|
Getting your Trinity Audio player ready...
|
Much has been said of threat actors leveraging AI tools to exploit exposures across organizations’ attack surfaces even faster and why a focus on preemptive cybersecurity, such as Continuous Exposure Management is more important than ever.
There are multiple security solutions and exposure management solutions that are “AI-powered” and leverage AI agents to complement missing features or improve efficiency. At XM Cyber we are focused on customer experience and value realization, so our new set of AI Agents is designed to help our customers minimize the window of exploitability for attackers, accelerate adoption of continuous exposure management, and improve security and IT operations.
Minimize the Exposure Window
The XM Cyber Continuous Exposure Management platform leverages AI agents internally and externally to streamline critical aspects of preemptive security for busy teams. From incorporating the very latest CVEs, to identifying priority user accounts and devices across a large attack surface, to streamlining mobilization and orchestrating remediation across teams.
Let’s take a closer look at the agents and the value they provide.

XM Researcher: The Latest Exposures, Faster, With In-Depth Context
The XM Cyber attack technique arsenal is unique in its broad coverage of exposure types, including vulnerabilities, misconfigurations, and identity and access exposures, from across the IT infrastructure. It is also unique in the in-depth information being collected and incorporated into the platform, including all the details of the exposure, its MITRE mapping, exploitability and reachability conditions, remediation guidelines and best practices.
The new XM Researcher agent consolidates the team’s cutting edge threat research into a single automated pipeline, and adds new vulnerabilities with full research data to the arsenal of the XM Cyber Continuous Exposure Management (CEM) platform. The agent allows simultaneous research, testing and validation of new exposures at a massive volume and at machine speed, accelerating the time between announcing a new CVE to analyzing it from 24-48 hours to 1-2 hours on average.
The agent also spins up a virtual machine matching the required conditions to test the exploitability of the vulnerability. With testing complete, details are automatically pushed to the threat research team for final checks. An XM Cyber expert reviews the test results to ensure all steps were properly completed and signs off for inclusion into the attack technique arsenal.
The XM Researcher is already in use by the XM Cyber research experts to give customers the most up-to-date, accurate and in-depth exposure arsenal and secure their business critical assets from the latest threats.
XM Detector: Continuous Detection of Business-Critical Assets
The primary value proposition of XM Cyber CEM platform is the ability to focus remediation efforts on those exposures that compromise critical assets, and have the highest impact on risk. Customers who do not already have their critical assets represented in a CMDB or an asset management solution often ask about the process of identifying the critical assets to their business. XM Cyber provides several mechanisms for identifying these automatically, and now there is an AI agent for just that.
The XM Detector automatically identifies and labels VIP users such as C-level executives, who are common targets for threat actors. The why is clear. VIP users often have access to sensitive information on their user accounts, drives or devices that could be of value in the wrong hands. The agent detects these key employees and their associated devices, tags them as “VIP Account” and automatically builds two attack scenarios.
The agent automatically creates two tailored scenarios in the XM Cyber platform. One which allows security teams to quickly assess the risk posed to these priority users and their devices across their hybrid environment, and the second that illustrates the blast radius if those users and devices were to be successfully compromised.
This makes it easy for security teams to continuously monitor the security posture of their VIP users and their devices and to quickly take any necessary remediation steps to fix issues. This agent is currently in Early Availability for select XM Cyber customers.

XM Operator: Automatically Generate a Streamlined Remediation Blueprint
XM Cyber already prioritizes issues based upon business impact so that busy security teams can quickly fix the highest impact exposures in their environment. Our new AI agent takes this a step further, creating a guided action plan so practitioners can start remediation efforts even faster, with minimal required investigation.
XM Operator consolidates key information including choke point score, critical asset impact and the complexity of deploying a fix and turns it into a step-by-step blueprint, meaning it is even easier to get started and address the highest business impact fixes first.
The process fully integrates standard remediation workflow options including ticket creation (e.g. Jira, ServiceNow), exporting recommendations to email to relevant stakeholders, performing further investigation of the issue before taking a decision, or declining to implement the fix at that time.
For our customers, it means a ready-to-go, prioritized action plan that automatically updates as issues are closed and new exposures are detected. In the future this agent will be extended to allow semi-autonomous operations with environment-specific remediation bundles, and opt-in recipes for low-risk changes and self-healing zones. This agent is currently in Early Availability for select XM Cyber customers.
XM Orchestrator: AI Assistant for Cross-Team Collaboration
Over the years we experienced first hand how orchestrating fixes across teams prolongs the mean time to remediate vulnerabilities. Getting the right approvals and collaborating on the why, what, when and how of IT changes can take days even when it is streamlined by a workflow engine. Each stage of the workflow requires investigation and negotiation to ensure efficiency, avoid business interruption, and comply with policy and regulations.
The XM Cyber customer services team works with large enterprises and heavily regulated industries and understands that while the objective is to close the exposure window faster, security teams cannot bypass policy-based workflows with autonomous remediation actions. That’s why the premium services team built this AI assistant that accommodates trusted, proven remediation flows while accelerating every stage in the remediation workflow.
XM Orchestrator learns the organizational structure and processes and represents the approval and operations personas who are part of the remediation workflow to automate collaboration. It simulates a conversation between fixers (IT), governance, and security to collaborate around the pros (reducing risk to critical business assets) and cons (implementation cost, bandwidth limitations, and potential interruptions) of driving action, providing all relevant data required by each stakeholder based on the exposure context and remediation guidelines from XM Cyber.
The agent is used by XM Cyber premium services team to address common delays in hand-off between teams and close the exposure windows of critical business assets with our most strategic customers.
Upcoming AI Agents: Driving Even More Efficiency Gains
We are currently working on several new AI agents that are designed to automate operations and act as a force multiplier for our customers. Some of these agents reveal unstructured multi-hop paths in the Attack Graph, automate what-if simulation of configuration and entitlements changes, run custom red team playbooks on the digital twin of the specific environment, and build custom controls into our security controls monitoring.
These will optimize exposure management, make preemptive security easier to adopt and provide better security ROI for organizations. Which means enhanced protection, less time spent on manual investigation and prioritization, and faster mean time to remediation.
The Future is Hybrid
Our mission at XM Cyber is simple. Build the most effective exposure management platform possible for our customers to help them reduce cybersecurity risk in a period where the time to react is shorter than ever before. We believe that is achieved via a hybrid approach – a combination of agentic automation to speed and scale, backed by the human touch of our industry-leading threat intel experts to deliver the best of both worlds to organizations.
For additional details about our AI usage policy, customers can read the Product Security Measures guide. To see the new AI Agents in action, request a demo.


XM Detector: Continuous Detection of Business-Critical Assets



XM Orchestrator: AI Assistant for Cross-Team Collaboration