📊 Key Data
  • 90% reduction in false positives with pre-correlation scoring
  • 750,000 suspicious samples and 2.5 billion URLs inspected daily by ESET's global research infrastructure
  • 80% improvement in analyst productivity with streamlined workflows
🎯 Expert Consensus

Experts would likely conclude that this partnership represents a significant advancement in proactive threat detection, addressing critical bottlenecks in traditional SecOps workflows through real-time intelligence integration.

about 11 hours ago
Stellar Cyber and ESET Redefine SecOps with Ingestion-Time Threat Intel

Stellar Cyber and ESET Redefine SecOps with Ingestion-Time Threat Intel

SAN JOSE, Calif. – September 16, 2026 – As enterprise networks expand and the velocity of cyberattacks accelerates, the traditional security operations center is buckling under the weight of retroactive alerts. In a bid to fundamentally rewire how security teams process and react to these threats, Stellar Cyber, a leader in open AI-native security operations, today announced a strategic technology partnership with global cybersecurity veteran ESET. The collaboration embeds the latter's premium threat intelligence directly into the former's Open Threat Intelligence Platform, executing a critical architectural shift: operationalizing intelligence at the exact moment of data ingestion.

For years, the industry standard within Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms has been to treat threat intelligence as an afterthought. Raw telemetry triggers a generic, rule-based alert, which is then sent via API to an external database for enrichment. This post-alert lookup process introduces fatal bottlenecks, including 15-to-60-second latency windows, API rate limits, and an avalanche of context-free threshold alerts that inevitably lead to analyst fatigue.

The newly announced integration dismantles this reactive pipeline. By leveraging a proprietary streaming data architecture known as Interflow, the San Jose-based SecOps provider normalizes disparate network, endpoint, cloud, and identity logs into structured JSON records at the ingestion boundary. As this streaming data enters the system, it is immediately evaluated against a continuously updated cache of high-confidence indicators of compromise (IoCs) provided by its new European partner.

"ESET has earned a global reputation for its highly actionable, curated threat intelligence, which cuts through the noise and provides real-world attack visibility from the cyber front lines," said Andrew Homer, Senior Vice President of Strategic Alliances at Stellar Cyber. "By integrating ESET Threat Intelligence directly into our Open Threat Intelligence Platform, we're helping customers operationalize that intelligence where it delivers the greatest value—during data ingestion. Rather than simply enriching alerts after the fact, we enable intelligence to become part of the detection process itself, allowing organizations to detect threats earlier, investigate faster, and respond with greater confidence."

Shifting Left: The Architecture of Proactive Detection

This "shift left" in the detection pipeline means that incoming telemetry is pre-scored for severity before machine learning anomaly detectors and graph-based correlation engines even begin their work. If an outbound DNS query attempts to contact a known ransomware command center, the event metadata is instantly appended with reputation scores, actor attribution, and malware family classifications.

Powering this real-time enrichment is a massive, globally distributed research infrastructure. The Slovakian cybersecurity giant inspects over 750,000 suspicious samples and 2.5 billion URLs daily across 11 global R&D centers. Unlike Western-centric firms, the company possesses historically deep sensor density across Central and Eastern Europe, Latin America, and emerging markets. This unique geographical footprint yields highly curated feeds tracking malicious file hashes, active botnet controllers, ransomware staging infrastructure, and state-sponsored advanced persistent threats.

By prioritizing high precision over high recall, these feeds are validated through automated multi-layer sandboxing and expert human malware research before publication. When applied at the ingestion stage, this rigorous filtering suppresses unverified noise. Independent deployment metrics reveal that this pre-correlation scoring reduces false positives by over 90%, ensuring that alerts only surface when telemetry demonstrates verified, contextual malice.

The Open XDR Antidote to Vendor Lock-In

Beyond the technical mechanics, the partnership represents a strategic maneuver in the broader cybersecurity market. The industry is currently locked in a structural rivalry between proprietary, single-vendor Extended Detection and Response (XDR) ecosystems—which often demand costly "rip and replace" overhauls—and Open XDR or Integrated SOC (ISOC) platforms that preserve a customer's existing technology stack.

Recognized recently in the Gartner Hype Cycle for Security Operations as a critical ISOC system, the open platform approach allows organizations to ingest logs from third-party firewalls, cloud environments, and competing endpoint solutions without punitive integration costs. For the threat intelligence provider, this open ecosystem is highly lucrative. While renowned for its proprietary endpoint protection suite, integrating its intelligence division directly into an agnostic SecOps platform allows the company to monetize its research across diverse, heterogeneous enterprise environments globally.

“AI is changing the scale of cyber risk, and organizations need threat intelligence that is both actionable and operational,” noted Ryan Grant, Country Manager, U.S. and Canada, at ESET North America. “We are thrilled to expand on our existing partnership with Stellar Cyber - enabling customers to seamlessly incorporate ESET Threat Intelligence into their day-to-day security operations through an open, AI-driven SecOps platform. Together, we're helping security teams reduce operational complexity while improving the speed, accuracy, and confidence of threat detection and response."

Empowering the MSSP and Lean Enterprise

The operational dividends of this integration are particularly potent for lean enterprise security teams and Managed Security Service Providers (MSSPs). Currently deployed by one-third of the world’s top 250 MSSPs, the unified platform architecture allows service providers to offer tiered, premium threat-hunting services without the burden of deploying and maintaining separate intelligence management infrastructure.

Historically, launching an intelligence-led managed detection and response (MDR) service required purchasing standalone TIP licenses that could cost upwards of $100,000 annually, alongside the operational overhead of managing API connectors. Under the new arrangement, customers and partners who license the intelligence feeds can simply configure their credentials directly within the unified user interface. The premium intelligence flows continuously into the environment, directly lowering the total cost of ownership per tenant while preserving provider margins.

For the analysts on the ground—often operating in teams of three to eight within mid-market enterprises—the integration eliminates "swivel-chair" fatigue. Instead of toggling between a primary dashboard, firewall logs, and external threat portals to manually verify IP reputations, analysts are presented with a single, case-ready incident. This streamlined workflow has been documented to improve analyst productivity by more than 80%, shrinking the mean time to detect and mean time to respond by exponential margins compared to legacy workflows.

The AI Horizon: Human-Augmented Autonomy

The September 2026 announcement is the culmination of a multi-stage alliance that began with basic telemetry ingestion and has now evolved into deep architectural fusion. Yet, the roadmap for this joint offering points toward an even more sophisticated future: automated incident containment driven by Agentic AI.

The platform's underlying "Multi-Layer AI" deliberately avoids relying on single, black-box large language models. Instead, it utilizes unsupervised machine learning for baseline traffic modeling, supervised graph AI for correlating disparate alerts across the MITRE ATT&CK matrix, and generative assistants to synthesize investigation steps into natural language. Pre-release customer trials of these agentic auto-triage workflows have already demonstrated a near-perfect agreement rate with human Tier 3 analysts.

By pairing high-confidence indicators with these automated response engines, future capabilities will focus on autonomous containment. This could involve automatically isolating a compromised endpoint or killing malicious sessions at the firewall level without human intervention. Crucially, however, both organizations maintain a strict commitment to human-in-the-loop safeguards, ensuring that automated kill switches and account lockouts require analyst authorization thresholds before impacting mission-critical production servers. As cyber warfare increasingly relies on machine speed, this fusion of ingestion-stage intelligence and guided AI response ensures that defenders are finally operating ahead of the breach.

Topics & Related

Event:
Partnership
Theme:
Agentic AI
Sector:
Cybersecurity

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 50284