SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Securonix expands SIEM with Sentinel & AI risk tools

Securonix expands SIEM with Sentinel & AI risk tools

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Securonix has expanded its Unified Defence SIEM platform with new data management, Microsoft Sentinel analytics and AI agent risk monitoring products aimed at enterprises and managed security providers.

The updates include broader licensing for its Data Pipeline Manager, the release of a DPM agent, wider Threat Analytics support for Microsoft Sentinel and new Governed AI Agent Detection and Response functions. Together, they address three issues security teams face: rising telemetry costs, threats that move across multiple environments and the spread of AI tools that can act inside business systems.

Security operations teams are under pressure to maintain visibility across identity, cloud, endpoint, application and third-party systems while limiting spending and avoiding extra operational burden. Securonix is positioning the changes as a way to manage data volumes, improve detection within existing customer environments and track activity from AI systems that can access sensitive applications and information.

"Security operations cannot scale by continually adding more data, more tools, and more analyst effort," said Toby Weiss, Chief Executive Officer, Securonix. "We are giving customers better control over the data they retain, stronger detection across the platforms they already use, and clear oversight of automated activity. That gives the SOC room to grow without losing control of cost, context, or risk."

Sentinel focus

A central part of the announcement is the expansion of Threat Analytics for Microsoft Sentinel. The product adds an analytics and enrichment layer on top of Microsoft's platform rather than replacing it, with detections returned to Sentinel for investigation and response within existing workflows.

The service applies behavioural analytics, user and entity behaviour analytics, correlation, entity context and risk scoring to telemetry already available in Sentinel. It also includes detection content maintained by Securonix Threat Labs. Customers can gain broader detection coverage and more context without deploying extra endpoint agents, duplicating data, building new data pipelines or operating a second SIEM.

According to Securonix, the expanded offering includes more than 2,400 detections designed to identify identity attacks, insider threats, ransomware, cloud compromise and advanced persistent threats. The company also sees an opportunity among managed security service providers and managed detection and response firms, which often need to standardise investigations across several customer environments while reducing false positives.

Simon Hunt outlined the approach for Microsoft customers.

"Sentinel customers have already made their platform choice," said Hunt. "We are adding depth where it counts: behavioral context, cross-source correlation, and risk-based prioritization. Analysts stay in Sentinel, while the detections reaching them carry more evidence and a clearer reason to act."

AI oversight

Securonix also introduced Governed AI Agent Detection and Response, designed to identify unusual or risky behaviour involving AI assistants, autonomous workflows and digital workers. The move reflects growing concern among security teams that AI tools are no longer limited to chat interfaces and can now reach mailboxes, software interfaces, internal tools and business processes.

The new functions track behaviour across both human and non-human identities. They are intended to detect abnormal agent activity, suspicious human-to-agent interactions, risky tool use, unusual prompt behaviour, unauthorised AI adoption and signs of misuse, compromise or policy breaches.

The monitoring is designed for supported enterprise AI environments including Anthropic Claude, Google Gemini, Microsoft Copilot and GitHub Copilot. Securonix said findings retain behavioural context, investigations remain explainable, response actions can be reviewed and audited, and human analysts stay responsible for major decisions.

"The moment an AI agent can access a mailbox, call an API, or change a business process, its behavior belongs in the security picture," said Hunt. "Analysts need to know what it touched, why it acted, and whether that activity fits policy. We are bringing that context into the same investigation and response process teams use every day."

Data costs

The third part of the update focuses on security data economics. Securonix has expanded Data Pipeline Manager licensing across eligible SIEM environments and started shipping the Securonix DPM agent, giving customers more control over how telemetry is collected, routed, retained and analysed.

Many organisations struggle to balance the cost of storing and processing large volumes of security data with the need to preserve it for investigations, compliance and threat hunting. Securonix said its approach allows high-priority data to be used for live analytics and detection, while other telemetry can be directed to lower-cost routes for later access.

The company said this can reduce SIEM data costs by 30% to 50% by ensuring only security-relevant data moves through the analytics pipeline, while investigation and compliance data are routed through less expensive pipelines. It argued that this could let enterprises and service providers expand coverage without discarding information that may later prove important in an incident review.

Alongside the product announcements, Securonix said it had been named a Leader in the 2026 QKS SPARK Matrix for Insider Risk Management, linking the recognition to the same behavioural analytics foundation used across its insider risk, Microsoft Sentinel and AI agent monitoring products.