惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
宝玉的分享
宝玉的分享
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
Last Week in AI
Last Week in AI
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
A
About on SuperTechFans
MyScale Blog
MyScale Blog
aimingoo的专栏
aimingoo的专栏
Microsoft Security Blog
Microsoft Security Blog
D
Docker
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
P
Proofpoint News Feed
L
LangChain Blog
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
博客园 - 【当耐特】
Martin Fowler
Martin Fowler

Proofpoint News Feed

Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity | Proofpoint US Four groups caught using the same Chrome and Windows exploit kit CISOs are feeling the security burden of accelerated AI use Chinese espionage groups swarm to exploit triple-link chain of zero-days Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate | Proofpoint US Proofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People Officer | Proofpoint US Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster | Proofpoint US Cybercriminals Turn to Indirect Prompt Injection Attacks Fox News Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats | Proofpoint US Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities | Proofpoint US Max-severity Exchange server flaw under active exploitation by Kremlin hackers New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | CNN Politics International alert spotlights Russia-linked attacks on Zimbra webmail US and allies say Russian hackers stole emails without social engineering If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective | Proofpoint US The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Suspected North Korean actors use fake ‘coding assignments’ to steal crypto China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America | Proofpoint US
Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models
Luis Millares · 2026-09-08 · via Proofpoint News Feed

Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Proofpoint has launched its SOC Analyst Agent, an agentic AI capability that uses OpenAI Daybreak models to help security teams investigate threats, connect signals across Proofpoint products, and automate recurring analysis.

Currently in private preview, the agent is designed to reduce the manual work involved in SOC investigations while keeping consequential remediation decisions in human hands. General availability is expected by the end of Q3 2026.

Proofpoint SOC Analyst Agent connects security signals

According to Proofpoint, the SOC Analyst Agent was built to address the “prioritization challenge” security teams currently face. 

Citing its 2025 Data Security Landscape report, the company said 54% of organizations already use AI-enhanced capabilities to triage and investigate alerts, but SOC teams still need to connect signals across security systems and determine what deserves attention next.

“The challenge for security teams is to cut through the noise to quickly identify which signals matter and reach a defensible decision fast enough to act,” said Daniel Rapp, chief data and AI officer at Proofpoint. 

“The Proofpoint SOC Analyst Agent brings together our security expertise and data with advanced AI reasoning from OpenAI to give analysts a faster path from investigation to action, while keeping people in control of consequential security decisions.”

The SOC Analyst Agent plans investigations and draws context from connected Proofpoint security data, including alerts, logs, data loss prevention (DLP) events, and user risk signals.

Natural-language investigations target SOC alert overload

Instead of switching between consoles or writing individual queries, Proofpoint says that with SOC Analyst Agent, analysts can use natural language to investigate security events and synthesize findings across connected Proofpoint products.

The agent is designed around three core capabilities:

  • Accelerate investigations: Analysts can investigate security events using natural language across connected Proofpoint products, reducing the manual work needed to assemble context.
  • Automate recurring analysis: Teams can configure scheduled workflows for threat hunts, data security investigations, and escalation reporting, with results routed to appropriate analysts.
  • Keep analysts in control: Findings are traceable to the underlying source data, allowing analysts to validate recommendations. The agent does not independently make account changes, contain threats, or initiate other consequential remediation actions.

Proofpoint expands its use of OpenAI Daybreak models

Proofpoint joined the OpenAI Daybreak Defense Network in June 2026, with plans to apply OpenAI’s cyber-focused models across its products, services, and security workflows.

The company is now exploring additional uses for the models across threat research, data security, and AI security. Potential applications include helping threat researchers trace confirmed malicious findings across networks and supporting workflows that move from detection and investigation to recommended fixes for human review.

“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, head of global cyber partnerships at OpenAI.

“Proofpoint’s SOC Analyst Agent shows how frontier AI can help defenders move faster without giving up control. By combining Proofpoint’s security data and human-behavior expertise with OpenAI’s Daybreak models, analysts can turn fragmented signals into clearer findings, faster investigations, and recommended next steps they can trust.”

Proofpoint recently launched a new OEM Program for security vendors and MSPs looking to embed its threat intelligence and detection capabilities into their own offerings. Read more about the program and what it offers security providers, vendors, and MSPs.