CFOtech US - Technology news for CFOs & financial decision-makers
United States
Intezer launches Org Brain for AI SOC investigations

Intezer launches Org Brain for AI SOC investigations

Thu, 23rd Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Intezer has launched Org Brain for its AI SOC platform, describing it as a system that gives investigations real-time organisational knowledge.

The product is designed to address what the cyber security company sees as a common weakness in AI-based security operations tools: reliance on context gathered during onboarding that can become outdated as users, assets, detections and workflows change.

Org Brain is a self-learning memory system that draws on historical knowledge, live information from an organisation's environment and insights captured after each alert is resolved. Intezer says this is intended to reduce repeated errors, improve consistency and preserve institutional knowledge that might otherwise remain with individual analysts.

The launch is aimed at security operations centres, where analysts triage and investigate alerts across an organisation's systems. In that setting, decision quality often depends on a mix of formal procedures and unwritten practices built up over time.

Intezer argues that older approaches to AI assistance in the SOC can leave agents working with incomplete or stale information, affecting decisions on whether an alert should be closed, escalated or investigated further.

"Most AI SOC products load organizational context once and call it done. But environments change, users change, threats change. A context store that was accurate at onboarding is a liability six months later," said Itai Tevet, Chief Executive Officer and Co-Founder of Intezer.

"Org Brain solves this. It continuously learns how the organization operates, what normal looks like for every user and asset, and how the SOC team has handled threats before. The difference shows up in every investigation with higher verdict accuracy, consistent quality across every agent and every shift, and security outcomes that compound rather than plateau. The goal is an AI agent that genuinely knows your organization the way a veteran human analyst does," Tevet said.

Two knowledge types

Intezer has divided Org Brain into two components: procedural knowledge, which it calls Muscle Memory, and declarative knowledge, described as Self-Awareness.

Procedural knowledge refers to the practical steps and habits a SOC team develops over time, such as which queries to run for a particular identity alert, which detections can be closed quickly after repeated benign firings, or how a noisy Data Loss Prevention rule has previously been tuned. Intezer says this kind of knowledge often sits with individual analysts rather than in documentation.

The declarative side is intended to hold information about assets, users, investigation history and the structure of security data in systems such as Security Information and Event Management platforms. This should help an AI agent understand how an organisation's environment is organised and where relevant evidence can be found.

According to Intezer, that distinction matters because a security investigation depends not only on knowing what steps to take, but also on understanding the context in which those steps are applied. A system that understands a user's typical login behaviour or the purpose of a specific asset may be better placed to judge whether an alert is routine or unusual.

Loop design

Intezer says Org Brain has been built around a cycle of acting, verifying, learning and repeating. In practice, the system starts with historical records, fetches live context during an investigation and then writes newly derived information back into its memory after a case is resolved.

Historical inputs can include closed cases, resolved tickets, previous escalation decisions and instances where alerts were closed without action. During an active investigation, the system can pull current information directly from the organisation's environment rather than rely solely on stored records.

After the investigation, one AI model reviews what happened, including analyst corrections and the path taken to reach a verdict, while another writes the conclusions back into memory. In Intezer's description, a tuning decision or analyst feedback may be stored as procedural knowledge, while a newly identified asset or changed user behaviour may be stored as declarative knowledge.

The launch comes as security teams face sustained pressure to process large alert volumes while limiting the need for manual review. Across the cyber security market, vendors are trying to show that AI can handle more of that work with fewer false positives and more reliable case handling, though accuracy and context remain central concerns.

Intezer says its AI SOC platform provides round-the-clock cyber alert triage and escalates less than 2% of alerts for human review. Its customers include NVIDIA, MGM Resorts, Equifax, Salesforce and Ferguson.

Within that broader platform, Org Brain is intended to make each investigation reflect both the organisation's current state and the history of how its security team has handled similar issues before.