Product1 publisher3 min readPublished
Exabeam's Nova agent now runs its own follow-up searches during security incidents
Exabeam's Nova AI agent now gathers context and entity profiles and runs its own secondary searches while an incident unfolds. Teams rolling it out should judge it by how often analysts overturn its findings and how quickly cases reach a triage decision.
The Product Desk · Product desk

What happened
- Related Cases, in early access since July, automatically groups connected incidents so analysts see the wider picture sooner.
- Prompts, tool calls and actions from Claude Enterprise deployments now land on one timeline that Exabeam analyzes for rogue agents and behavioral drift.
- On-premises LogRhythm gains collectors for ChatGPT, Gemini and Copilot activity and an MCP server that works with local AI models.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Buyers have to decide whether they are adopting a queue-sorter or an investigator, and the only customer testimony so far supports the queue-sorter.
- cost Analyst time moves from running searches to checking them; if Nova's secondary searches are not visible in the case, checking costs as much as doing.
- exposure Claude Enterprise agents become something the SOC investigates, with their prompts and tool calls kept as searchable evidence of drift.
- capability On-premises teams can run AI-assisted triage over sensitive logs without sending that data to an outside model, provided they run models locally.
The opening work on an incident is mostly fetching. Someone pulls the entity profiles, collects the surrounding context, then runs the follow-up search the first result suggested. Nova now does that part itself, while the incident is still unfolding, across the whole New-Scale platform [2]. Exabeam first introduced the agent in April 2025 [3].
Exabeam's pitch moves the analyst up a level. The company calls the destination the agentic security operations center, where agents take on much of the investigative legwork under an analyst's supervision [4]. Steve Wilson, its chief AI and product officer, said the future SOC will be defined "by how effectively people and AI agents work together" [5]. Teams that buy on that story picture an analyst reviewing finished investigations.
Here's what the one customer quoted in the launch coverage says users actually do. Eduardo Sulvarán Velázquez, subdirector of cyber risk management at Mexican payment processor E-Global, said the agent has helped analysts there prioritize cases [7]. AI can speed up investigations "without removing human judgment from the process," he said [8]. Prioritizing is sorting a queue. A case the agent ranks too low still sits in the queue for a person to open. The launch coverage does not include a price or any measured change in triage time [1].
Supervising an agent requires a record of what it did. For Claude Enterprise deployments, prompts, tool calls and actions now land on a single timeline. Exabeam runs event-time analysis and behavior-based correlation over that record to catch rogue agents and behavioral drift [9]. Praxen, the verification tool Exabeam open-sourced in June, now ties each finding and score more directly to its source material [11]. For Nova itself, the question to put to a demo is whether every secondary search shows up in the case with its query and its results.
The two product lines get different things. New-Scale cloud customers get an agent that investigates [1] [2]. LogRhythm's on-premises customers mostly get a view of their own staff's AI use. Collectors feed ChatGPT, Gemini and Copilot activity into LogRhythm Intelligence Analytics, and a community MCP server lets teams query that data with local models so sensitive data stays inside their environment [12].
For a Monday rollout, sort each agent task on two lines. The first is whether its output reorders the queue or closes a case. The second is whether it arrives with the evidence it used, in a form an analyst can check faster than redoing the search.
An agent that sorts the queue and shows its evidence is safe to switch on; track how often analysts re-rank its picks. E-Global's account sits in the sorting row [7]. Sorting without evidence is tolerable, because a mis-ranked case still gets opened, and the thing to track is low-ranked cases that turned out serious. Closing cases with evidence attached is the supervised model Exabeam describes [4], and there the figure to watch is the override rate. When the agent closes cases without showing its evidence, the analyst is approving work they cannot check, and that task should stay off.
A count of Nova searches per case measures how busy the agent is. To see value, track time from alert to a triage decision and the rate at which analysts reverse the agent.
What to watch
- Whether Exabeam or a customer publishes data on Nova's effect on time to triage or on how often analysts override it.
- Whether Nova's secondary searches get the evidence-committed scoring Praxen now uses, tying each finding to its source material.
- Whether Related Cases leaves early access, and what Exabeam charges for Nova's expanded role.