Transcript for "On Demand: April Product Launch Announcement. Exabeam New-Scale Security Operations Platform":
Alright. Good morning, everybody. Good evening. Good afternoon, depending on where and when you're listening to this webinar. My name is Kevin Binder. I am on the product marketing team here at Exabeam. Joining me is Matt Willems, director of product management. If, you've attend if you've attended one of these launch calls before in the past, you probably have seen, Matt and I teaming up before. So, you know, as a reminder, this time is really meant for you. You know, this is the once a quarter where you have access to the product team. You can ask any question you want. So please use the, the chat window there to ask questions, and, we'll answers we'll answer those questions in the chat window as we go. And then, hopefully, we'll have some time to answer some live questions on the call as well. So, yeah, so this launch, it's really about helping you, our customers, secure a workforce that now includes both humans and AI agents. And if you remember, we launched agent behavior analytics in January. And, and so what we're launching in the the ABA that we launched in January really is an extension of our new scale analytics, our UEBA capabilities. We're extending those capabilities over to the agents now. So, it's really using the same principles. We're profiling the behavior of AI agents just like we do for humans. So in the past ninety days since we did this launch in January, we've been really busy. You can almost think of this launch here. The April launch is sort of an agent behavior analytics part two. And so there's a lot of great stuff, to talk about today and just a ton of progress we've made just since the last time we've been together. So we'll cover quite a bit today. You know, first, how is the rise of the agentic enterprise creating challenges, and how do we solve for those challenges with Exabeam Solutions? Second then, we'll talk about what's new in the platform for q one and how it directly maps to solving that problem. And the goal here is really pretty simple. We want you to leave the session with a better understanding of how these new Xfibium features, particularly the stuff around, agent security, is gonna help you contribute to your success in your SOC. Okay. So we'll we'll we're gonna start with the, with the new scale updates. Remember, we have a separate webinar for logarithms. So if you're looking for, the logarithm platform, you can sign up in the same place you signed up for this web webinar, and, you can check that one out on demand too if you don't have time to watch it live. Okay. So, yeah, security operations today, as as many of you are aware, it's really built around human behavior. The rules, the alerts, the workflow, they're all currently assuming that there's a person behind that activity. There's someone's logging in. Someone's clicking. Someone's moving through systems, and doing so in a very predictable way. And that assumption has kinda shaped everything, but, you know, in terms of how detections were written, how alerts were prioritized, and, you know, even how analysts, do their investigations and go about their investigations. But that assumption now with AI agents, that assumption is, you know, more or less now broken. We have AI agents that are taking action inside systems. They're using credentials, calling APIs, accessing data, and initiating work workflows. Now the catch here is they can do all of that. They can do it faster. They can do it more frequently and, you know, often in ways that really don't follow human patterns, and that's sort of where the challenge comes in. They're machines, so they don't get tired. They don't slow down, and they can actually chain together multiple actions and sequences, in ways that might look normal at sort of each step in the process. But when you look at the full sequence, it the sequence of behavior wouldn't make sense and it, you know, would would show show risk when you when when you look at the full sequence. So that basically creates a gap. And because most detection logic is still looking for those human patterns, and not machine driven behavior, that's where traditional detection gets stuck a little bit. So, you know, I think the question for you or, you know, our customers is, is your current detection strategy set up to understand both agent and and machine behavior as well as humans? And if not, that's okay. You've got a lot of new detections now with this launch that really focus on independent agent behavior and activity. And we'll talk more about all those, detections in just a minute. Yep. And as usual, Matt, feel free to jump in Yeah. and anything additional, to add. This data point that we're showing on this slide, this one's really important because it it sort of validates what you're likely already starting to feel. 93% of organizations either see AI increasing insider risk or they expect it soon. So, this is not a future concern. This is already happening inside real environments. And what's changed is not really that category of risk around insider threat, but it's the speed and the scale of it now when you add agents to the mix. And, you know, insider threats have always been difficult, because the activity looks legitimate. The user's accessing data. They're running queries. They're moving between systems. And AI makes that even harder. Right? It can generate more convincing phishing. It can automate interactions and execute things at the speed that a human simply can't. So instead of a single suspicious action that you might be able to catch with rules, you now have hundreds of these very small, seemingly valid actions that add up to real risk. So it's really important you're able to understand what's happening over time. And, you know, because this activity is happening with legitimate access, legitimate credentials, it blends in, and it's hard to see. And that's the key shift that we're trying to solve for. Just just to reinforce that point, you know, for everybody on this call, you you've either intentionally adopted an AI platform enterprise wide or you're in the process of rolling it out or your users are doing it on their own. A AI is in your organization, unless somehow you're you're fully offline, you're, you know, a dark site or something like that where you really truly do have control over what gets plugged into the network. Unless that's the case, AI is there. I I promise you. It's just a question of whether you've done it formally or your your users are doing it on their own. And and to Kevin's point, that the the risk of that AI insider is only that much greater because it's a a new type of thing that, you know, your your users, your your security team doesn't necessarily know how to how to wrap their heads around and investigate and treat as a risk. But, also, like you said, the speed at which it can act, the, the kinda unintended consequences of granting it access to things means the blast radius can be that that much greater, and and the ability to audit, you know, what it has access to and what it's doing, is is paramount. Yep. There used to be everyone heard of shadow IT, right, where it was like, if IT doesn't you know, this is really kinda when SaaS was exploding. Right? And, you know, if IT didn't give you access to all these things that are gonna make you better at your job, people were gonna go out and figure out a way to get it on their own. And AI is the same way. We're calling it shadow AI. And when you think about it, the, AI is putting a ton of pressure on people because everyone is now the assumption is you're using AI, and so the expectation is that you're producing more in your job. You're doing you're being more productive in your job. You're being more efficient in your job. Now if you're expected to do that without the help of AI, you can imagine there's a lot of pressure. Right? And that pressure leads to them going out and figure out figuring out ways to use AI on their own, just like what used to happen with shadow IT. So as we dig a little bit deeper here, let's define the problem in a in a little bit more details. You know, agents don't introduce a completely new risk category. What they do is they amplify that existing insider risk. And, you know, insider threats have always been difficult to detect. That's why I'm sure many of you on the call, and and we've noticed just out talking to our customers, a lot of organizations have separate teams and even separate budgets for insider threat because it is really sort of a different beast, and traditional methods don't always catch it. That's why there's need for separate. teams and separate budgets to address that. And the reason is expanded access. If you look on the right hand side, expanded access where agents, they're operating with real credentials. So the everything looks legitimate. It's just happening much faster. The privilege abuse as well. Right? If compromised, they they look like trusted users. And so what we end up here with is a visibility gap where, you know, most tools cannot distinguish between the human and the agent activity. And, you know, the board level question that a lot of CISOs have to answer, and that we may have we probably certainly have some CISOs on the call here this morning is can you actually distinguish between trusted human activity from trusted machine activity? And can you explain the risk of both with a certain level of confidence? And excuse me. And at this point, you know, a lot of teams, they can't do that yet. So what we're gonna do now is jump into the features that we're delivering here for the launch. So this is where you're gonna see what's new. All the stuff is turned on and available for you in the NuScale platform. What we did is we organized this deck from here on out to map map back to four strategic priorities that we have for our product development. And these matter because each one of these reflects a different way that we're delivering value to you, our customers. So we've been listening to you. We think we understand what's gonna provide the most value to you, and these are sort of the key buckets that we're dropping things in. We've already talked a lot about insider threat today, so I won't spend too much time on that one. The second one is an interesting one, is this idea of human and agent teaming. And, you know, this is about how, oops. See, I forgot to advance the slide. I apologize. There we go. So the second icon you see here is this is about the human and the agent teaming. And, you know, this one here is about Exabeam Nova. Right? How Exabeam uses AI to help our customers run security operations more effectively. And with Exibeam Nova, the goal is not a fully autonomous SOC. If you've been on our webinars before, we don't believe in a fully autonomous SOC. We think that's super risky. But the the goal was the way we see it is more of this human on the loop model where AI agents are helping the analyst move faster. They're surfacing context. They're prioritizing risk, accelerating the investigation and the response itself, but there's still a human oversight over it. And so the value here for the second column is speed and efficiency without removing human judgment from the process. The third is how do we optimize our security? We know this is top of mind for a lot of our customers. How can we know what we're doing today. How can we do it better for tomorrow? And, you know, see, we realize that security teams, you're under pressure to prove outcomes, not just the activity you're doing. So, you know, more alerts don't help, but better prioritization maybe, faster investigations, being able to measure your progress, that does help. So the value here is helping teams improve their performance over time, think outcomes navigator for this one, and show their security operations are becoming more effective. And, you know, this is really important for CISOs, again, who need to explain to the board, how are they doing, what are they doing, why are they doing it, and maybe why they might need a bigger budget or some additional investment. And then the fourth one here is really around choice and flexibility. This is something near and dear to our heart. You know, there's a lot of mega vendors out there, and, you know, they want you to use everything from them. And if you don't use everything from the mega vendor, there's usually some sort of a penalty that you have to pay. That penalty could be in the form of dollars. That penalty could be in the form of complexity. Maybe you gotta hire someone to, do a integration for you. And, you know, but we believe here that, you know, if you wanna add a best of breed layer to your stack, you should be able to do that. And, you know, with Exabeam, we really pride ourselves in being open and agnostic in giving you that choice. We for example, Exabeam Nova is completely free. Right? We want you to use it. We want you to take advantage of it, regardless of what other products and and solutions you're using. So, when you put all of these together, you know, essentially, what you're getting is better detection for insider threats. You're getting faster human led operations with the AI assistance, measurable security improvement for the third one, and then really the flexibility to work in the environment that you already have and extend your existing investments. We don't want you to expect you to throw everything out and start from scratch just to be able to secure agents. Okay. So what are we delivering here for this launch? And this slide here really is about simplifying the problem. We know most organizations today, like Matt said, everyone's experimenting with AI, but they don't really have a clear model and a strategic plan on how to secure it. Not just secure the AI stuff being used today, but the AI stuff that's to come. So we break it down into three steps here. The first is to onboard. You might remember we talked about this last quarter when we added the Google Gemini collector. You have to get visibility into the AI activities. So that means ingesting the logs from tools like ChatGPG, Gemini, Copilot, and others. If the data is not there to start with, then, you know, really nothing else matters. And then the second is once these agents go to work, securing them, making sure that they're working in a secure way. And this is where the our new scale analytics comes in. We apply the, analytics, both the UEBA and the agent behavior analytics. And, you know, this allows us to understand both how humans and agents are behaving over time. And that's how you detect the misuse and the compromise and that drift from normal behavior. The third one here is how do we optimize. This is where outcomes navigator comes in. It helps you understand what is your agentic enterprise security coverage look like today. What gaps do you have? How can you track improvement over time? So instead of guessing how well you're you're protected, you can actually measure it and improve it. So you put all things together. You know, this is sort of the framework and sort of a goal you would wanna have. And most of the customers that we talked to today, they've got partial visibility into what's happening, but a lot of those controls are still fragmented, and, they don't have complete visibility across everything that's happening. So we wanna give you a complete model where the AI activity is visible, where the behavior is understood, and the security outcomes are something that you can measure over time. So, that's what it means to secure the AI workforce from end to end. Alright. So this is an exciting one. This this one, made me really happy. We actually got something delivered sooner than expected. And, you know, this slide makes the point that coverage really matters, because AI usage is already broad. It is fragmented. But similar to a lot of other technologies, most organizations are not standardizing on one AI platform. They're using several. So in many cases, some of the usage is approved. Some of it's not approved. But a surprising amount happens outside that formal security oversight, and that's what everyone needs to be concerned about. But that's also why the platform support matters so much. If your visibility only covers one or two tools or platforms, you're gonna be missing the bigger story. So we know employees are using a growing mix of AI agents. I use four different platforms myself. AI enabled applications across the business. Almost every application that your organization is already using probably has some sort of AI or agent, that's now embedded in it. So, not just looking at the platforms, but also understanding the applications you're already using are also now gonna be driven by agent activity. And so that the behavior of your applications and how your users are interacting with those app applications, it's all really important for discovering risk and discovering when something's gone awry. So, yeah, I mean, we have a lot of stuff that needs to be looked at. It's not just the behavior of how employees are interacting with applications, but now we have humans interacting with applications, human interacting with agents, agents interacting with applications on behalf of a human. And so traditional detection logic really struggles when you start to mix all of this stuff together. This is a good slide here because it really under helps you understand what the value behavior behavioral analytics brings to your detection strategy. Traditional threat detection is really good at finding out known bad activity. The rules, signatures, correlation logic, they're all designed to essentially match patterns that we've already seen. But there are two limitations or two key limitations here. The first is the short windows of, excuse me, where, you know, most SIM and XDR platforms are looking at activity over minutes. Right? The the window of when things are happening, minutes, maybe hours, maybe a couple days, but that works good for obvious fast attacks, but it doesn't work for the type of attacks that unfold over time. And then the second is there's no real stateful memory within the detection system. Right? The these systems, they process events, but they don't truly remember the behavior, and they don't build a long term profile of how a user or an agent normally behaves. And so everything's evaluated in these very narrow windows, and that creates a creates a gap. So because AI driven activity often looks legitimate in the moment, you know, an agent can follow rules, use valid credentials, very difficult to catch. And a key point here is that abnormal behavior does not always mean bad, and bad does not always look abnormal in a single event. So without memory and that long term view into behavior over time, you're gonna miss the pattern, and you're gonna miss the little things that add up to important risk and important indicators of risk. And so in a nutshell, what what this slide here shows is why new scale analytics is critical excuse me, critical for covering the gaps in your coverage that traditional event correlation, by itself might sometimes miss. Rules are important. Rules are not going away anytime soon, but rules plus analytics is gonna help you catch a lot more. That is such an eloquent point that abnormal doesn't always mean bad, and bad doesn't always look abnormal. I I I think that's a that's a great way to convey kind of a a an abstract concept in behavior analytics and kinda traditional threat detection that if you're only looking for things that are known bad, you're gonna miss a lot. And if you're only looking at things that are abnormal, you're gonna miss a lot of context. You're you're you're gonna spend a lot of money in cycles chasing things that are in in an inefficient way. And it and as the the slide says there, that's very weak to insider threat because users can can bad users, you know, whether that's a compromised user or a malicious insider, can get away with a lot of things that, might might, for the most part, look sort of normal with a with a few indicators here and there. And and if you're not looking for it the right way, it's, pretty hard to catch. Yep. Alright. One other thing I I should have pointed out two slides earlier when we're talking about adding the chat GPG, OpenAI, and my Microsoft Copilot to our list of platforms. You know, when we launched this in January, as many of our customers on the call know, we've have a very close relationship with Google. We have for many years. We develop things with them, and that's why we came out of the gate with Google Gemini. But, you know, a lot of customers we talked to said this is awesome, but we're doing more than just Google Gemini. We need we need the other big players. Right? We need the OpenAI, and, we need the Microsoft Copilot. So we're hoping now with this April launch, there's a lot of you now on on the call that are gonna be like, okay. Great. Now is the time to turn this stuff on. Now is the time to start taking advantage and really see the value that agent behavioral analytics is agent behavior analytics is gonna give me. Okay. So building on that last slide, I've got, I think, one more slide after this, and we'll hand over to Matt. But I wanted to look at the evolution of threat detection a little bit too and, sort of where we are today and and where we're going and why as an Exabeam customer, you're actually in a really great position. You know, most monitoring today answers a very simple basic question. Is is the system running as it's expected to be running? But that's, you know, really not enough anymore. We need to understand the intent. What is the agent actually trying to do? And, you know, level one here is the basic visibility. This is, you know, seeing a first time agent run or discovering that shadow AI. It's necessary, but by itself, it's not enough. It tells you some risk might exist or something exists, but it's not necessarily of danger. And then level two takes it to that next step, right, where level two evolves to the interactions. And here, we're looking at has a guardrail been violated, maybe someone attempting a prompt injection, or basic policy breaches here. This is where traditional DLP and the rule based systems play. This is where most of our most particularly prospects that we talk to. This is kinda where where they are today. And then level three is where Exabeam customers, are and can be, especially when they turn on ABA. And, you know, this is where the real battle is gonna be fought, which is detecting that rogue agent. And this goes beyond rules. It's about spotting abnormal workflows that technically might be allowed, but from a behavioral perspective, they don't make any sense. Catching those really hard to catch, those slow drip, data exports, slow and low attacks, living off the land, privilege escalation, and things like that. So the critical takeaway from this slide is you can do level one and level two with most legacy tools, but level level three really requires a stateful memory, the behavioral baselining that we were talking about before. And so the question is then what do we need for level three? And machine learned behavioral analytics is what you need. And Exabeam New Scale Analytics, which includes agent behavior analytics, so if you've got New Scale Analytics, you've got fusion. ABA costs you no extra money. You simply just need to turn it on. And, it gives you a really nice future proof, threat detection as you start, allowing more agents to, you know, work within your workforce. Okay. The oh, this is I mentioned earlier that something came early we weren't expecting. It was the Microsoft Copilot. We thought we're getting chat g p t, and we actually our engineering team did a and security research team did incredible work to get the Copilot out the door literally almost a quarter early. And then this slide here too also completely blew me away. In January, we launched agent behavior analytics, and we started with some of those first time detections. If you remember, I think we had six or seven. And, you know, these first time detections, they're really powerful on their own. You know, the first time an agent did something. And what these first time detections, the reason they're powerful is because it means some someone or something has changed. Right? Something has happened that's never happened before. It's it's binary in nature. Right? And, you know, in order to know if something has happened for the first time, you need to have that understanding of history of behavior over time. And, rules by themselves won't often catch that. So we launched with the, the first time detections. In ninety days since that launch on January 1, we've added five times the number of detections. And these are like our UEBA detections, which covers the whole span of users interacting with agents and what that behavior looks like. These ABA detections, this is really for independent agent activity. So we're literally looking at the behavior of how these agents are acting on their own. You know, and keeping in mind, we have hundreds of UEBA rule rules that already cover that human agent interaction. So now we're building that coverage of agents and human and agent interaction, and that's really part of the beauty of new scale analytics. Right? It's one behavioral engine that understands and monitors behavior, for both humans and nonhumans. In terms of some of the use cases now that these detections allow us to cover, we'll go a little bit deeper on the next slide. But, you know, we can now baseline some of the AI agent behavior. We can look at things like prompt and model abuse, detection. We can identity and privilege monitoring of the agents, we can cover that now. And then, really, the agent life cycle monitoring as well. As these logs come in, we can say, okay. Is is this a new agent? Is this a new agent that's been created? Who created it? Things like that. So just a massive amount of work in ninety days, and we're gonna continue to build the library of agent behaviors out. But we know this is important to our customers, and so we're putting a lot of all of our effort and focus onto, building out this library of detections. And, I I mean, I'll I'll echo what you said. You know, huge, huge kudos to the engineering and research teams. Huge amount of work that that came in early as a product manager. Always love to see that. That that that makes me go, okay. Now can we do even, even more than that next quarter and and things like that. But, you know, that's not always sustainable. But I I think it's also worth highlighting, kind of a nuance that you called out in there. You know, it it's very easy to say, okay. Well, if 5 or six is a good start and 25 or 30 is, you know, okay. That looks great. It's very tempting to then say, you know, oh, well, 500 would be awesome. What about 5,000? That's that's gotta be a thousand times better than five. Right? And and that's just not the case. There's a reason that we haven't labeled them rules in here that that we're talking about detection logic, because these are not scenario based rules. We're we're not looking for these individual specific scenarios. These are detections that get combined in the engine logic to say, you know, I I saw certain factors, what type of thing this was, what what risk factor there was. You mentioned some of the first time detections. Okay. Those are the first type of this type of thing. And and, the the variability in all of those different types of detections can get combined automatically by the engine to cover far more scenarios than a list of rules ever would. So I I like the way we've called it out in here. And I I just thought it was worth highlighting that nuance because it's very easy to get into a numbers game when. that that really is not, is is not how the the measuring stick works here. Yep. Cool. Kevin, is it over to me now? Yeah. If you wanna do this slide, this I wish we started. slide, yeah, this next slide we're showing here, I can tee it up for you, Matt, but you for those on the call and who follow us on social media, you probably know that we have two people here at Exabeam, both Steve Wilson and, our chief product officer, Scott Clinton, our vice president of product marketing, who are heavily involved in OWASP. And OWASP has really kind of exploded over the last few years as really, an authority of, you know, where is risk coming from and how can we categorize risk. And it they've and so what we what we wanted to do here is show, okay. Well, we've got all these new detections. What does that mean, and, what kind of coverage does that give us? So there's a OWASP, agentic top 10. There's an OWASP LLM top 10, and we we have coverage across all of the OWASP top 10 for the agentic, and quite a few for the LLM as well. What I wanted to point out on this slide, though, is you'll notice the two red circles here, the excessive agency and identity privilege and abuse. We put a lot of attention here. You can see the number of detection counts is far higher than a lot of the others, and you can probably guess why. Identity risk, also insider threat, and excessive agency, which also very closely tied to insider risk. These are the biggest coverage gaps we see over traditional SIMS. Right? And so we've talked about that a lot already. So for the areas where your coverage is likely gonna be the weakest, we put the extra attention there first and, you know, the stuff that's not likely to be triggered by a rule. So all of this stuff is available today. And, with that, Matt, do you wanna add anything to this slide or do you want me to move over to the next? You I I appreciate the the setup there. I I I was gonna speak just a little bit to kind of the the concept, that key concept that's called out in the corner here of of agents not being a separate risk category, but really kind of an extension of the the existing, identity and behavior risk. I think this is really interesting because, you know, the when when I was kind of early on in adopting some agentic tools, it was actually Steve Wilson that kind of kinda framed it, made the analogy of the these AI agents can kind of be, like, a really smart, really ambitious intern who's also really lazy. Right? Like, there there's all these all these qualities bundled up into one and intern and that you can kind of go like, okay, now go do this and come back and tell me when you're done and, like, really smart in the the amount of information it's able to consume and synthesize and and, you know, pulling together from disparate sources and code authoring and things like that. Ambitious in the, it can go after things that you wouldn't necessarily expect if you say, hey, go go go figure this out. Go give it a try. It's gonna go give it a try. And then also really lazy in that if it can figure out a shortcut or something seems kind of hard, it it it can it can act pretty lazy and just go like, well, that seems hard. I'm just gonna fake it all. I'm I'm I'm just gonna pretend that I did it and, like, since, synthesize a fake answer, you know, build it from scratch, that kind of thing. And and and I think that for me really reinforced the need for a lot of these detections. It acts like a person doing those things either on its own with with kind of that excessive agency just deciding that this is what needs to be done. This is almost the Silicon Valley like, well, you know, go go fix the bugs in the code. So it deleted all the code, and all the bugs are gone. Right? That kind of thing. Or, it's acting like a a a person in the, it's it's sitting beside me doing kinda doing my bidding almost. And for those reasons, like, you you still wanna use those kinda identity and behavior based, risk risky detections. Like, it it it fits right into that model. So while, yes, there are some, AI specific, detection logic that can be applied using the existing, sort of UEBA detections makes a ton of sense because it it it it's interacting with a person who's gonna be falling under UEBA. It's also sometimes acting on its own like like an agentic AI. It's an interesting model. So, now we're gonna go through some of the specific features. I'll spend a a few minutes talking about some of these. We'll go through a little bit of demo. The first one that's up, was a a really nice integration, specifically with Okta. We we use, Auth0 from Okta, on the back end, and, they released a feature called universal logout that, essentially allows for when an Okta user is disabled. There's a setting that allows, applications that are aware of this integration, this this kind of universal logout or back channel logout to essentially automatically revoke sessions for a disabled user. Typically speaking, what would happen is a user gets disabled in an identity platform, but they already have a session potentially, and that session is valid for a certain amount of time. Most applications will not kinda go back and check on every call or period of time to see if that session is still valid. It'll wait to refresh that session token until it expires. What universal logout and back channel logout do is it will actually push a revocation to applications that are aware of it to say this user was disabled, terminate their sessions. So it's kind of a heightened security control to say, nope. That user got disabled. Their next API call was gonna is gonna fail or they're you know, even if it's in in the UI, it's still an API call behind the scenes. So kind of a nice heightened security feature there, through a partnership with Okta. Moving right along, you know, we we, definitely hear feedback from users that analysts can can kinda spend some time going through the application, like, navigating new scale to find things in different places versus sort of having, exactly what they need at their fingertips. So we've, introduced this global search capability. Many of you have probably seen it already. We're kinda in the process of rolling it out, across regions and and accounts right now. That is is kind of the the platform wide search bar. So you'll see this this top of every page. It's really meant for quick access to users, like, not not users in the platform, but users that we're monitoring, and, you know, jumping into those user details, the timeline, running searches, those kinds of things. This will get extended over time into, additional things that we can search for. So if you have feedback, on any of that, please, feel free to reach out, drop it in chat, work with your account team, drop me an email or note on LinkedIn. Yeah. Happy to to, talk through feedback on on this feature. We'll do a little bit of a demo on this one just a little bit. So moving right along, another feature. This actually came it was part of advanced analytics and something that we were working on, kind of replicating and enhancing in new scale analytics. And that is, sort of an automated phishing investigation workflow, specifically relying on the ability for users to to forward phishing emails or send phishing emails to a a specific mailbox that's being monitored. And then automation picks that up and kinda runs the the automated investigation, can tell things like, you know, other users that might have received the same or similar, and and, you know, case creation and all that kind of, automation really handled as part of this automated workflow. This is in early access right now. So if it's something that you're interested in, please feel free to reach out, and we'll, we'll see about getting you access there. And you'll see this turned on, globally in the not too distant future. So really nice, addition here. Like I said, inspired by something that was in advanced analytics that that users were saying, hey. This this thing is actually really useful. I'd love to bring that along in, new scale analytics. So, responded to that feedback, and here you go. Alright. Another piece of feedback that we got, on new scale analytics is in threat center. If you were looking at a case and, you know, the scoring model from advanced analytics to new scale analytics really changed quite a bit, moving from this unbounded the score keeps accumulating over time as detections are added into this this kind of normalized score model. Users were trying to understand that score, and and the UI was just kinda challenging for some users to really grok, you know, what what did this score mean. The move was widely hailed as, hey. This is this is far, far easier for, an an analyst to understand and, you know, the normalized score is much more meaningful. You can wrap SLAs around. Here's how, how much time we have to respond to a 90 plus or, 50 to nine you know, you can you can do that kind of thing. Where the unbound score, that's that's really difficult. So the the change made a lot of sense, but then the explainability was kind kind of lacking. So, we we spent some time, revamping that UI for explaining the, how the risk, score calculation was made, and we'll we'll go through a little bit of demo on that in in just a little bit. We'll go through a little bit of demo on that right now, actually. I didn't realize it was the the last one before demo. So, let me take down the, the slides and switch over to my screen share. While I do that, I just have to say I really appreciate everybody's time this morning. This is absolutely one of my favorite, events throughout the quarter because, as a product manager, you know, this is the stuff that I spend my time absolutely neck deep in day in and day out is getting customer feedback and working with engineering to kinda bring it to fruition. So so this is kinda where the rubber meets the road. This is saying, hey. We we heard you guys. Here's what we've been working on. Now let me let me turn it loose and and, you know, watch customers start to adopt it. So one one of my absolute favorites. Alright. So what I have up on the screen, is that, that global search bar. So you can see it's just a search bar that lives at the top of the page. I can I can fill in, you know, part of a username, like like Gary in this case? You can see that that user got returned here. If I had a list, if this was, Steve and we've got 17 Steve's, it's gonna show a subset there. And that that's why we've added this search in attack surface insights app, because maybe we've we've filled out, how many users who are are, you know, just space wise able to be shown in here. Well, you can turn that into an ASI search really easily if you need to go do additional filtering, or narrow things down. You can also just click on that user and see their user, their user details coming back from ASI. So I can really easily see, okay, this is an active account, not on the VPN, unlocked, foreseen, all that kind of stuff. You know, all the details coming back from ASI. If I need to, I can jump to that user's timeline in search. So it's effectively gonna build a search for that user and and show me the, the user entity details, in the timeline view. Okay. That user happened to not have any. And the the last option in here was the, search in the search app. So I can fill in any term. It doesn't have to be user. I could plug in an IP address. I could plug in a, you know, hash, whatever it is I need to search for and just run that search in the search app. So we need to do kind of a a quick, full text search there, which is really handy. So once this is in there, now I can go, change the time range or anything like that that I might need to. We talked a little bit about that scoring change. So I wanted to jump over to threat center and, well, not not the not a scoring change, but the way we explain the score. So, what we're gonna look at is within this case, you can see this is a this case got a a score of 99. It happens to have been an AI guardrail violation. So we were just talking about, like, from time to time, depending on what's going on, sometimes it's the AI agent itself, and sometimes it's the user and how they're interacting with the AI where the detection is relevant. In this case, it's a a user who has, violated guardrails, that created this case. So let's see how that that score was calculated. So all the detection, underlying detections get added up. Their risk scores get added up, and that then gets normalized zero to a 100. So that becomes as 57. So those simply get, this score gets normalized zero to a 100. So we have this 57, and then business factor adjustments apply. So, it'll explain what business factor adjustments are, but basically context that you add from your business to impact that risk score. So in this case, this was a high scoring or there are high scoring fact based detections in this, in this case. The the the entities were determined to be of of a medium criticality and the rule severity. So some of the rules that were in here were actually, intentionally tuned down. But that added 42 points overall to that 57, so we end up with a 99. So, you know, took took me thirty seconds or something to explain kinda how we came up with that that score. Should make it far easier for, users to, sort of to really break that down. Then wanted to jump over to, threat detection management and show, some of those those, detections that we were talking about. If you're following along at home, the easiest way to do this is, viewing analytics rules. You can always filter by the use case, Agen to k I security, or the the family AI activity. In this case, they're gonna show the same thing. They don't always, for all use cases, but this is a pretty good way to show it in here. And you can see, the the out of the box rules here that are are in this environment, that we've added. So we went from that list, like Kevin was saying, of of five or six, to really cover a a lot more of that detection space. You know, some of those first time events, those are all still there, but we've added a ton to it, like, you know, different types of, access requests by AI agents and, token utilization and and things like that. So really covering a a lot more ground there. That's also visible in outcomes navigator. If you weren't already aware, AgenTek AI security has been added as a use case in outcomes navigator. And here you can see that underlying set of analytics rules. In in this case, our demo environment, we're always building this out, but, you know, we got most of them covered, not quite all of them. So, yeah, lot lots going on in here. And if you're working this in outcomes navigator, you can always view the rule details. If you wanna work on, you know, adding support for a particular detection, this will kinda tell you what you might need to go add in in parsing or on by onboarding of data sources in order to satisfy that rule logic. Kevin, did I miss anything, or are we good to, jump back over for q and a? Yeah. I think those were the key, the key things that we wanted to show. So, yeah, let's. let's flip while while we pull up q and a, I can probably make one more quick highlight, and that is, for the April launch, which is coming up in, next week, I think. that. We'll we'll be making available our, native MCP server. So there there will be documentation on kinda how to how to set that up and get credentials to, to take over to your AI of choice. But you can kinda see what that might look like in something like Claude. In this case, I'm using Claude Cowork. I actually have it set up to run an automated triage every morning. So this ran earlier this morning and triaged all the cases that came in overnight or were left open from the previous day. And it highlighted two critical cases for me here, a phishing campaign and then, I I think it was a network exfiltration, and wrote a pretty exhaustive report for me of great. Here's the executive summary. These need immediate attention. Here are some things that that seem to span cases. So you might have something that looks more like a campaign because multiple entities were involved. Breaking those down. Hey. This one really needs immediate attention. Here's what's going on. These are all the the key, data points from that case, all the way down through kind of the summaries of how many cases were looked at and breaking them down by severity and status, even making recommendations on things to tune. I like to highlight this because right now, I have this wired up to a staging environment that has demo data in it, like, just replay data. And Claude was doing too good of a job going, are you sure you wanna do this? Because every time I look at it, this this is replay data. Nothing's really changing. And and so I actually had to kind of instruct it, like, I need to do a demo of this. It isn't a real environment. Please just pretend that this is real data and and help me get through this demo. It was doing that good of a job of saying, like, just tune this stuff out. It's all replay. So, I I love that. So what you're seeing here is is after I instructed it, like, no. Let's let's just press on and pretend that we're looking at something real. So, I I really enjoyed that one. Cool. Alright. Q and a. Alright. So let's see here. Okay. Alright. Here's one. How should we think about securing AI agents differently from traditional users? What changes in detection strategy? We talked a little bit about some of this earlier. Yeah. Yeah. That's a good one. I mean, I think the I think the answer is both. I think the answer is you you do wanna apply a lot of the existing kind of behavior analytics concepts to the AI agent. I think what what really changes is this thing can move much faster. It may have, far reaching access. The agent doesn't have intent. You know, the agent does what it's told to do. It can be misguided. But in a lot of those cases, it's being misguided by a user or it's being misinformed. So, telling the difference between a a a compromised I I I don't like, a an an agent that's going rogue, which may maybe is starting to happen versus a a malicious insider or a compromised insider who's leveraging an internal AI tool to do their bad actor work faster and and, you know, more broadly. That that's where I think it's it's really gonna apply. You you really do have to monitor it both ways. Yep. It looks like we got one more. So what are teams doing today to measure their coverage against frameworks like OWASP? How do they know where they have gaps? Yeah. Good one. So so that really does, hit directly at outcomes navigator. I guess a bit of a preview. Team is starting to work on actually adding the OWASP Majestic top 10 and a handful of other, you know, common compliance and the security best practice frameworks to outcomes navigator. You can you can either look under the outcomes navigator space or just kinda watch for a set of features called compliance navigator. It's not a separate feature. It's really just an enhancement of outcomes navigator. You can already see PCI and HIPAA in there, and the team is working through a really, really ambitious robust list of things like NIST CSF, CRI, a lost progenitor top 10 we that we talked about, NIST 853, NIST two. There's there's a huge list that, is is getting built out in there. As we get content defined, you'll see those show up. And then, you know, you get to do similar things that you can in the rest of outcomes navigators. We'll be adding, like, a control level detail pages. You can see what content aligns and how to how to satisfy it and all those kinds of things. So that'll that'll be a big update and hopefully coming I'll I'll say hopefully. I can't make promises here, but, you know, tracking toward, getting a lot of that out in q two. Yeah. Yeah. That's awesome. I think when we were doing our prep for this, we kinda had to look at the detections and use an LLM to help us sort of map what we have to see what our coverage look like against the OWASP top 10. And, yeah, that'll certainly be something nice for the customers if they can check that coverage themselves right inside Outcomes Navigator. So good Yeah. stuff. Okay. Let's bring the slides back up. Let me click on slides here. Hopefully, I don't screw things up. And we are gonna go to this final slide here. That work? Yeah. Looks good. Okay. Okay. Great. Alright. So just a couple key key takeaways here today. You know, if you leave if you leave with three things, you know, remember this. You know, first, it's the AI agents expand the insider risk, which is already something that's difficult to cover. The second, security operations really need to evolve to support these agents. Right? Traditional detection needs a little bit of help. Although we know rules aren't going away, and we we discussed the the the benefit of knowing what's known bad, but also knowing what's abnormal in terms of behavior. They actually two methods actually help each other out, and provide for better overall detection strategy. So, the third one then is behavioral analytics are essential. I mean, this is the foundation of understanding behavior over time, whether it's an agent or a human. So, you know, these are all things that we wanna highlight. And the fact that you're an Exabeam customer, you're in great shape, you're future proofing yourself, and, we we're just excited to continue building out agent behavior analytics. We've got such great positive response from our customers that it was something they were worried about. And knowing that sort of Exabeam has their back in all this, it's been great to hear that sort of validation that where we're putting our effort in is, is resonating with you guys, our customers. So, as usual, thanks again for spending an hour with us. Cool. We'll be back next quarter and, do it again. Thanks, all.