<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Varonis Blog</title>
    <link>https://www.varonis.com/blog</link>
    <description>Insights and analysis on cybersecurity from the leaders in data security.</description>
    <language>en</language>
    <pubDate>Wed, 30 Sep 2026 18:00:54 GMT</pubDate>
    <dc:date>2026-09-30T18:00:54Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Varonis and Cohesity: Improving Cyber Resilience with Data Security</title>
      <link>https://www.varonis.com/blog/varonis-and-cohesity</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/varonis-and-cohesity?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_Varonis-Cohesity_202609.png" alt="Varonis and Cohesity address the gap between data security and cyber resilience" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Backup datasets often contain sensitive information —&amp;nbsp;from &lt;a href="https://www.varonis.com/blog/prevent-pii-exposure?hsLang=en"&gt;PII&lt;/a&gt; to intellectual property — and a wide range of business-critical data. Without visibility into their backups, security teams are left with a blind spot that increases the blast radius and impedes cyber recovery.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Backup datasets often contain sensitive information —&amp;nbsp;from &lt;a href="https://www.varonis.com/blog/prevent-pii-exposure?hsLang=en"&gt;PII&lt;/a&gt; to intellectual property — and a wide range of business-critical data. Without visibility into their backups, security teams are left with a blind spot that increases the blast radius and impedes cyber recovery.&lt;/p&gt; 
&lt;p&gt;Together, &lt;a href="https://www.varonis.com/data-security-platform?hsLang=en"&gt;Varonis&lt;/a&gt; and &lt;a href="https://www.cohesity.com/"&gt;Cohesity&lt;/a&gt; close that gap, pairing deep insight into backup data with stronger security and faster recovery.&lt;/p&gt; 
&lt;p&gt;Varonis integrates with Cohesity to combine proactive data security with cyber resilience, surfacing what’s inside backup data, automating remediation, detecting threats, and enabling secure recovery.&lt;/p&gt; 
&lt;h2&gt;How Varonis and Cohesity reduce risk and strengthen resilience&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;Varonis and Cohesity address the gap between data security and cyber resilience, from discovery through recovery. Each layer builds on the last:&lt;/p&gt; 
&lt;h3&gt;Discover and classify sensitive data&lt;/h3&gt; 
&lt;p&gt;Varonis automatically discovers and classifies sensitive and regulated data across Cohesity Data Cloud, helping organizations identify risk, reduce data exposure, strengthen cyber resilience, and accelerate recovery efforts. Continuous visibility into sensitive data supports compliance, retention requirements, and AI readiness.&lt;/p&gt; 
&lt;h3&gt;Lock down access and shrink the blast radius&lt;/h3&gt; 
&lt;p&gt;Overexposed data is a breach waiting to happen. Varonis maps your entire permissions structure, providing visibility into where data resides, who has access to it, and who's using it. From there, you can enforce &lt;a href="https://www.varonis.com/blog/why-polp-is-critical-for-ai-security?hsLang=en"&gt;least privilege&lt;/a&gt;: managing&amp;nbsp;access at a granular level and safely automating&amp;nbsp;permission changes, while shrinking&amp;nbsp;the blast radius with minimal effort.&lt;/p&gt; 
&lt;h3&gt;Detect and stop threats in real time&lt;/h3&gt; 
&lt;p&gt;Varonis builds &lt;a href="https://www.varonis.com/blog/user-entity-behavior-analytics-ueba?hsLang=en"&gt; baseline behavioral profiles &lt;/a&gt; for users and non-human identities, then continuously monitors for the activity that signals an attack, including suspicious data access, lateral movement, and privilege escalation. When something looks wrong, Varonis can alert your team&amp;nbsp;and leverage automated responses to prevent data from being affected, like shutting down user sessions and changing passwords, with no wait for manual triage.&lt;/p&gt; 
&lt;p&gt;And for organizations that want 24x7 coverage, &lt;a href="https://www.varonis.com/platform/mddr?hsLang=en"&gt;Varonis Managed Data Detection and Response (MDDR)&lt;/a&gt; provides expert-led monitoring, investigation, and response to help stop threats before they impact critical data.&lt;/p&gt; 
&lt;h3&gt;Contain ransomware and recover fast&lt;/h3&gt; 
&lt;p&gt;If &lt;a href="https://www.varonis.com/blog/how-to-prevent-ransomware?hsLang=en"&gt;ransomware&lt;/a&gt; reaches your data, the two platforms work together to contain and recover. Varonis flags the abnormal file activity that signals encryption and triggers an automated response to lock it down. Cohesity hardens the data itself with AES-256 encryption, multifactor authentication, DataLock for WORM and FIPS-compliant encryption.&lt;/p&gt; 
&lt;p&gt;And because Cohesity keeps unlimited, fully hydrated snapshots, you can mass-restore files, VMs and application objects almost instantly, cutting recovery time from days to minutes.&lt;/p&gt; 
&lt;h3&gt;Optimize cost&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=94YvYjHdCxo"&gt;Varonis Data Lifecyle Management&lt;/a&gt; continuously identifies redundant, obsolete, and trivial (ROT) data, helping organizations safely archive or dispose of data that no longer provides business value. By shrinking the amount of data stored and protected in Cohesity, customers can improve storage efficiency, reduce infrastructure costs, and maintain a cleaner, more manageable data estate while preserving compliance and security requirements.&lt;/p&gt; 
&lt;h2&gt;Complete visibility, protection, and recovery&lt;/h2&gt; 
&lt;p&gt;Security teams work faster when the picture is unified. By continuously identifying sensitive, stale, and overexposed data, Varonis helps organizations reduce cyber risk before an incident occurs and provides the context needed to prioritize recovery efforts when one does.&lt;/p&gt; 
&lt;p&gt;Cohesity gives you a single UI and enterprise search across silos, VMs, backups, data centers, remote sites, and multiple clouds. Varonis layers on the context that makes that data defensible: classification, automated remediation, threat detection, and ROT reduction.&lt;/p&gt; 
&lt;p&gt;Together, Varonis and Cohesity deliver a unified approach to data security and cyber resilience, helping organizations protect sensitive data throughout its lifecycle.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fvaronis-and-cohesity&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 30 Sep 2026 15:04:57 GMT</pubDate>
      <guid>https://www.varonis.com/blog/varonis-and-cohesity</guid>
      <dc:date>2026-09-30T15:04:57Z</dc:date>
      <dc:creator>Dan Petrillo</dc:creator>
    </item>
    <item>
      <title>AI Security Fundamentals: The Real Industry Shift Taking Place</title>
      <link>https://www.varonis.com/blog/ai-security-fundamentals</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/ai-security-fundamentals?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_Securing%20AI%20vs.%20AI%20security.png" alt="Using AI to enhance security measures is the new standard." class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Key takeaways&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;"Security for AI" isn't a distinct discipline.&amp;nbsp;AI systems need the same governance, access controls, and monitoring as everything else in the stack.&lt;/li&gt; 
 &lt;li&gt;Adopting AI often functions as an unplanned pen test, exposing pre-existing weaknesses like excessive permissions, weak identity controls, and poor data classification.&lt;/li&gt; 
 &lt;li&gt;AI's real advantage for defenders isn't securing AI itself — it's using AI to finally process, prioritize, and act on security data at a scale humans never could.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI adoption is forcing organizations to confront problems they've ignored for years, especially around data governance, identity management, and access controls. The real story isn't how to secure AI as its own category — it's how AI is exposing those long-standing gaps, and how it's finally giving defenders a way to keep up.&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;Key takeaways&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;"Security for AI" isn't a distinct discipline.&amp;nbsp;AI systems need the same governance, access controls, and monitoring as everything else in the stack.&lt;/li&gt; 
 &lt;li&gt;Adopting AI often functions as an unplanned pen test, exposing pre-existing weaknesses like excessive permissions, weak identity controls, and poor data classification.&lt;/li&gt; 
 &lt;li&gt;AI's real advantage for defenders isn't securing AI itself — it's using AI to finally process, prioritize, and act on security data at a scale humans never could.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI adoption is forcing organizations to confront problems they've ignored for years, especially around data governance, identity management, and access controls. The real story isn't how to secure AI as its own category — it's how AI is exposing those long-standing gaps, and how it's finally giving defenders a way to keep up.&lt;/p&gt; 
&lt;p&gt;Varonis recently sat down with cybersecurity leaders Mike Privette, the mind behind &lt;a href="https://www.returnonsecurity.com/"&gt;Return on Security,&lt;/a&gt;&amp;nbsp;and Matt Lock, former Field CTO at Varonis,&amp;nbsp;to unpack how AI is reshaping both sides of that equation. Here are the key takeaways from their conversation.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Security for AI vs. AI for security&lt;/h2&gt; 
&lt;p&gt;It boils down to this: Security for AI isn’t distinctive,&amp;nbsp;it’s security. AI systems are simply another piece of an organization’s technology stack that require the same governance, &lt;a href="https://www.varonis.com/blog/agent-intent-based-access-control?hsLang=en"&gt;access controls&lt;/a&gt;, monitoring, and protection as the rest.&lt;/p&gt; 
&lt;p&gt;When AI was first introduced, early security efforts took a narrow view: protecting chatbots and models, preventing leakage, securing system prompts. That&amp;nbsp;didn't last. The industry quickly moved from protecting AI to using AI to supercharge cybersecurity.&lt;/p&gt; 
&lt;p&gt;It's&amp;nbsp;the same trajectory cloud computing took. Companies once marketed themselves as &lt;em&gt;cloud companies, &lt;/em&gt;but today, using the cloud is simply assumed. Matt expects AI to reach that same point, where the question isn't whether a product uses AI, but whether it delivers better security outcomes because of it.&lt;/p&gt; 
&lt;h2&gt;Why AI exposes existing weaknesses&lt;/h2&gt; 
&lt;p&gt;An organization adopting AI opens itself up to what Mike calls “unexpected pen tests," because they&amp;nbsp;quickly face a reality check on the level of &lt;a href="https://www.varonis.com/blog/agentic-ai-security-risk?hsLang=en"&gt;unintended access an agent could have&lt;/a&gt;. That's because deploying tools like &lt;a href="https://www.varonis.com/blog/microsoft-copilot-security-product?hsLang=en"&gt;Copilot&lt;/a&gt; or &lt;a href="https://www.varonis.com/blog/claude-coverage?hsLang=en"&gt;Claude&lt;/a&gt;&amp;nbsp;reveal excessive permissions, weak identity controls, poor data classification, and other&amp;nbsp;issues. &amp;nbsp;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Agents accessing systems autonomously may also discover pathways security teams would not have otherwise anticipated. And for agents to do so in split seconds means that a sole bad actor with access to an organization’s unsecured AI can do serious damage in a short amount of time.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;AI vs. AI: The new security arms race&lt;/h2&gt; 
&lt;p&gt;Thanks to AI, attackers are seeing increases in both speed and scale. Matt&amp;nbsp;points out that cybercriminals don’t care about compliance, governance, or guardrails. They’ll do whatever it takes to get what they’re after. In many cases, that’s data.&lt;/p&gt; 
&lt;p&gt;For decades, cybersecurity has largely been reactive. AI may offer the first technology that allows defenders to be proactive. With things like automated detection, &lt;a href="https://www.varonis.com/platform/mddr?hsLang=en"&gt;24/7 monitoring&lt;/a&gt;, preemptive phishing takedowns and automated investigations, the playing field has certainly leveled.&lt;/p&gt; 
&lt;p&gt;Matt and Mike also propose an interesting tactic: making attacks too expensive for attackers. Strategies like AI honeypots and AI labyrinths can waste attacker time, burn through an attacker’s tokens, and force attackers through useless paths.&lt;/p&gt; 
&lt;h2&gt;Using AI to supercharge security&lt;/h2&gt; 
&lt;p&gt;AI’s biggest impact is enabling defenders to operate at machine speed. Security teams generate enormous amounts of data but struggle to sort through it manually.&amp;nbsp;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;With AI, security teams can easily:&amp;nbsp;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Investigate alerts&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Correlate signals&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Add context&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Reduce false positives&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Surface only meaningful threats&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Rather than having SOC analysts review everything, &lt;a href="https://www.varonis.com/blog/using-ai-to-investigate-security-alerts?hsLang=en"&gt;AI can help ensure only prioritized incidents reach humans&lt;/a&gt;.&lt;/p&gt; 
&lt;h3&gt;Vulnerability prioritization&lt;/h3&gt; 
&lt;p&gt;Matt also argues that the hard part isn’t finding the vulnerabilities, it’s fixing and prioritizing them. Historically, cybersecurity has been constrained by human capacity. AI changes that by helping enterprise security teams process more data, analyze more signals, reduce response time, and scale expertise across the security team.&lt;/p&gt; 
&lt;p&gt;The future of cybersecurity, then, is about knowing which ones are important.&lt;/p&gt; 
&lt;h2&gt;Security fundamentals still win&lt;/h2&gt; 
&lt;p&gt;Despite the excitement around AI security, the conversation repeatedly comes back to the same thing: organizations need to focus on the fundamentals. Every AI initiative relies on accurate permissions, clean identity models, and data governance.&lt;/p&gt; 
&lt;p&gt;Data and identity remain the core problems behind cybersecurity. An organization without control over their data, identity, and access opens themselves to immense risk. Matt has preached this to other cybersecurity professionals for over a decade, but he's only now hearing others say&amp;nbsp;the same thing back to him. &amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;The real AI security shift&lt;/h2&gt; 
&lt;p&gt;For all the discussion around agents, autonomous systems, vulnerability discovery, and AI-powered attacks, Matt and Mike repeatedly return to the same conclusion: AI is changing cybersecurity, but it's not changing &lt;em&gt;what&lt;/em&gt; cybersecurity is trying to accomplish.&lt;/p&gt; 
&lt;p&gt;The industry’s first reaction to AI was to ask: How do we secure AI? The more important question turned out to be: How do we use AI to solve security problems we've struggled with for decades?&lt;/p&gt; 
&lt;p&gt;If their predictions hold true, the future of cybersecurity won't be defined by who adopts AI first. It'll be defined by who uses it to solve the problems that have been there all along.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Watch their&amp;nbsp;full conversation:&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;div class="hs-responsive-embed-wrapper hs-responsive-embed" style="width: 100%; height: auto; position: relative; overflow: hidden; padding: 0; max-width: 1280px; max-height: 720px; min-width: 256px; margin: 0px auto; display: block;"&gt; 
 &lt;div class="hs-responsive-embed-inner-wrapper" style="position: relative; overflow: hidden; max-width: 100%; padding-bottom: 56.25%; margin: 0;"&gt;
  &lt;iframe class="hs-responsive-embed-iframe" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border: none;" src="https://www.youtube.com/embed/ZJZ7NqMrbTk?si=W0sEu1kBTb5OqF7A" width="1280" height="720" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fai-security-fundamentals&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI Security</category>
      <pubDate>Fri, 25 Sep 2026 18:27:54 GMT</pubDate>
      <guid>https://www.varonis.com/blog/ai-security-fundamentals</guid>
      <dc:date>2026-09-25T18:27:54Z</dc:date>
      <dc:creator>Jonathan Villa</dc:creator>
    </item>
    <item>
      <title>Meet AvisLoader: A Windows Loader Built to Outlast a Takedown</title>
      <link>https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_VTL-AvisLoader_202609.png" alt="AvisLoader" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/varonis-threat-labs?hsLang=en"&gt;Varonis Threat Labs&lt;/a&gt; recently discovered AvisLoader, a new Windows loader named after the Latin word for bird. We found it on an exposed staging server alongside a ClickFix lure, supporting tools, and its Command Center.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;a href="https://www.varonis.com/varonis-threat-labs?hsLang=en"&gt;Varonis Threat Labs&lt;/a&gt; recently discovered AvisLoader, a new Windows loader named after the Latin word for bird. We found it on an exposed staging server alongside a ClickFix lure, supporting tools, and its Command Center.&lt;/p&gt; 
&lt;p&gt;The attack starts with a familiar ClickFix lure. A page posing as a document-signing request asks visitors to copy and run an attacker-supplied command on their machine.&lt;/p&gt; 
&lt;p&gt;The more interesting part is how AvisLoader stays connected. It communicates via Tox, an encrypted peer-to-peer (P2P) messaging network that carries commands and additional payloads from the operator.&lt;/p&gt; 
&lt;p&gt;That setup makes traditional domain-based takedowns harder. The command-and-control (C2) channel does not depend on a fixed domain or server address, and operators can keep the same identity when moving to another server.&lt;/p&gt; 
&lt;p&gt;The seller references this in a cybercrime forum listing, claiming the controller can be moved by copying its Tox save file, with clients following without the need for a domain.&lt;/p&gt; 
&lt;p&gt;In this post, we look at how AvisLoader works, the MITRE ATT&amp;amp;CK techniques it uses, and the indicators security teams can use to detect it.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Delivery through ClickFix and Cloudflare&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The specific ClickFix lure we found alongside AvisLoader was hosted on Cloudflare Workers and made to look like a DocuSign signing request.&lt;/p&gt; 
&lt;p&gt;A fake “Manual verification” dialog claims “Verification is handled by Cloudflare” and asks visitors to paste a “verification code” into a terminal. It presents running the command as a step needed to access the document.&lt;/p&gt; 
&lt;p&gt;What lands on the clipboard is a command that retrieves and runs code from a Cloudflare Quick Tunnel address on trycloudflare.com. A download still takes place, but through the pasted command, outside the browser’s normal download flow.&lt;/p&gt; 
&lt;p&gt;Although the lure shows a macOS command, the exposed directory contained a Windows loader. We did not find a corresponding macOS payload among the recovered files.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Inside the loader&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The Windows payload is a single 3.4 MB 64-bit executable. Its manifest specifies asInvoker, meaning it inherits the privileges of the process that launches it without requesting User Account Control (UAC) elevation at startup.&lt;/p&gt; 
&lt;p&gt;Its section table contains seventeen additional sections of identical size, with names associated with well-known packers, including Themida, VMProtect, Enigma, and UPX. None is marked executable. These names appear intended to confuse packer identification, although the names alone do not establish that any of those packers was used.&lt;/p&gt; 
&lt;p&gt;Underneath, it’s a Tox client. The executable statically links c-toxcore, the reference implementation of the Tox protocol, and retains the developer’s build path, C:\Users\dev\Desktop\c-toxcore.&lt;/p&gt; 
&lt;p&gt;Using Tox lets the loader communicate with its controller as another peer on the network. This removes reliance on a single centralized command-and-control address, but the network connections remain observable alongside the loader’s activity on the host.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Escalation, persistence, and stealth&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;AvisLoader’s persistence code targets shortcuts on the desktop and in the taskbar-pinned folder. The executable contains shortcut-backup strings and a VBScript launcher associated with the name VLCAssistant. These artifacts indicate a mechanism designed to launch the malware when a user opens a modified shortcut, then start the intended application so it appears to open normally.&lt;/p&gt; 
&lt;p&gt;The recovered files also include auto.exe, a small helper that references method 41 from UACME, a public User Account Control (UAC) bypass project. Its strings identify the ICMLuaUtil interface and the Component Object Model (COM) elevation mechanism associated with that technique. The helper also warns that updated Windows versions may mitigate the bypass, so its presence does not establish successful elevation.&lt;/p&gt; 
&lt;p&gt;A separate dynamic-link library (DLL), hmn_hook.dll, provides process-hiding functionality. It hooks NtQuerySystemInformation, a Windows function used to retrieve process information, and filters a specified process name from the results. This could hide that process from software using the hooked function, but the recovered files do not establish that the DLL was loaded into Task Manager or used to hide AvisLoader itself.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;The AvisLoader command center&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The recovered tools give us a view of AvisLoader’s endpoint capabilities. Its web panel, branded the AvisLoader Command Center, shows how operators are meant to manage clients, configure tasks, and distribute files. The dashboard includes counts of total, online, and offline clients, along with a world map.&lt;/p&gt; 
&lt;p&gt;A Clients table includes fields for hostname, country, central processing unit (CPU), graphics processing unit (GPU), antivirus, administrator status, and a public key. These fields bring host information into one view. The public-key field is consistent with Tox’s peer identity model.&lt;/p&gt; 
&lt;p&gt;The Tasks tab lets operators configure shell commands and select clients by hardware, location, and administrator status. Its controls indicate support for tasks that run when matching clients come online, allowing operators to prepare commands ahead of a client connecting.&lt;/p&gt; 
&lt;p&gt;The Files tab provides an interface for staging files and describes delivery “to clients over Tox.” This gives operators a way to prepare additional payloads for distribution.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Defenses and takeaways&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;AvisLoader gives security teams several opportunities for detection, from the initial ClickFix command to shortcut changes and unexpected Tox traffic. The delivery setup and recovered files point to four areas for monitoring:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Treat document-signing or verification pages that ask users to paste commands into a terminal or the Windows Run dialog as suspicious. Users should report these requests before running the command.&lt;/li&gt; 
 &lt;li&gt;Investigate unfamiliar workers.dev and trycloudflare.com addresses when they appear in document-signing lures or commands that download and execute code. Both domains support legitimate services, so consider the page content and surrounding activity when assessing them.&lt;/li&gt; 
 &lt;li&gt;Monitor command shells and script interpreters that retrieve and execute remote code, especially when the activity follows a visit to a suspicious page. Check for unexpected Tox or other peer-to-peer traffic on the same device. A command pasted by a user may run without the browser appearing as its parent process.&lt;/li&gt; 
 &lt;li&gt;Hunt for modified desktop and taskbar shortcuts, associated .backup files, and references to VLCAssistant. Investigate matches for the recovered auto.exe and hmn_hook.dll samples, then examine the surrounding activity for elevation attempts or process-list hooks.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;&lt;strong&gt;What we learned from AvisLoader&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;AvisLoader brings familiar malware techniques together around Tox. The recovered Windows sample includes shortcut-persistence artifacts, while its Command Center offers shell tasks and file delivery over an encrypted peer-to-peer connection.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;For security teams, this means a legitimate messaging protocol can also carry operator commands and additional malware. Understanding that traffic means looking at the application behind it and what it does on the device, alongside the network connections it makes.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK&lt;/strong&gt;&lt;/h2&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td style="background-color: #000000;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Technique ID&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td style="background-color: #000000;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Technique name&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td style="background-color: #000000;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Supporting evidence&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;T1204.004&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;User Execution: Malicious Copy and Paste&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;The ClickFix lure instructs visitors to paste and run an attacker-supplied command.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;T1547.009&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Boot or Logon Autostart Execution: Shortcut Modification&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Loader artifacts support the modification of desktop and taskbar shortcuts to launch malware when opened. Boot or logon execution was not established.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;T1548.002&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Abuse Elevation Control Mechanism: Bypass User Account Control&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;The bundled auto.exe helper implements the UACME method 41 bypass. Successful elevation was not confirmed.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;T1014&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Rootkit&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;The bundled hmn_hook.dll hooks NtQuerySystemInformation to filter a specified process name from returned results. Its deployment was not confirmed.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;T1071&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Application Layer Protocol&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;The loader incorporates c-toxcore for Tox-based command-and-control communications.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;T1105&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Ingress Tool Transfer&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;The Command Center offers file delivery to clients over Tox. Successful transfers were not confirmed.&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;&lt;strong&gt;Indicators of compromise&lt;/strong&gt;&lt;/h2&gt; 
&lt;h3&gt;&lt;strong&gt;File indicators&lt;/strong&gt;&lt;/h3&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td style="background-color: #010203;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Filename&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td style="background-color: #010203;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;SHA-256&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; 
   &lt;td style="background-color: #010203;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Role&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;78324.exe&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2cc&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;AvisLoader Windows client&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;auto.exe&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;f0a6870cb774a55775eda15fd39e8a17eb3169d5b9365186dae8edff07ff3975&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Bundled elevation-bypass helper&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;hmn_hook.dll&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;cd1e835f52e5f55279dcdf3857e11bc9298ea6caa88eb214ea2d40ff5d38b5f5&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Bundled process-hiding library&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h3&gt;&lt;strong&gt;Host and analysis artifacts&lt;/strong&gt;&lt;/h3&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th style="background-color: #010203;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Attribute&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/th&gt; 
   &lt;th style="background-color: #010203;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Value&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Persistence-related launcher name&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;VLCAssistant&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Shortcut backup extension&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;.backup, relevant alongside modified desktop or taskbar shortcuts&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Embedded developer build path&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;C:\Users\dev\Desktop\c-toxcore, present inside the loader&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;hmn_hook.dll exports&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;HMN_HideStart, HMN_HideStatus, HMN_HideStop&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Function hooked by hmn_hook.dll&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;NtQuerySystemInformation, a legitimate Windows function&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Component Object Model (COM) class identifier referenced by auto.exe&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;{3E5FC7F9-9A51-4367-9063-A120244FBEC7}, associated with the elevation-bypass technique&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;&lt;strong&gt;How Varonis can help&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;Varonis' &lt;a href="https://www.varonis.com/data-security-platform?hsLang=en"&gt;Data Security Platform&lt;/a&gt; uses behavioral analytics to flag abnormal activity that matches these techniques, including unexpected process lineage from a browser or script interpreter, privilege escalation, and the data access that usually follows a loader.&lt;/p&gt; 
&lt;p&gt;Even when the command channel has no domain to block, Varonis catches what the intrusion does next. &lt;a href="https://www.varonis.com/platform/mddr?hsLang=en"&gt;Varonis MDDR&lt;/a&gt; pairs that detection with an expert team that triages and contains incidents like this one.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fmeet-avisloader-a-windows-loader-built-to-outlast-a-takedown&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Research</category>
      <pubDate>Wed, 23 Sep 2026 13:00:01 GMT</pubDate>
      <guid>https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown</guid>
      <dc:date>2026-09-23T13:00:01Z</dc:date>
      <dc:creator>Daniel Kelley</dc:creator>
    </item>
    <item>
      <title>Introducing Varonis Triage Agent: An Autonomous Incident Responder to Amplify MDDR Service</title>
      <link>https://www.varonis.com/blog/varonis-triage-agent-for-mddr</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/varonis-triage-agent-for-mddr?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_VaronisTriageAgent_202609_OptA.png" alt="Varonis Triage Agent appears in neon green text against a dark green background" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Key takeaways&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;The Varonis Triage Agent is an AI incident responder&amp;nbsp;that investigates alerts like an analyst, gathering evidence and testing explanations.&lt;/li&gt; 
 &lt;li&gt;With the Triage Agent, MDDR analysts respond to malicious activity more quickly.&lt;/li&gt; 
 &lt;li&gt;The agent maintains a production recall rate above 96%, reliably surfacing real threats without burying them in false-positive noise.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The average security analyst has minutes&amp;nbsp;to figure out whether a login attempt is a valid employee attempting to gain access or an attacker already inside the network. Every second spent gathering context — checking identity history, cross-referencing data access, ruling out false positives — is a second an attacker can use to move laterally and widen the blast radius of their reach.&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;Key takeaways&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;The Varonis Triage Agent is an AI incident responder&amp;nbsp;that investigates alerts like an analyst, gathering evidence and testing explanations.&lt;/li&gt; 
 &lt;li&gt;With the Triage Agent, MDDR analysts respond to malicious activity more quickly.&lt;/li&gt; 
 &lt;li&gt;The agent maintains a production recall rate above 96%, reliably surfacing real threats without burying them in false-positive noise.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The average security analyst has minutes&amp;nbsp;to figure out whether a login attempt is a valid employee attempting to gain access or an attacker already inside the network. Every second spent gathering context — checking identity history, cross-referencing data access, ruling out false positives — is a second an attacker can use to move laterally and widen the blast radius of their reach.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Varonis &lt;a href="https://www.varonis.com/platform/mddr?hsLang=en"&gt;Managed Data Detection and Response (MDDR)&lt;/a&gt; service is built to close that gap with a team of dedicated security experts who monitor customer environments around the clock, investigate alerts, and respond to real threats before they escalate.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;To stay ahead of threats, including attackers armed with AI, the MDDR team continues to &lt;a href="https://www.varonis.com/blog/threat-detection-with-agentic-ai?hsLang=en"&gt;innovate with AI&lt;/a&gt;, most recently with the &lt;a href="https://www.varonis.com/blog/using-ai-to-investigate-security-alerts?hsLang=en"&gt;Varonis Triage Agent&lt;/a&gt;.&lt;/p&gt; 
&lt;h2&gt;What is the Varonis Triage Agent?&lt;/h2&gt; 
&lt;p&gt;The Varonis Triage Agent is an automated AI agent trained to operate as an incident responder&amp;nbsp;and amplify MDDR’s ability to respond to threats decisively. Developed by security researchers and data scientists at Varonis, the agent weighs numerous signals, including identity behavior, data sensitivity, and login patterns, against the context of Varonis’ extensive repository of security incidents. The result enables the MDDR team to act even more quickly.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Varonis MDDR analysts have&amp;nbsp;&lt;a href="https://www.varonis.com/blog/threat-detection-with-agentic-ai?hsLang=en"&gt;used agentic AI since early 2025&lt;/a&gt; to help prioritize alerts to match the speed and scale of automated attacks. Just like an incident responder, the Triage Agent gathers evidence, considers alternative explanations, and analyzes signals for patterns against more than 300 threat scenarios.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;It's just one of the innovations that makes Varonis MDDR one of the most effective ways to keep your data continuously protected.&lt;/p&gt; 
&lt;h2&gt;How much faster does the Triage Agent make detection and response?&lt;/h2&gt; 
&lt;p&gt;The Triage Agent works alongside MDDR analysts, beginning the investigation earlier, connecting evidence across the environment, and giving analysts a well-constructed starting point rather than a blank page. That means analysts spend less time gathering evidence and connecting dots and more time acting on it.&lt;/p&gt; 
&lt;p&gt;With the Triage Agent, MDDR analysts can respond to malicious activity twice as fast.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;In production, Varonis has measured:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Up to 100% improvement in analyst efficiency.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;A production recall rate above 96%, meaning the agent reliably surfaces real threats rather than burying them in noise.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For customers, the practical effect is a faster path from signal to resolution.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;How the Triage Agent investigates an alert&lt;/h2&gt; 
&lt;p&gt;Rather than scoring an alert in isolation, the Triage Agent investigates the way an experienced analyst would: forming a hypothesis, gathering evidence, testing benign explanations, and changing direction when the facts don't fit.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;In one recent case, that approach let the agent connect a moderate, easy-to-overlook alert to two related alerts from the same day — reconstructing what looked like three isolated spikes into a single, escalating exfiltration attempt spanning over 17,000 file downloads. Learn more about how the agent reached that conclusion in our &lt;a href="https://www.varonis.com/blog/using-ai-to-investigate-security-alerts?hsLang=en"&gt;technical deep dive&lt;/a&gt;.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Why the Triage Agent can be trusted in production&lt;/h2&gt; 
&lt;p&gt;This was never simply a&amp;nbsp;prompting project. The orchestration, tools, and data foundation all mattered, but the system only became useful once those pieces were grounded in the investigative methods of experienced security researchers and tested against real outcomes.&lt;/p&gt; 
&lt;p&gt;Security researchers identified the questions and relationships that a human investigator checks reflexively. Data scientists translated those lessons into tools, context, guidance, and repeatable evaluation workflows. The shared loop between those disciplines — run, inspect, correct, measure — moved the agent forward.&lt;/p&gt; 
&lt;p&gt;The goal isn't to replace human judgment. It's to move analysts away from manually gathering context and toward reviewing evidence, making consequential decisions, and containing threats before the damage spreads.&lt;/p&gt; 
&lt;h2&gt;What’s next for Varonis MDDR&lt;/h2&gt; 
&lt;p&gt;Alert volumes aren't slowing down. If anything, &lt;a href="https://www.varonis.com/blog/ai-post-compromise-recon?hsLang=en"&gt;attackers using AI of their own&lt;/a&gt; are pushing them higher. The Triage Agent gives Varonis’ MDDR experts room to write broader, more sensitive detection rules without flooding analysts, because the agent absorbs the added volume and filters for what matters.&amp;nbsp;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;It's one piece of the ongoing work at Varonis to keep pace with that shift, and MDDR customers get it automatically as part of the service.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fvaronis-triage-agent-for-mddr&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 22 Sep 2026 13:38:36 GMT</pubDate>
      <guid>https://www.varonis.com/blog/varonis-triage-agent-for-mddr</guid>
      <dc:date>2026-09-22T13:38:36Z</dc:date>
      <dc:creator>Nolan Necoechea</dc:creator>
    </item>
    <item>
      <title>Varonis Named a Pace Setter in the September 2026 Gartner® Emerging Market Quadrant for AI Application Security</title>
      <link>https://www.varonis.com/blog/gartner-emq-for-ai-application-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/gartner-emq-for-ai-application-security?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_GartnerEMQ_202607_V1.png" alt="Varonis Named a Pace Setter in the September 2026 Gartner® Emerging Market Quadrant for AI Application Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Varonis is proud to be named &lt;a href="https://info.varonis.com/gartner-emq-ai-09-21-2026?hsLang=en"&gt;Pace Setter in the Gartner® Emerging Market Quadrant for AI Application Security&lt;/a&gt;, recognized for our approach to securing AI applications across the entire development and deployment lifecycle.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Varonis is proud to be named &lt;a href="https://info.varonis.com/gartner-emq-ai-09-21-2026?hsLang=en"&gt;Pace Setter in the Gartner® Emerging Market Quadrant for AI Application Security&lt;/a&gt;, recognized for our approach to securing AI applications across the entire development and deployment lifecycle.&lt;/p&gt; 
&lt;p&gt;We believe&amp;nbsp;this recognition is especially meaningful for organizations that need AI security they can use now, not capabilities that are still on the roadmap. Pace Setters are vendors with strong existing capabilities across mandatory AI application security functions, including discovery and inventory, runtime defense, and AI security testing. This matters because enterprises moving quickly with AI need security controls that can deliver rapid time to value, provide immediate coverage for enterprise AI use, and support production environments with reliability and readiness.&lt;/p&gt; 
&lt;p&gt;As organizations push to rapidly adopt AI-powered applications, the attack surface is expanding faster than most security programs can keep up. Sensitive data now flows through training pipelines, system prompts, agent permissions, and the dozens of tools developers use to build and ship AI, often with little to no visibility or control. We believe this recognition reflects Varonis Atlas's ability to close that gap and validates the growing demand for security platforms that can discover, govern, and protect data across the full AI lifecycle.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/platform/ai-security?hsLang=en"&gt;Varonis Atlas&lt;/a&gt; is purpose-built to address this shift, bringing deep data visibility, automated remediation, and contextual intelligence to AI environments, from the first line of training code to production runtime.&lt;/p&gt; 
&lt;h2&gt;The new AI attack surface: data, prompts, models, and agents&lt;/h2&gt; 
&lt;p&gt;AI applications introduce risks that extend beyond infrastructure and identities and into data, prompts, models, and outputs. Hundreds of thousands of organizations are now building AI applications, and the pace of development is outrunning the pace of security.&lt;/p&gt; 
&lt;p&gt;Unlike traditional software, data isn't just an input for AI applications; it determines how those applications behave. That reshapes the attack surface. Credentials that authenticate AI services, the system prompts that define agent behavior, and the training data that shapes model output all flow through the development cycle and into production, often outside the reach of conventional AppSec tooling.&lt;/p&gt; 
&lt;p&gt;The security risks show&amp;nbsp;up in a few consistent ways:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Training data and retrieval sources pull from production, so a single leaked credential can expose everything an AI agent is trained on or can query, not just one database.&lt;/li&gt; 
 &lt;li&gt;System prompts and model configurations, stored in repos and wikis, describe internal policies and data schemas, effectively handing attackers a roadmap of what they can exploit.&lt;/li&gt; 
 &lt;li&gt;AI agents are overprivileged by design. The broad access scopes granted during development often persist unchanged into production, where they carry real consequences. This is already happening, with a recent example that involved an AI agent with excessive permissions and no runtime guardrails that deleted its own operator's inbox, despite explicit instructions to ask first.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Traditional security approaches lack visibility into how sensitive data is used by AI, cannot enforce policy across dynamic AI workflows, and were never designed to detect misuse or overexposure in AI-driven environments. Legacy AppSec tools are good at finding secrets in code and scanning for known vulnerabilities, but they have no visibility into system prompts pasted into Confluence, excessive permissions granted to agents, or proprietary configurations pasted into ChatGPT for debugging.&lt;/p&gt; 
&lt;p&gt;Securing AI development means protecting sensitive data and configurations everywhere developers actually work: repos, wikis, issue trackers, artifact registries, and AI assistants, not just source code.&lt;/p&gt; 
&lt;h2&gt;&lt;span style="font-weight: 600; font-family: 'Graphik LC Web', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;"&gt;Securing AI through data-first architecture with Varonis&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;Every one of those insights, from a leaked credential in a repo an overprivileged agent in production, feeds into the same data security posture management (DSPM) functions your team already relies on through Varonis DSP. AI risk doesn't sit in a separate silo; it shows up alongside the rest of your sensitive data risk, with the same automated remediation and reporting you get across the platform.&lt;/p&gt; 
&lt;h2&gt;Varonis Atlas: built to disrupt AI security&lt;/h2&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/blog/atlas-ai-security?hsLang=en"&gt;Atlas represents Varonis' next evolution&lt;/a&gt; in data security, designed to address the complexity of AI-driven environments end to end. It provides:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Unified visibility across AI data flows, from development through production.&lt;/li&gt; 
 &lt;li&gt;Context-aware risk detection that understands how sensitive data, credentials, and permissions move through AI systems.&lt;/li&gt; 
 &lt;li&gt;AI security testing, including AI pen testing that proactively stress-tests systems for vulnerabilities like prompt injection and jailbreaks.&lt;/li&gt; 
 &lt;li&gt;Real-time runtime guardrails through an AI Gateway that inspects prompts, responses, and agent actions before they reach the model.&lt;/li&gt; 
 &lt;li&gt;Automated enforcement and integration with the broader Varonis platform.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Across the board, Varonis gives security teams a single place to answer the questions that matter: What sensitive data sits in the repos where an AI system was built? What credentials are embedded in the images running AI agents? What data have developers shared with external AI assistants? Who can access the documentation describing an agent's permission scopes? If those questions can't be answered today, the underlying AI systems most likely carry baked-in vulnerabilities.&lt;/p&gt; 
&lt;p&gt;AI is transforming how organizations build and operate, and security has to evolve just as quickly. Varonis is committed to leading that shift with Atlas, and to continuing to innovate at the intersection of data, AI, and security.&lt;/p&gt; 
&lt;p style="font-size: 12px;"&gt;&lt;em&gt;Gartner, Emerging Market Quadrant for AI Application Security — Established Vendors, Meghan Hollis, Dionisio Zumerle, Dennis Xu, Marissa Schmidt, 14 September 2026.&lt;/em&gt;&lt;/p&gt; 
&lt;p style="font-size: 12px;"&gt;&lt;em&gt;Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.&lt;/em&gt;&lt;/p&gt; 
&lt;p style="font-size: 12px;"&gt;&lt;em&gt;Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fgartner-emq-for-ai-application-security&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Varonis Products</category>
      <category>AI Security</category>
      <pubDate>Mon, 21 Sep 2026 12:55:47 GMT</pubDate>
      <author>rsobers@varonis.com (Rob Sobers)</author>
      <guid>https://www.varonis.com/blog/gartner-emq-for-ai-application-security</guid>
      <dc:date>2026-09-21T12:55:47Z</dc:date>
    </item>
    <item>
      <title>Teaching a Machine to Think Like an Incident Responder</title>
      <link>https://www.varonis.com/blog/using-ai-to-investigate-security-alerts</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/using-ai-to-investigate-security-alerts?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_VaronisTriageAgent_202609_OptB.png" alt="Varonis Triage Agent uses context to map suspicious activity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Key takeaways&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;The Varonis Triage Agent investigates alerts like an incident responder, forming hypotheses, gathering evidence, and testing benign explanations.&lt;/li&gt; 
 &lt;li&gt;In one case, the agent connected three separate alerts — invisible to rule-based scoring alone — into a single incident spanning over 17,000 file downloads, giving Varonis MDDR a complete picture from the start.&lt;/li&gt; 
 &lt;li&gt;In production, the agent has improved analyst efficiency while maintaining a recall rate above 96% on confirmed threats.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Every security incident starts as a story: a suspicious login, a user accessing &lt;a href="https://www.varonis.com/blog/rethinking-database-security?hsLang=en"&gt;sensitive data&lt;/a&gt;, or a weak signal buried inside thousands of noisy alerts. In today’s SOC, that story is hidden at an almost impossible scale considering the tens of thousands of alerts a team handles. Once an attacker gains a foothold, every minute matters because they can move laterally, expand access, and widen the blast radius before an analyst reaches the case.&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;Key takeaways&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;The Varonis Triage Agent investigates alerts like an incident responder, forming hypotheses, gathering evidence, and testing benign explanations.&lt;/li&gt; 
 &lt;li&gt;In one case, the agent connected three separate alerts — invisible to rule-based scoring alone — into a single incident spanning over 17,000 file downloads, giving Varonis MDDR a complete picture from the start.&lt;/li&gt; 
 &lt;li&gt;In production, the agent has improved analyst efficiency while maintaining a recall rate above 96% on confirmed threats.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Every security incident starts as a story: a suspicious login, a user accessing &lt;a href="https://www.varonis.com/blog/rethinking-database-security?hsLang=en"&gt;sensitive data&lt;/a&gt;, or a weak signal buried inside thousands of noisy alerts. In today’s SOC, that story is hidden at an almost impossible scale considering the tens of thousands of alerts a team handles. Once an attacker gains a foothold, every minute matters because they can move laterally, expand access, and widen the blast radius before an analyst reaches the case.&lt;/p&gt; 
&lt;p&gt;This pressure is driving the growth of &lt;a href="https://www.varonis.com/blog/detecting-agentic-ai-threats?hsLang=en"&gt;AI SOC systems&lt;/a&gt;&amp;nbsp;designed to perform meaningful investigative work before a human analyst opens the case. And it’s the challenge guiding the &lt;a href="https://www.varonis.com/blog/varonis-triage-agent-for-mddr?hsLang=en"&gt;Triage Agent&lt;/a&gt;: an autonomous AI agent Varonis built to investigate end-to-end alerts, surface the cases that matter most, and give analysts the context they need to act quickly.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/platform/mddr?hsLang=en"&gt;Varonis Managed Data Detection &amp;amp; Response (MDDR)&lt;/a&gt; analysts have spent years refining that process — investigating, ruling out false leads, and escalating real threats for customers around the clock. The Triage Agent didn't replace that expertise; instead,&amp;nbsp;it was built to encode it, so the same investigative reasoning can begin the moment an alert fires.&lt;/p&gt; 
&lt;p&gt;For Varonis, triage is about understanding the data through context: What sensitive information was accessed, by whom, whether the access was appropriate, and whether the activity represents normal work, insider misuse, or malicious exfiltration. This crucial information turns an alert into an actionable security decision.&lt;/p&gt; 
&lt;h2&gt;Why we built the Varonis Triage Agent&lt;/h2&gt; 
&lt;p&gt;Traditional triage relies on rules, hardcoded automations, and traditional machine-learning systems, all of which are an important foundation. But &lt;a href="https://www.varonis.com/blog/threat-detection-with-agentic-ai?hsLang=en"&gt;an agent can go further&lt;/a&gt; by selecting which evidence to gather next, adapting as new facts emerge, and connecting related findings into a broader incident.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Our challenge was not simply to rank alerts faster, but to give the agent the same context and adaptability our MDDR analysts already bring to every investigation — and let it apply that thinking before a human ever opens the case.&lt;/p&gt; 
&lt;h3&gt;Varonis’ context advantage&lt;/h3&gt; 
&lt;p&gt;An agent is only as useful as the context it can reason over. In security, context determines meaning. The same action can represent normal work, careless behavior, or an active attack depending on several different factors like the identity involved, the sensitivity of the data, the user’s permissions, their historical behavior, and the surrounding activity.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Varonis already had that context within its &lt;a href="https://www.varonis.com/data-security-platform?hsLang=en"&gt;Data Security Platform (DSP)&lt;/a&gt;. The agent could investigate identities, permissions, entitlements, behavioral patterns, sensitive data exposure, and related events instead of reasoning over an isolated alert. We also had a large repository of evidence from past incidents that offered real outcomes against which to evaluate the agent.&lt;/p&gt; 
&lt;p&gt;In other words, we weren’t teaching the system through abstract security theory alone. We could compare its assessments with years of real investigations, identify where its reasoning failed, and use those failures to improve it. But rich security data was not enough. Before the agent could investigate it, that data had to become consistent and available for querying.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;How the agent investigates&lt;/h2&gt; 
&lt;p&gt;Much of the work involved normalizing events from collaboration platforms, email, identity services, networks, and VPNs into a unified schema. This allowed the agent to reason over, for example, “a sensitive file was shared externally” without knowing which system emitted the signal.&lt;/p&gt; 
&lt;p&gt;The agent also has access to behavioral baselines, including precomputed summaries of how a user typically behaves and which destinations and volumes are expected. This lets it ask, “Is this normal for this user?” without rebuilding the baseline for every alert. A curated catalog&amp;nbsp;explains what each table contains and how to query it.&lt;/p&gt; 
&lt;h3&gt;Handling infinite context&lt;/h3&gt; 
&lt;p&gt;Varonis has an enormous amount of useful context, but useful is not the same as relevant. Loading all available context into the agent for every alert makes the system slower, more expensive, and less accurate because important signals get buried.&lt;/p&gt; 
&lt;p&gt;To address this, we organized investigations into investigation scenarios, such as data exfiltration, privilege escalation, phishing, and identity attacks. Each scenario identifies the sources, behaviors, and tables most likely to matter, so the agent starts with relevant context and expands only when the evidence calls for it.&lt;/p&gt; 
&lt;p&gt;This dynamic approach allowed us to match context for more than 300 scenarios without writing tailored instructions for each one. Think of investigation scenarios as providing a focused starting point without turning the investigation into a rigid script.&lt;/p&gt; 
&lt;h3&gt;Forging the mind of an incident responder&lt;/h3&gt; 
&lt;p&gt;Once we had the data, the next challenge was teaching the agent how to investigate. Answering a question is one problem. Working through an open-ended security case is another.&lt;/p&gt; 
&lt;p&gt;A good incident responder&amp;nbsp;forms an initial hypothesis, gathers evidence, looks for contradictions, and changes direction when the facts do not fit. Each finding influences the next step. That became our design target: not an alert explainer, but an agent that follows the reasoning process of an experienced incident responder.&lt;/p&gt; 
&lt;p&gt;The central tension we discovered was structure versus flexibility. Too little guidance produced shallow investigations, while too much created the same rigid playbook we were trying to overcome. The agent needed to gather enough evidence, consider alternative explanations, avoid treating every anomaly as malicious, and recognize when reassuring context was not enough to dismiss a real threat.&lt;/p&gt; 
&lt;p&gt;Building this required close collaboration between security researchers, who contributed investigative methodology and attacker mindsets, and data scientists, who built the orchestration and tool-calling infrastructure. We benchmarked early versions against real outcomes from our MDDR team, evaluating both the verdict and whether the investigation gathered enough evidence to justify it. Those failures became the roadmap.&lt;/p&gt; 
&lt;h3&gt;How we improved the agent&lt;/h3&gt; 
&lt;p&gt;Every run was traced as a step-by-step transcript. Using labeled outcomes, we could test the agent against cases where the answer was already known. Wrong verdicts were especially useful because the trace showed where the reasoning went off course.&lt;/p&gt; 
&lt;p&gt;The fixes rarely involved changing the model. They involved changing what the agent knew and how it was guided: Sharpening investigative guidance, improving how a table was described, or tightening a prompt so the agent did not jump to certainty too early.&lt;/p&gt; 
&lt;p&gt;The hard part was restraint. Every mistake invited another instruction, but too many instructions narrowed the agent until it could only follow a predefined path.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;The takeaway:&lt;/span&gt; A good tip nudges the investigation — it does not script it. For example, the agent repeatedly flagged file downloads as suspicious without checking whether the files belonged to the user. A hard rule such as “access to your own files is benign” would have created a blind spot when an owner shared sensitive files externally. Instead, we added one nudge: “Before treating file activity as suspicious, establish the relationship between the user and the resource.”&lt;/p&gt; 
&lt;p&gt;The agent began checking ownership routinely, dismissing benign self-access while still escalating genuine exposure based on the evidence.&lt;/p&gt; 
&lt;p&gt;Another useful technique was comparing two runs on the same alert, one correct and one incorrect. The difference often came down to a single move: one run checked the source of a suspicious burst, while the other assumed it. That fork showed us exactly what to reinforce.&lt;/p&gt; 
&lt;h2&gt;A real investigation, end to end&lt;/h2&gt; 
&lt;p&gt;It began as an alert few analysts would have rushed to open: A sales employee had pulled thousands of sensitive data files in a short window from an unfamiliar external IP. Large downloads can accompany migrations, backups, and quarter-end reporting, and this detection is among the platform’s highest-volume and noisiest. Rule-based and traditional machine-learning scoring placed the alert below the high-priority threshold — the kind of moderate signal that's easy to deprioritize at scale, even for a strong team, when it's sitting in a queue of tens of thousands.&lt;/p&gt; 
&lt;p&gt;The agent did not treat the download count as the verdict. It selected which evidence to examine, tested benign explanations, and changed direction as new facts emerged. It started with identity: a known employee in a non-technical sales role, not an administrator or service account. That proved nothing on its own, but it made programmatic collection of thousands of financial documents difficult to explain as routine.&lt;/p&gt; 
&lt;p&gt;Raw events showed that the downloads came from a Node.js client rather than a browser or managed productivity app, indicating scripted collection. The files spanned thousands of locations the user did not own, and many were labeled confidential or highly confidential. The question changed from “Was there a spike?” to “Why is a sales user scripting the collection of sensitive financial material they do not own?”&lt;/p&gt; 
&lt;p&gt;A 30-day baseline sharpened the contrast. Before that day, the user’s peak activity was only a handful of files. Network intelligence identified the source as an anonymous consumer VPN endpoint hosted in data center infrastructure. No other user in the environment touched it during the window, ruling out shared corporate egress and tying the concealed origin to this account.&lt;/p&gt; 
&lt;p&gt;No single fact decided the case. Volume can be legitimate work. A new IP can indicate travel. A scripted client can be sanctioned automation. The combination is what mattered, and what allowed the agent to determine,&amp;nbsp;“The combination of automated collection, concealment of origin, and targeting of highly sensitive financial data provides concrete evidence of mass data exfiltration.”&lt;/p&gt; 
&lt;p&gt;The agent classified the activity as malicious and critical while recording its limitation: authentication telemetry was unavailable, so it could not distinguish between stolen credentials, a hijacked session, or a deliberate insider.&lt;/p&gt; 
&lt;h3&gt;From isolated alerts to connected incidents&lt;/h3&gt; 
&lt;p&gt;The most consequential move came from looking beyond the ticket it was handed. The agent searched 14 days of detections on the same identity for impossible travel, external sharing, and uploads to personal cloud storage. None appeared. What did appear were two more alerts for the same download rule on the same day: an earlier burst of roughly 440 files and a later one of more than 11,500.&lt;/p&gt; 
&lt;p&gt;Together, the three windows totaled more than 17,000 downloads. A moderate spike below the priority threshold was one phase of sustained extraction escalating throughout the day.&lt;/p&gt; 
&lt;p&gt;The agent did not simply group alerts by user. It tested related attack behaviors, distinguished absent signals from contradictory evidence, and assembled the matching activity into a single timeline. This adaptive investigation and incident reconstruction, rather than any single indicator, was the agentic advantage.&lt;/p&gt; 
&lt;p&gt;The MDDR analyst opened the case with all of that evidence already gathered, confirmed the volume and consumer VPN source, and escalated it for customer action. The final disposition was a true-positive malicious external threat. The human still owned the decision, but instead of three disconnected tickets, they received one reconstructed incident.&lt;/p&gt; 
&lt;h3&gt;What it took to make the agent useful&lt;/h3&gt; 
&lt;p&gt;This was never simply a prompting project. The model, orchestration, tools, and data foundation all mattered. But the system only became useful when those pieces were grounded in the investigative methods of experienced security researchers and tested against real outcomes.&lt;/p&gt; 
&lt;p&gt;Security researchers identified the questions and relationships a human investigator checks by reflex. Data scientists translated those lessons into tools, context, guidance, and repeatable evaluation workflows. The shared loop between those disciplines, run, inspect, correct, and measure, moved the agent forward.&lt;/p&gt; 
&lt;p&gt;The result is the Varonis Triage Agent, a product in the emerging AI SOC category that does more than process alerts faster. It begins the investigation earlier, connects evidence across the environment, and gives analysts a&lt;span&gt;&amp;nbsp;richer and more comprehensive starting point&lt;/span&gt;.&lt;/p&gt; 
&lt;p&gt;In production, the agent has improved analyst efficiency, depending on each analyst’s baseline and experience working with it. Moving from machine-learning and playbook-based triage to agentic triage&lt;span&gt; reduced the manual investigation time required before escalation by an average of 16.4 analyst-hours per malicious case.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;Production recall is above 96%. Because Varonis MDDR analysts manually review every trace, fewer than 4% of confirmed attacks were not prioritized by the agent. The agent has already investigated dozens of production alerts, and that number continues to grow.&lt;/p&gt; 
&lt;p&gt;An accurate agent focused on triage also changes the calculus for detection engineering. When every new detection adds to an overwhelming queue, teams often keep rules narrow to avoid flooding analysts with false positives, sacrificing coverage. With a reliable agent absorbing the additional volume, detection engineers can write broader, more sensitive rules while the agent filters noise and surfaces the cases that warrant attention.&lt;/p&gt; 
&lt;p&gt;Ultimately, the goal is not to replace human judgment. It is to move analysts away from manually gathering context and toward reviewing evidence, making consequential decisions, and containing threats before the damage spreads.&lt;/p&gt; 
&lt;p&gt;&lt;span style="color: #010203;"&gt;This post&amp;nbsp;was co-authored by &lt;span&gt;&lt;a&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/hadas-shalev/"&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/hadas-shalev/"&gt;Hadas Shalev&lt;/a&gt;. &lt;/span&gt;Thank you to Oren Tevet, &lt;span&gt;&lt;a&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/jonathan-haldarov/"&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/jonathan-haldarov/"&gt;Yonatan Haldarov&lt;/a&gt;, and &lt;a href="https://www.linkedin.com/in/amit-daniel/"&gt;Amit Daniel&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="color: #010203;"&gt;for their contributions on the topic.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fusing-ai-to-investigate-security-alerts&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 18 Sep 2026 14:31:18 GMT</pubDate>
      <guid>https://www.varonis.com/blog/using-ai-to-investigate-security-alerts</guid>
      <dc:date>2026-09-18T14:31:18Z</dc:date>
      <dc:creator>Liav Alter</dc:creator>
    </item>
    <item>
      <title>TrustSink: How a Rogue External MFA Provider Steals Passwords</title>
      <link>https://www.varonis.com/blog/trustsink</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/trustsink?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_VTL-TrustSink_202608_FNL%20(1).png" alt="Varonis Threat Labs discovered TrustSink, a technique that turns a rogue external MFA provider into a persistent credential trap. See how it works in Microsoft Entra, why password resets may not remove the risk, and how defenders can detect rogue providers." class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/varonis-threat-labs?hsLang=en"&gt;Varonis Threat Labs&lt;/a&gt; identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;a href="https://www.varonis.com/varonis-threat-labs?hsLang=en"&gt;Varonis Threat Labs&lt;/a&gt; identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow.&lt;/p&gt; 
&lt;p&gt;While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow. The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error.&lt;/p&gt; 
&lt;p&gt;In our test tenant, every sign-in completed normally while our server received passwords with timestamps and source IP addresses. Resetting a captured password did not remove the rogue provider. It remained in the authentication flow and captured the replacement password at the user’s next sign-in.&lt;/p&gt; 
&lt;p&gt;We are sharing this research as a warning to defenders, and to help IT and security teams detect unauthorized changes to authentication infrastructure and remove rogue providers before resetting affected credentials.&lt;/p&gt; 
&lt;p&gt;TrustSink builds on a trust boundary &lt;a href="https://www.youtube.com/watch?v=eKFgOtNpxwU"&gt;highlighted by Dirk-jan Mollema &lt;/a&gt;in his x33fcon 2025 talk, “Bringing Your Own Identity in Entra ID.”&amp;nbsp;His research showed how a rogue registered EAM provider could be used to bypass MFA by returning a signed JWT without performing a real authentication check.&lt;/p&gt; 
&lt;p&gt;Our research uses that same trust boundary for a different objective: capturing plaintext passwords. We focus on the provider-controlled page the user sees, which can resemble a Microsoft password prompt and be used to collect the password before the provider completes sign-in&amp;nbsp;with a signed token.&lt;/p&gt; 
&lt;p&gt;TrustSink is a clever workaround for authentication. If we can’t trust authenticator apps, what can we trust?&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Building the rogue provider&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;We first built the provider by hand: a minimal OpenID Connect (OIDC) server written in Python with FastAPI. It has two jobs that pull in opposite directions.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;To the user, it must look exactly like the official Microsoft page.&lt;/li&gt; 
 &lt;li&gt;To Entra, it must look exactly like a compliant EAM provider.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Both of these jobs play out in a single sign-in.&lt;/p&gt; 
&lt;p&gt;The user enters their real Microsoft password. MFA triggers, and Entra sends their browser to our provider for the second check. From that moment, the two audiences see different things. The user sees a copy of Microsoft’s password page, and whatever they type, our server keeps. Entra sees a signed token claiming the check passed, and the signature validates, so the sign-in completes.&lt;/p&gt; 
&lt;p&gt;Four endpoints in total carry the loop (two for each audience).&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;&lt;span style="color: #000000;"&gt;1.&lt;/span&gt; The discovery document&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;This is how Entra learns the provider exists. Its /.well-known/openid-configuration URL is registered in the Authentication Methods Policy and fetched before any user is redirected. Our implementation returns the minimum metadata Entra needs: the issuer, authorization endpoint, JWKS URI, and supported signing algorithm (RS256). If the document is unreachable or invalid, Entra rejects the provider and the user sees an error page.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;&lt;span style="color: #000000;"&gt;2.&lt;/span&gt; The public key&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;This is how Entra believes the provider. The /jwks endpoint serves an RSA public key from a self-signed pair we generate at first launch. Entra retrieves this key to validate the tokens the provider returns and caches it, so fetches follow Microsoft's metadata refresh cycle rather than individual sign-ins. Microsoft checks only that the key ID matches and the signature is valid. It does not check the certificate chain or where the key came from.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;3. The page the user sees&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;This is where the trap sits. When MFA triggers, Entra redirects the browser to /eam/authorize and sends along everything we need to answer: an id_token_hint identifying the user, a nonce tying the response to this request, and the callback URI to post back to. Our server replies with a pixel-accurate copy of Microsoft’s own password prompt.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;4. The capture&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;This is where the password lands. When the user submits the form, /eam/complete writes it to a local credentials file with a timestamp and source IP. Then the server builds Microsoft's answer. It takes the user's identifier from the id_token_hint (Microsoft sends it deliberately expired. It takes the user’s identifier from the id_token_hint. Although Microsoft deliberately sends this token expired, our provider still validates its signature, issuer, audience, and relevant claims before using it) and adds the two claims that tell Entra a hardware-key check succeeded: acr: "possessionorinherence" and amr: ["hwk"]. It signs the token with the provider's private key, and an auto-submitting form posts it to Microsoft's callback.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;What the user sees&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The attack inserts one extra step into a routine the user has run hundreds of times. From their side of the screen, the sign-in looks like this.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;They enter their email at login.microsoftonline.com.&lt;/li&gt; 
 &lt;li&gt;They enter their password. This one goes to Microsoft.&lt;/li&gt; 
 &lt;li&gt;MFA is triggered.&lt;/li&gt; 
 &lt;li&gt;The browser lands on what looks like another Microsoft password page.&lt;/li&gt; 
 &lt;li&gt;They enter their password again. This one goes to us.&lt;/li&gt; 
 &lt;li&gt;The page moves on by itself.&lt;/li&gt; 
 &lt;li&gt;They arrive at their application. Sign-in complete, no errors.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The page at step four is a pixel-accurate copy of the real thing. Same fonts, same layout, same blue button.&lt;/p&gt; 
&lt;p&gt;It also arrives at the one moment a password request makes sense: the user has just typed their real password on Microsoft’s domain, so a second prompt inside the same flow does not raise suspicion the way an emailed link would.&lt;/p&gt; 
&lt;p&gt;From the user’s perspective, they signed in normally.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;From proof of concept to repeatable trap&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;Disclaimer: This proof of concept is provided strictly for educational and authorized security research purposes to help defenders understand and detect this attack vector. Do not use this tool against any environment without explicit written authorization.&lt;/p&gt; 
&lt;p&gt;At this point, everything has run successfully in our own tenant. An attacker in the real world would need it to work on every sign-in, for every targeted user, for as long as the provider stays registered. That takes two things: the privileges to register it, and a public address for it.&lt;/p&gt; 
&lt;p&gt;The privileges are the tricky part. Registering an external method means changing the Authentication Methods Policy, creating an application, a service principal, and a consent grant. Those actions require a Global Administrator or Authentication Policy Administrator account. TrustSink is therefore a post-compromise technique. It begins after an attacker has taken a privileged identity and decides to turn that one account into a standing credential trap.&lt;/p&gt; 
&lt;p&gt;The address is simpler. Entra fetches the discovery document and signing keys over HTTPS, and the victim's browser is sent to the same place during the redirect, so the provider needs a public URL. In our lab, that was ngrok, a tunneling service that exposes a local server behind a public HTTPS address.&lt;/p&gt; 
&lt;p&gt;A real attacker would choose something other than ngrok, perhaps a cloud VM behind something like auth-verify.microsoft-sso.com or a VPS with a free certificate. The domain appears in the address bar for a moment during the redirect, and most users never look. A well-chosen one is the difference between blending in and an analyst spotting an unfamiliar issuer in proxy logs.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Manual setup&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;In order to verify this setup, we ran the deployment through the Entra portal manually because a slow run shows exactly which artifacts the attack creates.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;We first ran the FastAPI server locally and exposed it through ngrok, giving it the public HTTPS address (https://trident-sip-filter.ngrok-free.dev) that Entra and the victim's browser would both use.&lt;/li&gt; 
 &lt;li&gt;In App registrations, we created an application named something innocuous (for example, "Security Verification"), scoped to accounts in this organizational directory only, set its Web redirect URI to Microsoft's external authentication callback (https://login.microsoftonline.com/common/federation/externalauthprovider), and enabled ID token issuance under Implicit grant.&lt;/li&gt; 
 &lt;li&gt;We created a Service Principal for the app. This happens automatically when the application is registered in the same tenant. We verified it existed under Enterprise applications.&lt;/li&gt; 
 &lt;li&gt;We added the delegated OpenID and profile permissions and granted admin consent so no consent prompt appears during the redirect.&lt;/li&gt; 
 &lt;li&gt;In the Authentication Methods Policy, we added the provider under a display name chosen to blend in (ours was "User's Password"), entered the application (client) ID of the app registered in step 2, pointed the Discovery URL at https://trident-sip-filter.ngrok-free.dev/eam/.well-known/openid-configuration, and scoped it to a security group holding one test account.&lt;/li&gt; 
 &lt;li&gt;We confirmed a Conditional Access policy required MFA for that group across all cloud apps. The trap was live.&lt;/li&gt; 
 &lt;li&gt;We signed in as the target user. After entering the real password, Entra redirected us to our server, where the fake password prompt caught the second entry. We signed the JWT and posted it back, and the sign-in completed normally.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;You can &lt;a href="https://varonis.wistia.com/s/trust-sink-manual"&gt;watch the manual deployment here&lt;/a&gt;.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Automated deployment&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;After the manual step, it was clear that the methodology worked, but it took a few minutes of clicking and left too much room for error. As a result, we packaged the same sequence of steps into a Python script (deploy.py) that drives it through Microsoft Graph in just one command:&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;For authentication, the script tries the Azure CLI first, which avoids creating a new sign-in event, and falls back to device code flow with Azure PowerShell’s client ID, which is pre-consented in most tenants.&lt;/li&gt; 
 &lt;li&gt;It creates the application via POST /v1.0/applications with the correct redirect URI and required openid/profile permissions, then creates the Service Principal via POST /v1.0/servicePrincipals, making the app usable in the tenant.&lt;/li&gt; 
 &lt;li&gt;It grants tenant-wide consent via POST /v1.0/oauth2PermissionGrants, scoped to AllPrincipals for openid and profile, so victims never see a consent prompt.&lt;/li&gt; 
 &lt;li&gt;It registers the external method via POST /beta/policies/authenticationMethodsPolicy/authenticationMethodConfigurations, adding the provider to the Authentication Methods Policy scoped to the target group.&lt;/li&gt; 
 &lt;li&gt;It saves everything it created to deploy_state.json, and rolls back automatically if any step fails. A companion script, cleanup_eam.py, reverses a full deployment in order, deleting the EAM config, removing admin consent, deleting the service principal, then the app registration, and only clears the state file once teardown fully succeeds.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;You can &lt;a href="https://varonis.wistia.com/s/trust-sink-automated"&gt;watch the automated deployment here.&lt;/a&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;How to detect and mitigate TrustSink&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;Most stages of a TrustSink deployment leave a trace in the logs. Registering the provider writes the method configuration into the Authentication Methods Policy, and an automated run adds its own trail, creating the application, the service principal, and the consent grant back-to-back through scripted Graph calls.&lt;/p&gt; 
&lt;p&gt;Five places are worth watching:&lt;/p&gt; 
&lt;p&gt;&lt;strong style="font-family: 'Graphik LC Web', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;"&gt;&lt;span style="color: #0077ff;"&gt;1. &lt;/span&gt;Authentication Methods Policy changes&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Registering the rogue provider wrote three audit events in sequence: the external method added, the user object updated, and the method confirmed as registered. It also appended a FIDO key to the test user’s SearchableDeviceKey property, a side effect we did not trigger deliberately. Any new externalAuthenticationMethodConfiguration entry outside a planned rollout is the clearest early warning.&lt;/p&gt; 
&lt;p&gt;&lt;strong style="font-family: 'Graphik LC Web', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;"&gt;&lt;span style="color: #0077ff;"&gt;2.&lt;/span&gt; Application registrations&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;The application we created used Microsoft’s external authentication callback, login.microsoftonline.com/common/federation/externalauthprovider, as its redirect URI, requested openid and profile permissions, and carried a display name chosen to blend in with a sign-in audience limited to the organization. Any application with no clear business purpose registering itself into the authentication path deserves review.&lt;/p&gt; 
&lt;p&gt;&lt;strong style="font-family: 'Graphik LC Web', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;"&gt;&lt;span style="color: #0077ff;"&gt;3.&lt;/span&gt; Service principals&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Registering the application also created a service principal, and its creation event carries the specifics: the app ID, the sign-in audience, the reply URLs pointing at infrastructure the attacker controls (in our test, an ngrok domain, not a Microsoft one), and the key material registered for token signing. A service principal holding credentials for an application you do not recognize is part of the same chain and appears in the same audit window.&lt;/p&gt; 
&lt;p&gt;&lt;strong style="font-family: 'Graphik LC Web', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;"&gt;&lt;span style="color: #0077ff;"&gt;4. &lt;/span&gt;Sign-in logs&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Every sign-in our provider handled recorded its issuer URL, and the claims are where the giveaway lives. A genuine hardware-key prompt produces them after a real ceremony. Ours were hardcoded as acr: "possessionorinherence" and amr: ["hwk"]. The record shows the first factor satisfied by token claims and the MFA requirement satisfied by the external provider. An unfamiliar issuer carrying hwk is the most reliable signal, because the provider cannot avoid leaving it.&lt;/p&gt; 
&lt;p&gt;&lt;strong style="font-family: 'Graphik LC Web', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif;"&gt;&lt;span style="color: #0077ff;"&gt;5.&lt;/span&gt; Automated tooling&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Our deployment tool stamped every Graph call with python-requests/2.33.1, and the events Add application, Add service principal, and Add delegated permission grant fired within seconds of each other. Real administrative work comes from the Azure portal or PowerShell, at human pace. The header is trivial to change, so treat it as a lead, not a signature.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;Resetting the password doesn't work with TrustSink. The old credential dies, but the provider is still live, so it harvests the replacement on the next sign-in. You have to remove the provider, not only rotate the credential.&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th style="background-color: #010203;"&gt; &lt;p&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Area&lt;/span&gt;&lt;span style="background-color: #000000;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/th&gt; 
   &lt;th style="background-color: #000000;"&gt; &lt;p&gt;&lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Action&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Provider&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Disable the external method in the Authentication Methods Policy and remove its group assignments before any password reset&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Application artifacts&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Remove the app registration, the service principal, the signing keys, the openid and profile consent grant, and the callback redirect URI&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Accounts&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Use the sign-in logs to identify every user who authenticated through the provider, reset their credentials, and review what those accounts did afterward&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Conditional Access&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Alert on policies modified to target new groups, and review any policy edited after a suspicious registration&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Authentication methods&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Move users to FIDO2 or Windows Hello for Business, so a password prompt during MFA reads as suspicious&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt; &lt;p&gt;Privileged access&lt;/p&gt; &lt;/td&gt; 
   &lt;td&gt; &lt;p&gt;Restrict standing Global Administrator and Authentication Policy Administrator roles, the two roles that can alter this path&lt;/p&gt; &lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;&lt;strong&gt;The bottom line&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The TrustSink technique exists because Entra trusts a signed token from a registered EAM without verifying what the provider shows the user.&lt;/p&gt; 
&lt;p&gt;Microsoft hands a third party the one screen every user trusts, and never checks what that party shows or returns. Controlling what the user sees, combined with automatic validation of whatever comes back, is all that was needed. The result was a credential-capture mechanism that operated within normal sign-ins.&lt;/p&gt; 
&lt;p&gt;That mechanism has a cost on both sides. The entry cost is high because an attacker needs a privileged account before any of this works. What they get in return is a standing trap that captures plaintext passwords in real time and stays in place when those passwords are reset.&lt;/p&gt; 
&lt;p&gt;For a red team, that is persistence worth having. For a blue team, it is one more reason to watch identity infrastructure changes as closely as the sign-ins themselves.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Ftrustsink&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Research</category>
      <pubDate>Wed, 16 Sep 2026 13:00:02 GMT</pubDate>
      <guid>https://www.varonis.com/blog/trustsink</guid>
      <dc:date>2026-09-16T13:00:02Z</dc:date>
      <dc:creator>Elad Ghvarh</dc:creator>
    </item>
    <item>
      <title>Introducing Varonis Data Lifecycle Management</title>
      <link>https://www.varonis.com/blog/introducing-data-lifecycle-management</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/introducing-data-lifecycle-management?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_DLMLaunch_202609_FNL3.png" alt="Introducing Varonis Data Lifecycle Management" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/solutions/data-lifecycle-management?hsLang=en"&gt;Varonis Data Lifecycle Management (DLM)&lt;/a&gt; is a new capability that automatically finds and quarantines redundant, obsolete, and trivial (ROT) data across your entire data estate. Cut storage costs, improve AI outputs, and reduce risk, effortlessly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;a href="https://www.varonis.com/solutions/data-lifecycle-management?hsLang=en"&gt;Varonis Data Lifecycle Management (DLM)&lt;/a&gt; is a new capability that automatically finds and quarantines redundant, obsolete, and trivial (ROT) data across your entire data estate. Cut storage costs, improve AI outputs, and reduce risk, effortlessly.&lt;/p&gt; 
&lt;h2&gt;ROT: The data you should &lt;em&gt;not&lt;/em&gt; have&lt;/h2&gt; 
&lt;p&gt;For the average enterprise, data volumes grow by 30% to 40% each&amp;nbsp;year, and that growth is accelerating due to AI. Every modern business is creating mountains of data, but few have an automated way to remove data when it’s no longer useful.&lt;/p&gt; 
&lt;p&gt;As a result, at least 30% of enterprise data is ROT, which leads to problems such as:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Wasted storage costs:&lt;/span&gt;&amp;nbsp;Industry estimates put storage costs at more than $650,000 per petabyte a year, before backup and replication, meaning you spend almost $200,000 per petabyte per year storing data that shouldn't exist.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Degraded AI quality:&lt;/span&gt;&amp;nbsp;AI processes and analyzes all the data it can access, including ROT. That means data that shouldn't exist gets to shape your AI's actions and responses.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Elevated risk:&amp;nbsp;&lt;/span&gt;Sensitive ROT data scattered across shares, drives, and forgotten data stores widens the blast radius of a breach. Data kept past its retention window can lead to fines under GDPR, CCPA, HIPAA, and other regulations.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Varonis Data Lifecycle Management: The power of automation&lt;/h2&gt; 
&lt;p&gt;With Varonis DLM, you can automatically find ROT across every data source, as well as enforce governance, retention, and residency policies. DLM is built on the &lt;a href="https://www.varonis.com/data-security-platform?hsLang=en"&gt;Varonis Data Security Platform (DSP)&lt;/a&gt;, which already helps thousands of customers understand and control their data.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Varonis DLM also shows you which data should and shouldn't exist across your data estate. Since the context around sensitivity, permissions, and activity already lives in Varonis, the platform not only finds ROT but also acts on it.&lt;/p&gt; 
&lt;p&gt;Legacy lifecycle tools find data that might be ROT and then rely on data owners to manually review lists of hundreds or thousands of deletion candidates, one record at a time. Only Varonis knows what's stale, overexposed, duplicated, or past its retention window, and quarantines it automatically.&lt;/p&gt; 
&lt;h3&gt;Unified ROT visibility&lt;/h3&gt; 
&lt;p&gt;One dashboard shows the full scope of ROT data across every connected platform. View total ROT volume, duplicate clusters, stale files and folders and data past its retention window. Filter by platform, classification category, sensitivity, data source, file type or owner.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Prioritize ROT based on potential cost savings and risk:&lt;/span&gt; See what's driving storage spend and exposure, so you can prioritize cleanup efforts and keep track of progress.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Surface ROT hiding in plain sight:&lt;/span&gt; Aggregated visibility flags stale and aged data even when hidden inside active folders.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3&gt;Full data context&lt;/h3&gt; 
&lt;p&gt;Knowing how much ROT you have is important, but it’s not enough to know what to do about it. Varonis DLM adds the context you need to make informed decisions. For example, you can drill into any duplicate group and see which copy is the original, which is most recent, where copies are across different platforms, and whether they are sensitive, overexposed, or past retention.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Detect every duplicate, not just the readable ones:&lt;/span&gt; Find the duplicates and ROT that classification can’t read, such as media files, installers, DLLs, and archives.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Act based on the full lifecycle of data:&lt;/span&gt; Varonis tracks how long each data record has gone untouched and how old it is, so you know exactly what's safe to remove.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3&gt;Complete lifecycle automation&lt;/h3&gt; 
&lt;p&gt;Out-of-the-box policies govern duplicates, staleness, and retention, all fully configurable to your scope and logic. When data violates a policy, Varonis automatically moves it to a secure quarantine. The automation is fully reversible, and Varonis deletes nothing until&amp;nbsp;you're sure.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Turn classification into enforcement: &lt;/span&gt;&lt;span style="font-weight: normal;"&gt;Don’t just label expired data — act on it. &lt;/span&gt;Retention policies map classification categories to legal windows, like financial and PCI over seven years old, PII and GDPR over two years old, PHI over six years old, and education data over five years old.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-family: inherit; font-size: inherit; font-style: inherit; font-variant-ligatures: inherit; font-variant-caps: inherit; font-weight: bold;"&gt;R&lt;/span&gt;&lt;span style="font-family: inherit; font-size: inherit; font-style: inherit; font-variant-ligatures: inherit; font-variant-caps: inherit; font-weight: inherit;"&gt;&lt;span style="font-weight: bold;"&gt;emediate without risk: &lt;/span&gt;Quarantine the duplicates you don't need and choose which copy to ke&lt;/span&gt;&lt;span style="font-family: inherit; font-size: inherit; font-style: inherit; font-variant-ligatures: inherit; font-variant-caps: inherit; font-weight: inherit;"&gt;ep, such as the original or&amp;nbsp;the most recent. Every action is reversible, so cleanup never breaks something you need.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;A security project that pays for itself&lt;/h2&gt; 
&lt;p&gt;Most security spending is insurance&amp;nbsp;you pay for and hope you'll never need. Varonis DLM is the exception: Not only does it deliver security and compliance outcomes, but it also cuts storage and backup costs. Varonis DLM is powerful because it's built on the Varonis DSP, so every lifecycle decision is driven by AI classification, complete permissions mapping, and full activity history on every data record, all correlated in real time across your whole environment.&lt;/p&gt; 
&lt;p&gt;The combination of classification, permissions, and activity is what allows Varonis to know "this is stale, overexposed, duplicate, past its retention," rather than "this might be ROT." &lt;a href="https://www.varonis.com/varonis-automated-data-security-every-second-everywhere?hsLang=en"&gt;Varonis automated remediation capabilities&lt;/a&gt;&amp;nbsp;automatically quarantine ROT rather than having to rely on data owners for cleanup. Other solutions may be able to classify data, but only Varonis has the context to act on it automatically, safely, and at scale.&lt;/p&gt; 
&lt;p&gt;Schedule a free &lt;a href="https://www.varonis.com/solutions/data-risk-assessment?hsLang=en"&gt;Varonis Data Risk Assessment&lt;/a&gt; to see how much ROT is hiding in your environment and find out exactly how much you could save.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fintroducing-data-lifecycle-management&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 15 Sep 2026 12:55:00 GMT</pubDate>
      <author>efeldman@varonis.com (Eugene Feldman)</author>
      <guid>https://www.varonis.com/blog/introducing-data-lifecycle-management</guid>
      <dc:date>2026-09-15T12:55:00Z</dc:date>
    </item>
    <item>
      <title>Varonis Achieves Snowflake Premier Partner Tier and Is Now Available on Snowflake Marketplace</title>
      <link>https://www.varonis.com/blog/varonis-available-on-snowflake-marketplace</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/varonis-available-on-snowflake-marketplace?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_Varonis-Snowflake.png" alt="Varonis Achieves Snowflake Premier Partner Tier and Is Now Available on Snowflake Marketplace" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;We're excited to share two milestones in our growing relationship with Snowflake. Varonis has achieved  &lt;a href="https://www.snowflake.com/en/why-snowflake/partners/all-partners/varonis-systems-inc/"&gt; Premier Partner &lt;/a&gt;  status in the Snowflake Partner Network and is now available on the  &lt;a href="https://app.snowflake.com/marketplace/listing/GZU6Z887E5A/varonis-varonis"&gt; Snowflake Marketplace. &lt;/a&gt;  &lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;We're excited to share two milestones in our growing relationship with Snowflake. Varonis has achieved  &lt;a href="https://www.snowflake.com/en/why-snowflake/partners/all-partners/varonis-systems-inc/"&gt; Premier Partner &lt;/a&gt;  status in the Snowflake Partner Network and is now available on the  &lt;a href="https://app.snowflake.com/marketplace/listing/GZU6Z887E5A/varonis-varonis"&gt; Snowflake Marketplace. &lt;/a&gt;  &lt;/p&gt;  
&lt;p&gt;&lt;a href="https://www.varonis.com/blog/agentic-ai-security-risk?hsLang=en"&gt;AI agents&lt;/a&gt;, copilots, and LLMs now read, write, and act on data flowing through data lakes, warehouses, and everywhere in between at machine speed. Varonis helps enterprises secure Snowflake environments so they can innovate fast with confidence. &lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.varonis.com/blog/snowflake-data-security?hsLang=en"&gt;Varonis integrates with Snowflake&lt;/a&gt; to continuously analyze data sensitivity, who can access sensitive data, and how data is being used. With Varonis, organizations can confidently use Snowflake for analytics, collaboration, and AI while maintaining security and compliance controls. &lt;/p&gt; 
&lt;p&gt;Varonis and Snowflake are more connected than ever, helping customers secure the data and AI that power their business. &lt;/p&gt; 
&lt;h2&gt;What’s new with Varonis for Snowflake&lt;/h2&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Premier Partner Tier. &lt;/span&gt;&lt;span style="height: auto; line-height: 20.85px; text-decoration-color: #000000; width: auto; font-weight: normal;"&gt;Reaching Premier Partner status&lt;/span&gt;&amp;nbsp;is further validation of Varonis' deep integration with Snowflake and enhances our ability to collaborate with Snowflake's teams on joint customer outcomes, co-selling, and roadmap alignment.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;&lt;span style="line-height: 20.85px;"&gt;Varonis on the Snowflake Marketplace.&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height: 20.85px;"&gt; &lt;/span&gt;Snowflake customers can now find Varonis directly on the Snowflake Marketplace and apply a portion of their committed capacity to Varonis via the Snowflake Marketplace Capacity Drawdown (MCD) program.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Why customers turn to Varonis to secure Snowflake&lt;/h2&gt; 
&lt;p&gt;Organizations adopt Snowflake to accelerate their data and AI initiatives. Rather than stitching together separate systems for storage, warehousing, and analytics, teams can consolidate and spend less time on infrastructure and more time analyzing data, collaborating, and building AI applications and agents.&lt;/p&gt; 
&lt;p&gt;Security is important,&amp;nbsp;but it must be balanced with the speed and flexibility that they adopted Snowflake for in the first place.&lt;/p&gt; 
&lt;p&gt;Customers adopt Varonis for Snowflake for the visibility and guardrails needed to move fast while staying secure, and map Snowflake permissions to clearly understand what data exists, who can access it, and how it is used.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;That's exactly why customers like Webster Bank&amp;nbsp;use Varonis to secure Snowflake:&amp;nbsp;&lt;/p&gt; 
&lt;br&gt;
&lt;br&gt; 
&lt;h2&gt;Varonis and Snowflake: Better together&lt;/h2&gt; 
&lt;p&gt;Varonis makes it easy to secure Snowflake environments without slowing innovation. Varonis provides the visibility and control security teams need to know where sensitive data lives, ensure access matches actual need, and catch misuse before it becomes a breach.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;a href="https://www.varonis.com/platform/data-discovery-and-classification?hsLang=en" style="font-weight: normal;"&gt;Automatically discover and classify sensitive data&lt;/a&gt;&lt;span style="font-weight: normal;"&gt;. &lt;/span&gt;Varonis discovers and classifies sensitive data across every Snowflake database, schema, table, and column to pinpoint PII, PHI, financial data, and more.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Map effective permissions for every user. Varonis cuts through nested role inheritance to show exactly who can reach what, and right-sizes access automatically.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Detect and stop threat. Varonis builds &lt;a href="https://www.varonis.com/platform/data-centric-ueba?hsLang=en" style="font-weight: normal;"&gt;&lt;span style="font-weight: normal;"&gt;behavioral baselines for every user and system&lt;/span&gt;&lt;/a&gt; and monitors the access patterns that indicate risk. From a compromised account to an insider threat to an AI system reaching data it shouldn't, Varonis provides real-time, contextual alerts, rather than noise.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;A stronger foundation for what's next&lt;/h2&gt; 
&lt;p&gt;It's now faster and easier than ever to secure your Snowflake environment with Varonis and start gaining visibility and control without slowing down data and AI initiatives.&lt;/p&gt; 
&lt;p&gt;If you're running sensitive data in Snowflake, there's no better time to see where you stand. Varonis offers a free &lt;a href="https://info.varonis.com/en/data-risk-assessment?hsLang=en"&gt;Snowflake Data Risk Assessment&lt;/a&gt; that shows you, within 24 hours, where your sensitive data lives, who can access it, and what's putting it at risk.&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fvaronis-available-on-snowflake-marketplace&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Data Security</category>
      <category>Varonis Products</category>
      <pubDate>Tue, 01 Sep 2026 12:45:00 GMT</pubDate>
      <guid>https://www.varonis.com/blog/varonis-available-on-snowflake-marketplace</guid>
      <dc:date>2026-09-01T12:45:00Z</dc:date>
      <dc:creator>Nolan Necoechea</dc:creator>
    </item>
    <item>
      <title>SIEM Is Not Enough: Why You Need DAM for Your Databases</title>
      <link>https://www.varonis.com/blog/siem-vs-dam-database-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.varonis.com/blog/siem-vs-dam-database-security?hsLang=en" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.varonis.com/hubfs/Blog_DAMNativeAudit_202608_V1.png" alt="SIEM Is Not Enough: Why You Need DAM for Your Databases" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Database security has followed the same playbook for years. Pick your ten or twenty most critical databases, deploy Imperva or Guardium on them, and take the eighteen-month, seven-figure hit. For the other several hundred databases, turn on native audit, ship the logs to your &lt;a href="https://www.varonis.com/blog/what-is-siem?hsLang=en"&gt;SIEM&lt;/a&gt;, and call it monitoring.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Database security has followed the same playbook for years. Pick your ten or twenty most critical databases, deploy Imperva or Guardium on them, and take the eighteen-month, seven-figure hit. For the other several hundred databases, turn on native audit, ship the logs to your &lt;a href="https://www.varonis.com/blog/what-is-siem?hsLang=en"&gt;SIEM&lt;/a&gt;, and call it monitoring.&lt;/p&gt;  
&lt;p&gt;That playbook made sense when &lt;a href="https://www.varonis.com/platform/database-activity-monitoring?hsLang=en"&gt; Database Activity Monitoring (DAM) &lt;/a&gt; was hard, when the only databases anyone bothered to protect were the ones facing regulatory scrutiny, and when the riskiest users hitting them were humans.&lt;/p&gt; 
&lt;p&gt;None of those assumptions hold anymore, and security professionals are exhausted by the burdens and costs of Guardium and Imperva deployments. The "ship it to Splunk" part of the playbook (the part covering most databases) was never database security. It was compliance theater with a receipt. And now it's not a handful of human users hitting those databases, it's hundreds or thousands of &lt;a href="https://www.varonis.com/blog/agentic-ai-security-risk?hsLang=en"&gt;autonomous agents&lt;/a&gt;, and a pile of logs in your SIEM does not secure any of it.&lt;/p&gt; 
&lt;p&gt;Varonis Next-Gen DAM brings every database into our unified Data Security Platform through native audit collection. All you need to do is point the logs your databases&amp;nbsp;&amp;nbsp;generated&amp;nbsp;to Varonis and you get real findings instead of raw events piling up in your SIEM.&lt;/p&gt; 
&lt;h2&gt;What "ship it to SIEM" actually delivers&lt;/h2&gt; 
&lt;p&gt;Talk to any team pushing native database logs into a SIEM today, and the picture is the same:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The bill is enormous: &lt;/span&gt;Raw audit volume is massive, and SIEM ingest is priced by the gigabyte. No matter which SIEM you use,&amp;nbsp;this quietly becomes the most expensive piece of database monitoring infrastructure your organization owns, and none of this money is buying security.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The alerts mean nothing:&lt;/span&gt; The SIEM has no idea which tables contain regulated data or the difference between a Select and a Show in SQL. Every event looks the same. Writing rules to find the activities that matter requires deep database knowledge the SOC does not have. Most teams give up and don't write the rules at all.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The audit report is still a manual process:&lt;/span&gt;&amp;nbsp;Quarterly, someone runs custom queries against the log store, hand-formats the output, and prays the auditor accepts it. It does nothing to reduce risk or secure data.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Meanwhile, the databases under an agent-based DAM tool are stuck in their own trap. Agent deployments take years, cover a fraction of the estate, and drown teams in undifferentiated alerts. The people who built that category will tell you so themselves.&lt;/p&gt; 
&lt;p&gt;Ron Bennatan, VP of Strategy at Varonis, explains: "&lt;em&gt;&lt;span&gt;We built agent-based DAM in an era with real hardware constraints and a real need for inline controls like blocking, dynamic masking, and connection throttling. The hardware constraints have been closed for years &lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt;with&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt; cloud and modern storage&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt;,&lt;/span&gt;&lt;/em&gt;&lt;span&gt; &lt;/span&gt;&lt;em&gt;&lt;span&gt;a&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt;nd inline controls&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt; are&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt; now&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt; primarily&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt; needed for&lt;/span&gt;&lt;/em&gt;&lt;span&gt; &lt;/span&gt;&lt;em&gt;&lt;span&gt;AI agents. Databases now need high-fidelity detection and a way to make sure AI agents &lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt;don't&lt;/span&gt;&lt;/em&gt;&lt;em&gt;&lt;span&gt; cause unintended consequences. The interesting problem now is how you turn millions of activity records into a small number of findings that actually mean something and how you understand agent intent."&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;Prior to joining Varonis, Ron spent 25 years building agent-based DAM as co-founder of Guardium (acquired by IBM) and jSonar (acquired by Imperva). Native audit overhead on modern databases is now measured well under five percent on par with agent-based collection.&lt;/p&gt; 
&lt;p&gt;The industry ended up with two failed modes running in parallel: (1) legacy DAM monitors a small subset of databases at enormous cost, and (2) SIEMs cover the rest, but don’t provide any security.&lt;/p&gt; 
&lt;h2&gt;Why the combination of legacy DAM + SIEM stopped working&lt;/h2&gt; 
&lt;p&gt;The legacy DAM-SIEM compromise assumed the databases not covered by DAM weren't worth the effort. That assumption dies the moment an AI agent starts querying them.&lt;/p&gt; 
&lt;p&gt;Consider a customer support agent built on an internal LLM:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;A user asks it a question&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The model decides it needs three rows from a customer database&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The MCP server runs the query under a shared service account&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The native log records: svc_ai_support read 3 rows from customers.payment_methods at 14:02&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Multiply that by ten thousand queries a day across a dozen AI workflows, and you have a feed that is both massive and useless. The human who triggered the request is invisible. The service account is doing things it wouldn't have been doing six months ago.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The SIEM has no context into the sensitivity of the data being accessed. Without that context, the SIEM has no way to tell whether any of this activity is normal. Multiply that by 100 or 1,000 agents, each capable of taking autonomous actions, prone to unintended behavior, or even going full "rogue," and now every database is at risk and not just the ten earmarked for legacy DAM coverage.&lt;/p&gt; 
&lt;h2&gt;Secure every database with Varonis Next-Gen DAM&lt;/h2&gt; 
&lt;p&gt;For years, the reason security teams didn't monitor every database was because monitoring every database was hard and came with a lot of overhead. Varonis Next-Gen DAM changes the math with two collection methods that share one SaaS platform:&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Native Audit Collection&lt;/span&gt; for the vast majority of your databases. All you need to do is point the built-in audit streams that ship with SQL Server, Oracle, PostgreSQL, MySQL, Snowflake, Databricks, Amazon RDS, and every other major engine at a Varonis collector. Nothing to install on the database host, no agents, inline devices, or DBA tickets.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;The Varonis Gatekeeper&lt;/span&gt; for the smaller set of hypercritical databases where you need inline enforcement like blocking, dynamic masking, and legacy database version support. This is the workload that used to justify agents in the first place.&lt;/p&gt; 
&lt;p&gt;Both feed the same SaaS platform. Which means every database, the ten critical ones and the several hundred that used to live in Splunk purgatory, get the same security treatment.&lt;/p&gt; 
&lt;h2&gt;What Varonis Next-Gen DAM delivers&lt;/h2&gt; 
&lt;p&gt;A log entry becomes a finding when the platform processing it knows three things: whether the data being touched is sensitive, whether the user should have access to it, and whether the behavior is normal for them.&lt;/p&gt; 
&lt;p&gt;Take a 2 a.m. SELECT against a customer table. To a SIEM ingesting raw audit, it is one event out of millions. To Varonis, three things happen in parallel:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The classification engine already knows the destination table holds PII, down to the column.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The identity graph resolves the database account back to a real corporate identity through Active Directory or Entra.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Then, by leveraging &lt;a href="https://www.varonis.com/blog/user-entity-behavior-analytics-ueba?hsLang=en"&gt; User Entity Behavior Analytics (UEBA)&lt;/a&gt;, Varonis shows that this user has never touched this table or column and rarely works after hours.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The result is a clear alert that something is wrong: this account just read regulated data it has never touched before, off-hours, from a new endpoint.&lt;/p&gt; 
&lt;p&gt;Apply the same three-way intersection to the AI agent example above. Classification knows customers.payment_methods is PCI scope. The identity layer traces svc_ai_support back to the originating workflow and, ultimately, the user prompt. Behavior modeling knows whether this agent has any business hitting this table at this volume. The log becomes a finding the same way it does for a human user.&lt;/p&gt; 
&lt;p&gt;That is the difference between shipping logs somewhere for a report and securing databases.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Why DAM is easier than you think&lt;/h2&gt; 
&lt;p&gt;Now, you can easily extend DAM to every database in your estate. The same database logs you've shipped to Splunk for years can now point at Varonis instead. Same stream, same effort, but now you get specific findings with complete data classification and identity resolution rather than a per-gigabyte bill for events that nobody reads.&lt;/p&gt; 
&lt;p&gt;Run a free &lt;a href="https://info.varonis.com/en/data-risk-assessment?hsLang=en"&gt;Varonis Data Risk Assessment&lt;/a&gt; to get started. Bring in any combination of databases (SQL Server, Oracle, PostgreSQL, MySQL, RDS, Snowflake, Databricks, and more) alongside your unstructured data in OneDrive, SharePoint, Google Workspace, Box, Salesforce, NAS, and the rest. One classification model, one identity graph, one set of findings.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;What you get:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;A complete map of where sensitive data lives across every database and every file store, with exposure and access risk quantified&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Identity mapping that resolves database accounts back to real corporate identities through Active Directory and Entra&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Live activity alerts surfaced by Varonis UEBA, watched 24x7x365 by an MDDR analyst for the length of the assessment&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;An executive-ready report with a prioritized remediation path, yours to keep whether you become a customer or not&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Setup takes less than an hour, with findings showing up within 24 hours.&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=142972&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.varonis.com%2Fblog%2Fsiem-vs-dam-database-security&amp;amp;bu=https%253A%252F%252Fwww.varonis.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Data Security</category>
      <pubDate>Mon, 31 Aug 2026 16:35:29 GMT</pubDate>
      <author>efeldman@varonis.com (Eugene Feldman)</author>
      <guid>https://www.varonis.com/blog/siem-vs-dam-database-security</guid>
      <dc:date>2026-08-31T16:35:29Z</dc:date>
    </item>
  </channel>
</rss>
