
Security Operations
Exabeam New-Scale Fusion Security Operations Platform
Cloud-native SIEM with built-in UEBA and agentic AI for threat detection and response.
Exabeam New-Scale Fusion Security Operations Platform Overview
What it does
Exabeam New-Scale Fusion is a cloud-native security operations platform that unifies Security Information and Event Management (SIEM), user and entity behavior analytics (UEBA), and agentic AI to surface threats that static correlation rules miss. Its differentiator is a behavioral analytics engine that learns normal activity for human and non-human identities and scores anomalies by rarity and business context, layered on a cloud-scale security data lake and the Exabeam Nova AI agents that automate triage and investigation.
How it works
The platform collects data through prebuilt collectors that process more than 2 million events per second and over 7,000 prebuilt log parsers, normalizing it at ingestion with a Common Information Model. New-Scale Analytics builds behavioral baselines for human and non-human identities and assigns risk scores by rarity and severity, while analysts author, test, and version detections and up to 1,000 correlation rules. Threat Center unifies alerts, cases, detections, and watchlists in one workbench, and Exabeam Nova AI agents automate triage, run natural-language investigations, and map coverage to MITRE ATT&CK. Named customers include NTT Data, Aeromexico, and Canadian Pacific Railway.
Credentials and traction
SOC 2 Type II certified, with ISO 27001, ISO 27017, and ISO 27018 certifications and a completed IRAP assessment at the PROTECTED level for Australian public-sector workloads. Exabeam is named a Leader in the 2025 Gartner Magic Quadrant for Security Information and Event Management (SIEM). The platform serves large enterprises and government agencies across financial services, healthcare, transportation, and the public sector, with customers including NASA, MUFG, and the New York MTA.
Key Capabilities
mapped to solution categoriesFilters, routes, transforms, and enriches event data in the ingestion pipeline before storage, letting teams drop low-value data and tier the rest to control volume and cost.
Normalizes, enriches and risk-scores ingested data from third-party systems such as threat intelligence sources and CMDB.
Lets analysts author, test, and version custom detections, including detection-as-code and imports of Sigma and YARA rules, with tooling depth varying across platforms.
Stores essential event data long term and keeps it available for long-term searching with flexible retention options.
Investigates, evidences and reports on security alerts with case management to support incident response.
Manages and applies threat intelligence natively to enrich and prioritize detections, supporting vendor-curated and third-party feeds with availability varying by platform.
Provides built-in orchestration and automated response through playbooks on alerts and cases rather than requiring a separate SOAR product.
Provides prebuilt reports and dashboards mapped to frameworks such as PCI DSS, HIPAA, and GDPR, with out-of-the-box breadth varying across platforms.
Stores security event data long term with searchable recall across tiered hot and cold storage, with support for embedded or bring-your-own data lakes varying by platform.
Includes behavioral baselining and anomaly detection for users and entities in the core platform, eliminating the need for a separate UEBA product and the associated data movement.
Interoperates with XDR and extended telemetry and response sources such as EDR and NDR.
Builds behavioral baselines per user account, device, and application, capturing access timing, resource usage patterns, and activity volumes specific to each entity rather than aggregate thresholds.
Models attacker-in-residence scenarios (pre-resignation data staging, after-hours privileged access, bulk download exceeding peer norms), with risk scores decaying appropriately for resolved anomalies.
Combines multiple weak behavioral signals into a single risk score per user or entity, ranking which accounts warrant investigation so analysts focus on the highest-risk anomalies.
Applies ML classification to incoming alerts to filter false positives, group related events, and route high-confidence detections to analysts, reducing L1 analyst workload.
Inserts AI-generated analysis, triage decisions, and enrichment into existing SIEM and SOAR case management workflows rather than requiring analysts to use a separate interface.
Accepts natural language queries over security telemetry and translates them to structured queries, enabling investigation without requiring analyst proficiency in SPL, KQL, or SQL.
Assembles chronological attack timelines from raw events across multiple data sources automatically, reducing the time to build an initial incident narrative.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on August 5, 2026
Buyers
See how Exabeam New-Scale Fusion Security Operations Platform fits your stack
Add Exabeam New-Scale Fusion Security Operations Platform to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.