Intezer launches Workflows to automate AI SOC response

scanx
Reviewed by
Ritika DScanX News Team
Key Highlights

Intezer has unveiled Workflows, a native automation and response builder for its AI SOC platform that allows security teams to integrate response actions directly into their investigation workflow. The solution eliminates the dependency on standalone SOAR systems by enabling natural-language workflow creation and automated remediation based on investigation context. Currently available in early access, the general release is scheduled for later this quarter.

powered bylight_fuzz_icon
48692682

*this image is generated using AI for illustrative purposes only.

Intezer launched Workflows, a native automation and response builder designed to complete the AI SOC lifecycle. The new feature enables security teams to create and customize response workflows directly within the Intezer platform, integrating post-investigation actions into the same environment used for alert triage and analysis.

The platform addresses the operational gap where security teams often rely on standalone SOAR platforms or manual processes after reaching an investigation verdict. By bringing response automation into the AI SOC, organizations can execute remediation steps such as closing alerts, isolating hosts, updating tickets, and notifying analysts without maintaining separate systems or custom integrations.

Key capabilities

Workflows provides several features aimed at streamlining security operations:

  • Custom response built into the AI SOC: Teams can build response logic directly in Intezer without maintaining a separate SOAR. Actions run across the security stack based on investigation outcomes with no additional API glue or polling required.
  • Natural-language workflow creation: Users can describe desired actions in plain language through Intezer’s MCP, then review, refine, test, and activate the generated workflow.
  • Investigation context carried into response: Workflows utilize evidence, data, and organizational context gathered during the investigation. Actions are reflected in relevant alerts or cases, with each run logged for audit and troubleshooting.

For Managed Security Service Providers (MSSPs), the tool can automate customer communications and per-tenant routing that typically requires manual processes.

Availability

Workflows is available immediately in early access to selected Intezer customers. General availability is planned for later this quarter. The company stated that its customer success team will assist teams in migrating existing SOAR playbooks.

Disclaimer: This article is AI-generated using data from ViewTrade. ScanX is not liable for any inaccuracies.

How will the consolidation of SOAR capabilities into the AI SOC platform impact the competitive landscape for standalone SOAR vendors?

What are the potential security risks associated with relying on natural-language prompts to generate automated response workflows?

Could this integrated approach accelerate the industry trend toward autonomous security operations that require minimal human intervention?

like19
dislike

Intezer launches SOC operating layer for Claude and Codex

scanx
Reviewed by
Radhika SScanX News Team
Key Highlights

Intezer launched a revamped Model Context Protocol (MCP) server to integrate AI agents like Claude and Codex into security operations, accelerating SOC tasks by 10x. The platform provides a forensic-grade foundation with 98% accuracy in verdicts, addressing coverage gaps in alert investigation. The solution is available now to all customers.

powered bylight_fuzz_icon
43341631

*this image is generated using AI for illustrative purposes only.

Intezer today announced a revamped Model Context Protocol (MCP) server, enabling organizations to adopt frontier AI agents such as Anthropic Claude and OpenAI Codex into their security operations. The new SOC operating layer accelerates SOC tasks by 10x by providing agents with a foundation of forensic-grade evidence and institutional memory.

The platform addresses the challenge of integrating AI agents directly into detection tools, which often results in inconsistent outcomes and coverage gaps. Intezer's framework includes a detection layer, an operations layer, and an agentic interaction layer. The operations layer ingests every alert from every source, applies forensic-grade investigation, and produces a verdict at 98% accuracy in under two minutes. Less than 2% of alerts are escalated to human review.

"An AI platform does its best work standing on a real foundation of security knowledge, not on a dozen raw feeds it has to assemble itself," said Itai Tevet, CEO and co-founder of Intezer. "This release gives Claude and Codex that foundation with all your cases, your workflows, your triage logic, your institutional memory. AI executes. Humans supervise. And now the supervising got a lot faster too."

SOC Framework for AI Adoption

Intezer's architecture is designed to support both autonomous AI and AI assistants in security operations. The framework consists of three distinct layers:

Layer Function Components
Detection (sensor) layer Alerts on specific attack surfaces EDR, NDR, SIEM, identity, cloud security, email security platforms
Operations layer Ingests alerts, applies investigation, produces verdicts Intezer AI SOC, system of record, forensic evidence accumulation
Agentic interaction layer Executes custom response actions Anthropic Claude, OpenAI Codex, Cursor, other AI agents via MCP

Capabilities and Availability

When connected to Intezer, AI platforms can investigate and close escalated cases, make autonomous triage smarter by writing tuning rules, convert investigations to incident reports, and hunt threats starting from a lead. The system allows security professionals to supervise high-judgment tasks while the autonomous layer handles scale.

The Intezer MCP server is available now to all customers. The platform is trusted by global enterprises including NVIDIA, MGM Resorts, Equifax, Salesforce, and Ferguson.

Disclaimer: This article is AI-generated using data from ViewTrade. ScanX is not liable for any inaccuracies.

How will the integration of frontier AI agents like Claude and Codex impact the staffing requirements and skill sets needed within modern Security Operations Centers?

What measures are in place to prevent 'hallucinations' by AI agents when they execute autonomous response actions based on the forensic evidence provided?

How might competitors in the SOC platform market respond to Intezer's standardization of the Model Context Protocol for security workflows?

like16
dislike