Threat Research Partner-ready

CRXfiltrate / Channel Kit

Co-sell talking points and a partner-angle one pager for GuidePoint Security, Myriad360, DXC AdvisoryX, and any partner who is selling proactive threat hunting alongside 7AI.

TLDR for partners

CRXfiltrate is a clean, defensible case study that proves the value of proactive threat hunting against raw telemetry. It surfaces a gap that exists in nearly every customer's current stack, regardless of which EDR, SIEM, or SOAR they run. For partners, this is your opening to position 7AI inside a customer's existing security architecture as the layer that catches what their alert pipelines miss. The conversation is technical, the proof is concrete, and the IOCs are already public and shareable.

Use with
CISO / SOC Director
Deal stage
Discovery / Demo
Best paired with
PLAID ELITE pitch
7AI partner channels
GP / Myriad / DXC

The opening

Lead a CISO conversation with this:

"We have a new piece of threat research that lands a point our customers tend to find uncomfortable but useful. The 7AI Threat Research Team disclosed a browser extension cluster running a JavaScript Execution Backdoor that bypasses Manifest V3 protections. It is live in enterprise environments today. The interesting part for the SOC conversation is that across the environments where this was running, the right telemetry already existed. DNS queries flagged. Endpoint sensors saw it. The alert pipelines never surfaced it. Worth fifteen minutes of your time?"

That framing does three things. It positions you as bringing field intel, not pitching a product. It surfaces a real gap in detection that nearly every customer has. And it opens the door to the proactive threat hunting conversation, which is where 7AI's PLAID ELITE differentiation actually lives.

Why this is a partner-friendly story

  • Stack-agnostic. CRXfiltrate evades every major EDR equally well, regardless of vendor. You are not asking the customer to replace anything. You are explaining a layer above what they already have.
  • Defensible technical detail. The mechanism (declarativeNetRequest CSP strip, DOM injection, identity harvesting) is documented at the source-code level. If a customer security engineer pushes, you have published proof.
  • Public IOCs. Your customers can deploy the YARA and Suricata rules immediately. That is a tangible deliverable from the meeting, not a follow-up.
  • No competitor naming required. The story is "your existing stack" generically. No need to compare 7AI to a named competitor.

Three pivots into a 7AI conversation

Pivot 01

From the gap to PLAID ELITE

If the CISO accepts that the gap exists, the next question is what to do about it. PLAID ELITE is fully managed agentic security operations with continuous proactive hunting built in. That's the answer.

"The gap CRXfiltrate exposes is structural. It exists in stacks running the best EDR and the best SIEM on the market. The work of running proactive hunts against raw telemetry on a continuous basis is real labor that nobody has the staff for. That is exactly the work PLAID ELITE handles. AI agents do the hunting against your environment continuously, and 7AI security engineers add the judgment when something needs human review."
Pivot 02

From the gap to a hunt service engagement

For partners running professional services or managed services alongside 7AI, this becomes an immediate engagement opener. You can offer a focused hunt as a paid engagement on top of 7AI's platform.

"Want us to run a CRXfiltrate-specific hunt across your environment as a starting point? It's a tight scope: a known IOC set, public detection rules, and our team can have results back to you in a week. If we find something, you have a finished investigation to act on. If we don't, you have validated coverage for one of the most active browser-based threats in production right now."
Pivot 03

From the gap to a wider portfolio

If the customer is buying through your portfolio, CRXfiltrate becomes a proof point for the broader proactive defense story you're already selling. 7AI slots in as the agentic layer.

"You're already investing in proactive defense across endpoint, network, and identity. The CRXfiltrate story is what happens when those investments are working but the surfacing layer above them isn't. 7AI is the layer that closes that gap. Their threat research team operates inside our customers' environments at scale, and the platform brings every signal forward to the queue."

What to send the customer after the meeting

If they are technical

Send the full research page and the IOC + detection rules bundle. Their security engineering team will appreciate the depth.

If they are executive

Send the one pager and the slide. Both are designed to be read in under five minutes and to hand to an internal stakeholder.

Partner-specific notes

GuidePoint Security

Pair with the proactive defense practice conversation. CRXfiltrate strengthens the case for hunting as a continuous discipline rather than a periodic engagement. GuidePoint AEs running PLAID ELITE conversations should lead with this story.

Myriad360

Pair with cloud-first security architecture conversations. CRXfiltrate's delivery mechanism (page-served, browser-based) is the kind of threat that traditional perimeter stacks were never designed for. Position 7AI as the cloud-native layer.

DXC AdvisoryX

DXC is the world's largest 7AI deployment. The CRXfiltrate story is operational proof of what scale plus agentic hunting produces. Use DXC's deployment as the implicit reference. The Mike Baker fireside at Gartner reinforces this.

All partners

Deal registration goes through your standard 7AI partner portal flow. Reach out to partners@7ai.com if you need a 7AI rep on the meeting. Channel-sourced pipeline is now 45% of total and growing 7x quarter over quarter, so we are heavily resourced to support partner-led conversations.