ExtraHop has launched the Agentic SOC Alliance initiative to define and standardize a new SOC operating model designed for machine-speed threats rather than human-speed workflows. The alliance establishes a three-layer architecture of Context, Harness, and Model that gives autonomous security agents the evidence, governance, and reasoning they need to act with precision .
ExtraHop launched the Agentic SOC Alliance with 15 founding members including CrowdStrike, LangChain, Torq, and Dropzone AI .
The alliance defines a three-layer architecture: Context, Harness, and Model, built for autonomous machine-speed defense .
Context is a continuously updated operational knowledge graph; Harness is the AI runtime and orchestration layer; Model is the interchangeable reasoning layer .
The traditional queue-enrich-triage-investigate-escalate SOC pipeline was built for human-speed threats; post-frontier AI adversaries now move laterally in minutes .
ExtraHop delivers high-fidelity, real-time operational knowledge graphs that agents reason over directly, reducing token costs and time spent inspecting raw data .
ExtraHop invites the rest of the industry to join the Alliance to help refine and validate this operating model .
The security operations center is being rebuilt around a new operating model, one designed for machine-speed threats rather than human-speed workflows. Today, ExtraHop, the leader in real-time network intelligence and modern network detection and response (NDR), launched the Agentic SOC Alliance initiative to define and standardize this new SOC operating model: a three-layer architecture of Context, Harness, and Model that gives autonomous security agents the evidence, governance, and reasoning they need to act with precision .
The queue-enrich-triage-investigate-escalate pipeline that has run every SOC for two decades was built for a threat that moved at human speed. Post-frontier-AI adversaries now find a vulnerability, weaponize it, and move laterally in minutes. That pipeline cannot be optimized fast enough to close the gap. It has to be replaced by an operating model built for autonomy from the ground up, with rich, discoverable context as its foundation .
"Post-Mythos AI has fundamentally changed cyber defense. Adversaries now operate at machine speed, yet most security operations are still built on architectures designed for a human-paced world," said Greg Clark, CEO, ExtraHop. "The industry needs a blueprint for how autonomous security should operate that combines real-time context, intelligent orchestration, and specialized AI agents into a new operating model. The Agentic SOC Alliance is bringing that blueprint together, giving organizations a foundation to detect, decide, and respond with the speed and accuracy that modern threats demand. This is a starting point, not a finished one. We invite the rest of the industry to join the Alliance and help us refine, validate, and perfect this operating model, because outpacing a machine-speed adversary is a challenge no single company can solve alone" .
Founded by AuthMind, Armadin, Command Zero, CrowdStrike, Dropzone AI, Exaforce, ExtraHop, Fig, Intezer, Kindo, LangChain, Prophet Security, ReversingLabs, TENEX.AI, and Torq, this diverse coalition spans network detection, endpoint, AI-native SOC platforms, orchestration, and agent frameworks, and reflects the reality that autonomous defense cannot be delivered by any single vendor. The Agentic SOC Alliance establishes the requirements, best practices, and implementation blueprints for a SOC built for autonomy from the ground up .
The Agentic SOC Alliance closes the gap between machine-speed attackers and defenders by uniting three foundational layers into a single post-Mythos architecture. Two of those layers, Context and the Harness, are durable. The third, the Model, is interchangeable by design .
Context is not a collection of telemetry sources, but a continuously updated, highly structured representation of enterprise reality that AI reasons over directly. Context should provide an operational knowledge graph of every device, identity, workload, connection, and behavior, discoverable and semantically detailed enough that an agent can find exactly what it needs and understand what it means. Assembled in real time, it includes insight from network, endpoint, identity, and threat intelligence. Because agents reason over this structured representation rather than raw logs, they reach more defensible conclusions while consuming far less inference: This results in lower reasoning complexity, fewer tokens, less time and cost spent inspecting raw data and faster answers. Fragmented logs force a model to reconstruct meaning on every turn. A structured, discoverable knowledge graph hands it the answer already assembled. This is the layer the rest of the architecture depends on. No model is good enough to reason its way out of missing evidence .
Harness is the AI runtime and orchestration layer that governs how agents actually operate, executing workflows, calling tools, managing state and memory, and coordinating agents across the environment, with governance, guardrails, permissions, human approval routing, and a complete audit trail as core responsibilities running throughout. This is where autonomous work actually runs, and where it stays controllable. Because the Harness layer holds the orchestration and the guardrails, a model can be swapped without re-earning trust from a standing start .
Model is the interchangeable reasoning layer, where specialized, multi-model AI performs triage, investigation, and response. Context and Harness are the durable layers the architecture is built on; the model is not. Customers can adopt each new generation of models, or run several at once, without re-architecting anything around them. The model is a component you upgrade, never a foundation you are locked into .
"Cybersecurity has reached the point where human-speed defense is no longer sufficient against machine-speed attacks. The Agentic SOC Alliance represents one of the industry's first serious efforts to define an open operational architecture for autonomous security operations, bringing together trusted context, governed AI, and coordinated response so enterprises can finally begin defending at the speed of their adversaries. I am excited to see the development." – Dr. Edward G. Amoroso, CEO, TAG Infosphere and Research Professor, NYU .
The primary barrier to agentic SOC accuracy is the AI context gap. Fed fragmented logs, autonomous agents lack the evidence to reach defensible conclusions, and they burn tokens and time reconstructing meaning the data should have carried in the first place. Structuring that evidence as a continuously updated operational knowledge graph, discoverable and semantically detailed rather than raw, closes both gaps at once; network, endpoint, and identity signals become continuously findable and understandable in place, so agents reason over answers rather than reconstructing them from raw material .
Within this ecosystem, ExtraHop delivers the high-fidelity, real-time operational knowledge graph, enriched with identity and endpoint data, that autonomous agents need. Its decrypted, protocol-level visibility closes the gaps that cause AI models to falter. Because that context arrives already structured, discoverable, and richly detailed rather than raw and fragmented, agents reach conclusions with lower reasoning complexity, fewer tokens, and less time and cost spent inspecting raw data, which makes autonomous detection, investigation, and response not just more accurate but more affordable at enterprise scale .
About ExtraHop
ExtraHop is a leader in real-time network intelligence, empowering organizations with the high-fidelity context they need to power security and IT AI automation, detect risks faster, and respond with confidence. ExtraHop anchors AI agents with the real-time, ground-truth foundation they need to operate reliably in the SOC and NOC. For security, that means surfacing threats and providing definitive evidence to investigate and respond to novel AI attacks and unsanctioned usage at machine speed .