In summary
- Securonix has expanded Threat Analytics for Microsoft Sentinel, adding more than 2,400 out-of-the-box detections covering identity attacks, insider threats, ransomware, cloud compromise and advanced persistent threats.
- New Governed AI Agent Detection and Response capabilities monitor AI assistants and non-human identities, flagging abnormal activity while letting human analysts retain oversight.
- Broader Data Pipeline Manager licensing routes telemetry by operational value and can reportedly cut SIEM data costs by 30% to 50%.
Securonix has announced three sets of additions to its Unified Defense SIEM platform: expanded threat analytics for Microsoft Sentinel, new governed AI agent detection and response capabilities, and broader Data Pipeline Manager licensing aimed at reducing security data costs for enterprises and managed security providers.
The announcements are directed at security operations teams facing rising telemetry volumes, threats spanning identity, cloud, endpoint and application environments, and growing risks from enterprise AI adoption.
Securonix has expanded Threat Analytics for Microsoft Sentinel, described as a cloud-native analytics layer that applies behavioural analytics, user and entity behaviour analytics (UEBA), cross-source correlation and risk scoring to telemetry already held in Sentinel.
Enriched detections are returned to Sentinel for triage and response, allowing analysts to remain in existing workflows without deploying additional agents or operating a second SIEM.
The company said the offering includes more than 2,400 out-of-the-box detections covering identity attacks, insider threats, ransomware, cloud compromise and advanced persistent threats.
For MSSPs and MDR providers, Securonix said the layer creates a path to differentiated managed detection services across multi-tenant environments, with faster onboarding and streamlined content management across multiple customers.
"We are adding depth where it counts: behavioural context, cross-source correlation, and risk-based prioritisation," said Simon Hunt, chief product officer at Securonix.
"Analysts stay in Sentinel, while the detections reaching them carry more evidence and a clearer reason to act.”
The new Governed AI Agent Detection and Response capabilities are designed to monitor activity by enterprise AI assistants, autonomous workflows and digital workers - what the industry terms non-human identities.
Securonix said the capabilities apply behavioural analytics across human and non-human identities to flag abnormal agent activity, suspicious human-to-agent interactions, risky tool invocation and potential policy violations.
Coverage includes Microsoft Copilot and other widely used AI assistants and developer tools, according to the company. Response actions can be reviewed and audited, and human analysts retain oversight of consequential decisions.
"The moment an AI agent can access a mailbox, call an API, or change a business process, its behaviour belongs in the security picture," Hunt said.
“Analysts need to know what it touched, why it acted, and whether that activity fits policy. We are bringing that context into the same investigation and response process teams use every day.”
Securonix has also expanded Data Pipeline Manager (DPM) licensing across eligible SIEM environments and begun shipping the Securonix DPM agent.
The company said the tools let enterprises route telemetry according to its operational value - high-priority data through real-time analytics pipelines, and lower-priority telemetry through cost-efficient pipelines for investigation, compliance and retrieval.
Securonix claimed Data Pipeline Manager can help organisations reduce SIEM data costs by 30% to 50% by ensuring only security-relevant data is processed through the analytics pipeline.
"Security operations cannot scale by continually adding more data, more tools, and more analyst effort," said Toby Weiss, chief executive of Securonix.
"We are giving customers better control over the data they retain, stronger detection across the platforms they already use, and clear oversight of automated activity."




