Empowering organizations with the high-fidelity context they need to power security and IT AI automation, detect risks faster, and respond with confidence.

Seattle, WA
Your must-stop spot for #FalCon2026: Booth #1422 🎉 🤝 Learn more about why ExtraHop is the context layer foundation for the Agentic SOC. 🎤 Hear from industry leaders paving the way for future of cybersecurity. 🖥️ Try our award-winning platform to see ExtraHop network intelligence in action. More details: xtra.li/4zqhwCx
1
139
Director of Engineering in the Insurance (except health) Industry gives RevealX 5/5 Rating in Gartner Peer Insights™ Network Detection and Response Market. Read the full review here: xtra.li/3SL4SgB
1
146
Manager Of Student Support Services in the Education Industry gives RevealX 5/5 Rating in Gartner Peer Insights™ Network Detection and Response. Read the full review here: xtra.li/4wrKgZb
163
Network Manager in the Banking Industry gives RevealX 5/5 Rating in Gartner Peer Insights™ Network Detection and Response Market. Read the full review here: xtra.li/4eQfwLI
116
Last day at #BHUSA! 👋 Heading out to the expo floor one final time? Make Booth #5512 your first stop. It's your last chance to catch live demos of our platform, meet with our team and #AgenticSOCAlliance partners, and learn how uncompromised network truth makes AI automation actually work. Don't head home without stopping by!
221
Good morning, #BHUSA! We're back for day 2 of the Business Hall and the conversation around the agentic SOC is heating up 🔥 If you’re building your team's automation strategy, don’t miss Paul Giorgi TODAY for his presentation: "Exhaust from the Contrails: Network Runtime as Ground Truth for the Agentic SOC." Catch him in one of two sessions: 🍽️ 12:05 PM | Lunch & Learn 🎤 2:05 PM | Theater Session When you're not in a session, come hang out with us at Booth #5512 to see live agentic SOC demos in action!
119
We've arrived at Black Hat USA ☀️ The expo floor is about to open and the ExtraHop team is waiting for you at booth #5512! While you're here... 🤖 Stop by for a live demo to see how our platform delivers the high-fidelity context autonomous AI agents need to act with confidence. 🧠 Our own Paul Giorgi will be taking the #BHUSA stage to show you what it takes to build an agentic SOC and how to successfully automate your defense. 🤝 Meet with our security experts and the #AgenticSOCAlliance members on-site to learn how your security stack can work together to stop machine-speed threats. See you soon!
1
1
195
IT Problem Management Manager in the Banking Industry gives RevealX 5/5 Rating in Gartner Peer Insights™ Network Detection and Response Market. Read the full review here: xtra.li/4p6WPqp
80
Seeing the Agentic SOC Alliance light up the Nasdaq tower in Times Square today was incredible! 🏙️ 🌟 Beyond the celebration, the mission behind this initiative is what truly matters. Adversaries are now operating at machine speed. Using AI, they can find vulnerabilities, weaponize them, and move laterally in minutes. Security operations centers (SOCs) can't keep relying on human-speed, manual triage to fight back. Thank you, Nasdaq, for celebrating with us and helping get this critical message out to the world! Want to learn more about the Agentic SOC Alliance and our incredible team of partners? Click here: xtra.li/4vHFeqV
156
If you give an AI agent the authority to take independent action, how do you ensure it isn't scaling a bad decision? If you are heading to Black Hat next week, you'lI want to add this sponsored session to your schedule! 🎙️ Exhaust from the Contrails: Network Runtime as Ground Truth for the Agentic SOC 📅 Wednesday, August 5 🕐 2:05 PM
76
The most dangerous assumption in cloud security? Believing that a compromised Kubernetes pod is a contained incident. In reality, the K8s attack surface extends far beyond the pod itself. Here is what the modern K8s attack surface actually looks like: ☁️ Container Escapes: Attackers are moving past the application layer, using kernel vulnerabilities to shatter container isolation and take over the host. ☁️ Credential Harvesting: Stolen service account tokens give attackers the keys to the kingdom, paving the way for massive data exfiltration. ☁️ Blind Lateral Movement: Because K8s networking is highly dynamic and ephemeral, traditional security tools often lose the thread when an attacker moves east-west between internal services. Our latest blog unpacks these complex attack paths and explains how to build a more resilient K8s defense. Read it here: xtra.li/3TiYDkr
118
Context. Harness. Model. That's the operating model behind the Agentic SOC Alliance, a new coalition made up of 16 of the most innovative names in security and AI. Adversaries are already moving at machine speed. Most SOCs, and most "AI" tools in the SOC today, can't keep up. The Alliance is closing that gap with an open standard for real-time context, governed autonomy, and interchangeable AI models, so agentic security operations are fast, accurate, and defensible. The outcome: less noise, faster response, a fewer incidents. Learn more about how the Agentic SOC Alliance is making autonomous security a reality for organizations around the globe: xtra.li/4vHFeqV
83
The ExtraHop research team is breaking down VECT 2.0, a new threat marketed as a professional Ransomware-as-a-Service. Under the hood, a massive coding error means it permanently destroys most enterprise files. For security leaders and SOC teams, this changes everything. You aren't dealing with a typical extortion event where paying the ransom is a worst-case fallback. It is a permanent data-loss event. To make incident response even harder, VECT 2.0 is built to cover its tracks. It actively wipes system logs and blinds local security tools, leaving defenders completely in the dark if they only rely on endpoint data. So, how do you defend your environment when the host goes dark? 🔗 Read the full analysis: xtra.li/4vIZ4C2
1
153
Information Security Engineer 1 in the Healthcare and Biotech Industry gives RevealX 5/5 Rating in Gartner Peer Insights™ Network Detection and Response Market. Read the full review here: xtra.li/3T34Two
87
Machine-speed threats require an open, industry-wide response. That's why we're proud to introduce the Agentic SOC Alliance. 🚨 The Problem For two decades, the SOC was built the assumption that human judgment can sit at the center of every alert, triage, and response decision. When AI-driven attacks find vulnerabilities, write exploits, and move laterally in minutes, that assumption collapses. Bolting an AI copilot onto a legacy SIEM queue doesn't fix a machine-speed problem... It just relocates the bottleneck. 🌐The Power of an Open Alliance One vendor can't solve this problem. The future of autonomous defense belongs to an open, interoperable ecosystem where best-of-breed technologies work together seamlessly across three core layers. 1️⃣ Real-Time Context: Ground-truth wire and network telemetry that eliminates AI hallucinations and delivers decision-grade evidence. 2️⃣ A Governed Harness: A dedicated control plane with strict guardrails and audit trails so autonomous agents take action safely. 3️⃣ Multi-Model Flexibility: A flexible AI framework that lets security teams adopt specialized models as technology evolves—without re-architecting their underlying infrastructure. The Agentic SOC Alliance brings together leaders across network detection, endpoint, identity, threat intelligence, and AI-native platforms to make this open operating model a reality for every security team. 🔗 Read ExtraHop CEO Greg Clark’s full perspective on rebuilding the SOC for the agentic era: xtra.li/4feg6TF
101
🚨 BIG NEWS FOR CYBERSECURITY! 🚨 We are thrilled to announce the launch of the Agentic SOC Alliance alongside a powerhouse coalition of founding partners! Modern security operations are facing a massive paradigm shift. Adversaries now use AI to automate attacks and move laterally in minutes. ...But human-speed pipelines can't keep up. Rushing to deploy autonomous AI agents, however, brings a whole new set of operational headaches: model hallucinations, runaway token costs, and rigid vendor lock-in. Machine-speed defense requires moving away from piecemeal automation and adopting an open operating model that breaks down data silos, grounds AI agents in real-time context, and gives security teams the freedom to evolve without tearing down their stacks. That's why we are joining forces with an incredible group of industry leaders to drive this initiative forward. AuthMind | @ArmadinSecurity | @cmdzero_io | @CrowdStrike | @DropzoneAI | @ExaforceAI | Fig Security | @IntezerLabs | @KindoAI | @LangChain | @ProphetSec | @ReversingLabs | @TENEXai | @torq_io 👉 Learn more about the Agentic SOC Alliance here: xtra.li/4gLL2Mb
2
106
How do we actually trust automated agents to make the right decisions? AI is only as smart as the telemetry feeding it. If your automated systems rely on delayed logs, fragmented visibility, or easily disabled endpoint agents, you run the risk of automating bad decisions at scale. To safely hand over the keys to AI, you need an unalterable, real-time source of truth that attackers can’t tamper with or evade. You need network context. If you’re looking to skip the hype and dive into the actual data architecture needed to make your agentic SOC work, join ExtraHop’s Paul Giorgi for lunch at #BHUSA! 📅 Wednesday, August 5 | 12:05 PM 📍 Mandalay Bay Convention Center, Level 2 (Lagoon Conference Rooms) We’ll break down the shift required to turn the network into the high-fidelity ground truth your automated tools need to operate safely and effectively. Can't make the lunch? Catch Paul's stage presentation later in the afternoon, or drop by Booth #5512 on the expo floor to learn more!
90
In the age of the AI adversary, the timeline from initial compromise to full blown cyberattack shrinks from weeks to minutes. Join us this Thursday, July 23 to learn how SOC teams can keep pace. We'll be covering: ▪️ How threat actors are using AI today ▪️ What to keep an eye out for ▪️ How to build resilience against tomorrow's threats Register to save your spot: xtra.li/4f98i5D
62
Black Hat 2026 is right around the corner, and the big conversation this year is all about moving toward the agentic SOC. But realizing the true potential of the agentic SOC comes down to a fundamental engineering challenge: How do we ensure our automated security agents are making decisions based on the highest-fidelity data possible? To trust AI, it needs a real-time, unalterable source of truth that attackers can’t tamper with or evade. At #BHUSA, it's all about the network. If you are mapping out your team's automation strategy, join ExtraHop’s Paul Giorgi on Wednesday for "Exhaust from the Contrails: Network Runtime as Ground Truth for the Agentic SOC," an educational deep dive into the world of #NDR. 🔹 12:05 PM | Lunch & Learn (Level 2, Lagoon Rooms): A 60-minute session over lunch. 🔹 2:05 PM | Theater Session (BHT-B): A high-impact version directly on the expo floor. You can also us at Booth #5512 all week. See you in Vegas! xtra.li/451MiUd
98
When an automated system isolates a host, quarantines a workload, or revokes a credential, regulators, auditors, and the board all want to know: Why? "The model said so" is not an acceptable answer. Welcome to the era of defensible AI. As security teams embrace autonomous actions, the new hurdle isn't speed; it's accountability. The underlying problem is that most data feeding security AI wasn't built to be evidence. Logs can be altered or deleted and identities can be compromised, leaving teams acting on incomplete or manipulated data. If your agentic tools make a major decision tomorrow, will you be able to defend it? xtra.li/4poeFWf
57