Securonix expands SIEM features
- Securonix on August 3 expanded its SIEM platform at Black Hat USA 2026 with Microsoft Sentinel analytics, AI-agent monitoring and new data-cost controls. (ciso.economictimes.indiatimes.com) - The most telling line is Securonix’s promise to improve Sentinel detection quality “while keeping analysts in familiar workflows,” alongside new DPM licensing. (securonix.com) - The new capabilities are available through Securonix’s Unified Defense SIEM platform, with details in company materials and Black Hat announcements. (securonix.com)
Securonix used Black Hat USA 2026 this week to widen its pitch to security operations teams that are struggling with rising telemetry costs, uneven detection coverage and a new class of risk from enterprise AI agents. The company said it added expanded Threat Analytics for Microsoft Sentinel, a “detection gap” workflow, broader Data Pipeline Manager licensing and governed monitoring for AI agents such as Microsoft Copilot, GitHub Copilot and Gemini. (ciso.economictimes.indiatimes.com) The announcement matters because it bundles three operational problems that security teams usually handle separately: how much data to process in real time, how to improve detections inside Microsoft’s SIEM, and how to investigate AI-agent behavior without creating a separate workflow. (securonix.com) Securonix said the additions extend its Unified Defense SIEM platform. ### Why is Microsoft Sentinel part of this launch? Microsoft Sentinel is central to the update because Securonix is selling an added analytics layer rather than asking customers to replace their existing Microsoft environment. Securonix’s Sentinel materials say the product is designed to close detection blind spots, reduce alert noise and improve real-time detections without changing where analysts store data, investigate incidents or respond to threats. (ciso.economictimes.indiatimes.com) Enterprise Times reported that Securonix framed the Sentinel expansion around better detection quality and threat context for Microsoft users “while keeping analysts in familiar workflows.” That wording tracks with the company’s own product pages, which emphasize behavior-driven analytics, risk-based prioritization and lower engineering overhead for custom detection content. (ciso.economictimes.indiatimes.com) ### What is the “detection gap” workflow trying to fix? Securonix tied the “detection gap” message to a common SIEM problem: not every useful signal gets analyzed in real time, and many teams are forced to choose between coverage and cost. The company said its data-processing model is meant to help customers decide which telemetry should be analyzed immediately and which data can be retained in lower-cost storage. (securonix.com) The company also said expanded Data Pipeline Manager, or DPM, licensing and the now-shipping DPM agent are intended to give customers more control over “security data economics.” In practice, that means packaging cost management and detection engineering as part of the same buying decision, not as separate projects. (enterprisetimes.co.uk) ### What did Securonix add for AI agents? Securonix said its new Governed AI Agent Detection and Response capabilities are aimed at organizations using enterprise AI agents including Microsoft Copilot, GitHub Copilot and Gemini. The company described the feature set as a way to monitor agent activity and manage risks tied to enterprise AI adoption. (ciso.economictimes.indiatimes.com) ETCISO reported that Securonix said detection findings retain behavioral context, investigations remain explainable, response actions can be reviewed and audited, and human analysts keep oversight of consequential decisions. Those details show how the company is trying to make AI-agent activity look like analyst-ready evidence rather than an opaque model output. (ciso.economictimes.indiatimes.com) ### Where does this leave buyers comparing SIEM platforms? Black Hat USA 2026 gave Securonix a venue to present the update as a platform expansion rather than a point feature release. The company’s press materials and follow-on product pages point buyers to Sentinel analytics, DPM controls and governed AI-agent monitoring as part of the same Unified Defense SIEM package. (ciso.economictimes.indiatimes.com) Securonix’s next step is commercial execution around those modules. The company said the DPM agent is now shipping, and its Sentinel and AI-agent materials are already posted in product briefs and licensing documents published in August and June 2026. (securonix.com) (ciso.economictimes.indiatimes.com)