Exaforce adds a kill switch for AI agents that go rogue
Agentic security operations startup Exaforce Inc. today launched Exaforce AI Security, capabilities that let security teams see the artificial intelligence agents running across their environments and shut down the ones that turn hostile.
Exaforce built the release around a gap in how enterprise logs record what agents do. Agents act with the identities and permissions of the people who deploy them, so an agent that rotates a key or pushes code leaves an audit trail pointing back at an employee. A reviewer scrolling those logs finds nothing unusual in any single entry. The sequence is what gives an attack away.
Attackers have been working that same gap since at least last year. A June compromise of Canadian competitive intelligence company Klue Labs Inc. exposed its customers’ OAuth tokens, which were then used to pull data from their Salesforce environments. The same technique hit more than 700 organizations through Salesloft Inc.’s Drift chatbot in August 2025. Developers were the target in the Nx “s1ngularity” attack on the npm registry, where their own coding agents, Claude Code and Gemini CLI among them, were turned into credential hunters.
Four capabilities make up the release. Agentless discovery runs continuously and needs nothing installed, turning up connected AI apps, coding agents such as Claude Code and Cursor, hosted agents including custom GPTs, Model Context Protocol servers, skills and development environment plugins.
Each one is tied back to the person and the permissions behind it. A risk layer grades what that turns up and flags excessive permissions or unsanctioned applications. Threat detection and automated response round out the set.
Exaforce matches agent and model provider activity against human identities, endpoint telemetry, file access and code context, looking for misuse and sensitive data exposure that individual log entries would not reveal. Those actions run through endpoint detection and response, identity and model provider admin controls.
The platform can revoke a session, deactivate a model provider key, isolate a device or end an agent’s process, what the company calls an agent kill switch. Security teams set the autonomy on each action, from analyst-approved to fully automatic.
Feeding all of that are endpoint data, productivity suite activity and model provider audit and usage logs, pulled into the knowledge graph Exaforce already builds from identity, cloud, software-as-a-service and code sources. The release extends an integration Exaforce shipped in June with Anthropic PBC’s Claude Compliance API, adding OpenAI Group PBC’s ChatGPT, Google LLC’s Gemini and Microsoft Corp.’s Copilot.
Ankur Singla, co-founder and chief executive of Exaforce, said existing software-as-a-service and endpoint tools were “never built for this era of AI.” Nearly every company is now weighing AI adoption against its risks, he said, and security teams need agent activity landing where their identity, cloud and endpoint data already sit, without another rollout to get it there.
Exaforce AI Security is generally available today on the company’s agentic security operations platform, self-operated or through its managed detection and response service.
HarbourVest Partners, Peak XV Partners, Mayfield Fund, Khosla Ventures and Seligman Ventures backed a $125 million Series B round for the San Francisco-based company in May at a reported $725 million valuation. Exaforce has raised $200 million since it was founded in 2023.
Image: Exaforce
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.