# Ent Emerges With $100M to Build Intent-Aware Endpoint Security for the AI-Agent Era


Startup promises predictive threat prevention before incidents occur, backed by RiskIQ veterans and marquee VCs


Endpoint security startup Ent has announced its public arrival with a landmark $100 million seed round, positioning itself at the intersection of artificial intelligence and cybersecurity—a space that's becoming critical as enterprises deploy autonomous AI agents across their infrastructure.


The San Francisco-based company, founded by cybersecurity veterans Elias Manousos and Brandon Dixon (both former RiskIQ executives who contributed to Microsoft Security Copilot), has developed a lightweight endpoint agent designed to interpret and predict risky behavior before it can be executed, fundamentally shifting security from reactive detection to proactive prevention.


## The Threat: Why Traditional Endpoint Security Is Failing


For over a decade, enterprise security has operated within a well-established paradigm: detect malicious activity after it occurs, then respond. This reactive loop has been the foundation of modern security stacks—endpoint detection and response (EDR), security information and event management (SIEM), and security orchestration platforms (SOAR) all follow this detect-then-respond model.


But the landscape has shifted dramatically.


Two simultaneous trends have created a critical blind spot:


  • Legitimate work now resembles attacks. As enterprises adopt cloud services, API-driven workflows, and data analytics, many normal business activities mirror the indicators that traditionally signal compromise—unusual login locations, bulk file transfers, API calls from unfamiliar sources.

  • AI agents execute at machine speed. When autonomous agents orchestrate workflows across corporate systems, they can perform in seconds what once took attackers hours or days to accomplish. By the time traditional security tools detect and alert on the activity, the damage is already done.

  • Ent's core thesis is that this timeline gap is now fatal. The company argues that waiting for an incident to manifest—even with advanced EDR—leaves enterprises too late in the attack chain.


    ## Background and Context: The Founders and Their Vision


    Manousos and Dixon aren't newcomers to enterprise security. Both are known for building RiskIQ, a threat intelligence platform that Microsoft acquired in 2021 for an undisclosed amount (reported in the $400–600 million range). Following the acquisition, both contributed to the development of Microsoft Security Copilot, Microsoft's flagship AI-powered security analysis tool.


    That background is significant: these founders understand both the promise and the limitations of current security infrastructure. In a statement, Manousos said:


    > "Security has been stuck in a reactive loop for over a decade, but AI-powered attacks require new thinking. What once took days now happens in seconds. By the time traditional security systems detect a problem, it is too late. We believe the future of security lies in understanding intent in real time across people and AI agents and stopping risk before it becomes an incident."


    The funding round reflects confidence from marquee investors:


    | Lead Investor | Co-investors |

    |---|---|

    | Decibel | Sequoia Capital, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis Ventures, In-Q-Tel |


    The presence of In-Q-Tel—the venture arm of the U.S. intelligence community—signals that government security agencies view Ent's approach as strategically important, particularly as federal agencies grapple with securing AI adoption across their own operations.


    ## Technical Details: How Intent-Aware Security Works


    Ent's platform departs from traditional endpoint detection by introducing real-time AI reasoning directly at the endpoint device. Rather than logging events and waiting for SIEM correlation or EDR detection rules to fire, Ent's lightweight software agent continuously evaluates behavior patterns as activities occur.


    The system operates on three core principles:


    1. Behavioral modeling of both users and agents. The platform learns legitimate behavior patterns for individual users and AI agents operating within the organization. This context is essential—what constitutes "suspicious" for a finance analyst differs from what's suspicious for a security engineer.


    2. Intent prediction before action completion. Rather than detecting that a file transfer occurred, the system evaluates the *intent* behind the transfer as it's initiated. Is a user attempting to exfiltrate sensitive data, or are they performing a legitimate backup? The system aims to make this determination before the action completes.


    3. Custom policy enforcement. Organizations define their own risk thresholds and acceptable behaviors. Ent applies these policies dynamically, triggering interventions (blocking, alerting, or requiring additional authentication) without waiting for downstream security tools to detect the activity.


    Ent is positioning its platform as a complementary layer, not a replacement for existing security infrastructure. The company states it works alongside EDR, SIEM, SOAR, and identity and access management (IAM) solutions, extending their capabilities rather than displacing them.


    ## Implications for Enterprise Security


    The funding announcement and Ent's emergence reflect a broader industry shift: the recognition that AI-augmented threat detection is becoming table stakes for enterprise security.


    ### For CISOs and Security Teams

    Ent's approach suggests that traditional security architecture—built around post-incident detection—may be insufficient for environments where autonomous agents and AI-powered workflows are commonplace. Security teams will need to rethink their detection and prevention strategies around intent prediction, not just anomaly detection.


    ### For Organizations Deploying AI Agents

    Enterprises scaling internal AI agents for workflow automation face a dilemma: these agents are powerful and efficient, but they also expand the attack surface. If a threat actor compromises the controls governing an AI agent, that agent can perform high-impact actions automatically. Ent's approach—understanding agent intent before action—directly addresses this risk.


    ### For Incident Response

    A successful intent-aware prevention system could fundamentally change incident response timelines. If incidents are prevented before execution, breach response teams shift from containing damage to investigating the *intent* that triggered an intervention.


    ## Recommendations for Organizations


    Evaluate your endpoint security posture:

  • Audit whether your current EDR and SIEM solutions can distinguish between legitimate and malicious behavior in AI-agent workflows. If not, this represents a gap.
  • Document how your organization currently handles AI agents with elevated permissions or sensitive access—this is a high-risk category.

  • Plan for behavioral analysis:

  • Begin baselining normal behavior patterns for critical users and systems. Intent-aware systems depend on understanding what "normal" looks like.
  • Establish clear policies for what constitutes acceptable behavior, particularly around data access and movement.

  • Integrate intent-aware tools strategically:

  • As platforms like Ent mature, consider how they might complement (not replace) your existing security stack.
  • Pilot any new endpoint security layer on non-critical systems first to understand false positive rates and tuning requirements.

  • ---


    ## HackWire Analysis


    The Real Story: Prediction as a Security Bottleneck


    The traditional security narrative frames this as a technology problem—better detection, faster response, smarter algorithms. Ent's framing is subtly different: it's a timing problem. And that distinction matters.


    The shift from reactive to predictive security has been promised before. Machine learning in security has been the industry's north star for five years, yet most organizations still operate primarily on detection and response. Why? Because prediction is fundamentally harder than detection, and false positives are expensive.


    Here's what Ent isn't saying explicitly but implies strongly: intent-aware security will require organizations to make tradeoffs. A system that prevents actions based on predicted intent will inevitably block some legitimate activities. The question isn't whether false positives exist—they will—but whether they're tolerable compared to the cost of a breach.


    The $100 million funding and the quality of the backers suggest the venture community believes this answer is yes. But the real test comes in deployment. Can Ent's system actually learn to distinguish between a data scientist legitimately pulling a large dataset for analysis and an insider exfiltrating trade secrets? Can it understand that an AI agent running a scheduled backup isn't the same as an AI agent exfiltrating data?


    The timing also matters. Ent's emergence coincides with a broader recognition that autonomous AI agents in the enterprise are no longer a theoretical future—they're here. Enterprise adoption of AI agents is accelerating faster than security practices are evolving to protect them. That gap is where Ent is positioning itself, and it's a genuine market inflection point.


    The signal from In-Q-Tel is particularly telling: the U.S. government is visibly concerned about securing AI adoption at scale. That concern isn't abstract—it's operational. Ent is solving a problem that matters at the highest levels of national security infrastructure.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [AI Security](https://www.hackwire.news/category/vulnerabilities) and [Endpoint Protection](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)