Intezer launches SOC operating layer for Claude and Codex
Intezer launched a revamped Model Context Protocol (MCP) server to integrate AI agents like Claude and Codex into security operations, accelerating SOC tasks by 10x. The platform provides a forensic-grade foundation with 98% accuracy in verdicts, addressing coverage gaps in alert investigation. The solution is available now to all customers.

*this image is generated using AI for illustrative purposes only.
Intezer today announced a revamped Model Context Protocol (MCP) server, enabling organizations to adopt frontier AI agents such as Anthropic Claude and OpenAI Codex into their security operations. The new SOC operating layer accelerates SOC tasks by 10x by providing agents with a foundation of forensic-grade evidence and institutional memory.
The platform addresses the challenge of integrating AI agents directly into detection tools, which often results in inconsistent outcomes and coverage gaps. Intezer's framework includes a detection layer, an operations layer, and an agentic interaction layer. The operations layer ingests every alert from every source, applies forensic-grade investigation, and produces a verdict at 98% accuracy in under two minutes. Less than 2% of alerts are escalated to human review.
"An AI platform does its best work standing on a real foundation of security knowledge, not on a dozen raw feeds it has to assemble itself," said Itai Tevet, CEO and co-founder of Intezer. "This release gives Claude and Codex that foundation with all your cases, your workflows, your triage logic, your institutional memory. AI executes. Humans supervise. And now the supervising got a lot faster too."
SOC Framework for AI Adoption
Intezer's architecture is designed to support both autonomous AI and AI assistants in security operations. The framework consists of three distinct layers:
| Layer | Function | Components |
|---|---|---|
| Detection (sensor) layer | Alerts on specific attack surfaces | EDR, NDR, SIEM, identity, cloud security, email security platforms |
| Operations layer | Ingests alerts, applies investigation, produces verdicts | Intezer AI SOC, system of record, forensic evidence accumulation |
| Agentic interaction layer | Executes custom response actions | Anthropic Claude, OpenAI Codex, Cursor, other AI agents via MCP |
Capabilities and Availability
When connected to Intezer, AI platforms can investigate and close escalated cases, make autonomous triage smarter by writing tuning rules, convert investigations to incident reports, and hunt threats starting from a lead. The system allows security professionals to supervise high-judgment tasks while the autonomous layer handles scale.
The Intezer MCP server is available now to all customers. The platform is trusted by global enterprises including NVIDIA, MGM Resorts, Equifax, Salesforce, and Ferguson.
How will the integration of frontier AI agents like Claude and Codex impact the staffing requirements and skill sets needed within modern Security Operations Centers?
What measures are in place to prevent 'hallucinations' by AI agents when they execute autonomous response actions based on the forensic evidence provided?
How might competitors in the SOC platform market respond to Intezer's standardization of the Model Context Protocol for security workflows?
























