WELCOME
7AI × Eaton Security Operations
01 / 14

THE MODERN
SECURITY OPERATIONS CENTER

An engineering- and AI-led SOC, built for Eaton — where autonomous agents and human expertise operate as one.

Prepared for Eaton Corporation  ·  7AI

Eaton

Proven in Production

The world's largest,
most successful AI SOC

Mike Baker

"Right off the bat we've seen an 80% reduction in tier-1 analyst time. As those tickets progressed through the funnel, we've seen easily a 95–99% reduction in the tickets that human beings have to look at. Incredible outcome. We believe this is the world's largest, most successful AI SOC deployment."

DXC Technology
Mike Baker — Chief Information Security Officer

80%

Less tier-1 analyst time.

95–99%

Fewer tickets reaching humans.

Scale

Largest AI SOC deployment to date.

Customer Voices

Security leaders are reinventing the SOC

Benjamin Dulieu

"The future of cybersecurity lies in leveraging AI to not only augment human capabilities but to fundamentally reshape how security operations are conducted. This is not incremental improvement — it's a reinvention of how we protect our organization in an increasingly complex threat landscape."

Duck Creek Technologies
Benjamin Dulieu — CISO & CIO
Kyle Kurdziolek

"I've envisioned this for five years — AI handling the mundane alert triage so my team could focus on creative, strategic work. 7AI made it real, scaling our team's capacity 10x and freeing analysts from burnout to work on the challenges that actually matter."

BigID
Kyle Kurdziolek — VP of Security

Quality · Speed · Coverage

Take on more — and improve Eaton's program

Against the incumbents Eaton already knows, the conclusions match — but 7AI reaches them faster and across far more of the alert volume. That headroom is what lets us expand scope: investigate everything, raise the quality bar, and strengthen the security program rather than just maintain it.

"The stat we presented to our CIO was that 7AI fully investigated 3.5x more alerts than Red Canary."

Flagship Pioneering
Julia Starr Chang — CISO

"No discrepancies from ReliaQuest in terms of conclusions — but you're processing 10x faster."

Graphic Packaging
Andy — Security Leadership

Quality

Same expert-grade verdicts — no discrepancies.

Speed

Conclusions reached up to 10x faster.

Coverage

3.5x more alerts fully investigated — nothing skipped.

The Inflection Point

The legacy SOC
can't scale with the threat

Alert volume compounds, tier-1 analysts burn out, and dwell time stays measured in days. Adding headcount linearly against an exponential problem is a losing equation. The next SOC is not staffed bigger — it is engineered differently.

11k+Daily alerts / enterprise
~70%Alerts never reviewed
277Avg. days to contain
3.4MUnfilled security roles

The 7AI Model

Four pillars, one operating system for security

01

AI

Agentic detection & response that works the alert, not just flags it.

02

Engineering

Detection-as-code and a platform that turns tradecraft into software.

03

MDR

24/7 managed service with expert humans on the loop, not the bottleneck.

04

Roadmap

A staged journey from co-pilot to autonomous, measured at every step.

Faster

Minutes to triage, not days.

Cheaper

Effort scales sub-linearly with volume.

Better

Consistent, auditable, every time.

Pillar 01 — Artificial Intelligence

The agentic flywheel

FEDERATED DATA LAYER FEDERATED SEARCH QUERY · STORE · CORRELATE THREAT INTEL HUNT DETECT INVESTIGATE RESPOND OPTIMIZE
Threat IntelNew intelligence arrives continuously and points the next hunt. The loop starts before the alert.
HuntHypotheses run across live telemetry and widen what we can see. It expands detection.
DetectSharper detections surface signals other pipelines bury. They trigger investigation.
InvestigateAgents assemble context and return a finding. Minutes, not days.
RespondAction is taken with humans on the loop. Decisive, not reckless.
OptimizeEvery cycle tunes the loop on the shared data layer. The next turn is sharper than the last.

Pillar 02 — Engineering

The best builders, engineering for Eaton

The modern SOC runs on AI and technology — and that only works with the best people developing and building the solutions behind it. Our engineers treat Eaton's defense as a product: detection-as-code, tested in CI, continuously improved, and purpose-built to advance Eaton's security program.

Author

Detection-as-code in Git.

Test

Validated in CI against telemetry.

Deploy

Pushed across your stack.

Tune

Feedback retrains the agents.

Measure

Coverage mapped to MITRE.

AI-Native

Built on technology, not headcount.

Best-in-Class

Top engineers building for Eaton.

Program-First

Engineered to improve Eaton's posture.

PLAID ELITE / MDR

A 24/7 SOC with humans on the loop

Legacy MDR
  • Humans do tier-1 triage — slow and inconsistent.
  • Pay per analyst; cost grows with alert volume.
  • Black-box alerts forwarded over the wall.
  • SLAs measured in hours, sometimes days.
7AI Managed SOC
  • Agents do tier-1; experts focus on decisions & hunting.
  • Cost decoupled from volume — efficiency scales.
  • Full transparency: see every step the AI took.
  • Verdicts in minutes, escalations with context.

24 / 7 / 365

Always-on coverage, no gaps.

Elite Analysts

Senior expertise on every escalation.

Your Stack

Works with the tools Eaton owns.

Pillar 04 — Future Roadmap

A staged path to the autonomous SOC

Phase 1
0–90 Days

Deploy & Co-PilotFoundation

Integrate telemetry, stand up agentic triage alongside Eaton's team. AI assists, humans decide.

Phase 2
3–6 Months

Trusted Automation

Agents auto-close validated false positives and run containment playbooks within agreed policy.

Phase 3
6–12 Months

Proactive Defense

Continuous threat hunting, custom detection engineering, and exposure reduction mapped to Eaton's risk.

Phase 4
12 Months+

Autonomous SOCVision

The majority of the response lifecycle runs autonomously; humans set strategy and handle the truly novel.

In-House Expertise

We didn't start with a product.
We started with people.

Phil, AI Security Engineer at 7AI
Phil
AI Security Engineer
Juliana, AI Security Engineer at 7AI
Juliana
AI Security Engineer
Steve, AI Security Engineer at 7AI
Steve
AI Security Engineer

The platform doesn't ask you to work its way. Your AI Security Engineer builds it to work yours.

Built for Eaton

Why this fits a global industrial leader

Scale

Global Footprint

Consistent coverage across every region, plant, and business unit — IT and OT alike.

Convergence

IT / OT Aware

Detections tuned for industrial and manufacturing environments, not just cloud and corporate IT.

Assurance

Audit-Ready

Every action logged and explainable — built for regulated, board-level reporting.

The result: Eaton's security team is freed from the alert treadmill to focus on the strategic risk decisions that protect the business.

The Day Ahead

Today’s agenda

01WELCOME & OFFICE TOUR9:00 AMBarry Wray
02MODERN SOC INTRO & AGENDA9:15 AMNate Burke & Barry Wray
03AI VISION / PURVIEW EV3 DEMO9:30 AMTanner Wilkerson & Michael Tan
04PLAID: RESULTS, ADDING WORKLOADS, WHAT’S NEXT10:55 AMBarry · Phil · Steve
05PRODUCT UPDATE12:30 PMAllen Lieberman & Erika Weiler
06THREAT HUNT1:25 PMJuliana Testa
07PLAID ELITE UPDATEIsrael Barak & Christie Kelly
08ELITE FOR EATON: BUILD WORKFLOWSChristie Kelly & Josh Jones
09WRAP-UP2:30 PMBrian McDonough

Breakfast 8:30 AM · Working lunch 12:00 PM · Departure 3:00 PM

PLAID · Results, Adding Workloads, What’s Next

POV → Production

We showed you how, on your data, in three weeks. Now we are ready to get started.

Owners · Barry Wray · Phil Royer · Steve Lazzaro

Executive summary

Proof of value = partnership

In a live deployment against Eaton’s production alert stream, 7AI’s agentic investigations met the core success criteria, surfaced novel threats existing tools missed, and sharpened Eaton’s own controls.

60Days platform testing
3,328Investigations completed
98Incident types
252,201Tool executions
57,552Agent steps
8+Custom threat hunts

Requests · Integrations & Capability

What Eaton asked for, and when we delivered

Deeper CrowdStrike enrichment

Into Sentinel incidents: IOA, registry keys, reaction status.

04/20
Write-back to Sentinel

Write AI findings and recommendations as comments on the incident.

04/15 · 05/19
New detection creation

Push analytic rules to Sentinel and IOAs to CrowdStrike, not just triage.

05/04
Threat-intel-to-hunt

Ingest an advisory (e.g. npm supply-chain) and hunt the environment.

04/15
ThreatConnect tie-in

Enrich with Eaton’s intel and CrowdStrike indicators.

05/19
Impossible-travel carve-out

From the auto-close-informational rule. Still investigate.

06/08
DTEX & Dragos (OT)

Raised as future integration targets.

Post-POV
Customer reference (DXC)

Shared host-name patterns and site codes for context.

05/11

Requirements Scorecard

37 platform requirements, tracked

Every requirement Eaton defined, scored with status, comments, and a link to validate in their own tenant. The live scorecard was delivered to Eaton.

37Requirements tracked
100%Self-service validation links
3Columns added: status · comments · link
Eaton AI-Enabled SOC requirements scorecard

Where We Started

Eaton’s requirements

Close-out & volume reduction

60%+ of alerts resolved by agentic investigation. Currently at a 95% deflection rate.

Safely test new detections

Stand up and evaluate new detections safely before they reach production.

Investigation depth

Every AI investigation shows the full picture: attack chain, root cause, and blast radius.

Work with Eaton’s stack

CrowdStrike, Microsoft Sentinel & Defender, Entra ID, Purview, Zscaler all supported.

Explainable decisions

Clear, transparent reasoning provides an auditable evidence chain.

>99% uptime

Production-grade reliability across the platform.

Agentic threat hunting

Ad-hoc natural-language hunts plus ongoing IOC-based hunts in Eaton’s environment.

Enrichment as force-multiplier

Auto-enrich context across tools so analysts stop pivoting between consoles.

Insource investigations

Empower Eaton’s team to bring work in-house and use institutional knowledge.

What 7AI built

Customizations built during the PoV

Not an out-of-the-box trial, the platform was shaped to Eaton.

Ingest tuning

EDR, identity and Purview ingestion shaped with autosuppress rules hand-selected to keep the queue on real signal.

CrowdStrike → Sentinel mapping

Underlying alerts mapped across incidents so the AI reviews every layer, not just the wrapper.

Identity tuning

Impossible Travel, MFA and Insider Threat streamlined to cut investigation noise.

Privileged accounts

Eaton’s admin naming convention (adminC, adminE, …) taught to the engine so privileged-identity activity is recognized and weighted.

ResponseAction

Zscaler response action

One-click URL block wired through Zscaler for automated containment.

PUP & benign tools

Eaton’s approved-software spreadsheet, Falcon Sandbox detonation, and custom reasoning together clear PUP and benign-tool noise.

ThreatConnect connector

Built and tuned to Eaton’s custom threat-intel data sources.

MilestoneGo-live

Production cutover

Validated in staging, then promoted to production.

Threat-hunt finding · May 8

7AI found what EDR could not

An agentic threat hunt in Eaton’s environment surfaced CRXfiltrate activity that endpoint tooling did not flag. Novel-threat discovery is the difference between signature-bound tooling and agentic hunting.

Agentic threat hunt CRXfiltrate Missed by EDR
app.sevenai.com, agentic threat hunt
7AI agentic threat hunt in Eaton environment
7ai.com/crxfiltrate, threat research
7AI CRXfiltrate threat research report
Explainable by design

Real investigations from Eaton’s data

IdentityBenign · auto-resolved

Impossible Travel

China–US sign-ins hours apart for one user. The AI ran IP reputation (Spur, VirusTotal, IPinfo), found the US endpoint was clean satellite internet (ViaSat), and resolved benign instead of escalating noise.

View investigation

… and 39 other Identity FPs

EndpointBenign · auto-resolved

Developer PowerShell

powershell.exe from System32, launched by VS Code and Visual Studio dev shells running local test scripts, no encoded commands, IEX or downloads. The AI confirmed benign developer activity and closed it.

View investigation

… and 2,302 other EDR FPs

IdentityEscalated

DigitalOcean sign-in

An unfamiliar sign-in from DigitalOcean datacenter hosting, nine failed attempts, blocked by Conditional Access, on an unmanaged device. With the risk unresolved, the AI escalated for human review.

View investigation

… and 384 other escalations

Confident false-positive closes reduce noise; genuine uncertainty escalates to a human. The platform never guesses silently.

The 7AI difference

Machine speed and scale enables your team

Response flow across Eaton’s environment
People-led

Control

Eaton’s analysts stay in control. Our experienced engineers customize the agents to your business needs.

Explainable

Trust

Every determination ships with its evidence chain, conclusions you can audit and trust.

AI-driven

Speed

The platform triages, investigates and responds quickly, saving time and reducing risk.

Recommendation

Where we go from here

The PoV met its bar. The recommendation is to move to a production partnership and close the open integration items.

01 · Validate

Confirm success criteria

Confirm the 40%+ volume-reduction target and explainability bar against Eaton’s own review.

02 · Integrate

Full coverage

Stand up remaining connectors: enrichment feeds, Purview depth, and the Dragos / ExtraHop path.

03 · Respond

Graduate to write actions

Move from read-only to gated, human-approved response on agreed alert types, at Eaton’s pace.

04 · Operate

Operationalize

Lock the PLAID ELITE 24x7 model, assigned engineers, and the multi-year path with GuidePoint.

Eaton + 7AI

Coverage & Expansion

From POV scope to full coverage

June 17, 2026
At a glance

What we cover · what's next

Covered today, running in production
CrowdStrike Detections EDR Defender ATP EDR Identity Protection (AAD) Identity Purview IRM Insider · via EV3
Phase 1

MSSP parity

  • Sentinel Custom (NCI/GOV)
  • Falcon Recon
  • Checkpoint IPS
  • Zscaler DLP / Web
Phase 2

MS-native + insider

  • Cloud App Security (MCAS)
  • Defender for Cloud
  • Identity Threat (AD ATP)
  • DLP / Data Exfiltration
Phase 3

Specialized

  • CC_AI-DSPM (Copilot/AI)
  • Dragos OT / ICS
  • ExtraHop NDR
  • DTEX · UEBA
Covered today

What 7AI runs now

Prod, 14 days: ~708 Sentinel incidents auto-investigated, 86% closed without an analyst, 16% malicious.

EDR · MSSP-workedCovered

CrowdStrike Detections

Prevented & not-prevented EPP/IDP/XDR/Cloud-IOA detections, the dominant alert family. Full autonomous triage with process-lineage, VT and approved-software enrichment.

~535 incidents / 14d
EDR / EndpointCovered

Defender ATP

Microsoft Defender for Endpoint, credential-theft, malware, suspicious Office/script behavior, investigated alongside the CrowdStrike signal.

~155 incidents / 14d
IdentityCovered

Identity Protection (AAD)

Entra ID risk, impossible travel, unfamiliar sign-in, password spray, privileged-role change. Routed to the identity investigation plan.

~150 incidents / 14d
Insider ThreatCovered · EV3

Purview IRM

Insider-risk data-leak issues, investigated via Engine V3 on the custom Purview Console connector built during the POV.

~170 issues / 14d
Phase 1 · expand to

MSSP parity

The four buckets Eaton's MSSP works that 7AI doesn't yet, admit them to the allowlist to reach parity.

Multi-domain · biggest gapPhase 1

Sentinel Custom (NCI/GOV)

Eaton's own analytic rules, Kerberos error-code abuse, excessive auth failures, perimeter denies, GOV-tagged alerts. Largest single expansion; requires relaxing the GOV-drop rule.

~650 incidents / 14d
Threat Intel / brandPhase 1

Falcon Recon

Exposed-credential, typosquatting, VIP-mention and criminal-marketplace intel across Eaton/Souriau/Fibrebond. Mostly "unactionable", pair with a low-cost enrich + auto-close plan.

~200 incidents / 14d
Network / PerimeterPhase 1

Checkpoint IPS

Check Point IPS high-severity alerts. Low volume, cheap to admit, a straightforward parity win.

~6 incidents / 14d
Network / DLPPhase 1

Zscaler DLP / Web

Web & DLP events, the Zscaler ZIA connector is already wired, so enrichment depth is there from day one.

via ZIA connector
Phase 1 · expansion deep-dive

Inside Sentinel Custom (NCI/GOV)

671 incidents / 14d across 10 of Eaton's own analytic rules, 95% auto-closed by the MSSP today, none autonomously investigated.

Kerberos Error Code, UncommonT1558.003457
Medium · 99% closed
Dragos OT Monitoring, uptime (noise → suppress)84
Info · 100% closed
Cloud (Azure) Account LockoutT111074
Medium · 73% closed
Kerberos Error Code, ExcessiveT1558.00340
Medium · 83% closed
Checkpoint IPS Alerts, High6
High · 83% closed
Linux Login Failure → SuccessT1110.0015
Medium
Perimeter, Excessive Outbound FW DeniesT10713
Medium
GOV Alert: sign-in / DLPGOV2
High · dropped today
671incidents · 14d · 10 rules

Why it's the #1 expansion

  • 95% auto-closed by the MSSP, no analyst eyes, no autonomous verdict today.
  • Kerberos abuse (T1558.003) = 74%, classic Kerberoasting signal, all Medium.
  • Eaton custom rules (product Azure Sentinel), invisible to the CrowdStrike/Defender feeds we run now.
  • YARA change: add NCI: / Eaton: NCI to the allowlist + relax the GOV-drop.
Phase 2 · expand to

Microsoft-native + insider

Telemetry Eaton already feeds 7AI directly, onboard the plans to cover it.

Cloud / SaaS (MCAS)Phase 2

Cloud App Security

SaaS session anomalies, OAuth abuse, personal-account setup. Suppress the Eaton-auto-closed noise, investigate the rest.

~71 incidents / 14d
Cloud posture / runtimePhase 2

Defender for Cloud

Azure workload alerts, storage exfil, Cosmos DB key extraction, VM script abuse. Keep the IP-baseline auto-close as a suppress so only real alerts run.

~103 incidents / 14d
Identity / on-prem ADPhase 2

Identity Threat (AD ATP)

Defender for Identity, pass-the-hash/ticket, AS-REP, recon against on-prem Active Directory. Complements the AAD coverage already live.

~13 incidents / 14d
Insider ThreatPhase 2

DLP / Data Exfiltration

Sensitive-file sharing, local email collection, webmail egress, the data-movement signal that pairs with Purview IRM.

emerging volume
Phase 3 · expand to

Specialized telemetry

Full-coverage round-out, OT, network, AI-risk and behavioral sources.

Cloud / AI riskPhase 3

CC_AI-DSPM (Copilot/AI)

Prompt-shield jailbreaks, AI-app anomalies, prompt-leakage, Copilot misuse, a net-new, executive-visible risk domain.

~70 incidents / 14d
Network / OTPhase 3

Dragos OT / ICS

Operational-technology detections for the plant floor. Suppress the cert-reissue / uptime noise, investigate the real OT threats.

~190 incidents / 14d
Network detectionPhase 3

ExtraHop NDR

Wire-level network detections, lateral movement, beaconing, protocol anomalies the EDR can't see.

~18 incidents / 14d
Insider / behavioralPhase 3

DTEX · UEBA

High-risk-user scoring (DTEX) and behavioral priority (UEBA), corroborating signal that sharpens insider-threat investigations.

~20 incidents / 14d
Eaton + 7AI · Platform update

Engine V3

The autonomous investigation engine now running your alerts, from a one-step false positive to a multi-stage threat, every verdict reasoned end-to-end and backed by evidence.

Session 03 · AI Vision

AI Vision

Tanner’s AI vision.

7AI

Our AI Vision

The future of a modern, agentic SOC.
7AI01
02 / The vision

One closed loop, not a pile of point tools.

Security operations is one continuous loop, but most tools own a single stage and leave you the seams between them. Our vision: run the entire cycle as one system, with AI agents at every stage drawing on knowledge and practices encoded by elite security engineers.

01Detecttune sources, close coverage gaps
02Investigateevery alert, in full context
03Respondticket, orchestrate, or act
04Huntfind what never alerted
↺ and it compounds: verdicts tune detection, confirmed hunts become new detections, context sharpens every future call
People-Led, AI-Driven  ·  AI runs it at machine speed; your experts own the judgment
The vision: one closed loop02
03 / Our AI vision

One engine. Many modules.

We didn't build a separate AI system for triage, another for hunting, another for chat. That's the legacy trap, and it's prohibitively expensive. We built one engine (Engine v3) and express each capability as a module. As the engine improves, every module wins.

Alert Investigation
Autonomous triage of every alert
Threat Hunting
Analyst-steered, interactive hunts
Threat-Intel Hunting
IoC prevalence across your tools
Federated Search
One question, every connector
Chat w/ Investigation
Ask the case anything
Reporting
Analytics in natural language
One engine, many modules03
04 / Built for speed

New AI capabilities in weeks, on one engine.

  • A new agentic use case = a Module + Skills + a frontend. The engine provides the hard parts (memory, durable state, recovery, live streaming) for free.
  • Proof: Threat-Intel Hunting, a brand-new product, was built as a module and running end to end in about a month.
  • A production chat interface is under ten lines of code for a module owner. The platform handles the plumbing.
  • Every module that ships makes the engine better, and every engine improvement lifts every module.

This is an architecture choice that compounds, not a feature list. A new capability is weeks of work, not a new system.

New capabilities in weeks04
05 / What AI-native actually means

Purpose-built for how AI understands and accesses data.

Legacy security tools were built for people: dashboards to read, query languages to type, schemas to memorize. Bolt AI on top and it inherits a human-shaped world it has to translate. AI-native means the opposite: we build the data layer, the connectors, and the way data is described and reached for how an AI actually works.

// semantic understanding

Data that knows what it means

Fields, entities, and relationships are modeled so the AI reasons over meaning, not raw rows. It understands your environment, not just queries it.

// AI access patterns

Reached the way an agent works

The AI gets to data by intent, across every tool, querying where it lives, not through the consoles and syntax built for a person.

When the systems around the AI are built for the AI, it spends its effort investigating, not translating.

AI-native is an architecture05
06 / How the agent thinks

It works the case like a senior analyst: one hypothesis at a time.

·Hypothesizewhat would explain this alert?
·Testrun the queries that prove or disprove it
·Weighdoes the evidence hold up?
·Pivotconfirm, rule out, or form a new one
↺ hypothesis by hypothesis, until the evidence is conclusive
  • Working memory is a structured picture of the case: the agent searches it by exact indicator and by meaning, the way an analyst works an evidence board.
  • It chases independent leads in parallel where it helps, and it's bounded: it knows when to stop, not just when to go.
How the agent thinks06
07 / The logic is yours to shape

Three kinds of skill: your knobs to turn.

Connector

Shapes the query

How to query a given tool (Splunk SPL, Sentinel KQL), matched to each step.

API

Adds capability

Enrichment tools the agent can call: reputation, sandboxing, lookups.

Strategy

Shapes the plan

Investigation methodology, injected at planning. Where your team encodes how an analyst should approach a case.

Bring your own skills. Your playbooks steer the plan itself, not just the query. The SME's knowledge isn't a suggestion to the model; it's wired into where decisions get made.

The skills you can shape07
08 / Why we own the engine

We own the engine, so memory and learning live in the core.

  • Working memory, per investigation. Everything the agent learns becomes a structured picture of the case it can search by keyword, by meaning, and by relationship at once, not a scrolling chat log.
  • It learns what works, per customer. The engine records which queries actually produced answers in your environment and reuses them. That learning never crosses tenant boundaries.
  • Durable and replayable. State is recorded as it runs, so any investigation can be reconstructed step by step, or resumed if a worker dies mid-run.

A vendor wrapping a model, or bolting an assistant onto a SIEM, gets a context window and nothing else. Because we built the engine, memory and learning are first-class, not features we ask someone else's product for.

Why we own the engine08
09 / Trust by construction

Grounded in evidence, not guesswork.

// cite or clamp

It can't bluff

A finding must point to the evidence that supports it. A claim it can't ground is flagged for review, never published as fact.

// fail toward caution

It says "I don't know"

When it's unsure or a tool fails, it escalates and routes to a human, never a silent all-clear.

// tested, not assumed

It verifies

It tests hypotheses against your live data, rather than asserting from training priors.

Grounded, and it shows its work09
10 / How do we know it's right?

Graded against labeled production data, not vibes.

  • Validated on real production investigations, graded against analyst-labeled outcomes.
  • Confidence is reported as a level, High / Medium / Low, not a false-precision score.
  • Every run is replayable, so a disputed verdict can be re-examined against the exact state the engine saw.
  • Humans review and feed corrections back, so the bar keeps rising.

Most AI tools ask you to trust the verdict. We grade ours against labeled outcomes, and we'll show you the grade.

How do we know it's right?10
11 / Live demo

Now watch it work, on a real alert.

A live Engine v3 investigation of a real Microsoft Purview data-loss alert, from the moment it fires to a grounded verdict.

  • The hypothesis loop: it forms theories and tests each against real data.
  • The citations: every finding points back to the evidence behind it.
  • A verdict it can defend, with the response gated for a human.
Mike Tan, AI Security Engineer  ·  live, in the platform
Live demo11
12 / Who builds your AI

Security and AI experts, pushing the frontier together.

Cybersecurity experts and AI experts in the same room, no silos. We run aggressive applied R&D, innovating on agentic AI itself (how agents reason, remember, and plan), then aiming it at security.

AI & applied research

Build the engine

Engineers and researchers from AWS, Microsoft, MIT, and Harvard, building a novel agentic engine from the ground up, not wrapping someone else's.

Security operators

Encode the expertise

Front-line defenders from Cybereason, Carbon Black, MITRE, Unit 8200, Palo Alto Networks, and SentinelOne, with decades working real incidents.

Most vendors send a sales team. You're meeting the people who build it.

Who builds your AI12
13 / A day in the life

Two roles, one platform, built to move fast together.

AI Engineer

Builds the engine

  • Ships core capability: streaming, memory, multi-agent orchestration.
  • Benchmarks models per task (latency, precision, cost) and instruments the platform end to end.
  • Exposes clean extension points so use cases ship without touching engine internals.
AI Security Engineer

Owns the use case

  • Authors and tunes investigation strategies, encoding analyst playbooks as versioned, testable skills.
  • Replays real investigations against changes, grading against analyst-labeled ground truth.
  • The customer's technical partner: cuts false positives, onboards new alert types.
The security engineer ships a use case; if the engine needs a new capability, they file a precise request and the AI engineer exposes an extension point  ·  integration to production in days, not quarters
A day in the life13
14 / The takeaway
We're closing the loop, and we show our work the whole way.

The fully-closed, self-improving loop is the vision. What you saw is how the AI does the work today: it reasons hypothesis by hypothesis, cites its evidence, and gets sharper every cycle.

  • Can it show its work, step by step?
  • Can it cite its evidence, and say "I don't know"?
  • Can you replay any decision, and shape its judgment?
  • Does it query your data where it lives, or copy your logs?
7AI  ·  Our AI Vision14

AI Vision · Live Demo

Purview investigations with Engine V3

Mike shows a live Purview investigation with Engine V3, the work Eaton’s analysts spend hours on today. First investigation shown live; second if time permits.

Presenter is logged into Eaton’s environment; buttons open the live investigations. Owner: Michael Tan.

Session 05 · Product · 12:30 PM

Product Update

Near and mid-term roadmap (the Q2 / Q3 timeline Grace and John asked for) and agentic reporting, the piece John and Grace were most interested in. Shown in demo.

Open the Product Roadmap →

PLAID ELITE

PLAID ELITE

AI speed and scale. Human trust.

Owners · Israel Barak · Christie Kelly · Joshua Jones · Juliana Testa

Core Components

PLAID ELITE core components

AI Agent Oversight

PLAID ELITE analysts review escalated “high risk” alerts in your environment. Findings and corrections land in Notes & Investigations, then route back to you or close. Only what needs your attention is brought to you.

Elite Response

We execute response per your runbook, whether an analyst performs them, you take them, or you enable auto-response. For malicious escalated alerts with unauthorized containment, we call you directly.

Expert Collaboration

Collaborate with PLAID ELITE analysts using the Collaborate button. Analysts available 24x7 in an emergency. Human support when you need it most.

Full Coverage. No Gaps.

Every signal resolved

Customized to your context

AI agents configured for your environment, tools, workflows, and expected outcomes.

Consistent results at AI speed

Every alert investigated at machine speed. No sampling. No queue. No shift gaps.

Full transparency, every case

Every investigation documented, reasoned, and explainable. Your team sees exactly what happened.

7AI’s Role

AI speed and scale. Human trust.

01
24x7 monitoring, investigation, response

The 7AI security team operates 24x7 in collaboration with you.

02
AI agent oversight

We validate “high risk” alerts.

03
Incident response, your way

Response according to your policies and your workflows.

04
Full transparency

Detailed reasoning for every action.

Call anytime: 1-844-7AI-LINE.

Monthly Business Review

The Month in Review

Eaton’s PLAID ELITE monthly review for May 15 to June 15: alert volume, what we found, where it came from, and where we tune next. Presented live by Christie. The full review opens in its own view.

Open the Monthly Business Review →

PLAID ELITE · Tuning Review

What we found

3Noise sources confirmed
8Tuning actions
1Proactive recommendation

Confirmed false-positive clusters across your alert queue, all attributable to known, benign activity.

Three Noise Sources

Where the volume came from

Build Infrastructure · Packer Builds

CS Dropper exclusion for the eatonpacker service account and %TEMP%\winrmcp-*.tmp. Build-host device group with reduced OnWrite-ML policy. Approve build toolchain in software inventory.

CI/CD Runner · GitHub Actions

CS exclusion (OnWrite-ML Low where Runner.Worker.exe is in the process tree). Approve node.js tools (npm, esbuild, ls-lint, bare-* packages). Add APAC proxy as known-safe.

Endpoint Software · PowerToys

CS IOA exclusion for the WorkspacesWindowArranger chain. Prevention exclusion to stop the binary kill on every Workspaces launch. Approve PowerToys binaries.

Your Tuning Actions

Six actions, effective immediately

01
CrowdStrike packer account exclusion

authenticating user = eatonpacker & write path %TEMP%\winrmcp-*.tmp.

02
CrowdStrike build-host ML policy

Tag INSTANCE* hosts as packer-build-hosts; disable OnWrite-ML during build windows.

03
CrowdStrike GitHub Actions exclusion

Exclude OnWrite-ML Low where Runner.Worker.exe is in the process tree + actions-runner write path.

04
CrowdStrike PowerToys IOA + prevention

IOA exclusion for the WorkspacesWindowArranger chain; prevention exclusion to stop the binary kill.

05
Software inventory approvals

Build toolchain, node/npm/esbuild/ls-lint/bare-*, PowerToys binaries, PCMover, Nexthink nxtcod.exe.

06
Network: add APAC proxy

proxy.apac.etn.com / 151.110.126.120:8080 as a known-safe destination.

Proactive Opportunity

Silence noise before the queue

Eaton’s internal tools follow consistent version-stamped naming patterns (EatonStatPro, EatonW1, Kit_Tracker and others). They are high-noise because they are never in the approved inventory.

Scope an EI rule

Auto-approve executables matching your internal naming convention. This silences future noise before it reaches the queue, with no per-tool approval needed.

Immediate add

PCMover and Nexthink RemoteActions (nxtcod.exe) are also generating volume. Add to the approved catalog now.

What’s Next

Three steps

01
Implement tuning

Apply the six actions. CrowdStrike changes are effective immediately, no host restart required.

02
Design the EI rule

Work with 7AI to scope an Emerging Intelligence rule for the internal tooling naming pattern.

03
30-day follow-up

PLAID ELITE monitors impact. Expect measurable alert-volume reduction within the first week.

Placeholder · Content Pending

PLAID ELITE · Threat Hunt

Live Threat Hunt

Presented live in Eaton’s environment.

Tagged to resolveJuliana Testa. Live hunt; cover only.

Build Workflows · Platform Primer

Three concepts to know first

What is a Workflow?

A saved sequence of actions you build once and run on demand or automatically. A repeatable playbook: enrich this host, post to Slack, open a case. You define it once; the platform runs it every time.

What is a Trigger?

The event that fires a workflow automatically and turns it into an orchestration. Pick a trigger type (case updated, investigation completed) and add a condition so it fires only when criteria are met.

What is Dynamic Calling?

The single setting that controls how much a workflow does on its own when the engine considers it as a response action.

Trigger Reference

When does a workflow fire?

You click Run · Manual

An analyst starts the workflow from the Workflows tab. For ad-hoc enrichment, on-call paging, or any action that needs human judgment first.

Case Updated · Orchestration

Fires when a case is created or updated. Pair with a condition like severity is critical to run only on the cases that matter.

Alert Linked to Case · Orchestration

Fires the moment a new alert or incident is linked to a case, the earliest possible point in the investigation.

Dynamic Calling

You control how much it does on its own

Automatic · platform acts

The engine executes without asking anyone. For enrichment, notifications, case creation, and low-risk actions where speed is the priority.

Confirmation required · analyst approves

The engine surfaces a one-click approval. For device isolation, account disablement, any action with real-world impact that deserves a second set of eyes.

Skipped · engine stands down

The workflow is available but the engine will not call it automatically.

Common Workflows

From notification to containment

01 · Notification · Analyst email

When a case hits High or Critical, the assigned analyst is emailed with context before they open the platform. No critical case goes unnoticed. (Automatic)

02 · Containment · Phishing response

On a phishing alert: quarantine the email from all inboxes, block the sender domain, and notify the user, simultaneously. Exposure closes in seconds. (Automatic)

03 · Containment · Guarded host isolation

Before isolating any device, the workflow runs guard checks first, then isolates with the right approvals.

Wrap-Up

Wrap Up

Open Discussion

← → / Space  ·  Swipe  ·  Type # + Enter