Securonix says it has expanded its Unified Defense SIEM portfolio with governed detection and response for enterprise AI agents, broader Data Pipeline Manager licensing and a newly shipping DPM agent, plus Threat Analytics that enriches detections inside Microsoft Sentinel. For Microsoft-heavy security operations teams, the practical promise is familiar but significant: retain Sentinel as the analyst console while adding Securonix behavioral analytics and data-routing controls around it. The announcement, published by ET CIO on August 5 and timed to Black Hat USA 2026 in Las Vegas, bundles three distinct products under one operational argument: organizations need to watch AI systems that act on behalf of users, reduce the cost of security telemetry without losing it, and improve signal quality without forcing a SIEM replacement. Securonix’s own Black Hat event page confirms it is exhibiting on August 5–6 and promoting its agentic-AI security operations strategy, although the company’s public newsroom did not yet list this specific launch at publication.
What Securonix has not published alongside the announcement is almost as important as what it has. There are no public prices, no list of “eligible SIEM environments” for expanded DPM licensing, no supported-log-source matrix for the Sentinel analytics offering, and no technical deployment guide for the newly shipping DPM agent. That leaves customers with an announcement-level description rather than enough detail to determine whether the products reduce a current bill, add another bill, or require changes to their log-routing architecture.

Analyst monitors a futuristic cybersecurity dashboard with global maps, alerts, networks, and data visualizations.The Sentinel pitch adds analytics, but Microsoft already supplies UEBA​

Securonix’s Threat Analytics for Microsoft Sentinel is positioned as an enrichment layer rather than a replacement SIEM. According to the company, it applies user and entity behavior analytics, cross-source correlation, entity context, dynamic risk scoring and its Threat Labs detection content to telemetry already in Sentinel, then sends higher-confidence findings back to Sentinel for triage and response.
The distinction is commercially useful: a customer can buy Securonix’s detection content and behavioral analytics without moving incident workflows, automation, data connectors or analyst training away from Microsoft Sentinel. For MSSPs and MDR providers, that could also mean using Securonix logic across multiple Sentinel tenants while continuing to present Sentinel as the customer-facing SOC platform.
But the claim needs to be read against what Microsoft already includes. Microsoft Sentinel has native UEBA capabilities that build behavior profiles for users, hosts, IP addresses and applications from connected data sources. Microsoft says that feature can identify anomalous activity using machine learning, with UEBA enrichments stored in Sentinel’s own Log Analytics tables. Microsoft also provides an optional UEBA Essentials solution with prebuilt hunting queries and has been moving Sentinel’s operational center toward the Microsoft Defender portal.
In other words, Securonix is not bringing behavioral analytics to a Sentinel environment that otherwise lacks it. It is offering a second analytics layer intended to provide more detection logic, broader correlation and potentially a different risk model. Whether that produces meaningfully better alerts than Sentinel’s native UEBA will depend on which sources are connected, how Securonix normalizes the data, what rules are included, and how much duplicated telemetry or storage the integration creates.
Securonix says its offering has more than 2,400 continuously maintained detections backed by its Threat Labs team. That is a content-volume claim, not a measure of coverage or accuracy. The company has not publicly identified how many of those detections are available specifically to Sentinel customers, which data connectors they require, which are enabled by default, or what false-positive performance customers should expect.
There is also a naming problem administrators should clarify before buying. Microsoft already calls its own in-product threat-intelligence experience “Threat analytics,” currently available to Sentinel customers through the Defender portal in preview. Microsoft’s product tracks threat actors, campaigns, vulnerabilities and attack techniques; Securonix’s similarly named offering is described as behavioral detection and enrichment. They are different tools with overlapping terminology, and teams should make sure procurement, engineering and incident-response staff are discussing the same product.

AI-agent oversight is a detection layer, not proof of control​

The newest part of the package is Governed AI Agent Detection and Response. Securonix says it can identify abnormal or risky activity across human and non-human identities, including suspicious human-to-agent interactions, unusual prompt behavior, risky tool invocation, unauthorized AI adoption and possible compromise or policy violations.
The target environments named in the announcement are Anthropic Claude, Google Gemini, Microsoft Copilot and GitHub Copilot. Securonix says findings retain behavioral context, investigations are explainable, actions are auditable and human analysts retain oversight of consequential decisions.
That is the right operational direction, but the wording leaves critical implementation questions unanswered. Observing an agent that “accesses a mailbox, calls an API, or changes a business process” requires usable audit events from the AI platform, identity system, application and often the API gateway or workflow engine. A SIEM can correlate those events only if they are generated, retained, normalized and connected to an identifiable agent or service principal.
The announcement does not state whether Securonix ingests native audit logs from each named AI platform, relies on intermediary SaaS-security or identity logs, requires a browser or endpoint control, or supports tool-call and prompt telemetry at all. “Unusual prompt behavior” is especially difficult to assess from ordinary authentication and API logs; prompt-level detection would need access to content or structured metadata, which raises privacy, retention and regulatory questions of its own.
For Windows and Microsoft 365 administrators, the immediate concern is scope. Microsoft Copilot activity can span Entra ID, Microsoft 365 audit records, SharePoint and OneDrive permissions, Exchange mailboxes, Power Platform workflows and external connectors. Detecting that an agent did something unusual is useful. Determining whether it was authorized, whether the agent inherited excessive permissions, and whether the action can be reversed is the control problem security teams still need to solve through identity governance, data classification, conditional access and approval workflows.
Securonix’s product could help identify the resulting anomalies, particularly when agent behavior is correlated with a user account, endpoint or cloud identity. It does not eliminate the need to configure those controls before deploying AI agents. The company’s own emphasis on human review is an implicit acknowledgement that response automation involving AI-operated business processes can carry material operational risk.

DPM licensing shifts the economics, but customers need the meter​

The DPM portion of the launch may prove more immediately relevant to organizations staring at SIEM ingestion bills. Securonix says customers can send high-priority telemetry through its Analytics Pipeline for real-time detection while retaining other records in lower-cost Investigation or Basic Logs pipelines for hunting, compliance and later retrieval.
The company has promoted this model before through DPM Flex. Its prior datasheet describes a single ingestion entitlement divided among three tiers: Analytics at a one-to-one consumption ratio, Investigation at one-to-two, and Basic Logs at one-to-four. Securonix has previously framed that as 30–70% greater effective data capacity for the same committed spend. The new announcement instead says DPM can reduce SIEM data costs by 30–50% by processing only security-relevant records through the Analytics Pipeline.
Those are vendor estimates based on different measures: additional effective capacity in the existing DPM Flex material, versus a potential reduction in SIEM data costs in the Black Hat announcement. They should not be treated as a guaranteed savings range. A customer’s result will turn on the volume and type of telemetry moved out of the analytics tier, the retention period, the cost of the secondary pipeline, and whether incident response later requires rehydrating or searching that retained data.
The operational trade-off is sharper than the launch language suggests. Routing a log stream to cheap retention preserves it for compliance and post-incident use, but it may remove that stream from real-time correlation and behavioral baselining. If the records that establish an identity’s normal behavior are retained but not analyzed, an anomaly model can become less complete precisely when an attacker moves between systems.
That does not make tiered data routing a bad idea. It means a DPM project should begin with detection engineering rather than finance. Teams should identify which sources underpin active analytic rules, which fields feed identity and entity baselines, which data is required for legal retention, and how quickly lower-tier records can be queried during an incident. Only then can they decide what is genuinely low-value telemetry.
The “now-shipping Securonix DPM agent” needs similar scrutiny. Securonix’s March materials already described a Data Pipeline Agent within its agentic-AI lineup, but the Black Hat announcement does not explain whether the DPM agent is that capability, a new collector, a routing component, or a separately licensed deployment artifact. The distinction affects endpoint footprint, network paths, privileged access and operational ownership.

The missing deployment details are the decision point​

Securonix’s announcement is strongest as a statement of product direction: extend security analytics into AI-agent activity, sell data management as a way to control SIEM economics, and meet Microsoft Sentinel users where they already investigate incidents. That approach is likely to appeal most to Sentinel customers that want supplementary detection capabilities but cannot justify a disruptive migration to another SIEM.
It is not yet a complete implementation case. Before committing, security teams should demand a data-flow diagram showing where logs are collected, processed, stored and returned to Sentinel; a per-source coverage list for each named AI platform; the exact DPM licensing units and tier conversion rules; and a clear explanation of how Securonix’s enriched findings coexist with Sentinel’s native UEBA, analytics rules and Defender portal workflows.
Microsoft has already set March 31, 2027 as the date after which Sentinel will no longer be supported in the Azure portal, with customers redirected to the Defender portal. Any Securonix deployment sold as “keeping Sentinel at the center” should therefore be validated in the Defender portal experience from day one. The product decision is not whether to add another dashboard; Securonix explicitly says analysts remain in Sentinel. It is whether the company can prove that its extra analytics and data-routing layer improves detection enough to justify its cost and complexity before that platform transition arrives.

References​

  1. Primary source: ETCISO.in
    Published: 2026-08-05T02:31:00+00:00
  2. Related coverage: learn.microsoft.com
  3. Related coverage: learn.microsoft.com
  4. Related coverage: securonix.com
  5. Related coverage: securonix.com
  6. Related coverage: connect.securonix.com
  7. Related coverage: sans.org
  8. Related coverage: pages.securonix.com