The AI-based “Attack Signal Intelligence” component provides SOC teams with a holistic view of their cybersecurity posture and any ongoing attacks on networks, identities, clouds and GenAI tools
Vectra AI, Inc., leader in the artificial intelligence-based XDR (extended detection and response) sector, announces the expansion of its Vectra AI Platform to provide Security Operations Center (SOC) teams with a dynamic posture to proactively detect and locate where the hybrid environment is exposed to attackers. With this expansion, the patented component “Attack Signal Intelligence™” of the Vectra AI Platform offers a holistic view with analytics to identify, prevent, detect and block cyber attacks.
To stay ahead of attackers, it is critical that SOC teams know where the organization is vulnerable to intrusions, propagation activities, and lateral movement of hackers across the hybrid environment. The inability to keep a dynamic and constantly evolving attack surface under control allows cyber criminals to carry out their campaigns while remaining invisible and therefore unstoppable.
“In the evolving attack environment, at Vectra AI we are constantly innovating to stay one step ahead of attackers,” said Hitesh Sheth, founder and CEO of Vectra AI. "As a leader in AI-powered accurate attacks quickly and at scale."
With Vectra AI's proactive “Attack Signal Intelligence” defense, SOC teams receive a complete view of their network, identity, cloud and GenAI active posture. Active posture in the hybrid environment gives SOC teams a real-time view of how the attack surface they are tasked with defending is changing, something that other tools that rely on static information cannot offer. Armed with the active posture component “Attack Signal Intelligence,” companies can proactively discover security gaps related to what users and devices are actually doing. This is thanks to the monitoring of over 20 different AI-enhanced data streams and hundreds of different attributes that allow teams to stop a potential threat. This solution finds gaps that other tools fail to catch, such as:
- Identity hygiene issues such as account logins without two-factor authentication, use of legacy login protocols, weak location-based access controls, and overly permissive access to tools such as the backend Microsoft Graph API and PowerShell. On average in a week, 99% of organizations have more than one user accessing Azure AD via Powershell or some scripting engine, any of which can be exploited by an attacker and breached;
- Network location with visibility into related risks such as external RDP access, IPMI usage, weak or unencrypted data transfers, and SMB1 usage. More than a third of businesses still have SMBv1 enabled, putting them at risk of ransomware and other vulnerabilities from hackers;
- Clear insight into Copilot for M365 usage across your organization allows teams to understand adoption and usage, enabling better governance over data access controls and permissions, including potential abuse by attackers. Vectra AI notes that more than 40% of its customers have started adopting Copilot for M365 in their environment.
“Vectra AI’s “Customers already using the Vectra AI Platform can now effectively discover, inhibit, detect and stop hybrid attackers, proactively addressing the entire cycle of a potential breach, and using these capabilities for free.”
This further expansion of the Vectra AI platform follows the one announced in Maggio 2024 which introduced features to detect attacker misuse of GenAI tools such as Microsoft Copilot for M365.






