Frontier Models
eSentire Atlas Achieves 43x Faster SOC Investigations with Claude
The managed detection and response provider integrated Anthropic's Claude into its Atlas platform on Amazon Bedrock to automate expert-level threat analysis, yielding higher detection rates and reduced response times for enterprise customers.
Atlas is eSentire's managed detection and response platform that integrates Anthropic's Claude to conduct autonomous threat investigations across endpoint, identity, network, and cloud telemetry.
Executive Summary
eSentire, a managed detection and response provider, deployed Anthropic's Claude within its Atlas platform hosted on Amazon Bedrock to automate threat investigations. The system performs autonomous analysis across endpoint, identity, network, and cloud telemetry, averaging 44 tool calls per case. This has resulted in investigations completing in seven minutes instead of five hours.
The deployment has led to 41 percent more confirmed attacks detected per customer and an 11 percent reduction in overall alert volume. Additionally, 99.96 percent of ransomware attacks were contained before encryption, exceeding the industry average of 44 percent. These outcomes stem from the platform's ability to match senior analyst decisions with 95 percent accuracy.
The quantified win includes execution of over 5 million tool calls in 12 months, equivalent to 468,000 hours of analyst work. This augmentation allows SOC teams to handle more cases with expert-level depth according to data from the company's production environment.
What background and context led eSentire to implement agentic AI for security operations?
In the cybersecurity sector, security operations centers face increasing volumes of alerts from diverse data sources including endpoint, network, and cloud systems. Traditional manual investigations can take up to five hours for complex cases involving multiple evidence-gathering steps. With attackers potentially using AI agents, response capabilities must match that speed to limit dwell time, which carries a global median of 11 days.
eSentire identified the need for AI that could solve unknown problems in live customer environments thousands of times a day with expert-level depth. The company turned to frontier models to augment rather than replace analyst work, focusing on better outcomes through dynamic generation of investigation steps.
The global rise in sophisticated attacks prompted evaluation of models capable of continuous production use. eSentire conducted validation with 1,000 real-world investigations to compare decisions against senior SOC experts before full deployment on Amazon Bedrock.
This context aligns with broader industry shifts where managed detection and response providers seek scalable ways to process telemetry without proportional increases in headcount. The approach addresses the gap between human analyst capacity and the volume of potential threats.
What new capabilities does the Atlas platform introduce with Claude?
Atlas now executes investigations averaging 44 autonomous tool calls per case, dynamically adapting to the specific security context of each alert. This replaces static playbooks with context-aware sequences that gather evidence across multiple data domains in parallel.
The platform delivers results in an average of six minutes while maintaining above 90 percent alignment with top SOC experts in ongoing evaluations. It processes endpoint, network, identity, and cloud data to produce comprehensive reports that previously required hours of coordinated analyst effort.
New capabilities include stopping 99.3 percent of attacks on the first machine and containing 99.96 percent of ransomware before any file encryption occurs. These metrics reflect the system's ability to act at machine speed across thousands of daily investigations.
The addition of Claude enables the system to handle unknown problems in live environments rather than only benchmarked scenarios. This represents a shift from reactive alert triage to proactive, autonomous resolution at scale.
What technical specifics define the Claude integration in Atlas?
The integration runs on Amazon Bedrock and uses Claude Opus 4.6 to orchestrate tool calls for evidence collection and analysis. Each investigation generates up to 30 different evidence-gathering steps tailored to the incident at hand, according to statements from eSentire leadership.
Over 12 months the platform executed more than 5 million tool calls, equivalent to 468,000 hours of expert analyst effort. The system maintains 95 percent alignment with senior SOC analyst decision-making across diverse endpoint security scenarios as validated in production.
Technical evaluation involved rigorous comparison of Claude outputs against the company's most senior experts on 1,000 real-world cases. Results showed consistent performance in live customer environments rather than controlled benchmarks alone.
The architecture supports continuous production evaluation where alignment remains above 90 percent with top experts. This setup allows the model to address novel attack patterns without requiring predefined rules for every scenario.
Integration on Amazon Bedrock provides the scalability needed for enterprise MDR workloads while preserving data residency and compliance requirements typical in the sector.
| Metric | Traditional Approach | Atlas with Claude |
|---|---|---|
| Investigation Time | 5 hours | 7 minutes |
| Alert Volume Change | Baseline | Reduced 11% |
| Confirmed Attacks Detected | Baseline | Increased 41% |
| Ransomware Containment | 44% industry average | 99.96% |
| Attack Stopped on First Machine | Variable | 99.3% |
| Tool Calls per Case | Manual steps | Average 44 autonomous |
What market and stakeholder implications arise from these results?
Enterprise customers gain from 41 percent more confirmed attacks detected per account alongside reduced alert fatigue. The 11 percent drop in overall alert volume allows security teams to focus on higher-value tasks rather than triage.
The 99.96 percent ransomware containment rate more than doubles the industry average of 44 percent, providing a measurable differentiator for MDR providers. Stakeholders including CISOs can cite these figures when evaluating vendor performance.
Market implications include pressure on peer organizations to adopt similar agentic approaches to remain competitive in detection and response capabilities. The results demonstrate that frontier models can deliver production-grade outcomes in regulated environments.
Workforce implications center on augmentation rather than replacement, with the system handling the equivalent of 468,000 analyst hours over 12 months. This frees senior experts for strategic work while maintaining coverage across high-volume telemetry.
- Review current SOC investigation times against the five-hour baseline.
- Evaluate alignment of existing tools with expert decisions using 95 percent as a target.
- Assess ransomware containment rates relative to the 44 percent industry average.
- Pilot agentic systems on a subset of alerts to measure tool call efficiency.
- Track dwell time reductions against the global median of 11 days.
How have experts and executives reacted to the Atlas performance?
When attackers can run AI agents that move faster than any human SOC, the only viable response is AI that defends at the same speed and depth. That's what we built on Claude.Dustin Hillard, CPTO, eSentire
Dustin Hillard, CPTO at eSentire, noted that benchmarks alone are insufficient because the model must solve unknown problems in live environments thousands of times daily. He emphasized that Opus 4.6 meets this challenge through consistent expert-level depth.
Hill further stated that the goal is not to remove work but to deliver better outcomes, with five hours of work compressed into minutes through 30 dynamically generated evidence steps. This perspective appears in coverage from both Anthropic and VentureBeat sources.
The reactions highlight a shift in how security leaders view AI deployment, moving from experimental pilots to core infrastructure for threat response. Alignment metrics provide the confidence needed for C-suite adoption.
What is next for eSentire and the adoption of agentic AI in cybersecurity?
eSentire plans continued refinement of the Atlas system to handle emerging attack vectors while preserving the 95 percent expert alignment threshold. Expansion may include additional telemetry sources and deeper integration with customer environments.
Broader industry adoption is likely as other MDR providers observe the 43x speed improvement and corresponding gains in detection volume. The AWS case study documents the validation process that other organizations can reference for their own deployments.
Future developments could focus on scaling the 5 million tool calls achieved in the first year while monitoring attacker dwell time reductions. Executives should track how these capabilities evolve in response to AI-augmented threats.
The results position agentic AI as a standard component in security operations rather than an optional enhancement. Peer firms are expected to conduct similar 1,000-case validations before production rollout.
How does the 95 percent alignment metric compare across evaluation methods?
The 95 percent figure comes from direct comparison of Claude decisions against senior SOC experts on 1,000 real-world investigations as detailed in the AWS case study. This exceeds the above 90 percent threshold observed in continuous production monitoring.
VentureBeat reporting confirms the same 95 percent alignment with senior analyst decision-making, providing independent corroboration. The metric covers diverse endpoint security scenarios rather than a narrow set of test cases.
This level of agreement supports the claim that the system replicates expert judgment at scale without requiring human review for every step. It also underpins the decision to run 44 tool calls autonomously per investigation.
Frequently asked
What company achieved the 43x investigation speedup and in which sector?
eSentire, operating in the managed detection and response sector, achieved the 43x speedup through its Atlas platform powered by Claude.
What is the primary quantified outcome from the Claude deployment?
The primary outcome is compression of threat investigations from five hours to seven minutes while detecting 41 percent more confirmed attacks per customer.
Which sources provide the alignment and time metrics?
VentureBeat and Anthropic customer case studies both report the 95 percent alignment and seven-minute average investigation time.
Sources
- VentureBeat — eSentire's Atlas platform compresses comprehensive threat investigations from five hours to seven minutes while matching senior SOC analyst decision-making with 95 percent accuracy.
- Anthropic — Atlas uses Claude to run autonomous threat investigations achieving above 90 percent alignment with top SOC experts and executing over 5 million tool calls in 12 months.
- Amazon Web Services — Using Claude on Amazon Bedrock, eSentire achieved 95 percent alignment across 1,000 real-world investigations and stopped 99.3 percent of attacks on the first machine.
- eSentire — Originally posted by https://claude.com/customers/esentire. eSentire... Its Atlas platform uses Claude to run autonomous threat investigations...