Wednesday, August 5, 2026

Today’s Edition

AI Intel Report

MARKETS

Frontier Models

eSentire Atlas Achieves 43x Faster SOC Investigations with Claude

The managed detection and response provider integrated Anthropic's Claude into its Atlas platform on Amazon Bedrock to automate expert-level threat analysis, yielding higher detection rates and reduced response times for enterprise customers.

7 MIN READ
A modern enterprise security operations center features multiple anonymous analysts seated at long rows of ergonomic desks each equipped with arrays of flat screen monitors displaying dense multicolored network topology maps threat heatmaps timeline graphs of alert patterns and layered data flow diagrams representing automated expert level analysis. The analysts wear neutral business casual attire with backs or sides visible to the viewer and hands positioned on keyboards or pointing at screen sections indicating collaborative review of complex security incidents. Behind the workstations tall black server racks with visible cabling and status indicator lights stand in ordered rows symbolizing the integrated Atlas platform infrastructure running on Amazon Bedrock cloud services. Subtle environmental details include overhead fluorescent lighting reflecting off polished floors large wall mounted displays showing abstract security dashboards with geometric shapes and arrows denoting rapid data processing and reduced response pathways and nearby conference tables holding open laptops and printed reference materials without legible content. The overall composition emphasizes efficiency through the presence of multiple active workstations fewer personnel than typical for the volume of visualized alerts and organized cable management suggesting streamlined operations. Additional elements include a background area with storage cabinets holding hardware components and a glass partition revealing further server equipment rows to convey the scale of managed detection and response capabilities. The scene captures a calm focused professional environment where human experts interact with AI augmented tools for higher detection accuracy and accelerated investigation workflows grounded in real enterprise cybersecurity settings without any text logos numbers or identifiable individuals. Dense visual layers include reflections on monitor surfaces varied screen color palettes from blues greens and reds indicating different threat categories ergonomic chair adjustments personal items like water bottles and notepads on desks and subtle architectural features such as acoustic wall panels and ventilation grilles contributing to the authentic operational atmosphere of a high performance security team leveraging advanced artificial intelligence integration for threat analysis.
Illustration: AI Intel Report

Atlas is eSentire's managed detection and response platform that integrates Anthropic's Claude to conduct autonomous threat investigations across endpoint, identity, network, and cloud telemetry.

Executive Summary

eSentire, a managed detection and response provider, deployed Anthropic's Claude within its Atlas platform hosted on Amazon Bedrock to automate threat investigations. The system performs autonomous analysis across endpoint, identity, network, and cloud telemetry, averaging 44 tool calls per case. This has resulted in investigations completing in seven minutes instead of five hours.

The deployment has led to 41 percent more confirmed attacks detected per customer and an 11 percent reduction in overall alert volume. Additionally, 99.96 percent of ransomware attacks were contained before encryption, exceeding the industry average of 44 percent. These outcomes stem from the platform's ability to match senior analyst decisions with 95 percent accuracy.

The quantified win includes execution of over 5 million tool calls in 12 months, equivalent to 468,000 hours of analyst work. This augmentation allows SOC teams to handle more cases with expert-level depth according to data from the company's production environment.

What background and context led eSentire to implement agentic AI for security operations?

In the cybersecurity sector, security operations centers face increasing volumes of alerts from diverse data sources including endpoint, network, and cloud systems. Traditional manual investigations can take up to five hours for complex cases involving multiple evidence-gathering steps. With attackers potentially using AI agents, response capabilities must match that speed to limit dwell time, which carries a global median of 11 days.

eSentire identified the need for AI that could solve unknown problems in live customer environments thousands of times a day with expert-level depth. The company turned to frontier models to augment rather than replace analyst work, focusing on better outcomes through dynamic generation of investigation steps.

The global rise in sophisticated attacks prompted evaluation of models capable of continuous production use. eSentire conducted validation with 1,000 real-world investigations to compare decisions against senior SOC experts before full deployment on Amazon Bedrock.

This context aligns with broader industry shifts where managed detection and response providers seek scalable ways to process telemetry without proportional increases in headcount. The approach addresses the gap between human analyst capacity and the volume of potential threats.

What new capabilities does the Atlas platform introduce with Claude?

Atlas now executes investigations averaging 44 autonomous tool calls per case, dynamically adapting to the specific security context of each alert. This replaces static playbooks with context-aware sequences that gather evidence across multiple data domains in parallel.

The platform delivers results in an average of six minutes while maintaining above 90 percent alignment with top SOC experts in ongoing evaluations. It processes endpoint, network, identity, and cloud data to produce comprehensive reports that previously required hours of coordinated analyst effort.

New capabilities include stopping 99.3 percent of attacks on the first machine and containing 99.96 percent of ransomware before any file encryption occurs. These metrics reflect the system's ability to act at machine speed across thousands of daily investigations.

The addition of Claude enables the system to handle unknown problems in live environments rather than only benchmarked scenarios. This represents a shift from reactive alert triage to proactive, autonomous resolution at scale.

What technical specifics define the Claude integration in Atlas?

The integration runs on Amazon Bedrock and uses Claude Opus 4.6 to orchestrate tool calls for evidence collection and analysis. Each investigation generates up to 30 different evidence-gathering steps tailored to the incident at hand, according to statements from eSentire leadership.

Over 12 months the platform executed more than 5 million tool calls, equivalent to 468,000 hours of expert analyst effort. The system maintains 95 percent alignment with senior SOC analyst decision-making across diverse endpoint security scenarios as validated in production.

Technical evaluation involved rigorous comparison of Claude outputs against the company's most senior experts on 1,000 real-world cases. Results showed consistent performance in live customer environments rather than controlled benchmarks alone.

The architecture supports continuous production evaluation where alignment remains above 90 percent with top experts. This setup allows the model to address novel attack patterns without requiring predefined rules for every scenario.

Integration on Amazon Bedrock provides the scalability needed for enterprise MDR workloads while preserving data residency and compliance requirements typical in the sector.

Performance metrics comparison before and after Atlas deployment with Claude
MetricTraditional ApproachAtlas with Claude
Investigation Time5 hours7 minutes
Alert Volume ChangeBaselineReduced 11%
Confirmed Attacks DetectedBaselineIncreased 41%
Ransomware Containment44% industry average99.96%
Attack Stopped on First MachineVariable99.3%
Tool Calls per CaseManual stepsAverage 44 autonomous

What market and stakeholder implications arise from these results?

Enterprise customers gain from 41 percent more confirmed attacks detected per account alongside reduced alert fatigue. The 11 percent drop in overall alert volume allows security teams to focus on higher-value tasks rather than triage.

The 99.96 percent ransomware containment rate more than doubles the industry average of 44 percent, providing a measurable differentiator for MDR providers. Stakeholders including CISOs can cite these figures when evaluating vendor performance.

Market implications include pressure on peer organizations to adopt similar agentic approaches to remain competitive in detection and response capabilities. The results demonstrate that frontier models can deliver production-grade outcomes in regulated environments.

Workforce implications center on augmentation rather than replacement, with the system handling the equivalent of 468,000 analyst hours over 12 months. This frees senior experts for strategic work while maintaining coverage across high-volume telemetry.

  1. Review current SOC investigation times against the five-hour baseline.
  2. Evaluate alignment of existing tools with expert decisions using 95 percent as a target.
  3. Assess ransomware containment rates relative to the 44 percent industry average.
  4. Pilot agentic systems on a subset of alerts to measure tool call efficiency.
  5. Track dwell time reductions against the global median of 11 days.

How have experts and executives reacted to the Atlas performance?

When attackers can run AI agents that move faster than any human SOC, the only viable response is AI that defends at the same speed and depth. That's what we built on Claude.Dustin Hillard, CPTO, eSentire

Dustin Hillard, CPTO at eSentire, noted that benchmarks alone are insufficient because the model must solve unknown problems in live environments thousands of times daily. He emphasized that Opus 4.6 meets this challenge through consistent expert-level depth.

Hill further stated that the goal is not to remove work but to deliver better outcomes, with five hours of work compressed into minutes through 30 dynamically generated evidence steps. This perspective appears in coverage from both Anthropic and VentureBeat sources.

The reactions highlight a shift in how security leaders view AI deployment, moving from experimental pilots to core infrastructure for threat response. Alignment metrics provide the confidence needed for C-suite adoption.

What is next for eSentire and the adoption of agentic AI in cybersecurity?

eSentire plans continued refinement of the Atlas system to handle emerging attack vectors while preserving the 95 percent expert alignment threshold. Expansion may include additional telemetry sources and deeper integration with customer environments.

Broader industry adoption is likely as other MDR providers observe the 43x speed improvement and corresponding gains in detection volume. The AWS case study documents the validation process that other organizations can reference for their own deployments.

Future developments could focus on scaling the 5 million tool calls achieved in the first year while monitoring attacker dwell time reductions. Executives should track how these capabilities evolve in response to AI-augmented threats.

The results position agentic AI as a standard component in security operations rather than an optional enhancement. Peer firms are expected to conduct similar 1,000-case validations before production rollout.

How does the 95 percent alignment metric compare across evaluation methods?

The 95 percent figure comes from direct comparison of Claude decisions against senior SOC experts on 1,000 real-world investigations as detailed in the AWS case study. This exceeds the above 90 percent threshold observed in continuous production monitoring.

VentureBeat reporting confirms the same 95 percent alignment with senior analyst decision-making, providing independent corroboration. The metric covers diverse endpoint security scenarios rather than a narrow set of test cases.

This level of agreement supports the claim that the system replicates expert judgment at scale without requiring human review for every step. It also underpins the decision to run 44 tool calls autonomously per investigation.

Frequently asked

What company achieved the 43x investigation speedup and in which sector?

eSentire, operating in the managed detection and response sector, achieved the 43x speedup through its Atlas platform powered by Claude.

What is the primary quantified outcome from the Claude deployment?

The primary outcome is compression of threat investigations from five hours to seven minutes while detecting 41 percent more confirmed attacks per customer.

Which sources provide the alignment and time metrics?

VentureBeat and Anthropic customer case studies both report the 95 percent alignment and seven-minute average investigation time.

Sources

  1. VentureBeat — eSentire's Atlas platform compresses comprehensive threat investigations from five hours to seven minutes while matching senior SOC analyst decision-making with 95 percent accuracy.
  2. Anthropic — Atlas uses Claude to run autonomous threat investigations achieving above 90 percent alignment with top SOC experts and executing over 5 million tool calls in 12 months.
  3. Amazon Web Services — Using Claude on Amazon Bedrock, eSentire achieved 95 percent alignment across 1,000 real-world investigations and stopped 99.3 percent of attacks on the first machine.
  4. eSentire — Originally posted by https://claude.com/customers/esentire. eSentire... Its Atlas platform uses Claude to run autonomous threat investigations...