Stellar Cyber 7.0 brings case metrics to AI-driven SOCs

Stellar Cyber 7.0 brings case metrics to AI-driven SOCs

Stellar Cyber has released version 7.0 of its security operations platform. The update pairs AI-driven case triage with new ways to measure how a security operations center (SOC) is performing.

The company describes the release as the step that turns its "Human-Augmented Autonomous SOC" from a concept into a working operating model. Version 7.0 combines AI-powered case triage, measurable SOC workflows, more investigative evidence, wider automated response options and new APIs for running security operations at scale.

According to Stellar Cyber, the aim goes beyond helping analysts work faster. The platform is meant to help teams decide what matters, understand why, take the right action, and then check whether the SOC is actually getting better.

"Security operations has spent years focused on collecting more data and generating more detections," said Aimei Wei, CTO of Stellar Cyber. "The next era is about outcomes. Did we identify the real attack? How quickly did we understand it? Did we take the right action? And are we improving over time? Stellar Cyber 7.0 brings those pieces together so organizations can safely automate more of the SOC while keeping human judgment where it matters most."

Choosing where AI takes over

The biggest change is in how the AI features are switched on. Organizations can now enable AI case analysis and automated triage per case queue. This lets teams decide where automation applies, instead of handling every incident the same way.

Stellar Cyber gives a few examples. A managed security service provider (MSSP), a company that runs security monitoring for multiple clients, could have high-priority cases triaged automatically across several customer environments before an analyst picks them up. A smaller enterprise security team would find its critical cases already analyzed and ranked. More mature SOCs could set different levels of automation depending on risk, customer requirements or workflow.

The vendor says the point is to let machines handle repetitive analysis, so analysts can spend their time on decisions with the highest risk and consequence. This ties into a wider debate about how AI is changing analyst work, including concerns that entry-level SOC jobs are getting harder.

Case Metrics for accountability

To go with the extra autonomy, version 7.0 adds a feature called Case Metrics. It tracks operational milestones such as the time between a case being created and an analyst acknowledging it, or between creation and resolution.

Security leaders can use these numbers to check whether critical cases are handled fast enough, whether automation is cutting investigation time, where bottlenecks are forming, and whether service levels are improving.

Stellar Cyber says this is especially relevant for MSSPs. It gives them a clearer way to link AI-driven operations to the results their customers care about.

Evidence and response in one place

The release also puts more evidence directly inside the investigation view. Analysts get expanded malware sandbox evidence, visibility into network payloads, and access to the original records behind correlation-based detections. The goal is to reduce how often they have to jump between tools to piece together what happened.

Once a threat is confirmed, analysts can move straight to containment. New response integrations cover Microsoft Defender for Endpoint, Fortinet FortiGate and Cybereason, which broadens the actions that can be triggered from within Stellar Cyber.

This follows the logic of the company's Open XDR architecture. XDR, short for extended detection and response, refers to platforms that correlate signals across many security products. Stellar Cyber's approach is that customers keep the tools they already use. The platform correlates their signals, helps decide what matters, and uses existing controls to respond.

Automating the platform itself

For MSSPs and large enterprises, Stellar Cyber also wants to cut the manual work of running the platform. Version 7.0 expands APIs for the System Action Center, sensor lifecycle management and other operational functions. Teams can use them to automate policies and administrative workflows across large environments.

Parser Studio, the tool for handling incoming data formats, has also been updated. It now makes it easier to manage, reuse and optimize parsers, and it supports more security and infrastructure data sources.

Taken together, these changes are meant to let organizations run security through consistent policy, automation and APIs rather than repetitive manual administration.

Our Take

The most notable part of this release is arguably not the AI triage, which many vendors now offer, but the focus on measurement. Case Metrics tries to answer a question security leaders keep asking: is the automation actually making things better? Being able to see time to acknowledgment and time to resolution gives teams a way to test vendor claims against their own data.

The release fits a clear trend. Several vendors are pushing "agentic" or autonomous SOC features, with Exabeam recently bringing AI investigations on-premises. At the same time, Microsoft has warned that attackers currently lead defenders in the early AI race, which adds pressure on SOC teams to speed up.

Per-queue control over automation suggests vendors understand that buyers do not want an all-or-nothing switch. It is worth watching whether customers publish real results from these metrics, and whether automated response through third-party tools like FortiGate and Defender holds up without causing costly mistakes.