Privileged access management, AI/ML, MSSP

KeeperAI Adds Real-Time Threat Detection to Privileged Access Management

Keeper Security has launched KeeperAI, a new agentic AI feature within its KeeperPAM platform that brings automated, real-time monitoring and response to privileged accounts. The system continuously analyzes active sessions, classifies anomalies by risk level, and can terminate high-risk activity in seconds, well before an incident escalates.

Jeremy London, Director of Engineering, AI and Threat Analytics at Keeper Security told MSSP Alert, “KeeperAI represents a fundamental shift from legacy PAM solutions that rely on manual log reviews and static, rule-based alerts. Traditional PAM vendors have layered limited AI features onto existing tools, often creating noise without actionable context. KeeperAI, by contrast, is an AI-native solution purpose-built for privileged session analysis,” said

100% Automated Analysis Across Privileged Sessions

KeeperAI continuously analyzes session activity, from metadata and keystrokes to command execution. Detected anomalies are classified into risk levels ranging from low to critical. Based on policies set by administrators, the system can automatically terminate risky sessions, send alerts, or continue monitoring while flagging activity for review.

London explained how this raises the bar compared to existing tools. He explained, "With KeeperAI, threats are detected and categorized in under 10 seconds, with automated termination of high-risk sessions - eliminating the hours or days of lag common with log aggregation or post-event analysis. It enables organizations to achieve 100% automated analysis across privileged sessions, compared to less than 5% with manual review.”

Core Features at a Glance

KeeperAI delivers automated session analysis to detect anomalies across privileged activity, with threat classification that assigns severity levels ranging from low to critical. Administrators can configure responses - whether to terminate a session, send an alert, or simply continue monitoring - based on policy. The platform also makes sessions fully searchable, allowing security teams to track specific commands or behaviors across histories. And with support for both cloud and on-premises inference, including integration with AWS Bedrock, Anthropic, Google Gemini, and OpenAI, KeeperAI fits into a wide range of deployment models without locking customers into a single provider.

Accuracy and false positives are major concerns for enterprises deploying AI in security. London addressed this directly.

He explains, “KeeperAI was designed to give security teams accuracy and control, not more noise. The system provides contextual, command-by-command analysis and categorizes activity by risk level, which dramatically reduces false positives. Teams can start in a ‘Monitor’ mode to build confidence before enabling automated termination for high-risk sessions. That combination of context, customization and gradual rollout prevents alert fatigue while ensuring legitimate work isn’t disrupted.”

Built with Sovereignty in Mind

KeeperAI is built to fit within different operational environments. It supports SSH sessions with plans to extend to RDP, VNC, RBI, and databases. Incident data and risk assessments flow into the Keeper Vault UI, giving teams one place to investigate, document, and maintain compliance. Integration with SIEM and SOC tools is enabled through Keeper’s Advanced Reporting and Alerts Module.

The deployment model is also built with sovereignty in mind. "KeeperAI is built on our zero-knowledge foundation, which means all analysis happens within the customer’s own environment - Keeper never has access to their data. Session files are encrypted with the customer’s private key, and communication flows directly to the LLM provider of their choice. Whether in the cloud or fully air-gapped on-premises, customers retain full ownership of their infrastructure, keys and data,” London said.

Balancing Automation with Data Control

This design helps highly regulated industries adopt AI-driven defense without introducing third-party risk. By supporting both cloud and on-premises inference, KeeperAI provides flexibility without forcing vendor lock-in. That balance of automation and control ensures scalability without compromising governance.

For managed security service providers (MSSPs), the platform also extends into multi-client operations.
“KeeperAI is designed to support MSSPs by extending real-time detection and automated response into each client environment while preserving strict tenant isolation. Each gateway is owned and configured by the customer, ensuring data sovereignty while allowing providers to deliver advanced monitoring and threat response as part of their managed services,” London explained.

Building a Proactive, Autonomous Defense Layer

For security teams facing an endless stream of alerts and limited staff capacity, KeeperAI offers a way to cut through the noise. Its automation accelerates response times to seconds, reduces false positives, and gives administrators control to fine-tune detection to their environment.

“KeeperAI transforms privileged access monitoring from a reactive process into a proactive, autonomous defense layer that strengthens both security and operational resilience,” London said. Instead of only auditing sessions after they happen, organizations can detect, classify, and respond in real time. This helps security teams cut down on manual work, ease alert fatigue, and act faster with the resources they have.

The platform also brings practical benefits around cost transparency and workflow integration. On average, each command analysis consumes about 550 tokens, while a session summary consumes about 400 tokens. This allows organizations to estimate usage and plan costs when using third-party LLM providers. AI-driven detections feed directly into ARAM events, ensuring findings flow into SIEM platforms and compliance tools without creating silos. By automating session-level defense while maintaining control of sensitive data, KeeperAI offers security teams a way to scale operations, improve accuracy, and focus on strategy instead of constant firefighting.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds