Vectra AI has launched Vectra AI Pro, a new offering designed to provide what the company calls “trusted signal intelligence” for security operations centers (SOCs) adopting AI-powered workflows.
Announced at Black Hat USA 2026, the platform continuously correlates network, identity, cloud, SaaS, SASE, and endpoint telemetry into a unified view of attacker behavior.
Behavioral intelligence as the key to AI defense
According to the company, its new solution aims to help SOC teams better detect and respond to AI-powered attacks.
Speaking with Channel Insider, Wojtasiak said Vectra AI Pro extends the company’s core mission since its 2013 founding: understanding attacker behavior across enterprise environments.
Wojtasiak argued that this approach is especially critical today, as AI has enabled adversaries to evolve and operate at a much faster pace, citing the recent Mythos and Hugging Face incidents as examples.
“The only true defense is behavioral,” Wojtasiak said. “You can’t write signatures fast enough, you can’t patch fast enough. The SOC has to work at the speed of the attack.”
Rather than focusing on isolated alerts, Vectra AI applies behavioral AI and machine learning to network and identity telemetry to understand how users, devices, workloads, and AI agents behave across an environment.
By correlating those behaviors into a broader attack story, the platform aims to provide what the company describes as trusted signal intelligence, giving AI systems and human analysts the context they need to make response decisions.
Wojtasiak said that approach has become more important as organizations contend with AI attacks capable of exploiting identities and moving through environments much faster than human defenders can manually investigate.
That behavioral foundation also underpins the practical capabilities Vectra AI Pro delivers inside the SOC.
Reducing SOC latency through agentic workflows
Built on that behavioral foundation, Vectra AI Pro’s trusted signal intelligence combines four aspects:
- Behavioral intelligence: Detects attacker behaviors across the attack lifecycle, including reconnaissance, credential abuse, privilege escalation, lateral movement, command-and-control, and data exfiltration.
- Identity and Device Intelligence: Attributes activity across users, AI agents, service accounts, workloads, hosts, devices, cloud resources and unmanaged systems while correlating network, identity, cloud, SASE and EDR telemetry into a unified attack story.
- Risk and Forensic Intelligence: Prioritizes the entities, behaviors, and attack paths that matter most while providing the contextual details AI agents need to understand what happened, who was involved, and why it matters.
- Exposure Validation: Enables AI agents to investigate, hunt, respond, report, and prove attack exposure is reduced, attack paths are removed, active attacks are mitigated, and controls are effective.
Asked what improvements organizations can expect from Vectra AI Pro, Wojtasiak said one of its biggest advantages is reducing latency throughout the SOC workflow.
“Signals are the biggest one. It’s like, how do you remove latency anywhere in the SOC analyst’s workflow?” Wojtasiak said.
He pointed to unified observability across on-premises, multicloud, SaaS, identity, OT, and IoT environments as one example.
Other use cases include discovering AI agents on the network, maintaining asset inventories, generating attack summaries, supporting AI-assisted threat hunting, and exposing trusted signal intelligence through REST APIs and Vectra AI’s MCP server for organizations building their own agentic SOCs.
Human trust as central to the agentic SOC
While Vectra AI envisions an AI-powered SOC workflow, Wojtasiak believes AI must still earn analysts’ trust before organizations become comfortable allowing agents to make higher-impact response decisions.
“You’ve got to earn that trust over time,” Wojtasiak said. “The human is the critical thinker. The human’s still the one that’s looking at the evidence and saying, ‘Okay, yes, this is something that we need to do.'”
Wojtasiak said organizations should not expect AI agents to take over SOC teams overnight, particularly when response actions could affect critical systems or business processes.
Instead, he sees AI’s near-term role as helping analysts by taking on repetitive work and surfacing the context needed to make faster, more informed decisions.
“Take all the mundane stuff off their hands, maximize their talent,” Wojtasiak said, adding that AI should free analysts to focus on higher-value work such as threat hunting and attack-path analysis while humans remain responsible for critical decisions.
How AI adversaries are changing the partner conversation
Turning to the channel and how the platform can potentially impact MSPs and MSSPs, Wojtasiak said Vectra AI Pro is designed to help CISOs and technology leaders tackle the challenge of defending against AI-powered attacks.
“A lot of the big question a lot of CISOs have is, ‘What should I be doing?’” Wojtasiak said. “And the answer is, you should be thinking about how you’re redefining your security operations. And you’re redefining it and reimagining it for resilience.”
Wojtasiak said that shift allows channel partners to act as strategic advisors, helping customers reimagine their security operations for resilience.
He added that streamlining detection, investigation, and response could allow MSPs, MSSPs, and solution providers to expand beyond traditional MDR services by offering more proactive defense and resilience-focused services.
What successful SOCs will do differently in the AI era
As the conversation turned to the future of security operations, Wojtasiak pointed to one quality he believes will distinguish successful organizations from those that struggle.
“In a word, it’s probably resilience. I think the good SOC teams and the organizations that have established a forward-looking strategy today for resilience and put the right AI in place – not only defining what resilience means to them, because it means different things to different companies – are the ones that are going to be successful,” Wojtasiak said.
He said organizations should continuously measure and improve their resilience as AI-driven attacks become more widespread and increase in volume and variety. That, he said, will require shifting from a detection-and-response mindset to a proactive resilience mindset.
“I don’t think it’s a three-to-five-year plan. I think they need to start now,” Wojtasiak added.
Another Black Hat USA 2026 announcement came from Arctic Wolf, which introduced a new partner accelerator program, cyber resilience offering, and AI-powered Agentic SOC. Read more about what the updates mean for MSPs and MSSPs.





