DataCentreNews Ireland - Specialist news for cloud & data centre decision-makers
Ireland
ExtraHop launches 400 Gbps sensor for RevealX platform

ExtraHop launches 400 Gbps sensor for RevealX platform

Tue, 25th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

ExtraHop has launched a 400 Gbps sensor for its RevealX network detection and response platform, saying it makes RevealX the first NDR platform able to analyse enterprise data centre traffic in full at that speed.

The launch addresses a problem for security teams as data centre networks have moved to 400 Gbps while many detection and response tools remain limited to 100 Gbps. As a result, some organisations sample traffic instead of inspecting all of it, creating visibility gaps in high-speed environments.

According to ExtraHop, the new sensor analyses traffic at line rate and feeds that data into RevealX, which maps devices, identities, workloads and network conversations in real time. Security operations teams and automated systems can then query that information through APIs and Model Context Protocol interfaces, and access underlying records such as behavioural detections, protocol activity, transaction data across more than 90 protocols, and packet capture.

The announcement comes as security vendors and customers grapple with the rise of automated attacks and the growing use of AI systems in corporate infrastructure. ExtraHop pointed to a sharp fall in mean time to exploit, from 23.2 days in 2025 to about 1.6 days in 2026, arguing that tools that see only part of network traffic leave little room for an effective response.

Dense east-west traffic inside data centres has also become harder to inspect as organisations add GPU clusters, Kubernetes workloads, model training pipelines, inference systems and traffic between software agents. ExtraHop said these conditions have made network sampling less viable and increased the risk that lateral movement, identity compromise and other intrusions go undetected.

Context Layer

ExtraHop positioned the sensor as part of a wider shift towards what it called an agentic security operations centre, where automated agents play a larger role in detection and response. In that model, the quality and completeness of available data become central, because partial telemetry can cause automated tools to make incorrect decisions quickly and at scale.

The company said the 400 Gbps sensor sits in the Context layer of the three-layer architecture used by the Agentic SOC Alliance: Context, Harness and Model. It argued that real-time structured evidence should sit alongside established systems such as security information and event management platforms and forensic data lakes, which are more often used for historical analysis.

Chris Konrad, Vice President of Global Cyber at World Wide Technology, said complete visibility at modern data centre speeds had become more urgent. "AI is compounding the volume of data moving across our infrastructure every day, and our security tooling has not kept pace with our data center," Konrad said. "Complete visibility at this scale is no longer optional post-Mythos. AI-powered attacks move at record speed, and the AI-powered systems need to be able to tell the difference between a quiet network and a network they are only partially seeing."

Market Pressure

ExtraHop said operating at 400 Gbps could also reduce the number of sensors needed in high-speed networks, cutting operational complexity and lowering overall cost. It added that a single real-time view of network activity could serve both security and IT operations teams, reducing the need to reconcile different data sources across tools.

The vendor also said the system supports a live inventory of AI-related assets, including large language model usage, MCP servers, tool endpoints and communication paths between agents. That reflects a broader push among security suppliers to give customers more visibility into how AI components are used inside enterprise environments.

Kanaiya Vasani, Chief Product Officer at ExtraHop, said the issue was less about adding AI to existing tools and more about the data beneath them. "The reflex across the industry has been to bolt AI onto the SOC we already have, and the harder problem is the context substrate underneath," Vasani said. "SIEMs, forensic data lakes, and security warehouses are built to look backward. They are valuable as depth and memory, but they cannot be the first and only source of truth for an agent that has to decide something right now. RevealX is the prevention side of that equation: structured, queryable evidence whose latency budget matches the attack. At 400 Gbps, the busiest networks in the world can hand their agents complete evidence instead of a sample, which is the difference between autonomy a CISO can defend to a regulator and autonomy that is confidently wrong at scale."