What shipped, and when
Stellar Cyber announced 7.0 on October 5 as a release meant to turn its Human-Augmented Autonomous SOC idea into a practical operating model. The announcement targets MSSPs and lean enterprise security teams.
The dates are messy, so keep them separate:
- The announcement came on October 5.
- Stellar Cyber's 7.0.0 release notes list a software release date of September 15, 2026, with notes updated September 29.
- A "7.0.0s" variant of the notes lists a software release date of August 25, 2026.
- The press release says 7.0.0s is scheduled for software release on October 5, 2026.
I can't tell from these sources how the "s" build relates to the standard build. If you manage an upgrade, confirm the exact build and date with your Stellar Cyber representative.
Queue-level AI: the main change
The central idea is that autonomy is chosen per case queue. The Case Summary setting enables AI-generated summaries and analysis for cases in a queue. The Auto-Triage setting enables the triage agent for cases matching the queue's conditions. Default queues, previously not editable, can now be edited for these settings. A new default AI Analyst queue for critical cases is created with both enabled.
Auto-Triage gives each alert one of four verdicts: True Positive, Benign True Positive, False Positive, or Inconclusive. It does this with structured checks the vendor calls Verdict Signal Checks. Stellar Cyber's documentation says these checks draw on endpoint and identity sources, including Microsoft Defender and Entra ID, plus network and file-reputation data. Each connected integration deepens the evidence available.
Analysts can confirm or override verdicts only at the alert level. They can't directly override the case verdict. When alert verdicts change, the platform reevaluates the case verdict.
Case Summary is a different thing. It is a narrative built from evidence already in the case. Auto-Triage investigates alerts and enriches the case. Case Summary is available to all customers. Auto-Triage is not.
Licensing, capacity and availability
These limits matter most before an MSSP scales the feature across tenants:
- License: SaaS Auto-Triage needs an add-on license. A seven-day trial is offered.
- On-premises: Auto-Triage is in the Early Access Program. It also needs outbound connectivity to Stellar Cyber's cloud AI service. AI features are not available in air-gapped environments.
- Daily capacity: The platform supports up to 560 automatic case analyses per day. Automatic and manual analyses combined cannot exceed 600. Manual analyses are guaranteed at least 40 per day. Counts reset at 00:00 UTC.
- Default trigger: The default AI Analysis Queue analyzes cases scoring 75 or higher, or marked Critical.
- Reanalysis: A case is reanalyzed automatically when its score moves 10 or more points from the score at the last analysis.
- VirusTotal: Triage uses VirusTotal as one intelligence source. You must install a VirusTotal API key to enable that integration.
The 600-per-day figure is shared across the organization's tenants. For an MSSP, one noisy customer can use up the pool. Channel Insider makes the same point and recommends setting an allocation policy. That is sensible advice, but the documentation doesn't describe a per-tenant reservation mechanism.
Data handling: vendor claims, not audit findings
Stellar Cyber says raw telemetry stays inside the on-premises deployment. The deployment prepares minimized context locally and sends it over encrypted TLS to Stellar Cyber's cloud AI services. It does not talk directly to the external LLM. The documentation says:
- Each LLM request is stateless.
- Submitted data is not retained or used for training.
- Tenant requests are isolated.
- AI processing happens in the United States by default.
- EU deployments in the Early Access Program use a Frankfurt endpoint.
- Where data is stored does not necessarily determine where AI processing occurs.
These are vendor-described terms. No independent audit is cited. An MSSP serving regulated customers should check them against contract language and residency rules.
Case Metrics: measuring workflow, not proving AI works
Case Metrics are configurable timers that start, pause and stop on conditions you define. Examples are creation to analyst acknowledgment and creation to resolution. They appear as case queue columns and on the Case Detail page.
Stellar Cyber's marketing frames this as answering whether automation is reducing investigation time. The metric measures elapsed workflow time. It doesn't show that AI caused any improvement. To make that case, an MSSP needs a baseline from before enabling Auto-Triage and a comparison afterward.
Multi-tenant automation APIs
System Action Center API. Actions can now be created programmatically across eight trigger categories:
- Case Management
- Cluster Health
- Data Storage Capacity
- Disk Capacity
- NFS Data Sink Capacity
- Scheduled Report Monitoring
- User Modifications
- License Usage
Triggers include case activity, cluster health turning red, and capacity thresholds. They also include report failures, account lockouts, privilege escalation, and drops in licensed asset count.
Sensor installation tokens (SaaS only). POST /connect/api/v1/data_sensors/installation_tokens takes cust_id, sifter_policy_id and expire_days. It returns an OS-agnostic token for device sensors and for Windows or Linux Server Sensors. It requires the /token_management privilege.
Remote uninstall. POST /connect/api/v1/data_sensors/{sensor_id}/uninstall works only for connected Windows and Linux Server Sensors. It is asynchronous. The request is accepted first, and the sensor record disappears only after the sensor confirms a successful uninstall. Deleting a record for any other sensor type removes only the platform record. The software stays on the host.
Parser Studio. Changes include:
- Bulk enable and disable of modular parsers.
- A rolling 7-day ingestion column with a threshold filter.
- A Disable Inactive Parsers workflow.
- Cross-tenant download and upload of parser configurations, for modular parsers only.
The 7-day figure is a periodically refreshed per-tenant snapshot. It isn't shown in the All-Tenants view. A confirmation warns you if selected parsers are still ingesting data.
Microsoft and Fortinet hooks
For Microsoft shops, the notable additions are:
- Defender for Endpoint actions in Threat Hunting and Action History: Collect Investigation Package, Restrict App Execution, Stop and Quarantine File, and Run Antivirus Scan. They need Defender machine identifiers in the alert or host record. Stop and Quarantine File also needs a SHA-1 evidence field. These run through a configured Defender connector. They add a control path and don't replace Defender's own controls.
- New detections: a Microsoft 365/Entra ID sign-in from a never-before-seen ASN, with configurable lookback and training periods. There is also a Possible Pass-the-Ticket alert. It fires when a Kerberos service ticket request comes from an IP that never obtained a ticket-granting ticket for that account.
- FortiGate: domain and URL blocking and unblocking, alongside existing IP blocking. Block URL needs a Web Filter applied to a firewall policy.
- Parsers: a built-in parser for Claude Code OpenTelemetry telemetry, which gives SOC teams a view of AI coding-assistant activity.
Upgrade checklist
The release notes include several warnings:
- Path: Upgrade directly to 7.0.0 from platform 6.5.0 or later. Earlier versions must reach 6.5.0 first.
- Sensors: Linux Server Sensors can upgrade directly from 6.5.x or 6.6.x. Windows Server Sensors can upgrade from 6.4.x and later.
- RBAC on sensor endpoints: Public
/data_sensorsendpoints now enforce role-based access. Previously any authenticated API user could reach them. API users without the matching privilege get a 403 where calls used to succeed. Enforcement on the pre-existing endpoints can be disabled for an organization as a transition measure. The check on the new uninstall endpoint is always enforced. - Error field rename: API errors now return
request_idinstead ofrequestId. Scripts that parse the old name may break or lose log correlation. - Tenant group logos: The
tgrp_logofield is gone from list responses. Fetch logos through/tenant_group/{id}/logo. - Resources: CPU and memory use may rise depending on workload.
- Air-gapped sites: Some included Early Access components can't be enabled after installation without connectivity to required external URLs. Check this before upgrading.
Analysis: sensible controls, unproven outcomes
The queue-level design is the right instinct. Letting an administrator decide where AI triage applies is more defensible than a global switch. Stellar Cyber's own advice is to start with critical and high-severity alerts and review the results for a while before expanding. That fits Channel Insider's recommendation to compare AI verdicts with analysts' final dispositions.
Three caveats apply:
- Sources. The main feature claims come from the vendor's own documentation and press materials. The trade coverage I found largely restates them. I found no independent accuracy testing of the triage verdicts.
- Scaling. A shared daily pool of 600 analyses is a real constraint for large multi-tenant providers.
- Hidden work. The API and RBAC changes can create migration work before they save any. Teams that script against sensor endpoints should audit API-user privileges first.
For Microsoft-centric SOCs, the Defender actions and the Entra ID and Kerberos detections are the most immediately relevant additions. The value of the AI triage depends on how many integrations you've connected and how closely your analysts review verdicts.
References
- Stellar Cyber 7.0 Adds AI Triage and MSSP Automation - Channel Insider Channel Insider · 2026-10-07T20:00:40+00:00
- Stellar Cyber 7.0 adds measurable workflows for AI-powered SOCs - Help Net Security helpnetsecurity.com
- Stellar Cyber 7.0.0s Release Notes docs.stellarcyber.ai