Blumira's Hearth Turns Security Investigations from Hours Into Minutes With AI Reasoning

Blumira's Hearth Turns Security Investigations from Hours Into Minutes With AI Reasoning

BackerLeader 44 258 456
calendar_todayschedule3 min read

Security teams already know the real problem isn't a lack of tools. It's the time it takes to move between them. A detection fires in one product, the context lives in three others, and by the time someone's pieced together what actually happened, the window to respond fast has already narrowed.

Blumira is launching Hearth, an AI command center built to close that gap. It's not a replacement for the company's existing SIEM or its Kindling triage engine — it's a separate layer that sits on top of a team's full stack, Blumira or not, and reasons across it.

Why triage isn't the hard part

Most detection products can already take some kind of action on their own — kill a process, isolate a machine. According to Blumira CEO Matt Warner, that's the easy half. The hard half is coordinating a response across every tool a team runs, especially when none of those tools were built to talk to each other.

That's the distinction Blumira is drawing between Kindling, which handles alert triage inside the platform, and Hearth, which extends investigation, response, and follow-up across a team's entire toolset. Ask Hearth to run a full DFIR investigation, and it pulls from five sources at once: stored logs, direct API connections, daily environment risk analysis, memory from past investigations, and the accumulated knowledge the team has generated through prior use. Warner says the goal is to make that kind of investigation something a user can trigger with a single ask, rather than something that requires stitching data together by hand.

Autonomy with a leash

The part likely to draw the most scrutiny from security teams is how much Hearth is allowed to do on its own. Blumira's answer is a risk-tiered system. Low-risk actions — sending an email, posting to Teams — can move without much friction. Medium-risk actions, like disabling a user or adding a hash to a CrowdStrike blocklist, get more scrutiny. High-risk, harder-to-reverse actions — deleting files, deleting users — require explicit human approval every time. Warner puts the underlying rule simply: disable a user rather than delete one, whenever the situation allows it.

That framing tracks with what Warner says he's hearing from midmarket and channel customers: they're less worried about AI taking automated action than they used to be, particularly for identity-based threats, where a fast reversible action beats waiting on a human who might not be watching in time.

Working outside the Blumira stack

Blumira is positioning Hearth as usable even by organizations that don't run any Blumira products at all. Warner's example: a company running Microsoft Sentinel for SIEM, M365 for identity, CrowdStrike for endpoint detection, and Oracle for cloud. A CrowdStrike detection on its own might not carry enough context to act on. Hearth pulls in the M365 identity data for that same user, and if the pattern matches something like a ClickFix attack, it can recommend resetting credentials, isolating the host, and flagging the incident as more serious — all without anyone having pre-mapped how those tools relate to each other.

Built for MSPs managing more than one environment

For managed service providers, the pitch is fleet-wide visibility: ask which clients in a portfolio are exposed to a given CVE, and get an answer across every environment at once instead of opening a dashboard per client. Blumira says tenant boundaries are enforced through its own access mapping combined with role-based access control, so each user's data access is scoped to what they're provisioned to see — a detail that matters as much for compliance as it does for accuracy.

Blumira has started onboarding MSPs onto Hearth and says the biggest shift they're reporting is the ability to do fleet-wide discovery and research with far less manual effort, cutting into how often they need to bring in outside incident response help for that last stretch of an investigation.

An early reaction from the field

Stephen Biasotto, lead systems engineer at Nettology, offered one of the more grounded endorsements available in security marketing right now: "A lot of products are throwing AI in just to say they have it. Hearth is cool and it's actually useful. I like the way Blumira designs things — the ideas make sense, the product works, and it's easy to use."

What it costs

Hearth is a separate product from Blumira's core platform, though it integrates natively with it. Existing Blumira customers get a lower price, but Warner says Hearth is available to any team, regardless of what else is in their stack.

For engineering and security teams already drowning in tool sprawl, the appeal isn't the AI label — it's whether Hearth actually cuts the time between "something happened" and "here's what we did about it." Blumira's early MSP feedback suggests it's moving that needle. Whether it holds up at scale, and with harder numbers behind it, is worth watching as more teams put it to use.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Helping Clients Move from Pilot to Production: The Agentic AI Governance Playbook

Tom Smithverified - Jun 8

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

From Prompts to Goals: The Rise of Outcome-Driven Development

Tom Smithverified - Apr 11

Torq SOC Brain: Why Reasoning From Precedent Beats Retrieving It

Tom Smithverified - Jul 28

The Security Conversation Your Clients Aren't Having About Agentic AI

Tom Smithverified - Jun 29
chevron_left
17.7k Points758 Badges
236Posts
135Comments
100Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

5 comments
2 comments
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!