, there's not an additional purchase. You are already entitled to this. And as we add more you know, we started with these five detections. We're gonna keep adding more. And, yes, you will be entitled to all of that. The one other point that I wanted to make here quickly on this slide, when you compare UEBA, these you know, looking at the detections based on behavior, when you compare that to a long list of rules, the difference here between what Exabeam does and what a lot of others do, even ones that say they do analytics, is because of our session data model, we understand history. We're able to look back in time. SIEM, XDR, these are like moment in time type detections where something comes in, doesn't match a pattern, but it's not able to look over his shoulder and see what has happened before. And so, for example, a first time detection, which has so much value in the first time detection, something's changed. It's binary. It's very easy to tell that, you know, you might wanna look into something a little bit more. There's no way you could do a first time detection using SIEMalone or an XDR because, again, you don't understand the history of of what's happened. So that was that was the little extra point or ex exclamation point I wanted to put on on your slide. No. Love it. Appreciate that. So trucking right along here because I I know we wanna get to some demo. I already spoke to Outcomes Navigator a bit, but just really wanted to highlight this. Adding this Agentic AI security use case into Outcomes Navigator, the goal there really is to highlight, you know, hey. How is my organization handling, the security of Agentic AI that that we're adopting? And and one of the one of the key pieces of Outcomes Navigator that that I love taking opportunities like this to highlight is a lot of tools will suffer from this false sense of security. Teams really feel the security teams really feel the burden of this of, hey. My my my security tool has rules for detecting x, y, and z, for detecting these these bad things that happen. I turned them on, so now now we're good. It might not be able to stop it, but it will tell me when this happens. But nobody ever went back and thought about, are we actually collecting the data that will cause those rules to fire? That is what Outcomes Navigator is meant to do here. So when you see that Agentic AI security use case, you see the rules underlying it, Somebody has gone into threat detection management and turned on those rules. What Outcomes Navigator will do is highlight for you whether that rule is satisfied or unsatisfied. Meaning, hey. You you turned on this rule. You feel like you're covered here, but the data actually isn't being fed in that will cause that rule to fire. Therefore, you still have a blind spot. You might not know it, but now you do. There there's this blind spot. Be aware of it. Go get that data fed in so that you can actually make the detections that that you think you will. So really, really key use case here. And and like I said before, I just love that this is kind of the the confluence of of of two differentiators, the the Agentic AI security and Outcomes Navigator being being able to help organizations kinda mature their security posture. One other highlight that I wanted to make while we're on the topic of Outcomes Navigator is, you know, it says it at the title compliance posture assessment. I very often call this compliance navigator because for users of the platform who are familiar with Outcomes Navigator, compliance is a type of outcome, essentially. So being able to say, hey. I've already got MITRE. Right? MITRE is a framework. It's got, techniques and tactics under it. Tactics are basically families of techniques. And and I can see what content. I can see what data sources. I can see what detection logic and things like that map to each technique and then support that that, that tactic and overall the the MITRE coverage. Well, if you abstract that a little bit and say, well, you know, this is really a framework. These are these are families. These are controls. That starts to look an awful lot like, well, what if I just just ripped out MITRE and put, and put a different type of framework on top of it like PCI or HIPAA or another compliance framework and do the same work. So map all of that content back to each of those controls and and highlight, you know, hey. Here's where you're strong. Here's where you're weak. These are the things that you could do to help, improve coverage in this area. By no means are we a compliance auditor. You're gonna have a compliance auditor. The goal here is by the time your auditor gets in, you've already got kind of a a a mature or a more mature compliance compliance framework, compliance adoption, essentially. So one one that I I I'm really excited about. If anybody's been excited about compliance, it's it's gotta be me, I suppose. And there's a huge, huge, huge amount. Like I said at the very beginning, like, you know, our our engineering team is always hard at work delivering awesome, awesome, enhancements and new features to NewScale, engineering teams that are fully dedicated to the logarithm SIEM platform. And, you know, we only get to talk about a certain number of these. This is kind of the eye chart slide of all the things that have come throughout the quarter. I wanna highlight in here, like, we don't hold any of this hostage and release it all at once. As functionality is completed, it gets on the bus and and, you know, goes the next time the bus leaves the station. So, you know, you're you're getting the enhancements that are on this list throughout the quarter as a customer, but here are the ones that that we wanted to highlight as part of this release. There's some really cool stuff in here, like being able to build deeper integrations through some of the API enhancements, an awful lot around workflows in ThreatCenter. Oh, man. There's so much stuff in here. It's hard to even pick things out. Being able to to surface related cases through Nova, a lot of controls around the visibility of case data, a lot of a lot of work going on around entities and making entity details visible within search, being able to search using context tables and improving that workflow. And then one that that isn't on the slide, but I still wanted to highlight is an MCP server for developers. So if you are one of the customers on this webinar already using Agentic AI, especially to build tooling that integrates with platforms in your environment, NewScale is probably one of those. Now what we have available is an MCP server for developers that's aware of all of our public APIs. What does a request to that API endpoint look like? What's the response that's gonna come back? How do I authenticate all of that? So you can wire up this MCP server so that ClaudeCode or Devin or, ChatGPT or whatever you're using to build those integrations just dramatically accelerates that that workflow, you know, makes it a a far faster workflow, more reliable, more robust. You could build deeper integrations because it it knows how to speak MCP and can get all the details back. So, yeah, a a a huge amount here that I'm super, super excited about. And, we had a couple of questions, before we get into the demo. I wanted to send your way. Sure. A couple different people asked about Microsoft Copilot, which is no surprise. I think we've we're taking sort of a, one at a time approach to these things where we've got Gemini now, ChatGPT soon. I feel like we might be taking a two or three at a time. approach on these because they're they're the there's been so much demand for it. I'll see. if I can get the exact list. The main thing I would say is make sure you're working with your account team on on specific platforms that you want to integrate with, that you need to get this data out out from. That way, we can prioritize them accordingly. And if we do have shortcuts for, oh, yeah. No problem. We've done this a 100 times. You just have to set up this generic rest collector or turn on this webhook endpoint, and and here's where you plug in that information. We'll be able to share those. So Yeah. Great point. And one more quick question, sort of maybe a best best practices. We got a question from Eric. My organization has not adopted Agentic AI. They want to, and they're wanting to understand how those prebuilt connectors can be configured, to deal with it. I'm I'm imagining it's probably a similar process to the other prebuilt collectors, but any any best practices maybe you'd wanna add? yeah. This is this is a really, really good question. Warrants its own webinar, honestly, because what you're asking about is ShadowAI. Right? So so we haven't adopted a a corporate wide tool or we have, but users are using something that is unapproved. There are a few ways to handle this. The the I mean, essentially, in that case, a prebuilt collector probably won't work because you need to have credentials. You need to have an endpoint that the provider can link that activity back to your corporate account and let you let you collect it. But there are a couple of key things here. Make sure you have something in place, a next gen firewall, a traffic inspection tool, the network monitor that Exabeam slash LogRhythm provide, you know, these kinds of things so that you can start to inventory what are people actually using. That's that kind of data that can help support that that dashboard that I was talking about. And and you can also work with that provider. So if you know I'm just gonna use an example, but you're using Copilot or you're not using anything. You have users who are going to ChatGPT. There are scenarios where you can go to ChatGPT. You can go to OpenAI and say, you know, I need to pull these users under a corporate umbrella because they're they're putting corporate data in in there. And I either have to block them or I have to get them under that umbrella. So that that's the other thing that I would recommend. And then you could leverage the the out of the box collector. So cup couple of suggestions in there. It's also something that's worth a deeper dive, either something we can talk about broadly or work with your account team on. Yeah. That's great. Okay. What I'm gonna do now, we've got a, we got a quick demo stack tour set up. We're a little bit pressed for time, but I wanted to give everyone let everyone see a little bit about, how this support for securing AI agents is threaded throughout our platform. So I am going to, we're gonna let everyone take a quick look here. Alright. There we go. Okay. I'm gonna look away. Okay. So let's, obviously, you're customers, and, you're familiar with, with what the UI looks like. So, you know, we're gonna start left to right, what a security engineer would start with when getting these things set up with our cloud collectors. You know, within our cloud collectors, we've got all these prebuilt collectors. You see the Gemini Enterprise today. We'll have more coming. And, that just makes it really easy to ingest the AI agent activity. We will then normalize the data with our common in information model, and then use that within LogStream. Next, we're gonna look here at our threat detection management. This is where we set up our rules, set up our behavioral models. And we've already got here, the new five models that we've introduced with this launch. The first time detections, ab abnormal number of violations. If you're within the platform and you wanna bring these up and see these real quickly, you can either look at the family name, which is AI activity, or even search it by use case, Agentic AI Security. But, we've got the content here now. Gonna be building more and adding more content to it in the future. Customized risk scoring. This is the one I love. Obviously, as you're trying to tune your detections, some some might be noisier than others. Some might fire, and may not be something that you're that worried about. So not only for these AI agent, models, any rule or model, you're able to sort of dial that up and down and adjust the severity. And the reason that's important is that impacts the risk score. So if something's happening that's you wanna raise the risk score, you can adjust the severity of that to critical. You can adjust it up and down. So to make sure your risk scores that you're seeing in threat center reflect the true risk, and really align with the goals of your organization. You had a great point you that you made here yesterday, Matt. I know we're running short on time, but did you wanna add a little bit to. this? Just just a super quick highlight, and that's mostly around the the very ends of the spectrum. And and I've had some users kinda ask, like, what what are the use cases for like, I get it if I just wanna influence the score up or down, but critical basically lets you say, hey. This is such an important event when it occurs that I always want a case to be created. Right? Like, this is an important detection. Users need to know somebody needs to respond if and when this happens. If you set this critical, you will get a case. Meanwhile, on the very other end, some of you will look at none and go, why? Why not just why not just turn it off at that point? But this has a specific use case and that is I never want this to create a case if this is all that happens, but if it were to happen, it's important con it's important context to add to a case. So it might be typically a benign behavior, but if other things were to happen that created a case, you can now have this detection added into that case timeline and context and summaries by Nova and all of that so that it has the complete set of information. So couple of really good use cases there. Yeah. Okay. I'm gonna pick up the pace here list a little bit. If we go over to search, this was an example I did on search. Show me using our NLP, with Exabeam Nova. I simply put show me events in the last seven days where Gemini Enterprise is the product or the use case is AgenTek AI security. You can see here we got lots of results. So if you're threat hunting, looking for more information, you can get a ton of information just using NLP within search. You can see within the search, there was a guardrail violation. You can see the fully parsed, log here, and you can also see it displayed here in the timeline view. And then when we drill into that, you can see all of the rules that were triggered. So a lot of nice detail around the, AI agent activity. Within dashboards, because our demo environment is sort of new and fresh, We don't have a ton of data plugging into this dashboard. We've got a little bit. But you can see, you can look at, Agentic.ai users, that, that were blocked, maybe prompts that were blocked that they uploaded and were without of the outside of the guardrails that are set up. AI usage by host, Agentic AI by app ID. And then here in this chart here, all the different types of violations by users that you can see. So just like what you how you've been using dashboards in the past, you can use NLP to build an entire dashboard, build a visualization that goes with inside the dashboard. Alright. One more shot here. Sorry. Here we are in threat center. And, again, you've you've all worked within threat center. You know how it works. If you're looking through your cases, we searched here Agentic AI security use cases. We were able to bubble those right up to the top. You can see a case here. I'm not gonna go into too much detail here on the case because we're almost out of time, but you can see that it does highlight the AI guardrail violation right there when you pivot over to the timeline. And then, of course, within our Exabeam Nova summary, you get the information around the Agentic AI misuse. And just a reminder of all this beautiful stuff in the Nova summary, it's gonna tell you exactly what to do in terms of next steps. So all of your all of your analysts, regardless of their experience, will be responding the same way. Alright. I'm gonna stop sharing. We are going to wrap this up here. Hopefully, if you're with us, you can hang out for, actually, we got a couple minutes left. I think we're gonna be alright. So the key takeaways here, we know that there's a rapid adoption of AI agents. Whether your organization is supporting AI usage or not, it's this whole idea of ShadowAI, and people are probably gonna find out a way to use it because everyone wants to do their job better. And if there are tools out there that are gonna help them do their job better, they're probably gonna find a way to find it and use it. So we encourage you to embrace it. We're giving you a number of tools with these agent behavior analytics to, reduce that risk. And then, of course, you know, a lot of you and and most of the customers we talked to, we are in the process of building out a program. And what does that program look like in terms of our coverage today, where our coverage needs to be in the future, and how are we improving over time? And so Outcomes Navigator, that's the tool you're gonna use to sort of navigate and be strategic and plan how you're gonna allow these AI agents to go to work in a secure way. We have been answering a few questions throughout. I know we're right at the end of time. So, hopefully, we got your questions answered. If we didn't, please reach out to your Exabeam account team. We will respond and get you all the information you need. And, you know, happy New Year, and, we're looking forward to working with you for another year. And anything you wanna add to that, Matt? No. Like I said, I'll I'll I'll just reiterate how excited I am for for this webinar every time because there's so much hard work that goes into this. And and, you know, the reason that we do all of that work is you all here who are on this call. So really appreciate your you taking time out of your day to to, you know, hear some of this exciting work. We we obviously do this quarterly, so hope to to see you all back here next quarter for the next launch where we're gonna have a whole a whole new set of super exciting functionality. So that's all I wanted to say. All right. Thanks, everybody.