VYPR
researchPublished Sep 29, 2026· 1 source

Vega II Platform Integrates AI for Enhanced SOC Operations and Persistent Memory

Vega II, the latest platform release from Vega, introduces AI trained for security operations, aiming to improve detection, triage, and investigation with lasting memory and broader data access.

Vega has unveiled Vega II, its most significant platform update since its emergence from stealth. This new release integrates advanced AI, specifically trained for security operations, directly into the Security Operations Center (SOC). The platform aims to provide security teams with a persistent memory of learned information, enhancing their ability to detect, triage, and investigate threats more effectively. By addressing limitations inherent in traditional Security Information and Event Management (SIEM) systems and data pipelines, Vega II seeks to make critical security data more accessible and actionable.

Vega II is designed to serve as a comprehensive harness for cyber defense. It enables AI agents to autonomously manage detection, triage, and investigation processes in a continuous loop. This autonomous operation is guided by the expertise of human defenders, and crucially, the platform can ingest data from sources previously excluded from SIEMs due to integration complexities or data volume issues. Shay Sandler, CEO of Vega, emphasized that while adversaries are rapidly adopting frontier AI models, defenders can counter this trend by leveraging purpose-built AI agents, comprehensive data access, and specialized knowledge.

The "Why Now" behind Vega II stems from the accelerating pace at which adversaries are adopting new AI technologies. Defenders, conversely, often rely on reasoning models not specifically tuned for cybersecurity, lose valuable context when investigations close, and face significant hurdles in accessing data stored across disparate systems. Generic AI models, while powerful, can be slow, requiring them to reason from scratch for every alert, which is insufficient against fast-moving attackers. Vega II aims to break down these barriers, enabling AI to function with expertise it has acquired, apply learned knowledge, and investigate data sources previously out of reach.

The platform is built around two core components: the harness and the model. Agentic Cyber Defense, as envisioned by Vega, requires a purpose-built AI model, a lasting memory of the security environment, and unfettered access to all relevant data, regardless of its storage location. Vega II provides these capabilities, allowing security teams to deploy specialized AI reasoning tailored for cybersecurity challenges.

Vega's first model, purpose-built and post-trained for agentic cyber defense, operates with remarkable speed. It can reach conclusions much faster than generic AI models, ensuring that every alert receives an expert-level assessment at a scale that human teams alone cannot achieve. This speed is critical in a threat landscape where rapid response can mean the difference between containment and a significant breach.

Furthermore, Vega Memory ensures that lessons learned and environmental ground truth are persistently stored. This means that each new investigation or alert analysis can begin with the benefit of prior knowledge, avoiding the need to re-discover established facts. Engineers have granular control over what data is saved, allowing for inspection, tracing, and management of the stored information.

To address data accessibility, Vega Gateway facilitates the streaming of any data source into low-cost object storage. Utilizing protocols like OpenTelemetry, webhooks, or APIs, it bypasses the need for complex data pipelines or legacy connectors. This capability allows Vega's in-place analytics to extend to data sources that were previously inaccessible, enabling investigations to follow attackers across the entire digital footprint, even into areas traditional SIEMs could not reach.

Synthesized by Vypr AI