-

ExtraHop® Closes Enterprise Data Center Blind Spots with the First NDR Platform to Run at 400 Gbps

Full-fidelity context at line rate gives autonomous agents the rapid evidence needed to match machine-speed attacks with machine-speed defense

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in real-time network intelligence and modern network detection and response (NDR), today announced the debut of its 400 Gbps sensor, making ExtraHop RevealX™ the first NDR platform to analyze enterprise data center traffic in full at the speed modern data centers actually operate. The sensor ingests and analyzes traffic at line rate, anchors a flexible detection framework for advanced threat detection, and delivers an open and extensible real-time context substrate to power the agentic SOC.

At 400 Gbps, the busiest networks in the world can hand their agents complete evidence instead of a sample, which is the difference between autonomy a CISO can defend to a regulator and autonomy that is confidently wrong at scale.

Share

"AI is compounding the volume of data moving across our infrastructure every day, and our security tooling has not kept pace with our data center," said Chris Konrad, Vice President Global Cyber, World Wide Technology (WWT). "Complete visibility at this scale is no longer optional post-Mythos. AI-powered attacks move at record speed, and the AI-powered systems need to be able to tell the difference between a quiet network and a network they are only partially seeing."

Autonomous defenses fail when an agent bases decisions on incomplete evidence. An agent fed partial telemetry can reach the wrong conclusion about an attack yet take action confidently at machine speed, across thousands of cases. The resulting audit trail might appear sound yet a breach no one can explain still occurs.

When enterprise data centers and neoclouds moved to 400 Gbps, most detection and response tools remained at 100 Gbps, sampling traffic rather than analyzing it in full, leaving significant security gaps or creating costly clustering overhead. Accelerated AI adoption has made full visibility even more challenging: GPU clusters, Kubernetes workloads, model training and inference pipelines, and agent-to-agent traffic generate dense, encrypted east-west traffic in volumes that make sampling untenable. The result is blind spots where lateral movement, living-off-the-land techniques, and identity compromise go undetected. These gaps compound as the attack window collapses: mean time to exploit has fallen from 23.2 days in 2025 to roughly 1.6 days in 2026, leaving no margin for a defense that sees only part of the wire.

ExtraHop RevealX analyzes full data center traffic at 400 Gbps and structures it into a live, continuously updated semantic map of every device, identity, workload, and conversation on the network, the instant it happens. Instead of querying the raw feed, SOC agents query discoverable, structured context through APIs and MCP— including the relationship structure of the environment. From there, agents can drill into the underlying evidence on demand: real-time behavioral detections, assets and entities, protocol metrics and activity maps, L7 transaction records across more than 90 protocols, and full-fidelity packet capture. To keep reasoning both accurate and affordable as volume grows, agents start at the highest-signal layer and examine the full details only when an investigation demands more.

"The reflex across the industry has been to bolt AI onto the SOC we already have, and the harder problem is the context substrate underneath," said Kanaiya Vasani, Chief Product Officer, ExtraHop. "SIEMs, forensic data lakes, and security warehouses are built to look backward. They are valuable as depth and memory, but they cannot be the first and only source of truth for an agent that has to decide something right now. RevealX is the prevention side of that equation: structured, queryable evidence whose latency budget matches the attack. At 400 Gbps, the busiest networks in the world can hand their agents complete evidence instead of a sample, which is the difference between autonomy a CISO can defend to a regulator and autonomy that is confidently wrong at scale."

In the recently launched Agentic SOC Alliance’s three-layer architecture — Context, Harness, and Model — the 400 Gbps sensor is the Context layer delivered at data center scale. What 400 Gbps delivers to the Context layer:

  • Complete evidence, not a sample – Full analysis at line rate means an agent’s conclusions rest on what actually happened on the wire, including the encrypted east-west traffic where modern intrusions live.
  • Real-time evidence rather than retrospective – Storage-first tools describe what already happened. ExtraHop produces evidence while the attack is still unfolding, leaving the SIEM and data lake to provide depth and history.
  • Structured and queryable context on arrival – Context arrives structured and addressable, with relationships intact, ready for agents to query through API and MCP, not as raw logs a model has to reconstruct meaning from on every turn, which lowers reasoning complexity, token consumption, latency, and cost per investigation.
  • Open context, verifiably – Evidence semantics that are published, discoverable, and addressable. Customers and third-party agents query the same surfaces ExtraHop’s own tooling uses, with no proprietary runtime required.
  • A live AI asset inventory – Continuous discovery of LLM usage, MCP servers, tool endpoints, and agent-to-agent communication paths as they appear.
  • Fewer sensors for lower total cost – 400 Gbps coverage reduces sensor count, cost, and operational complexity on high-speed networks.
  • One ground truth across SOC and NOC – Security teams, IT teams, and every agent in the environment reason over the same real-time view, with nothing to reconcile across tools.

The ExtraHop 400 Gbps sensor will be generally available in Q4 2026.

To learn more, visit ExtraHop at Fal.Con 2026 Booth #1422, or read more about the Agentic SOC Alliance and why the SOC needs a new operating model.

Additional Resources

About ExtraHop®

ExtraHop is a leader in real-time network intelligence, empowering organizations with the high-fidelity context they need to power security and IT AI automation, detect risks faster, and respond with confidence.

ExtraHop anchors AI agents with the real-time, ground-truth foundation they need to operate reliably in the SOC and NOC. For security, that means surfacing threats and providing definitive evidence to investigate and respond to novel AI attacks and unsanctioned usage at machine speed. For IT operations, it means identifying and resolving performance issues in seconds to keep critical systems running.

Engineered for unmatched scale, the ExtraHop RevealX platform delivers a complete, unified view of the network for the largest enterprises in the world. Capturing and analyzing network data across data centers, campus, branch, cloud, and AI environments, ExtraHop combines behavioral analysis with deep visibility into encrypted traffic to uncover what others miss.

To learn more, visit www.extrahop.com or follow us on LinkedIn.

© 2026 ExtraHop Networks, Inc., RevealX, RevealX 360, RevealX Enterprise, and ExtraHop are registered trademarks or trademarks of ExtraHop Networks, Inc.

Contacts

ExtraHop Contact: pr@extrahop.com

ExtraHop

Details
Headquarters: Seattle, Washington
CEO: Greg Clark
Employees: 700
Organization: PRI

Release Versions

Contacts

ExtraHop Contact: pr@extrahop.com

Social Media Profiles
More News From ExtraHop

ExtraHop® Launches the Agentic SOC Alliance to Validate a Shared Operating Model for Machine-Speed Defense

SEATTLE--(BUSINESS WIRE)--The security operations center is being rebuilt around a new operating model, one designed for machine-speed threats rather than human-speed workflows. Today, ExtraHop®, the leader in real-time network intelligence and modern network detection and response (NDR), launched the Agentic SOC Alliance initiative to define and standardize this new SOC operating model: a three-layer architecture of Context, Harness, and Model that gives autonomous security agents the evidence...

ExtraHop® Report Finds Nearly Half of Ransomware Victims Suffer Data Theft Before Detection

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today released the 2026 ExtraHop Global Threat Landscape Report, exposing the reality of modern cyber defense in the age of AI.The comprehensive analysis examines an environment where rapid AI adoption has unlocked new entry points for adversaries and accelerated their velocity, while security teams still struggle to keep pace, unable to uncover hidden threats while drowning in prolonged dwell times and...

ExtraHop® and Ignition Expand Partnership to Drive Agentic SOC Innovation Across North America

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today announced it has expanded its partnership with Ignition, operating under Exclusive Networks, in North America. As security teams increasingly turn to AI-powered defenses, they’re realizing that even the best models are sidelined by poor data, making it impossible to detect or stop threats with confidence. ExtraHop addresses this directly with its industry-leading NDR platform, which decrypts and...
Back to Newsroom