Today, we introduce Vega II, the next generation of the Vega Agentic Cyber Defense platform. Vega II brings the first model built for agentic cyber defense to the fight, gives the SOC a memory that outlasts every ticket, and tears down the legacy SIEM and pipeline barriers that kept data out of reach.
Experience Vega II at Cyber Defense at the Frontier on October 21, 2026 at 8:00 AM PT / 11:00 AM ET / 4:00 PM BST.
This is our most important release since emerging from stealth. It delivers on the vision we have been building toward: Agentic Cyber Defense that detects, triages, and investigates autonomously, directed by the judgment of its best defenders, across all the security data an enterprise keeps. Delivering it meant advancing everything around the agent, not just the model.
Frontier models can write code, use tools, and work through increasingly complex tasks. In an attacker’s hands, those capabilities can help research targets, develop attack tooling, and troubleshoot exploit code. Every model release makes that work faster and cheaper for the attacker.
Defenders should gain just as much from that progress, but a capable model still needs a way to do the work inside an enterprise. The evidence may sit in a source the legacy SIEM never onboarded, while the explanation for an unusual account lives in a ticket someone closed six months ago. Even when both are available, the agent needs cyber defense expertise and the team’s direction to make sense of them. What comes next?
The harness for cyber defense
Vega is the harness for Cyber Defense Engineering, bringing AI agents into the environment where security work happens with everything the team needs to direct them and stay in control. The platform runs a first-of-its-kind agentic defense loop across data lakes, object storage, cloud, SaaS, and the legacy SIEM an enterprise already has.
Cyber Defense Engineers write the instructions the agents follow, read the reasoning behind every verdict, and approve every change. That is the system behind every agent’s conclusions, and it is how a small team of expert defenders does the work of a much larger one: their judgment runs in every investigation, not only the ones they had time to open.
Vega’s first model: built for cyber defense and ready for the fight
Vega’s harness already gets more out of frontier models by routing each task to the right model and matching compute to the case, so the same models perform measurably better inside it than off the shelf. Vega II adds a layer on top: a proprietary, open-weight model working alongside the frontier models already in the loop. The expertise is in the model and the harness together: the reasoning an investigation demands when evidence is incomplete, activity is ambiguous, and the next question matters as much as the first answer.
A model can know cyber defense well and still not know why an account exists in your business or what your engineers established about it last quarter. So our model runs inside the harness: it brings the expertise, Memory brings the environment, the engineers bring the instructions. It also handles the evidence investigations actually contain. Generic models carry guardrails written for the general public and hesitate over a credential dump, a phishing kit, or exploit traffic; ours treats that evidence as the work it is, within the data access the security team sets.
Then there is speed. A general-purpose model thinks from scratch on every alert and arrives minutes later. Vega already investigates 44x faster than manual work in the legacy SIEM, but the comparison that matters now is against other AI. On our benchmark, built from real cases with defined ground truth, the gains come in two steps: frontier models inside the harness beat the same models off the shelf, and our model beats that configuration in turn. A model that knows the work reaches the verdict while a general-purpose one is still gathering context.
Vega Memory: make every lesson last
An investigation often produces knowledge that is useful long after the alert is closed: why a service account exists, which system owns it, or what an unusual but approved deployment looks like. The same is true of a hunt that clears a noisy host or a search an engineer refines by hand. Too often, that knowledge stays in a ticket or in one person’s head while the next investigator starts from the same questions. Vega Memory keeps what the team and its agents learn across triage, investigations, and hunts, and every agent in the environment works from it, so the tenth alert on that account is never worked like the first.
Memory captures the environment’s ground truth and actions taken, giving agents context for the evidence in front of them. If the team has established that a deployment account belongs to a particular application and normally operates in one region, activity from a second region is judged against that fact, not from zero. Memory is knowledge of the environment, not a substitute for judgment: a familiar account still gets checked against the current evidence. Engineers inspect everything saved, trace any record back to the case that produced it, and correct or delete it as the environment changes.
Vega Gateway: access all your data
Vega runs analytics in place, on the data an enterprise already keeps, and that is the reach every investigation starts with. Vega Gateway extends it to the sources with nowhere to live yet: a new application, an AI agent’s activity log, or a SaaS tool no connector was ever written for. The same analytics run over those sources too, without making each one a pipeline project or another legacy SIEM ingest bill.
Gateway streams any source into low-cost object storage over OpenTelemetry, webhook, or API. For an OpenTelemetry log source, the team simply points a supported exporter at the Gateway endpoint with the credentials and source identifier it needs. Vega lands the logs in managed object storage, indexes them, and automatically onboards the source, making the data queryable alongside the sources Vega already accesses in place.
No pipeline to build, no schema project before the first query. Defenders follow activity into an application whose logs were out of reach yesterday and connect it to the identity and cloud evidence they already hold. Sources too costly to centralize onboard in minutes, Vega’s analytics follow attackers where the SIEM never looked, and every one of those sources becomes part of the SOC’s view of the business.
One investigation
Let’s say a developer’s AI coding agent starts behaving like an attacker, the team’s knowledge establishes what normal agent use looks like, and Vega investigates with that knowledge and the team’s judgment in hand.
A developer’s Claude Code session switches to bypassPermissions, the mode where the agent runs every command without asking, and Vega’s detection fires. The flip alone proves nothing: developers turn off the approval prompt every day. But the agent’s shell, file, and API access is exactly what an attacker needs, and a hijacked account or session turns it into an intrusion toolkit running at AI pace. The agent’s logs show intent. The proof is scattered across endpoint, network, cloud, and identity logs in object storage, cold storage, and the legacy SIEM, and the agent telemetry is too voluminous to ingest at SIEM prices. Correlating it by hand takes hours, and the agent does not wait.
Step 1: Bring the agent’s telemetry into the investigation. Claude Code exports its session activity over OpenTelemetry: permission-mode changes, tool decisions, and the model’s own safety refusals. The team points the exporter at the Vega Gateway endpoint. Vega lands the events in object storage, indexes them, and onboards the source in minutes, so the agent’s activity sits beside the endpoint, cloud audit, and identity logs Vega already reaches where they live. The detection is running against it the same day.
Step 2: Triage two alerts, escalate one. The detection fires twice. Vega works each alert through the triage Skills attached to it, reasoning with our proprietary model and frontier intelligence, and Memory supplies a fact the team recorded when a case closed last quarter: the platform team runs Claude Code unattended on two build runners as approved automation. The first alert is one of those runners. Not Escalated, with the memory cited and the decision traceable to the record behind it. The second alert is a developer laptop, with repeated mode changes and a cyber-category refusal in the same session: the model declined a request, which means a person made it. Escalated.
Vega opens an incident and posts it to the team’s Slack channel. From the thread, the engineer asks @Vega what the laptop touched outside the Claude Code session, and the answer comes back in the thread with the sources it queried.
The investigation Skill’s one rule takes over: never stop at the agent’s own logs. Vega pivots on the host, the user, and the outbound IP across EDR, network, cloud, and the identity logs still indexed in the legacy SIEM, queried without moving them. It finds a tunneling binary posing as a build tool in a user-writable temp folder, an internal port sweep from the same host, a batch of secrets pulled from the cloud secrets manager, and a platform API key created from a non-corporate IP. Verdict: compromised developer account. The evidence sits behind each step, and the next actions are ranked: isolate the host, revoke the key, rotate the secrets. The engineer reviews the reasoning and signs off before anything changes.
Step 3: Carry the finding forward. Memory keeps the confirmed verdict, the actions taken, and what the case established about the environment, each attributed to the incident that produced it. The engineer reviews what was saved and edits or disables anything that should not persist. The next bypass alert on an approved runner is dismissed for the same reason. The next one that arrives with a refusal beside it starts from this case, not from zero. And the tightened escalation check ships as a Skill proposal the engineer approves before it runs.
Start anywhere
An enterprise can begin with the gap that matters most: a source its legacy SIEM could never afford, an alert queue that needs deeper investigation, or the AI agents now running inside the business. Nothing gets ripped out. What one use case connects and learns, the next one inherits. The legacy SIEM becomes a data source, and customers retire it on their timeline, once Vega has earned it.
Experience it live
We believe every advance in AI should make defenders more capable, and every investigation should leave the SOC better equipped for the next one. The models carry the reasoning. Memory carries what you’ve learned. Data carries the evidence. Vega II starts with all three.
Experience Vega II at Cyber Defense at the Frontier on October 21, 2026 at 8:00 AM PT / 11:00 AM ET / 4:00 PM BST. Follow one case from alert to verdict, then see how the team’s findings carry forward in Memory.
Explore further: Read the press release · Book a demo