-

Stellar Cyber Agentic AI Auto-Triage Agrees With Human Analysts 99.7% of the Time in Customer Trials

Independent report shows Agentic AI security alert prioritization returns one day per week to human analysts—enabling them to work more cases per shift, improve MTTD and MTTR, and focus on preemptive exposure management—while handling the equivalent of 1.5 full-time analysts’ annual workload.

SAN JOSE, Calif.--(BUSINESS WIRE)--Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its award-winning Agentic Auto Triage capability. The independent study based on customer trials evaluated 138,475 real security alerts and reached the same verdict as human analysts 99.7% of the time. The findings, drawn from customer-submitted end-of-trial reports, addressed the central question facing every security team weighing autonomous SOC technology: Can AI actually be trusted to make decisions?

AI-driven tools have made it easier than ever for adversaries to design highly convincing phishing and ransomware attacks. In response, organizations have doubled down on security awareness and training, resulting in a surge in reports of potential threats. The World Economic Forum reports potential security threats have surged dramatically over the last two years, with ransomware attacks jumping by up to 48% year-over-year and phishing attempts exploding by 1200% since late 2022. This escalation is largely driven by GenAI-enhanced tactics. Automatic Triage, powered by Agentic AI, levels the playing field for human security analysts by automatically ingesting, correlating, analyzing, and prioritizing suspicious events from the user’s environment.

Finding #1: Auto Triage returns 19 minutes of every hour, translating to 1 day a week of productivity

Across the trials, Auto Triage returned roughly 19 minutes of every analyst hour to higher-value work, including working more cases per shift and dedicating more time to exposure management, anticipating adversary behavior, and closing exposures. This time translates to about one day per week per analyst, or the equivalent of 1.5 full-time analysts reclaimed annually. By closing out confident false positives and surfacing real threats before a human ever opens them, Auto Triage reduces noise, helps teams move from an alert-centric mode to a case-management mode, and transforms the job of the human security analyst. This shift helps improve MTTD and MTTR while giving analysts time to think like attackers, anticipate likely attack paths, and close visible gaps before they are exploited.

“Security operations have reached a tipping point. The volume and complexity of alerts are simply beyond what human analysts can manage alone," said Aimei Wei, Chief Technology Officer at Stellar Cyber. "This real-world study proves that our approach of combining machine-speed analysis with human judgment is the right way forward. These results show what that looks like in practice: the AI does the alert work at scale, the analyst stays in control, and they almost always agree—freeing analysts to manage more cases and get ahead of emerging exposure.”

Finding #2: 64% of False Positives closed; 15% of True Positives escalated

Using machine learning models trained on real-world phishing patterns, the platform delivers reliable, actionable verdicts in seconds. Auto Triage assigns each alert a decision through an AI-driven Verdict Signal Check, with human-in-the-loop oversight and a closed-loop learning process that improves accuracy over time.

During the trials, the system analyzed 138,475 alerts, disposing of 64% of them as confident false-positive closures. Auto Triage escalated 15% of the alerts as true positives for human analyst review, and routed the remainder as informational, clearing noise before it reached a person.

“The Agentic AI built into Auto Triage is designed to address one of the most pressing challenges security analysts deal with on a daily basis: tuning out the noise and focusing on legitimate threats to the business,” said Christopher M. Steffen, CISSP, CISA, CCZT, VP of Research, Information Security, Risk, and Compliance Management at EMA. “This study proves that Stellar Cyber’s approach of automatic ingestion and analysis, AI-driven prioritization, and highly accurate decision-making has the power to transform the way analysts work in the enterprise SOC—from processing alerts to managing cases, moving from MTTD and MTTR, towards MTTN - mean time to neutralize, and spending more time proactively reducing exposure.”

Lean security teams at enterprise SOCs and MSSPs face mounting alert volumes without the budget to scale headcount. For MSSPs, reclaimed analyst capacity translates directly into broader coverage, better customer service, and protected margins.

"The results from this study underscore what we’ve experienced in our own SOC. For an MSSP, the math of human-only security operations simply can’t scale against today's alert volumes,” said Chant Vartanian, Chief Executive Officer, M-Theory Group. “Auto Triage effectively returns a full day of productivity per analyst and successfully closes 64% of false positives. That data is truly transformative for organizations like ours. It allows us to shift our team's focus to high-value threat investigation and exposure management, work more cases per shift, which directly improves our service margins and enables us to provide broader, more consistent coverage for our clients without the need for costly headcount expansion.”

Auto Triage is available now as part of the Stellar Cyber AI-native SecOps platform. The full trial methodology and results are available here. Stellar Cyber will showcase Auto Triage and the results of this independent study live at Black Hat USA, August 1-6, 2026, in Las Vegas.

About Stellar Cyber

Stellar Cyber is a full-cycle AI-native SecOps platform purpose-built for MSSPs and lean enterprise security teams. Since 2015, Stellar Cyber has helped organizations illuminate the darkest corners of cybersecurity to see every threat, know what matters most, and act with speed and confidence — always with the human in the loop.

By applying the right tool to the right problem, Stellar Cyber combines machine learning to uncover hidden anomalies, agentic AI to guide responses in real time, and human-augmented decision-making where expertise is essential. The result is real-world impact: analyst productivity improved by more than 80%, false positives reduced by over 90%, and security teams free to focus on what matters.

Stellar Cyber’s open SecOps platform unifies SIEM, NDR/OT, ITDR/UEBA, detection, investigation, triage, response, and Multi-Layer AI™ under one license. Stellar Cyber is trusted by one-third of the world’s top 250 MSSPs and over 15,000 organizations worldwide.

Learn more at stellarcyber.ai.

Contacts

Stellar Cyber Media Inquiries:
Michelle Barry
Chameleon Collective for Stellar Cyber
Michelle.barry@chameleon.co
+1 (603) 809-2748

More News From Stellar Cyber

Stellar Cyber and M-Theory to Demo Proof-Based AI SOC at Black Hat USA 2026

SAN JOSE, Calif. & LOS ANGELES--(BUSINESS WIRE)--Stellar Cyber, Stellar Cyber, the full-cycle AI-native SecOps platform company, and M-Theory Group, a leader in business-aligned IT infrastructure, cloud and cybersecurity solutions, today announced that M-Theory will participate with Stellar Cyber as its Managed Detection and Response (MDR) partner at Black Hat USA 2026. Together, the companies will demonstrate how a co-managed, AI-powered SOC can help enterprises, lean security teams and MSSPs...

Stellar Cyber Names Brite, Inspira and M-Theory as First Infinity Delivery Partners

SAN JOSE, Calif.--(BUSINESS WIRE)--Stellar Cyber today announced that Brite, Inspira and M-Theory are the first partners approved to deliver services through its award-winning Infinity Delivery Partner Program, a partner services model designed to help qualified partners take a larger role in customer success by delivering advanced deployment, integration, tuning, automation, and operational services across the Stellar Cyber AI-native SecOps platform. The Infinity Delivery Partner Program is bu...

Stellar Cyber Named a Top 3 XDR Solution by EMA, Recognized for Delivering Operational Outcomes with Its Fully Cyber AI Native SecOps Platform

SAN JOSE, Calif.--(BUSINESS WIRE)--Stellar Cyber, the Full Cycle AI Native SecOps Platform company, today announced that it has been named a Top 3 solution in the EMA Top 3 Buyer’s Guide for Extended Detection and Response (XDR). EMA recognized Stellar Cyber as one of the Best for the Mid-Market solutions and also named Stellar Cyber a Top 3 solution for connector breadth, cross-domain telemetry, and coverage gap visibility. EMA selected Stellar Cyber because of its open architecture, ability t...
Back to Newsroom