Intezer has launched Org Brain, a memory system that helps its AI SOC platform keep up with changes in a customer’s environment. It uses past investigations, live security data, and analyst feedback to add more context during alert triage.
AI SOC platforms often rely on information gathered during onboarding. That context can become outdated as users change roles, new assets are added, and security teams adjust detections and response processes. Org Brain updates that knowledge during each investigation. It looks at how similar alerts were handled, checks current data from connected systems, and saves what it learns after the case is closed.
Itai Tevet, CEO and co-founder of Intezer, told MSSP Alert, Org Brain’s distinction lies in how the learning process is triggered and how much work analysts must do to maintain it.
“‘The AI learns your environment’ is now a standard pitch across the AI SOC category. Our competitors do indeed build on investigation history, and we don’t claim otherwise,” Tevet said. “Where Org Brain differs is in what triggers the learning and how much manual curation it needs.”
Capturing how the SOC works
Intezer splits Org Brain’s knowledge into two parts: Muscle Memory and Self-Awareness. Muscle Memory captures how analysts investigate and respond to alerts. That can include which queries they run, why they close a known benign detection, or how they have tuned a noisy data loss prevention rule. This information often lives in tickets, investigation notes, or analysts’ heads. Org Brain applies it to future alerts to make investigations more consistent across teams and shifts.
Self-Awareness focuses on the organization’s environment. It builds context around users, assets, past cases, and security data. That includes what a server does, how a user normally logs in, where information sits in the security information and event management platform and how the team handled similar threats before.
Tevet said some platforms depend partly on customers or analysts to add facts such as office locations, company-owned IP ranges, or systems with specialized functions.
“That’s a hybrid model, with some parts automated inference but more reliant on human analyst input,” he said. “Org Brain is built to run that whole loop autonomously.”
According to Tevet, the system can ingest years of historical case data and organize what it learns into the two memory types.
“It ties tuning decisions and analyst corrections directly into two structured memory types, what we call muscle memory for procedure and self-awareness for organizational facts, and closes the loop after every single investigation using a separate reviewer model that checks what the investigating agent got right or wrong,” he said.
That process is intended to reduce the amount of information analysts must manually enter or maintain.
“Analysts don’t need to teach it facts for it to get smarter,” Tevet said.
Learning before, during and after investigations
Org Brain uses what Intezer calls loop engineering. It learns from past cases, pulls current data during an investigation, and saves new findings after the case is resolved. The system can use closed tickets, past escalations, and alerts that required no action to build its starting knowledge base. That gives it access to the SOC’s existing experience from the beginning. During an investigation, Org Brain also checks live data from connected systems. This helps prevent decisions based on outdated information about users, assets, or detections.
“In a real investigation, that shows up as fresher context, pulled live rather than from a database someone forgot to refresh, fewer tickets that need a human, and verdicts that account for both organizational facts and how your specific team has historically handled similar cases,” Tevet said.
He added that procedural memory remains an underdeveloped part of the broader AI SOC conversation.
“That last part, procedural memory, is something most vendors haven’t articulated as a distinct layer,” he said.
Preventing bad data from spreading
A system that learns continuously also creates a governance problem. Incorrect verdicts, outdated practices, or bad analyst decisions could become part of the platform’s memory and influence later investigations.
“Bad data compounds fast if a system is agentic and learning continuously,” Tevet said.
Intezer said Org Brain weighs new information against the rest of its stored knowledge rather than treating every new conclusion as permanent. The system is designed to identify contradictions and hold back conclusions with weak supporting evidence.
“Org Brain has built-in logic that weighs new information against everything else it holds, so a single bad verdict doesn’t automatically become a permanent lesson,” Tevet said. “It’s designed to catch contradictions and flag low-confidence conclusions before they harden into policy.”
Analysts can also inspect what the system has learned and override specific conclusions or behaviors. Intezer refers to those explicit instructions internally as “inceptions.”
“The safety net has two layers, automated consistency checks plus a human override that’s always available and always wins,” Tevet said.
Intezer targets fewer human reviews
Intezer says fewer than 2% of alerts handled by its platform currently require human review. The company expects Org Brain to reduce that number further, although it does not yet have enough customer data to publish validated performance results.
“We think there’s meaningful room to push that further, and our internal estimate is roughly another 50% reduction, getting close to 1% of alerts requiring a human touch,” Tevet said. “This is an early estimate, not a validated benchmark.”
Intezer is not yet making specific claims about accuracy, investigation speed, or missed threats. The company said it needs more production data from customers before publishing those results.
“We’re not going to publish precise before-and-after numbers on accuracy, investigation time, or missed threats until we have a larger customer base running Org Brain long enough to measure it properly,” Tevet said.
Intezer expects improvements to come from better investigation context, access to experienced analysts’ knowledge, and fewer cases that require human review.
“What we can say directionally is that the improvement should come from three places at once, richer and more current context per investigation, procedural knowledge that used to live only in senior analysts’ heads, and a shrinking need for a human to re-verify what the system already handled correctly,” Tevet said.