{"id":140322,"date":"2026-08-14T18:44:17","date_gmt":"2026-08-14T18:44:17","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/140322\/"},"modified":"2026-08-14T18:44:17","modified_gmt":"2026-08-14T18:44:17","slug":"sysdig-ai-cnapp-agents-identify-threats-and-surface-remediation-recommendations","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/140322\/","title":{"rendered":"Sysdig AI CNAPP Agents Identify Threats and Surface Remediation Recommendations"},"content":{"rendered":"<p>\t\t\tTL;DR \u2014 Key Takeaways<br \/>\nSysdig Secure AI adds specialized AI agents to its CNAPP to prioritize cloud risks and recommend remediation using runtime data.<br \/>\nThe agents use Falco telemetry to determine what is normal, what is critical and which cloud assets require the most attention.<br \/>\nSysdig claims Secure AI can support more than 10 times as many investigations as human analysts alone at an 88% lower cost.<\/p>\n<p>Sysdig has added a set of artificial intelligence (AI) agents for its cloud native application protection platform (CNAPP) that are specifically trained to use data collected at runtime to both identify business risks that require urgent attention and surface remediation recommendations.<\/p>\n<p>Conor Sherman, global CISO for Sysdig, said <a href=\"https:\/\/www.sysdig.com\/press-releases\/sysdig-launches-secure-ai-to-democratize-machine-speed-cloud-defense\" rel=\"nofollow noopener\" target=\"_blank\">Sysdig Secure AI<\/a> makes it possible for cybersecurity teams to respond faster to cyberattacks that are increasingly occurring at machine speed as adversaries embrace AI. Sysdig Secure AI relies on AI skills tuned for each pillar of cloud defense that learn what\u2019s normal, what\u2019s critical, and which assets matter most within a cloud computing environment.<\/p>\n<p>The overall goal is to provide cybersecurity teams with a cloud-loop framework that enables them to leverage AI to thwart attacks as they continue to increase in volume via a natural language tool or a set of application programming interfaces that AI tools can use to <a href=\"https:\/\/securityboulevard.com\/2026\/05\/sysdig-launches-headless-cloud-security-platform-designed-for-ai-agents\/\" rel=\"nofollow noopener\" target=\"_blank\">invoke headless Sysdig services<\/a>, said Sherman.<\/p>\n<p>The Sysdig CNAPP is based on Falco, an open source threat detection engine that is now being advanced under the auspices of the Cloud Native Computing Foundation (CNCF). Sysdig is now integrating that engine with AI agents that are capable of analyzing the massive amounts of telemetry data collected via Falco.<\/p>\n<p>Sysdig claims that approach makes it possible for cybersecurity teams to handle more than 10 times as many investigations as human experts alone would be able to conduct at an 88% lower cost. For example, the company reports that a vulnerability investigation that takes three skilled analysts 45 minutes each at about $135 today can be done by one analyst with Sysdig Secure AI in under 15 minutes for $16, roughly $3.75 of that in tokens.<\/p>\n<p><a href=\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2026\/08\/Sysdig-2.jpg\" rel=\"nofollow noopener\" target=\"_blank\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-2113856 aligncenter\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/Sysdig-2-300x169.jpg\" alt=\"\" width=\"937\" height=\"528\"  \/><\/a><\/p>\n<p>It\u2019s not clear at what pace cybersecurity teams are embracing AI, but cybercriminals have not yet begun launching attacks using novel techniques enabled by AI, said Sherman. Instead, they are for the most part using AI to extend their existing tactics and techniques to launch attacks at machine speed, he added.<\/p>\n<p>Sysdig researchers, however, have previously observed an AI agent move from a single vulnerability to an organization\u2019s internal database in under one hour. They have also exposed JADEPUFFER, the first documented case of a ransomware attack managed end to end by an AI agent.<\/p>\n<p>Unfortunately, too many organizations are focused on trying to ascertain whether there are novel attacks being launched using AI versus using AI to automate the best practices that are already proven to thwart most of the attacks being launched against cloud computing environments, said Sherman.<\/p>\n<p>The challenge cybersecurity teams face is finding a way to thwart those attacks at scale while at the same time reducing the amount of expertise currently needed to secure a complex cloud computing environment, he added.<\/p>\n<p>There are, as always, a lot of competing priorities when it comes time to allocating limited cybersecurity resources, but as more applications are built using AI, the overall size of the attack surface that needs to be defended in the cloud is only going to increase to a point where no cybersecurity team alone is going to be able to secure it without help from AI.<\/p>\n<p>Frequently Asked QuestionsWhat is Sysdig Secure AI?<\/p>\n<p>Sysdig Secure AI is a set of AI agents integrated into Sysdig\u2019s cloud native application protection platform to identify risks, investigate threats and recommend remediation.<\/p>\n<p>How does Sysdig Secure AI use runtime data?<\/p>\n<p>It analyzes telemetry collected from cloud environments, including data generated through Falco, to understand normal behavior, prioritize critical assets and identify suspicious activity.<\/p>\n<p>What is Falco?<\/p>\n<p>Falco is an open source runtime threat detection engine originally created by Sysdig and now maintained under the Cloud Native Computing Foundation.<\/p>\n","protected":false},"excerpt":{"rendered":"TL;DR \u2014 Key Takeaways Sysdig Secure AI adds specialized AI agents to its CNAPP to prioritize cloud risks&hellip;\n","protected":false},"author":2,"featured_media":140323,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,24,405,7537,45874,69113,19417],"class_list":["post-140322","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-cnapp","tag-surface-remediation","tag-sysdig"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/140322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=140322"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/140322\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/140323"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=140322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=140322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=140322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}