{"id":130440,"date":"2026-08-05T16:14:11","date_gmt":"2026-08-05T16:14:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/130440\/"},"modified":"2026-08-05T16:14:11","modified_gmt":"2026-08-05T16:14:11","slug":"stellar-cybers-auto-triage-ai-matches-human-analysts-99-7-of-the-time","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/130440\/","title":{"rendered":"Stellar Cyber&#8217;s Auto-Triage AI matches human analysts 99.7% of the time"},"content":{"rendered":"<p><a href=\"https:\/\/stellarcyber.ai\/\" target=\"_blank\" rel=\"nofollow noopener\">Stellar Cyber<\/a>, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its <a href=\"https:\/\/stellarcyber.ai\/automatically-triage-phishing-emails-with-stellar-cyber\/\" target=\"_blank\" rel=\"nofollow noopener\">Agentic Auto Triage<\/a> capability.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/stellarcyber-agentic_auto_triage.webp\" class=\"aligncenter\" alt=\"Stellar Cyber Agentic Auto Triage\" title=\"Stellar Cyber Agentic Auto Triage\"\/><\/p>\n<p>The independent study based on customer trials evaluated 138,475 real security alerts and reached the same verdict as human analysts 99.7% of the time. The findings, drawn from customer-submitted end-of-trial reports, addressed the central question facing every security team weighing autonomous SOC technology: Can AI actually be trusted to make decisions?<\/p>\n<p>AI-driven tools have made it easier than ever for adversaries to design highly convincing phishing and ransomware attacks. In response, organizations have doubled down on security awareness and training, resulting in a surge in reports of potential threats. The World Economic Forum reports potential security threats have surged dramatically over the last two years, with ransomware attacks jumping by up to 48% year-over-year and phishing attempts exploding by 1200% since late 2022. This escalation is largely driven by GenAI-enhanced tactics. Automatic Triage, powered by Agentic AI, levels the playing field for human security analysts by automatically ingesting, correlating, analyzing, and prioritizing suspicious events from the user\u2019s environment.<\/p>\n<p>Finding #1: Auto Triage returns 19 minutes of every hour, translating to 1 day a week of productivity<\/p>\n<p>Across the trials, Auto Triage returned roughly 19 minutes of every analyst hour to higher-value work, including working more cases per shift and dedicating more time to exposure management, anticipating adversary behavior, and closing exposures. This time translates to about one day per week per analyst, or the equivalent of 1.5 full-time analysts reclaimed annually.<\/p>\n<p>By closing out confident false positives and surfacing real threats before a human ever opens them, Auto Triage reduces noise, helps teams move from an alert-centric mode to a case-management mode, and transforms the job of the human security analyst. This shift helps improve MTTD and MTTR while giving analysts time to think like attackers, anticipate likely attack paths, and close visible gaps before they are exploited.<\/p>\n<p>\u201cSecurity operations have reached a tipping point. The volume and complexity of alerts are simply beyond what human analysts can manage alone,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/aimei-wei-3857331b\/\" target=\"_blank\" rel=\"nofollow noopener\">Aimei Wei<\/a>, CTO at Stellar Cyber. \u201cThis real-world study proves that our approach of combining machine-speed analysis with human judgment is the right way forward. These results show what that looks like in practice: the AI does the alert work at scale, the analyst stays in control, and they almost always agree\u2014freeing analysts to manage more cases and get ahead of emerging exposure.\u201d<\/p>\n<p>Finding #2: 64% of False Positives closed; 15% of True Positives escalated<\/p>\n<p>Using machine learning models trained on real-world phishing patterns, the platform delivers reliable, actionable verdicts in seconds. Auto Triage assigns each alert a decision through an AI-driven Verdict Signal Check, with human-in-the-loop oversight and a closed-loop learning process that improves accuracy over time.<\/p>\n<p>During the trials, the system analyzed 138,475 alerts, disposing of 64% of them as confident false-positive closures. Auto Triage escalated 15% of the alerts as true positives for human analyst review, and routed the remainder as informational, clearing noise before it reached a person.<\/p>\n<p>\u201cThe Agentic AI built into Auto Triage is designed to address one of the most pressing challenges security analysts deal with on a daily basis: tuning out the noise and focusing on legitimate threats to the business,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/chrissteffen\/\" target=\"_blank\" rel=\"nofollow noopener\">Christopher M. Steffen<\/a>, CISSP, CISA, CCZT, VP of Research, Information Security, Risk, and Compliance Management at EMA. \u201cThis study proves that Stellar Cyber\u2019s approach of automatic ingestion and analysis, AI-driven prioritization, and highly accurate decision-making has the power to transform the way analysts work in the enterprise SOC\u2014from processing alerts to managing cases, moving from MTTD and MTTR, towards MTTN \u2013 mean time to neutralize, and spending more time proactively reducing exposure.\u201d<\/p>\n<p>Lean security teams at enterprise SOCs and MSSPs face mounting alert volumes without the budget to scale headcount. For MSSPs, reclaimed analyst capacity translates directly into broader coverage, better customer service, and protected margins.<\/p>\n<p>\u201cThe results from this study underscore what we\u2019ve experienced in our own SOC. For an MSSP, the math of human-only security operations simply can\u2019t scale against today\u2019s alert volumes,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/chantv\/\" target=\"_blank\" rel=\"nofollow noopener\">Chant Vartanian<\/a>, CEO, M-Theory Group. \u201cAuto Triage effectively returns a full day of productivity per analyst and successfully closes 64% of false positives. That data is truly transformative for organizations like ours. It allows us to shift our team\u2019s focus to high-value threat investigation and exposure management, work more cases per shift, which directly improves our service margins and enables us to provide broader, more consistent coverage for our clients without the need for costly headcount expansion.\u201d<\/p>\n<p>Auto Triage is available now as part of the Stellar Cyber AI-native SecOps platform. Stellar Cyber will showcase Auto Triage and the results of this independent study live at Black Hat USA (Booth #5542), August 1-6, 2026, in Las Vegas. <a href=\"https:\/\/stellarcyber.ai\/blackhat-mandalay-bay-las-vegas\/\" target=\"_blank\" rel=\"nofollow noopener\">Book a demo<\/a> today!<\/p>\n","protected":false},"excerpt":{"rendered":"Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124&hellip;\n","protected":false},"author":2,"featured_media":130441,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,40923,61544,64457],"class_list":["post-130440","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-black-hat","tag-black-hat-usa-2026","tag-stellar-cyber"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/130440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=130440"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/130440\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/130441"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=130440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=130440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=130440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}