Stellar Cyber 7.0 adds measurable workflows for AI-powered SOCs
Stellar Cyber has announced Stellar Cyber 7.0, a release that advances the Human-Augmented Autonomous SOC from a vision for applying AI to security operations into a practical operating model for running them.
Stellar Cyber 7.0 unifies AI-powered case triage, measurable SOC workflows, deeper investigative evidence, expanded automated response and new APIs for operating security at scale.
The result marks significant progress from simply using AI to help analysts work faster. Stellar Cyber 7.0 will help security teams determine what matters, understand why it matters, take the right action and measure whether the SOC is actually improving.
“Security operations has spent years focused on collecting more data and generating more detections,” said Aimei Wei, CTO of Stellar Cyber. “The next era is about outcomes. Did we identify the real attack? How quickly did we understand it? Did we take the right action? And are we improving over time? Stellar Cyber 7.0 brings those pieces together so organizations can safely automate more of the SOC while keeping human judgment where it matters most.”
From AI assistance to an autonomous operating model
Stellar Cyber 7.0 embodies the evolving logic of AI in security operations. Rather than simply tacking on AI as productivity-enhancer, 7.0 integrates AI to uplevel your analysts strategically.
Organizations can now enable AI case analysis and automated triage at the case-queue level, so security teams can determine where autonomy should be applied rather than treating every incident the same way.
For an MSSP, this means automatically triaging high-priority cases across multiple customer environments before an analyst begins work. For a lean enterprise team, it means having critical cases already analyzed and prioritized. More mature SOCs can apply different levels of automation based on risk, customer requirements or workflow.
AI simply for AI’s sake is not enough. But if machines handle repetitive analysis, analysts can focus and refine their expertise on the decisions that carry the greatest risk and consequence.
Make SOC performance measurable
Autonomy without accountability is not enough.
Stellar Cyber 7.0 introduces Case Metrics, for organizations to measure important operational milestones such as the time from case creation to analyst acknowledgment or from creation to resolution.
Security leaders use those measurements to answer practical questions: Are critical cases being handled quickly enough? Is automation reducing investigation time? Where are operational bottlenecks developing? Are service levels improving?
For MSSPs in particular, this drives a stronger connection between AI-driven operations and the outcomes customers actually care about.
Put the evidence and response in the workflow
Stellar Cyber 7.0 also gives analysts more of the evidence required to validate a threat directly within the investigation.
Expanded malware sandbox evidence, network payload visibility and access to the original records behind correlation-based detections reduce the need to move between multiple tools simply to reconstruct what happened.
Once a threat is understood, expanded integrations help analysts move directly from investigation to containment. New response capabilities with technologies including Microsoft Defender for Endpoint, Fortinet FortiGate and Cybereason broaden the actions teams can take from Stellar Cyber.
That reinforces a core principle behind Stellar Cyber’s Open XDR architecture: customers do not need to replace the security technologies they already trust to build a more autonomous SOC. Stellar Cyber can correlate the signals, help determine what matters and use existing controls as part of the response.
Operate the SOC at machine scale
For MSSPs and large enterprises, autonomy also means reducing the manual work required to operate the security platform itself.
Stellar Cyber 7.0 expands APIs for the System Action Center, sensor lifecycle management and other operational functions, allowing security teams to automate policies and administrative workflows across large environments.
Enhancements to Parser Studio also make it easier to manage, reuse and optimize parsers while adding support for additional security and infrastructure data sources.
These capabilities allow organizations to operate security through consistent policy, automation and APIs instead of repetitive manual administration.