ExtraHop® Launches the Agentic SOC Alliance to Validate a Shared Operating Model for Machine-Speed Defense
Alliance members will validate architectural requirements for the AI SOC across Context, Harness, and Model, anchored by discoverable, semantically rich context every agent can query and reason on, so enterprises can adopt autonomous, machine-speed defence.

The security operations centre is being rebuilt around a new operating model, one designed for machine-speed threats rather than human-speed workflows. Today, ExtraHop®, the leader in real-time network intelligence and modern network detection and response (NDR), launched the Agentic SOC Alliance initiative to define and standardise this new SOC operating model: a three-layer architecture of Context, Harness, and Model that gives autonomous security agents the evidence, governance, and reasoning they need to act with precision.
The queue-enrich-triage-investigate-escalate pipeline that has run every SOC for two decades was built for a threat that moved at human speed. Post-frontier-AI adversaries now find a vulnerability, weaponise it, and move laterally in minutes. That pipeline cannot be optimised fast enough to close the gap. It has to be replaced by an operating model built for autonomy from the ground up, with rich, discoverable context as its foundation.
“Post-Mythos AI has fundamentally changed cyber defence. Adversaries now operate at machine speed, yet most security operations are still built on architectures designed for a human-paced world,” said Greg Clark, CEO at ExtraHop. “The industry needs a blueprint for how autonomous security should operate that combines real-time context, intelligent orchestration, and specialised AI agents into a new operating model. The Agentic SOC Alliance is bringing that blueprint together, giving organisations a foundation to detect, decide, and respond with the speed and accuracy that modern threats demand. This is a starting point, not a finished one. We invite the rest of the industry to join the Alliance and help us refine, validate, and perfect this operating model, because outpacing a machine-speed adversary is a challenge no single company can solve alone.”
Founded by AuthMind, Armadin, Command Zero, CrowdStrike, Dropzone AI, Exaforce, ExtraHop, Fig, Intezer, Kindo, LangChain, Prophet Security, ReversingLabs, TENEX.AI, and Torq, this diverse coalition spans network detection, endpoint, AI-native SOC platforms, orchestration, and agent frameworks, and reflects the reality that autonomous defence cannot be delivered by any single vendor. The Agentic SOC Alliance establishes the requirements, best practices, and implementation blueprints for a SOC built for autonomy from the ground up.
Machine-Speed Attackers Demand Machine-Speed Defenders
As Mythos-class frontier models reshape the threat landscape, adversaries now automate reconnaissance, exploit development, and lateral movement at machine speed. Security teams are racing to deploy autonomous defences of their own, but most of these AI systems flood analysts with false positives, send investigations down the wrong path, and let real threats slip through the noise.
The Agentic SOC Alliance closes that gap by uniting three foundational layers into a single post-Mythos architecture designed so autonomous agents can act with precision and be trusted to do it. Two of those layers, Context and the Harness, are durable. The third, the Model, is interchangeable by design.
Context
Not a collection of telemetry sources, but a continuously updated, highly structured representation of enterprise reality that AI reasons over directly.
Context should provide an operational knowledge graph of every device, identity, workload, connection, and behaviour, discoverable and semantically detailed enough that an agent can find exactly what it needs and understand what it means. Assembled in real time, it includes insight from network, endpoint, identity, and threat intelligence. Because agents reason over this structured representation rather than raw logs, they reach more defensible conclusions while consuming far less inference. This results in lower reasoning complexity, fewer tokens, less time and cost spent inspecting raw data, and faster answers. Fragmented logs force a model to reconstruct meaning on every turn. A structured, discoverable knowledge graph hands it the answer already assembled. This is the layer the rest of the architecture depends on. No model is good enough to reason its way out of missing evidence.
Harness
The AI runtime and orchestration layer that governs how agents actually operate, executing workflows, calling tools, managing state and memory, and coordinating agents across the environment, with governance, guardrails, permissions, human approval routing, and a complete audit trail as core responsibilities running throughout.
This is where autonomous work actually runs, and where it stays controllable. Because the Harness layer holds the orchestration and the guardrails, a model can be swapped without re-earning trust from a standing start.
Model
The interchangeable reasoning layer, where specialised, multi-model AI performs triage, investigation, and response.
Context and Harness are the durable layers the architecture is built on; the Model is not. Customers can adopt each new generation of models, or run several at once, without re-architecting anything around them. The Model is a component you upgrade, never a foundation you are locked into.
“Cybersecurity has reached the point where human-speed defence is no longer sufficient against machine-speed attacks. The Agentic SOC Alliance represents one of the industry’s first serious efforts to define an open operational architecture for autonomous security operations, bringing together trusted context, governed AI, and coordinated response so enterprises can finally begin defending at the speed of their adversaries. I am excited to see the development,” said Dr Edward G. Amoroso, CEO at TAG Infosphere and Research Professor, NYU.
By aligning the Context, Harness, and Model layers across a shared ecosystem, the Agentic SOC Alliance helps joint customers modernise the SOC around a more accurate and governable autonomous operating model.
Trustworthy Context: The Foundation the Rest of the Architecture Reasons On
The primary barrier to agentic SOC accuracy is the AI context gap. Fed fragmented logs, autonomous agents lack the evidence to reach defensible conclusions, and they burn tokens and time reconstructing meaning the data should have carried in the first place. Structuring that evidence as a continuously updated operational knowledge graph, discoverable and semantically detailed rather than raw, closes both gaps at once; network, endpoint, and identity signals become continuously findable and understandable in place, so agents reason over answers rather than reconstructing them from raw material.
Within this ecosystem, ExtraHop delivers the high-fidelity, real-time operational knowledge graph, enriched with identity and endpoint data, that autonomous agents need. Its decrypted, protocol-level visibility closes the gaps that cause AI models to falter. Because that context arrives already structured, discoverable, and richly detailed rather than raw and fragmented, agents reach conclusions with lower reasoning complexity, fewer tokens, and less time and cost spent inspecting raw data, which makes autonomous detection, investigation, and response not just more accurate but more affordable at enterprise scale.



