Exaforce extends its AI security tool to monitor more than just Claude
Exaforce AI Security extends beyond Claude to monitor OpenAI, Gemini, and Copilot agents using existing SOC telemetry, no new endpoint agents.
Exaforce expanded its June Claude Compliance API integration into Exaforce AI Security, adding monitoring for OpenAI, Gemini, Microsoft Copilot, and OAuth-connected AI apps. The tool inventories AI agents by correlating EDR, cloud, SaaS, and model-provider logs without new gateways or endpoint agents, and can respond by revoking sessions, deactivating API keys, isolating devices, or killing agent processes via existing controls. Analysts note the agentless approach lowers friction but lacks runtime inspection and inline blocking offered by competitors such as Palo Alto Prisma AIRS, SentinelOne Prompt AI Agent Security, and CrowdStrike Falcon Guardian. A March 2026 Cloud Security Alliance survey found 68% of organizations cannot distinguish human from AI-agent activity and 74% report AI agents receive excessive access.
- Extends Claude-only monitoring to OpenAI, Gemini, Copilot, and OAuth AI apps
- Uses existing EDR, SaaS, and model-provider telemetry; no new agents or gateways
- Response actions include session revocation, API key deactivation, device isolation
- Competitors Palo Alto, SentinelOne, CrowdStrike pursue agent- and MCP-centric approaches
- CSA survey: 68% of orgs cannot distinguish human vs AI-agent activity
Full article742 words · extracted from csoonline.com · click to collapse
Exaforce is offering to help enterprise security teams discover and monitor AI agents using security telemetry they already collect, rather than requiring yet another endpoint sensor.
By combining usage data from agentic AI platforms with endpoint, cloud, SaaS and code data, Exaforce AI Security can identify risks, detect suspicious behavior, and respond to threats, the company said.
“Exaforce uses data the SOC already collects to inventory every AI app and agent, connect each one to the person, device and permissions behind it, detect misuse and threats that look legitimate action by action, and contain them through the controls already in place,” said Exaforce co-founder Ariful Huq.
The new product builds on the Claude Compliance API integration Exaforce announced in June.
Exaforce AI Security extends that to monitor other model providers, including OpenAI, Gemini and Microsoft Copilot, along with OAuth-connected AI apps and endpoint context. This can be correlated with existing SOC data to identify what an AI agent is doing, who is operating it, what it can access and whether its behavior poses a threat.
Osterman Research Principal Analyst Michael Sampson said that Exaforce is looking at the right signals, because AI agents work across devices, data sources, repositories, and identities.
Existing solutions such as EDR, IAM, SaaS security or model-provider logging tools alone may not be sufficient, he said: “Something needs to bring the behaviors and actions together across the whole and determine whether what is happening should be happening or not.”
Exaforce said it needs no new gateway, browser extension, or endpoint agent to assemble all that data, instead gathering it from EDR systems, audit and usage logs from model providers, and activity from productivity suites to build a contextual picture of what AI agents are doing.
Independent analyst Avivah Litan said this approach “lowers friction, avoids endpoint politics, and matches how most early guardian-agent deployments actually start.” But, she said, such “passive, agentless oversight is weaker for the runtime inspection and automatic blocking the market still largely lacks.”
Not just passive monitoring
Exaforce is not limiting itself to passive monitoring: It said that when a threat is detected it can use existing EDR, identity and model-provider admin controls to take actions including revoking a session, deactivating a model-provider API key, isolating a device, or ending an agent’s process.
Its competitors are taking markedly different approaches to the problem of agentic AI security.
With the launch of Prisma AIRS 3.0 in March, Palo Alto Networks focused on centralized AI agent visibility, policy enforcement, and controls around MCP servers to secure the agentic AI lifecycle. SentinelOne also targeted MCP discovery with its Prompt AI Agent Security, also tackling risk assessment, least privilege enforcement and runtime blocking of malicious interactions such as prompt injection. And with its September launch of Falcon Guardian, CrowdStrike introduced a new endpoint software agent specifally to detect and respond to AI.
While most of these efforts focused on AI agent discovery, a recent study showed that this is only part of the puzzle that enterprises need to solve. A March 2026 survey by the Cloud Security Alliance found 68% of organizations could not distinguish human activity from AI-agent activity, necessitating agent discovery. But even the agents they did know about were not necessarily under control: 74% of respondents said their AI agents received more access than necessary, and 52% said agents sometimes inherited access originally intended for humans.
That makes the AI-agent security problem more complicated, and it remains to be seen whether Exaforce’s bet on correlating existing security telemetry can provide enough control without dedicated agent identities, tightly scoped permissions and controls enforced at the point where an agent acts.
“Most current offerings remain observation and posture management, with very limited in-line blocking or remediation, and platform-native controls typically stop at their own cloud borders,” Litan said, adding that an effective solution would need to “discover sanctioned and unsanctioned agents across clouds and hosting environments, map the human and machine owner, tie activity to the right nonhuman identity when no global agent registry exists, and enforce policy once an agent leaves the platform that created it.”
Exaforce’s Huq said Exaforce AI Security is getting there: It brings AI and agent data into a system that has all relevant data to provide the required context to distinguish between a human identity and the agent that has inherited that identity.
Exaforce AI Security is generally available now on the Exaforce Agentic SOC platform, self-operated or through Exaforce MDR.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4222191/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude.html