Vectra AI has released Vectra AI Pro, a platform designed to deliver what the firm describes as "trusted signal intelligence" for security operations centers confronting AI-driven threats. Unveiled at Black Hat USA 2026, the system merges network, identity, cloud, SaaS, SASE, and endpoint data streams into a single picture of how attackers behave, according to the company. The offering represents the vendor's effort to help SOC teams keep pace with adversaries who now operate faster thanks to artificial intelligence.

The platform centers on four components, according to Vectra AI. Behavioral intelligence tracks attacker moves across reconnaissance, credential misuse, privilege escalation, lateral movement, command-and-control, and data theft. Identity and device intelligence links actions across users, AI agents, service accounts, workloads, hosts, devices, cloud resources, and unmanaged systems while stitching together network, identity, cloud, SASE, and EDR telemetry into one attack narrative. Risk and forensic intelligence ranks which entities, behaviors, and attack routes matter most and supplies the detail AI agents need to grasp what occurred, who participated, and why it's significant. Exposure validation lets AI agents investigate, hunt, respond, report, and confirm that attack exposure has dropped, attack paths have been eliminated, active threats have been stopped, and controls are working.

Mark Wojtasiak, SVP of Research and Strategy at Vectra, told Channel Insider the new solution extends the company's founding mission from 2013: grasping attacker behavior across enterprise systems. "The only true defense is behavioral," Wojtasiak said. "You can't write signatures fast enough, you can't patch fast enough. The SOC has to work at the speed of the attack." Wojtasiak pointed to recent Mythos and Hugging Face incidents as proof that AI has enabled adversaries to evolve and move at a much quicker tempo. Rather than relying on isolated alerts, the platform applies behavioral AI and machine learning to network and identity telemetry to understand how users, devices, workloads, and AI agents act across an environment, the company says. That approach matters more now because organizations face AI attacks capable of exploiting identities and traversing environments much faster than human defenders can manually examine, according to Wojtasiak.

Wojtasiak explained that one of the platform's biggest gains is cutting latency across the SOC workflow, with unified visibility spanning on-premises, multicloud, SaaS, identity, OT, and IoT environments as a prime example. Other applications include spotting AI agents on the network, keeping asset inventories current, creating attack summaries, enabling AI-assisted threat hunting, and exposing trusted signal intelligence through REST APIs and Vectra AI's MCP server for organizations constructing their own agentic SOCs. Yet Wojtasiak stressed that AI must earn analysts' trust before organizations feel comfortable letting agents make higher-impact response calls, especially when actions could touch critical systems or business processes. "The human is the critical thinker," Wojtasiak said. "The human's still the one that's looking at the evidence and saying, 'Okay, yes, this is something that we need to do.'" He sees AI's near-term role as handling repetitive work and surfacing the context analysts need to make faster, better-informed decisions, freeing them to focus on higher-value tasks like threat hunting and attack-path analysis while humans retain responsibility for critical choices.

Looking ahead, Wojtasiak said resilience will separate successful organizations from those that falter. He told Channel Insider that good SOC teams and organizations establishing a forward-looking resilience strategy today—including defining what resilience means to them and deploying the right AI—will succeed as AI-driven attacks grow more common and diverse. That shift demands moving from a detection-and-response mindset to a proactive resilience posture, he said. "I don't think it's a three-to-five-year plan. I think they need to start now," Wojtasiak added. For channel partners, he said the platform positions MSPs, MSSPs, and solution providers to act as strategic advisors, helping customers reimagine security operations for resilience and potentially expanding beyond traditional MDR services into more proactive defense and resilience-focused offerings. Organizations that delay building behavioral defenses may find themselves structurally unable to respond when automated attacks exceed the speed of manual investigation. Partners that master resilience advisory today will likely capture margin share as customers realize detection alone no longer provides adequate protection.