AI agent defense

Agents break detection built for people.

Agents run commands, touch data, and change state at machine speed. They act nothing like human users, and most of the time they are not malicious. Rules and conventional ML read that as thousands of alerts a day. The Intelligent Defense Platform reads it as behavior: LogLM scores the compound sequence, Vigil investigates it to a decision.

Runs in your environment. On premises, in your data lake, or fully air-gapped.

LogLM sequence scoreagent-svc-07
09:14:02package install from internal mirror x340in profile
09:21:55writes notes into shared artifact storeoff profile
09:48:10reads peers' notes, adopts a shared protocoloff profile
10:02:41server-side fetch to external host via mirroregress
10:05:19retrieves exposed credential, validates write accessescalation
CASE OPENED

Vigil: individually low-signal. As one sequence, a service account turned a package mirror into an egress path and reached a live credential. Grouped, enriched with identity and asset context, raised as one case, not 1,200 alerts.

The problem

The output is not the risk. The sequence is.

A single agent action tells you almost nothing. A package install, a file written to shared storage, a fetch through a mirror: each is ordinary in isolation, and a rule written for one of them either stays silent or fires on everything. Agents generate these actions in volume, around the clock, with no regard for the working-hours and single-session patterns detection was tuned against.

The signal lives in the combination. LogLM was built to read sequences of telemetry as compound behavior, so a run of individually benign steps that together describe egress and escalation surfaces as one concerning sequence rather than a thousand disconnected anomalies. Vigil takes that sequence, assembles the identity, asset, and history around it, and resolves it to a case a person can act on.

Proof points
99%

zero-shot detection accuracy, across environments LogLM has never seen

1% or fewer

false positives, so analysts work cases, not noise

0.7 to 0.9%

false-negative rates measured at a top-four global bank and at BNY

45%

lower SIEM cost by moving detection off raw-log volume

How it works

Two layers, one owned loop.

Detection and investigation are different problems. The platform keeps them distinct, and keeps the learning loop that connects them inside your environment, under your control.

LogLM
Detection

Compound detection at machine speed

LogLM is an encoder-only foundation model that understands cybersecurity telemetry across protocols and sources. It embeds sequences of activity into a high-dimensional space, then purpose-built classifiers score what that behavior means. Because it is trained across diverse environments rather than tuned to one tenant, it works on day one, with no baselining period and no learning window.

  • Reads agent behavior as a sequence, not a stream of unrelated events
  • Scores the combination of steps that individually clear every rule
  • Computationally inexpensive and always on, so it holds up as attackers add intelligence and volume
Vigil
Investigation

The investigation and context layer

Vigil is the leading open-source AI SOC, Apache 2.0, and it performs substantially all of a SOC's day-to-day work. It takes a scored sequence and does what a good analyst does: pulls the identity behind the actor, the assets it touched, the history that precedes it, and the detections already covering it, then resolves the whole thing to a decision-ready case. Agent actions trigger the same investigation logic as a human's.

  • Groups low-signal events into one case instead of a flood of alerts
  • Manages the detection rules an environment runs, including federated detections in Splunk and Elastic
  • Reconstructs a full agent session across endpoint, network, cloud, and the agent's own log
Closed loop
Control

Red team your own environment, keep what you learn

The learning loop spans the whole platform, Vigil's workflows, Vigil itself, and LogLM, and it stays in your environment. Teams red team their own systems, turn that experience into detections, and measure efficacy inside the loop. Declared intent lives as Markdown under change control per environment. Nothing egresses to a vendor cloud for this to work.

  • Detection coverage assessment against the behavior you actually see
  • Policy and intent stored as versioned, reviewable artifacts
  • The loop that connects detection to investigation is yours to own and secure
Why agents defeat conventional detection

Not human. Mostly not malicious. Still a detection crisis.

Conventional ML and rules assume a human on the other end: a person who sleeps, works one session at a time, and whose intent can be inferred from a single bad action. Agents violate every one of those assumptions. They persist across tasks, coordinate over channels no one provisioned, and chain weak permissions into paths that are invisible when each weakness is assessed alone.

The result, before anyone is attacked, is noise. Benign agents trip the same tripwires as adversaries, and the SOC drowns. The answer is not a tighter rule. It is detection that reads behavior as a sequence and an investigation layer that turns that sequence into a decision.

Read the deep dive on the OpenAI and Hugging Face incident

What a rule sees vs. what LogLM sees

The same five actions, two readings.

RULEfive separate events, four below threshold, one generic external fetch among thousands
LOGLMone sequence: a service account built an egress path and reached a credential
VIGILone case, enriched with identity and asset context, ready for a human in seconds
What you get

See it, detect it, investigate it.

Sequence-level detection

LogLM scores the combination of actions an agent takes, catching what single-event rules miss and what per-tenant ML needs weeks to learn.

Agents treated like any other actor

Agent activity runs through the same detection and investigation path as a human's, with the identity and asset context attached.

One session, every layer

Vigil reconstructs a full agent session across endpoint, network, cloud, and the agent's own log, in a single timeline.

Fewer alerts, better cases

Low-signal events group into investigated cases. Analysts spend their time on decisions, not on triaging benign agent noise.

Works with what you own

Vigil extends existing detections, including federated rules in Splunk and Elastic, rather than asking you to rip and replace.

No egress required

Defense does not depend on a model provider's compliance API or a vendor cloud. The model travels to your data; your telemetry stays in place.

Deployment

Inside your boundary, on your terms.

On premises or air-gapped

Run the full platform where your telemetry already lives, including fully disconnected environments, with no special-purpose hardware.

In your data lake

Ingestion scales horizontally through the platform's scale-out architecture. Batch or continuous real-time stream, your choice.

Bring your own cloud

BYOC or Kubernetes. The control plane scales LogLM inference alongside ingestion as volume grows.

Get started

See a benign agent flood become one investigated case.

Send us telemetry for an assessment, or stand up Vigil in your own environment. Either way, you keep control of the data and the loop.