,

How Deepwatch NEXA™ AI Turns Security Data into Decisive Action

By Rhyme Upadhyaya & Jude Daniel

Estimated Reading Time: 10 minutes

Security teams do not have a data problem. They have a decision problem.

Vulnerability scanners identify exposures. Endpoint, cloud, identity and network tools generate alerts. Threat intelligence tracks emerging campaigns. Ticketing systems preserve years of investigation history. Yet when a new threat appears, security leaders still need fast, defensible answers to three questions:

What should we fix first?

Would we detect this threat before it causes impact?

Have we seen this before – and what did we learn?

Answering those questions often requires teams to move across disconnected tools, correlate signals manually, and reconstruct context before they can act. That slows prioritization at the moment clarity matters most.

The market is moving from AI that summarizes security data to AI that helps teams make and defend the next security decision.

Deepwatch NEXA is built for that shift. NEXA is a collaborative agentic AI ecosystem for managed detection and response (MDR), bringing specialized AI agents and human expertise together across the security lifecycle. Instead of asking one general-purpose assistant to do everything, NEXA applies focused agents to focused decisions, grounding guidance in the customer’s security environment and operational context.

Specialized Agents. Shared Context. Better Decisions.

NEXA’s customer-facing agents connect three forms of security intelligence that are too often considered separately: exposure, detection readiness, and operational history.

Prioritize Real Risk With The Nexa CTEM Agent

A long vulnerability list is not a remediation strategy. Security teams need to understand which exposures are reachable, relevant to current threats, and connected to assets that matter to the business.

The NEXA CTEM Agent brings together exposure and risk context to help teams focus remediation on the conditions most likely to create business impact. It turns the question “What is vulnerable?” into the decision that matters: What should we fix first?

Strengthen Detection Readiness With The Nexa Detection Advisor Agent

Reducing exposure is one part of cyber defense. Teams also need confidence that their controls can identify the attacker behaviors associated with an active threat.

The NEXA Detection Advisor Agent helps customers understand current detection coverage, identify potential gaps, explain detection logic, and evaluate opportunities to strengthen coverage using frameworks such as MITRE ATT&CK. The result is a clearer answer to: “Would we detect this threat before it causes impact?”

Activate Institutional Security Knowledge With The Nexa Ticket Analyzer Agent

Every investigation creates knowledge: what analysts observed, which actions worked, where remediation stalled, and how similar cases were resolved. Too often, that knowledge remains buried in historical tickets.

The NEXA Ticket Analyzer Agent makes prior investigation and remediation context easier to access through conversational analysis. Teams can surface related cases, recurring patterns, and investigation status and previous response actions, helping them answer: “Have we seen this before and what did we learn?”

One Threat. One Consolidated NEXA View.

A recent security incident involving Hugging Face shows why modern threats cannot be evaluated through a single lens. In July 2026, Hugging Face disclosed an intrusion that began in a data-processing pipeline and progressed through code execution, credential access, and lateral movement across internal infrastructure. OpenAI later confirmed that models undergoing a cybersecurity evaluation had chained vulnerabilities across multiple environments.

In response, Deepwatch issued a customer advisory outlining the incident, associated attack techniques, relevant Deepwatch detections, and guidance to help customers assess potential exposure and detection readiness: https://www.deepwatch.com/labs/ca-26-027-openai-frontier-agent-sandbox-escape-hugging-face-intrusion/

For security leaders following the incident, the most important question was not simply, “What happened to Hugging Face?” but rather,  “Could a similar attack path exist in our environment and would we be prepared to stop it?”

Answering that question requires more than a vulnerability search, a review of detection rules, or a scan through previous investigations. It requires the agents to work as a team, each adding context to the same decision.

For example, a customer investigating a similar threat might see:

Assets With Potential Exposure

  • Internet-facing AI inference service running an affected application version
  • Kubernetes cluster supporting the application environment
  • CI/CD runner with access to production workloads
  • Service account with elevated access to cloud resources

Detection Readiness

NEXA can surface the Deepwatch detections relevant to the threat advisory, including:

  • Risk Object Transition to Threat Object
  • Suspicious Copilot Interaction Detected by Microsoft
  • Microsoft Copilot Interaction Accessed Large Amount of Resources
  • Exploitation Commands – Linux
  • AWS Instance Metadata Retrieval
  • Exploit Tool Execution – Linux

Alongside the enabled detections, NEXA can highlight any gaps in coverage or missing telemetry that could reduce visibility into the attack path.

The consolidated view can also surface related tickets, for example:

  • Ticket #INC-10482 –  Suspicious exploitation commands detected on Linux workload
    Associated with Exploitation Commands – Linux
  • Ticket #INC-11597 –  AWS instance metadata accessed from compromised workload
    Associated with AWS Instance Metadata Retrieval

Instead of requiring the security team to independently correlate assets, detection coverage, telemetry gaps, and remediation activity, NEXA brings those perspectives together around the threat.

The result is not three separate agent responses. It is one coordinated view that helps the team understand what is affected, which detections are in place, what visibility gaps remain, and what actions are already underway.

The Next MDR Advantage Is Decision Intelligence

AI in security will not be judged by how many answers it can generate. It will be judged by whether those answers are grounded, accurate, and useful in the moments that matter.

Deepwatch NEXA brings that standard to managed detection and response through collaborative agents built around a shared purpose: helping customers move from security data to decisive, risk-informed action.

Ready to see how NEXA can help your team connect exposure, detection readiness, and operational context? Explore Deepwatch NEXA or request a demo.

Share

LinkedIn Twitter Facebook