ADVERTISEMENT
Advertisement
Silicon IP

Macnica Launches Prophet AI, Japan's First AI-Powered Next-Generation SOC Platform

Listen to this story

AI NARRATED
0:00 / 0:00

Macnica announced that it has entered into an agency agreement with California based Prophet Security and will begin offering the Prophet Agentic AI SOC Platform, referred to as Prophet AI. The company described it as the first AI-powered next-generation SOC platform in Japan.

Companies face challenges in security operations as cyberattacks grow more sophisticated and complex. These include an expanding scope of monitoring, a rising volume of alerts, increased operational burden, and a shortage of security personnel. In Security Operations Centers (SOCs), the workload for daily alert processing and initial investigations has increased, along with variations in judgment quality stemming from differences in personnel experience. Companies that rely on outsourcing also struggle to accumulate in-house investigative knowledge, which makes continuous improvement of operational quality and rapid decision-making difficult. Organizations are focusing on AI to support security operations that maintain speed and quality with limited personnel.

Prophet AI is a platform that streamlines tasks involved in detecting, investigating, and responding to security threats and supports the advancement of SOCs. It integrates with existing security infrastructure such as EDR, SIEM, identity management, cloud, network, and email to streamline initial response to alerts. The platform consistently executes the full incident response process, including investigation planning, evidence gathering, alert prioritization, and response proposals, to enable rapid and stable security operations.

The system incorporates Agentic AI specifically designed for SOC operations. This AI was developed by experts with many years of experience in SOC operations and is based on real-world operational practices and challenges. It provides high transparency that allows humans to track and verify what investigations were conducted and why decisions were reached. Its open design is independent of specific security products and helps avoid vendor lock-in.

ADVERTISEMENT
Advertisement

The system uses an integrated architecture in which each function works in conjunction, covering alert triage, threat hunting, and detection logic improvement. Information obtained from detection is used to improve investigation accuracy, while investigation results are used to improve detection accuracy and reduce unnecessary alerts. Insights from threat hunting lead to new detections, enabling a continuous improvement cycle through operation.

Knowledge accumulated through daily operations can be utilized as an asset for the entire organization, supporting continuous transfer of expertise even when personnel changes occur. The accumulated knowledge is optimized to suit each customer’s environment, so operational value increases with continued use.

Prophet AI includes the following product features:

1. Automation of initial investigation and triage using SOC-specific Agentic AI. The AI handles summarizing alerts, generating investigation plans, collecting and analyzing relevant data, prioritizing tasks, and suggesting response strategies. This allows SOC analysts to focus on more critical decisions and actions.

2. Visualization of the investigation process and the basis for judgments. Users can verify which information the AI reviewed and the basis for its decisions. This provides transparency so that humans can operate the system while confirming validity as needed, rather than leaving everything to the AI.

ADVERTISEMENT
Advertisement

3. Integration with existing environments and continuous adaptation. The open design, independent of specific products, supports SOC operations that avoid vendor lock-in. It integrates with existing environments including security products such as EDR, SIEM, ID, cloud, and email, as well as case management and collaboration tools. The integrated architecture adapts to each company’s environment and policies while incorporating the judgments of SOC analysts and the organization’s unique characteristics and preconditions.

4. Proactive threat hunting. AI proactively hunts for threats based on hypotheses and quickly verifies the presence or absence of threats in the customer’s environment. Through carefully selected hunting templates and continuous monitoring, it can detect potential threats before they manifest as alerts.

5. Continuous improvement of detection accuracy. The AI analyzes existing detection rules and log acquisition status, visualizing overlooked attack methods and noisy detections in light of the MITRE ATT&CK framework. It specifically suggests areas for improvement and tuning options to support optimization of detection rules and continuously improve the accuracy and comprehensiveness of detections.

Macnica provides comprehensive support for implementing and utilizing Prophet AI in a manner tailored to real-world operations. Drawing on expertise from handling a diverse range of security products including EDR, SIEM, ID, cloud, email, and threat intelligence, Macnica covers PoC and technical verification. This includes selection of target alerts and data sources, organization of evaluation criteria, connection with existing operational flows, post-implementation adoption, and integration with other security products. By promoting use of Prophet AI tailored to each company’s operational realities, Macnica aims to contribute to the construction of sustainable security operational systems for Japanese companies and the strengthening of cybersecurity for society as a whole.

E

EEHerald News Desk

Editor, Electronics Engineering Herald


More from Silicon IP