TempMail Ninja
//

CyberAgents Exchange Launched by Tenable for AI Security Tools

7 min read
TempMail Ninja
CyberAgents Exchange Launched by Tenable for AI Security Tools

At Black Hat USA 2026 in Las Vegas, Tenable officially unveiled the CyberAgents Exchange, introducing the industry’s first purpose-built, open-source registry designed to help cybersecurity practitioners discover, test, share, and deploy artificial intelligence (AI) security tools. Built as a completely free, vendor-agnostic platform, the CyberAgents Exchange directly targets one of the most critical structural bottlenecks in modern security engineering: the tendency of cyber defenders to build custom AI agents in isolation. As security operations centers (SOCs) grapple with unsustainable alert volumes, sprawling attack surfaces, and rapid vulnerability disclosure cycles, teams have increasingly turned to autonomous agents and Model Context Protocol (MCP) implementations. However, operating in technical silos has historically led to duplicated engineering efforts, fragmented workflows, and restrictive vendor lock-in. By offering a centralized, peer-audited hub, Tenable and its founding partners are establishing a collaborative “town square” aimed at shifting cyber defense from isolated scripts to collective, enterprise-grade AI automation.

The Fragmented State of Agentic Security: Why Solitary AI Development Fails

Over the past several years, the cybersecurity landscape has undergone a major paradigm shift. The security industry has transitioned from passive Large Language Model (LLM) chat prompts—which merely answer static queries or generate basic remediation scripts—to active, agentic AI workflows capable of executing multi-step investigations, triggering API calls, and enforcing policy responses. Yet, as security developers and security operations engineers began constructing bespoke agents, a persistent challenge emerged. Defender tooling suffered from acute fragmentation.

When an enterprise security engineering team constructs an agent to automate vulnerability triage or cloud security posture management (CSPM) auditing, that intellectual property rarely leaves the enterprise ecosystem. Across thousands of organizations, engineers end up writing nearly identical python scripts, prompt templates, and API connectors. Existing AI model hubs and tool marketplaces present two major drawbacks for security professionals:

  • General-Purpose AI Repositories: Broad AI registries lack cybersecurity domain context, requiring defenders to filter through thousands of consumer, marketing, or general software tools to find relevant security utilities.
  • Vendor-Gated Ecosystems: Proprietary vendor marketplaces tie agentic workflows to specific commercial stacks, preventing practitioners from orchestrating tools across multi-cloud and multi-vendor security telemetry.

To overcome these barriers, security operations require a unified framework built on open standards where defense tools can interface across disparate telemetry sources—such as Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Cloud Security Posture Management (CSPM), and Vulnerability Management (VM). The launch of the CyberAgents Exchange delivers this exact missing architecture, creating an ecosystem built “by defenders, for defenders”.

Dissecting the CyberAgents Exchange: Architecture, Registry Components, and Open Standards

Hosted publicly at exchange.tenable.com, the CyberAgents Exchange operates as an open-source, vendor-neutral registry. Rather than serving as a simple code repository, the platform categorizes security automation into four foundational building blocks:

  1. AI Agents: Autonomous units of intelligence capable of receiving complex natural language objectives, planning execution steps, invoking external tools, and evaluating outcomes dynamically.
  2. Skill Files: Modular, task-specific logic packages or prompt definitions that equip an underlying model with specialized domain knowledge—such as parsing threat intelligence feeds or executing specific hunting patterns.
  3. Model Context Protocol (MCP) Servers: Standardized protocol servers that expose data pipelines, system APIs, and security services to any MCP-compliant client, removing the need for proprietary wrapper code.
  4. Multi-Agent Playbooks: Orchestrated sequences where multiple AI agents collaborate, passing context, evidence, and execution authorization between specialized roles.

The exchange debuts with over 50 open-source AI components available under permissive open-source licenses. Key tools available at launch showcase the breadth of community and vendor contributions:

  • Navi (Agent): Developed as an open-source command-line interface (CLI) tool, Navi integrates directly with Tenable One Vulnerability Management APIs. It allows security engineers to execute natural-language queries against exposure data, automate routine vulnerability triage, evaluate asset criticality scores, and streamline cyber exposure reporting across vast asset inventories.
  • SentinelOne Purple AI MCP Server: Built upon the open Model Context Protocol framework, this MCP server enables security analysts to query telemetry and trigger SentinelOne endpoint protection actions from any MCP-compatible AI client or interface. By decoupling the AI client from the underlying security stack, organizations gain the ability to orchestrate endpoint response capabilities seamlessly.
  • Recorded Future MITRE APT Attack Path Analysis (Skill): This automated threat intelligence skill fetches an organization’s live Recorded Future threat landscape, extracts Advanced Persistent Threat (APT) group tactics, techniques, and procedures (TTPs), and maps them directly against MITRE ATT&CK frameworks. By cross-referencing these mappings against live Tenable exposure findings, the skill pinpoints which attack path nodes are actively exploitable in real time.
  • SOC-Hunter (Skill): Developed and used internally by Tenable’s own security operations center team, SOC-Hunter provides proactive, hypothesis-driven threat hunting across SIEM, EDR, VM, CSPM, Cloud Access Security Broker (CASB), and code search environments. Operating on structured methodologies like the LOCK pattern (Learn, Observe, Check, Keep) and the TRACE pattern (Trigger, Recon, Assess, Conclude, Emit), SOC-Hunter enables SOC analysts to execute count-first query layer analysis, maintain session memory graphs, and detect statistical behavioral anomalies.
  • The Hounds Pack (Playbook): A multi-agent playbook that packages specialized threat-hunting and exposure management skills into a coordinated execution chain, demonstrating how independent agents can collaborate to resolve enterprise incidents.

Addressing the Supply Chain Paradox: Code-Level Transparency and Zero-Trust Verification

Integrating AI agents into enterprise security environments introduces unique risk vectors. Because security agents require high-privilege access—such as querying vulnerability databases, reading log streams, and executing containment commands via APIs—untrusted or compromised AI components pose severe software supply-chain risks. An unchecked third-party agent could potentially leak sensitive credentials, execute unverified commands, or exhibit hallucinated decision-making during critical security incidents.

To eliminate this threat vector, the CyberAgents Exchange is built on a framework of code-level transparency and zero-trust verification. Before deploying any component into production environments, security teams can inspect the complete source code, review clear author provenance, verify build timestamps, and check peer-audit status. This transparent architecture allows security architects to perform static analysis, verify API endpoints, and establish strict containment guardrails.

Furthermore, the exchange supports human-in-the-loop governance patterns, ensuring that high-impact actions—such as rotating enterprise credentials or isolating mission-critical cloud workloads—require explicit human validation. By combining open-source visibility with clear audit trails, the registry provides the trust model necessary for conservative enterprise risk teams to adopt agentic automation confidently.

Ecosystem Velocity: Founding Partners, Industry Response, and the SWARM Hackathon

The success of an open-source exchange relies heavily on continuous community participation and ecosystem backing. Demonstrating broad industry alignment, leading cybersecurity and threat intelligence providers have joined Tenable as founding members. Industry leaders including SentinelOne and Recorded Future have pledged ongoing contributions, supplying open-source playbooks, agent skills, and threat intelligence modules directly to the registry.

Tenable Chief Technology Officer Vlad Korsunsky emphasized the necessity of a unified defender ecosystem during the launch, stating: “Security is a team sport. We’ve addressed a gaping hole in the ecosystem of AI Agents, built for defenders, by defenders.” Jamie Zajac, Chief Product Officer at Recorded Future, underscored the operational value of open frameworks, noting that the exchange provides the necessary foundation for autonomous defense tools that are “traceable, auditable and repeatable.”

Practitioners in enterprise environments have expressed strong support for the collaborative model. Seth Fogie, Director of Security at Baptist Memorial Health Care, highlighted the strategic parallel between threat intelligence sharing and AI tooling: “The CyberAgents Exchange fills a major and pressing industry need… Its core philosophy of working together is what made the threat intelligence community so invaluable.”

To catalyze community contributions at launch, Tenable hosted SWARM: The Cybersecurity Agentic AI Build Event alongside Black Hat USA 2026. Sponsored by Amazon Web Services (AWS) and presented with support from Anthropic, the multi-day event brought together hundreds of security engineers, developers, and researchers. Participants competed in hands-on building sessions at the Four Seasons Hotel in Las Vegas to construct open-source agents, skill files, and MCP servers. With incentives including up to $2,000 in Anthropic Claude credits per winning team member and a grand raffle for an Nvidia DGX Spark compute cluster, the SWARM event produced a diverse wave of community-built defense tools that were published directly to the exchange platform.

Strategic Outlook: What the CyberAgents Exchange Means for the Future SOC

The launch of the CyberAgents Exchange marks a critical milestone in the evolution of security operations. As AI capabilities advance, the enterprise SOC is undergoing a fundamental transformation from human-only manual triage to governed human-agent collaboration. Instead of requiring security analysts to manually correlate log alerts, search for vulnerability exploits, and write mitigation scripts, agentic architectures enable digital defenders to act as strategic orchestrators.

By standardizing how security tools communicate through protocols like MCP and providing a vendor-agnostic repository, the CyberAgents Exchange lowers the barrier to entry for enterprise security automation. Security teams no longer need to spend months developing custom integrations from scratch. Instead, they can pull peer-reviewed components from the registry, customize the logic to fit their specific risk tolerance, and deploy automated defenses in hours rather than months.

In an environment where threat actors leverage AI for automated reconnaissance and rapid exploit delivery, defensive operations must operate with equivalent speed and agility. By replacing fragmented, isolated development with an open, transparent, and collaborative registry, the CyberAgents Exchange provides the structural foundation needed to scale agentic security operations across the global digital ecosystem.

TN

Written by

TempMail Ninja

Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.