AI for SecOps vendor directory · SecOps Unpacked
All 140 vendor profiles in full
Independent, practitioner-run research directory. Generated 2026-07-26. Each heading links to the vendor's own page, which is the canonical citation URL. Also available as plain text; site guide at llms.txt.
- Capabilities
- AI SOC Pure Play, MDR
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://7ai.com/
Profile last updated 2026-06-26.
Above turns scattered telemetry into defensible stories of intent, not just isolated events.
Instead of flooding teams with alerts or relying on blunt blocking, Above detects risky human behavior in real time to prevent it from becoming an incident.
Above is an insider risk management platform built around narrative intelligence: it continuously observes how employees interact with data, apps, identities, and AI tools.
Those signals get stitched into clear, human-readable timelines that explain what happened, why it happened, and how risk evolved over time. Humans are at the center of everything we do. With in-the-moment coaching, and automatically produced investigation-ready narratives that security, legal, and HR can actually use.
- Primary category
- Insider Threat / DLP
- Capabilities
- Insider Threat / DLP, Data Analytics / UABA, SecOps Resilience
- Deployment archetype
- Plug and Play
- Headquarters
- Wilmington, United States
- Founded
- 2025
- Funding stage
- Series A
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.above.security/
Profile last updated 2026-07-10.
A security-native SIEM built for how modern SOCs actually work. Composable architecture means your data stays in your environment, routes anywhere, and isn't held hostage by a single vendor's pricing model. Streaming pipelines, AI-assisted detection, and scalable retention that bends to your stack.
- Capabilities
- SIEM, AI SOC Capability, Data Analytics / UABA, Detection Engineering
- Deployment archetype
- Plug and Play
- Headquarters
- Palo Alto, United States
- Founded
- 2023
- Funding stage
- Series A
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.abstract.security/
Profile last updated 2026-06-26.
- Primary category
- MDR
- Capabilities
- MDR, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- http://www.airmdr.com/
Profile last updated 2026-07-10.
- Capabilities
- Automation, AI Agent Builder, AI SOC Pure Play
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://airrived.ai/
Profile last updated 2026-06-26.
AiStrike delivers an AI-native approach to modern security operations by covering the full lifecycle of detection, investigation, and response. The platform stands out for its ability to operate across both the “left side” and “right side” of the incident response lifecycle, combining detection engineering, threat intelligence operations, automated triage, investigation, response, and remediation into a unified operational model.
On the left side, AiStrike focuses on improving detection coverage, operational visibility, and threat intelligence utilization. The platform helps organizations continuously refine detections, enrich security context, and identify emerging threats before they escalate into incidents. This positions AiStrike beyond traditional alert-handling solutions by addressing the upstream operational challenges that often create investigation bottlenecks inside the SOC.
In the middle of the lifecycle, AiStrike accelerates triage and investigation workflows through AI-driven analysis, correlation, and operational automation. The platform reduces manual investigation effort while helping analysts prioritize high-fidelity threats and reduce alert fatigue.
On the right side, AiStrike extends into response and remediation, enabling organizations to operationalize findings and automate corrective actions across their environment. Combined with its MDR offering, AiStrike provides organizations with both AI-driven automation and human-led expertise, supporting a more proactive and continuously adaptive security operations model.
- Capabilities
- AI SOC Pure Play, Detection Engineering, Automation, Threat Intel, MDR
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- Funding stage
- Seed
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.aistrike.com/
Profile last updated 2026-06-26.
- Capabilities
- Data Analytics / UABA, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering
- Website
- https://www.alphalevel.ai/
Profile last updated 2026-06-26.
Andesite, the Human-AI SOC, puts humans at the helm, empowering cyber defenders to oversee AI-driven workflows, assess threats, respond immediately, reduce risk, and focus on prevention.
Our product enables SOC teams to configure their agents and playbooks, oversee and guide AI-driven automated triage, enrichment, investigation, and response. Using Andesite, cyber defenders work at machine speed while validating evidence and making the critical decisions they are accountable for.
Built for the high-complexity, high-risk world of enterprise and national security, Andesite's architecture adapts to customers' tools, workflows, and use cases. It connects silos, reduces inefficiencies, and uses contextual awareness to analyze risk and exposure, offering CISOs a future-proof, flexible product that evolves with their ecosystem.
- Capabilities
- AI Agent Builder, AI SOC Pure Play, Threat Intel, Threat Hunting, Data Analytics / UABA
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- McLean, United States
- Founded
- 2024
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://andesite.ai/
Profile last updated 2026-07-13.
- Capabilities
- AI SOC Capability, Data Analytics / UABA, SIEM, Threat Intel, Threat Hunting
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.anomali.com/
Profile last updated 2026-06-26.
At a glance AI SOC platform that unifies detection engineering, AI triage, and workflow automation across existing SIEMs (Splunk, Sentinel) and cloud data lakes (Snowflake, Databricks, Azure). Runs on your data — no rip-and-replace required. Deployment model SaaS — BYOD (Bring Your Own Data Lake) Anvilogic is a cloud-hosted platform that connects to the customer's own data environment.
- Capabilities
- SIEM, Detection Engineering, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- Palo Alto, CA, USA
- Founded
- 2019
- Funding stage
- 85M - Series C
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://anvilogic.com/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play, Data Analytics / UABA
- Deployment archetype
- Plug and Play
- Headquarters
- India
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://aquilai.io/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.arcanna.ai/
Profile last updated 2026-06-26.
- Primary category
- MDR
- Capabilities
- MDR, SIEM, Data Analytics / UABA, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://arcticwolf.com/
Profile last updated 2026-07-10.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, Threat Hunting, Threat Intel, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://artemissecurity.com/
Profile last updated 2026-06-26.
- Primary category
- Data Ingestion & Processing
- Capabilities
- Data Ingestion & Processing, Data Analytics / UABA
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Hungary
- SecOps Shift Map coverage
- Data
- Website
- https://axoflow.com/
Profile last updated 2026-07-10.
- Capabilities
- SIEM, Automation, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://beacon.security/
Profile last updated 2026-06-26.
Binalyze is an Investigation Automation and Response platform that makes a SOC complete. Built for security operations and incident response teams, Binalyze AIR transforms alerts into actionable understanding through automated investigation and forensic-level visibility across endpoint, cloud, and hybrid environments.
By integrating with existing SIEM, EDR, XDR, and SOAR technologies, AIR enables organizations to investigate threats faster, uncover root cause with confidence, and respond with clarity and precision.
Trusted by enterprises, MSSPs, and incident response providers worldwide, Binalyze helps defenders reduce complexity, strengthen cyber resilience, and turn fragmented signals into conclusive answers. Learn more at binalyze.com.
- Primary category
- DFIR / Forensics
- Capabilities
- DFIR / Forensics, Automation, Threat Hunting, CIRM / Case Management, AI SOC Capability, AI Agent Builder
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Tallinn, Estonia
- Founded
- 2018
- Funding stage
- Series A
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- www.binalyze.com
Profile last updated 2026-07-10.
Binary Defense is one of the most trusted names in MDR, founded by offensive security operators who built the company on a simple idea: the best defense thinks like the attacker. That legacy lives on in our Agentic MDR, where human instinct and AI speed work together to help organizations.
- Primary category
- MDR
- Capabilities
- MDR, Threat Hunting, AI SOC Capability, Automation, CIRM / Case Management, Data Ingestion & Processing, DFIR / Forensics
- Deployment archetype
- Plug and Play
- Headquarters
- Cleveland, United States
- Founded
- 2012
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://binarydefense.com/
Profile last updated 2026-07-10.
BlinkOps is an Agentic Security Operations Platform built for enterprise-scale security teams that need to operate faster than manual processes and point solutions allow.
The platform is built around a composable agent architecture that combines deterministic agents for high-volume, known patterns with reasoning agents for complex, evolving threats. Security teams can deploy across every major security function, including SOC, threat hunting, vulnerability management, IAM, GRC, cloud security, and asset management, from a single platform rather than stitching together disconnected tools.
Where most AI SOC vendors operate as black boxes, BlinkOps gives teams full visibility into agent logic, execution, and decisions. Human-in-the-loop controls are built in, not bolted on. Every action is auditable.
Deployment starts with pre-built solutions like Agentic SOC, then scales through 30,000+ integrations to fit any existing stack. For teams that need faster time-to-value, AI-as-a-Service provides forward-deployed engineers who assess, design, and build customized agentic solutions from day one.
BlinkOps is purpose-built for enterprises that want to replace fragmented, manual security operations with a single platform that agents can run at scale, without giving up control of how decisions get made..
- Primary category
- AI Agent Builder
- Capabilities
- AI Agent Builder, SOAR, Threat Hunting, Threat Intel, AI SOC Capability
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- Austin, United States
- Founded
- 2021
- Funding stage
- Series B
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.blinkops.com/?utm_campaign=44388369-chnl-influencer-secops-unpacked&utm_source=blog&utm_content=learn_more
Profile last updated 2026-07-10.
Bricklayer AI enables organizations to deploy specialized AI agents that share investigative context, collaborate through structured procedures, and operate under defined governance and human oversight. Built around the architectural principles of Context, Coordination, and Control, Bricklayer enables security teams to reduce noise, accelerate investigations, and scale security operations.
- Capabilities
- Threat Hunting, Threat Intel, AI SOC Pure Play
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- Arlington, United States
- Founded
- 2023
- Funding stage
- Seed
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.bricklayer.ai/
Profile last updated 2026-06-26.
- Capabilities
- Automation, AI Agent Builder, AI SOC Pure Play
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.cantina.security/
Profile last updated 2026-06-26.
Five layers. One lakehouse. Land your security data as OCSF Parquet on any S3-compatible storage. Query it in seven languages, SPL, SQL, KQL, Sigma, PromQL, natural language, or the native Caver UI, over one lake you own. Caver is the enterprise SIEM you run on top: no per-GB ingest tax
- Capabilities
- AI SOC Capability, SIEM, Data Ingestion & Processing, Data Analytics / UABA, SOAR, Threat Intel, Threat Hunting, DFIR / Forensics
- Deployment archetype
- Plug and Play
- Headquarters
- Nashville , United States
- Founded
- 2026
- Funding stage
- Bootstrapped
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://etairos.ai/caver/
Profile last updated 2026-06-26.
- Capabilities
- MDR, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Saudi Arabia
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.cognna.com/
Profile last updated 2026-06-26.
Command Zero is the autonomous and AI-assisted SOC platform built for complex enterprise environments. The platform combines an expert-encoded knowledge base, controlled AI agents, and human-led investigation tools to deliver consistent, auditable analysis at scale.
Through a federated data model, Command Zero connects directly to your existing data sources—identity systems, EDR, cloud platforms, SIEM—without data ingestion or migration. Analysts and AI agents work from the same encoded knowledge base, ensuring predictable outcomes across all tiers.
AI agents handle high-volume tier-1 tasks and standard investigations, then pass their work—tools, context, and findings—to human analysts for complex cases.
The result: Faster mean time to understand and respond, with best practices that scale through both AI automation and human expertise.
- Capabilities
- AI SOC Pure Play, Threat Hunting, CIRM / Case Management, Automation, Insider Threat / DLP
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Austin, United States
- Founded
- 2022
- Funding stage
- Seed
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.cmdzero.io/
Profile last updated 2026-06-26.
- Capabilities
- CIRM / Case Management, Detection Engineering, SecOps Resilience, Threat Hunting, Threat Intel, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.conifers.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI Agent Builder, AI SOC Pure Play
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.cotool.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://countershadow.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Data Analytics / UABA, Data Ingestion & Processing, Detection Engineering, AI SOC Capability
- Deployment archetype
- Build it Yourself
- Headquarters
- San Francisco, United States
- Funding stage
- Series D+
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://cribl.io/solutions/initiatives/investigations/
- Primary category
- MDR
- Capabilities
- MDR, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.criticalstart.com/
Profile last updated 2026-07-10.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.crogl.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Data Analytics / UABA, SOAR, Threat Hunting, MDR, DFIR / Forensics, Threat Intel, AI SOC Capability, AI Agent Builder
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.crowdstrike.com/en-us/platform/charlotte-ai/agentic-soar/
Profile last updated 2026-07-06.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.culminatesecurity.com/
Acquired by Datadog.
Profile last updated 2026-06-26.
- Capabilities
- Data Analytics / UABA, DFIR / Forensics, SIEM, Threat Hunting, AI SOC Capability, Automation
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United Kingdom
- Founded
- 2009
- Website
- https://emilyai.io/#platform
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Capability, Data Analytics / UABA
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.cyberproof.com/defense-management/
Profile last updated 2026-06-26.
- Capabilities
- CIRM / Case Management, AI SOC Capability
- Deployment archetype
- Build it Yourself
- Headquarters
- Australia
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.cydarm.com/
Profile last updated 2026-06-26.
Next Generation SaaS Security Platform - One unified cloud platform to achieve your security, compliance, and operational objectives.
- Primary category
- SIEM
- Capabilities
- SIEM, AI SOC Capability, SOAR, MDR, Data Ingestion & Processing, Detection Engineering, Threat Hunting, Data Analytics / UABA
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://cylerian.com/
Profile last updated 2026-06-26.
Cymph is an Incident Response Readiness platform that gives security teams continuous visibility into their response coverage: which threats they are ready to address, where the gaps are, and the tools to close those gaps.
- Capabilities
- SecOps Resilience
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Tallinn, Estonia
- Founded
- 2023
- Funding stage
- Bootstrapped
- SecOps Shift Map coverage
- Detection Engineering
- Website
- https://www.cymph.io
Profile last updated 2026-07-10.
- Capabilities
- CIRM / Case Management, Threat Intel, AI SOC Capability
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://cyware.com/
Profile last updated 2026-06-26.
D3 Security builds Morpheus, an AI-autonomous SOC platform. Running on one purpose-built reasoning engine, it performs L2-depth Attack Path Discovery on every alert across your existing security stack—triaging up to 95% in under two minutes—then orchestrates governed response through a built-in SOAR engine and case management, delivering end-to-end alert investigation and incident response on a single platform.
Where most agentic SOC vendors ship a fleet of separate agents—each with its own logic and log format, each requiring its own governance review—Morpheus inverts that. Triage, investigation, AI-augmented playbook building, and response are surfaces of the same engine, sharing one per-tenant context and producing one unified audit trail per incident. That trail reads identically to a SEC examiner, a NIS2 competent authority, or a DORA supervisor.
Four selectable autonomy modes—from fully deterministic to end-to-end autonomous—are configurable per workflow, per tenant, per regulator, and migration between them is a configuration change, not a rebuild. Self-healing integrations adapt automatically when vendor APIs change, so the alert pipeline never goes dark.
Morpheus is built to scale—for large enterprises, multi-tenant MSSP deployments, and SOC teams moving from SOAR to AI SOC who still require a full, governable, accountable incident response solution.
- Primary category
- AI SOC Capability
- Capabilities
- AI SOC Capability, SOAR, SecOps Resilience, Threat Hunting
- Deployment archetype
- Build it Yourself
- Headquarters
- Vancouver, Canada
- Founded
- 2012
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- http://www.d3security.com/
Profile last updated 2026-07-06.
- Capabilities
- AI SOC Capability, Data Analytics / UABA, DFIR / Forensics
- Deployment archetype
- Plug and Play
- Headquarters
- United Kingdom
- SecOps Shift Map coverage
- Data, Triage and Investigation
- Website
- https://www.darktrace.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Automation, AI Agent Builder
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://www.databricks.com/product/lakewatch
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI Agent Builder, AI SOC Capability
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.datadoghq.com/product/ai/bits-ai-security-analyst/
Profile last updated 2026-06-26.
Daylight is a security services company delivering Managed Agentic Security Services (MASS), including MDR, threat hunting, security data lake, and more, through a fundamentally different architecture than traditional security services providers.
Daylight's architecture combines an agentic platform that runs the full cycle from detection to response with security experts from IR and threat hunting backgrounds. The platform integrates deeply across your environment - cloud, identity, SaaS, endpoints - and collects identity and business context to investigate alerts the way a senior analyst would. It continuously learns your environment to make better decisions over time. Security experts validate decisions, feed insights into the platform, optimize detections, and take over in case of an incident.
The result: security teams move from firefighting mode to strategic work that improves their security posture.
- Capabilities
- AI SOC Pure Play, MDR, Threat Hunting
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- Founded
- 2024
- Funding stage
- Series A
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://daylight.ai/
Profile last updated 2026-06-26.
- Capabilities
- Data Analytics / UABA, AI SOC Pure Play, Threat Hunting
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.deeptempo.ai/
Profile last updated 2026-06-26.
- Capabilities
- MDR, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.deepwatch.com/
Profile last updated 2026-06-26.
- Capabilities
- Detection Engineering, SecOps Resilience, AI SOC Capability
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering
- Website
- https://www.detections.ai/
Profile last updated 2026-06-26.
Digital Hands is an AI SOC cybersecurity company that helps enterprise businesses achieve world class security without the constraints. Our approach centers on Unified Security Posture Management, bringing identities (human & non-human), data, cloud, applications, AI, and OT into one continuously assessed, continuously improved posture.
- Capabilities
- MDR, AI SOC Capability, Threat Hunting, ITDR, Data Ingestion & Processing
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Tampa, Florida, United States
- Founded
- 2001
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.digitalhands.com/
Profile last updated 2026-07-13.
Dndx AI Agentic SOC Platform
- Primary category
- Automation
- Capabilities
- Automation, AI SOC Pure Play, MDR
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- İstanbul, Turkey
- Founded
- 2022
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://dndx.com.tr/
Profile last updated 2026-07-14.
Dropzone AI weaponizes LLMs for cyber defenders, delivering the Agentic SOC: AI agents that collaborate 24/7 to beat attackers at scale. Dropzone is ready to go on Day 1 and integrates into your existing tools. AI agents start work immediately to investigate alerts, respond to emerging threats, and proactively hunt attackers.
Dropzone works with enterprises and MSSPs including ECS, Avalara, UiPath, and Zapier, and is actively protecting over 300 companies.
Self-guided demo available (live environment) here: https://www.dropzone.ai/self-guided-demo
- Capabilities
- AI SOC Pure Play, Threat Hunting, Threat Intel
- Deployment archetype
- plug_and_play
- Headquarters
- Seattle, United States
- Founded
- 2023
- Funding stage
- Series B
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://hubs.li/Q04q5kp90
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI Agent Builder, AI SOC Capability, Data Ingestion & Processing, Threat Hunting, Threat Intel
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.elastic.co/security/ai
Profile last updated 2026-07-03.
Embed Security is focused on security noise cancellation® for demanding SecOps environments. Embed’s AI SOC agentic security platform reduces alert fatigue and accelerates threat response across multiple attack surfaces by autonomously triaging and investigating security alerts, so teams can focus on real threats. Founded in 2024 by experienced security practitioners.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- Founded
- 2024
- Funding stage
- Seed
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://embedsecurity.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI SOC Capability
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.exabeam.com/platform/exabeam-nova/
Profile last updated 2026-06-26.
Exaforce is an AI-native agentic SOC platform built to transform how security teams detect, triage, investigate, and respond to threats. Rather than applying AI to isolated pieces of SOC optimization, Exaforce delivers AI-native capabilities across the entire security operations lifecycle, supporting analysts, detection engineers, DevOps teams, and threat hunters.
At the core is a real-time knowledge graph and Multi-Model AI engine combining data semantics, behavioral baselining, machine learning, and large language models to deliver fast, precise, and trustworthy security decisions, avoiding the hallucination risks of standalone LLMs.
AI agents called Exabots deliver 24/7 tier-1 to tier-3 analyst coverage without extra headcount, reviewing 100% of alerts in real time and surfacing hidden threats at lower TCO. The platform is available as SaaS or a fully managed MDR service, helping teams work faster and more accurately than with traditional SOC tooling.
Exaforce has raised $200 million across funding rounds, led by Mayfield, Khosla Ventures, Harbourvest, Peak XV, and others, with a founding team drawing on experience from Google, F5, and Palo Alto Networks.
- Capabilities
- AI SOC Pure Play, SIEM, Data Analytics / UABA, Detection Engineering, SOAR, Threat Hunting, Threat Intel, MDR, Data Ingestion & Processing
- Deployment archetype
- Plug and Play
- Headquarters
- San Jose, CA
- Founded
- 2023
- Funding stage
- 200M - Series B
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.exaforce.com/
Profile last updated 2026-06-26.
- Primary category
- MDR
- Capabilities
- MDR, AI SOC Capability, Threat Hunting, CIRM / Case Management
- Deployment archetype
- Plug and Play
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://expel.com/
Profile last updated 2026-07-10.
Fig leads Security Operations Resilience, keeping detection and response working through constant change. The Fig platform delivers the full SecOps engineering lifecycle: build, ship, and observe every change, on any infrastructure, with confidence. Founded by veterans of Google SecOps and Siemplify, and backed by Team8 and Ten Eleven Ventures, Fig serves some of the world’s largest and most complex SOCs from offices in New York and Tel Aviv. With Fig, change powers the SOC instead of breaking it.
- Capabilities
- SecOps Resilience, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- New York, United States
- Founded
- 2025
- Funding stage
- Series A
- SecOps Shift Map coverage
- Detection Engineering
- Website
- https://www.fig.security/
Profile last updated 2026-07-20.
- Capabilities
- AI SOC Capability, SOAR, SIEM, MDR, Data Analytics / UABA, Detection Engineering, Data Ingestion & Processing
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.fortinet.com/solutions/soc-platform
Profile last updated 2026-06-26.
- Capabilities
- AI Agent Builder, AI SOC Capability
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- Founded
- 2022
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://ghostsecurity.ai/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, Threat Intel, AI SOC Capability, Data Ingestion & Processing
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://cloud.google.com/security/products/security-operations
Profile last updated 2026-07-06.
- Capabilities
- Data Analytics / UABA, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://guarddog.ai/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Data Analytics / UABA, SOAR, AI SOC Capability
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://gurucul.com/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- India
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://harkx.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Capability, Data Analytics / UABA, SOAR, Threat Hunting, Threat Intel, Detection Engineering, Data Ingestion & Processing
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United Arab Emirates
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://hawk-eye.io/
Profile last updated 2026-06-26.
- Capabilities
- Threat Hunting, AI SOC Pure Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.huntbase.io/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Capability, SIEM, Data Analytics / UABA
- Deployment archetype
- Plug and Play
- Headquarters
- Israel
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://www.hunters.security/
Profile last updated 2026-06-26.
HydraNexus is an AI-driven threat analysis platform for SOC teams and MSSPs. Six parallel LLM analysis heads evaluate security events with evidence-gated reasoning, synthesized into a single auditable verdict by an arbiter layer — reducing false positives and hallucinated findings compared to single-model AI security tools.
- Capabilities
- Threat Intel, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- Naperville, Illinois, United States
- Founded
- 2016
- Funding stage
- Bootstrapped
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://hydranexus.io/
Profile last updated 2026-07-07.
- Capabilities
- SOAR, DFIR / Forensics, AI SOC Pure Play, AI Agent Builder
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- Netherlands
- Founded
- 2023
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation, Response
- Website
- https://imperum.io/
Profile last updated 2026-07-06.
Intezer crosses the trust threshold by combining forensic depth with agentic AI to accurately determine what really happened. This enables enterprise customers to safely offload Tier 1 and Tier 2 investigation work, shifting humans from investigating alerts to supervising outcomes.
- Capabilities
- AI SOC Pure Play, Threat Hunting, DFIR / Forensics, Threat Intel
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- New York, United States
- Founded
- 2015
- Funding stage
- Series C
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://intezer.com/
Profile last updated 2026-06-26.
- Capabilities
- Insider Threat / DLP, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- New York, United States
- Founded
- 2024
- Funding stage
- Series A
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.jazz.security/
Profile last updated 2026-06-26.
- Capabilities
- AI Agent Builder, AI SOC Pure Play
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://joon.co/
Profile last updated 2026-06-26.
- Capabilities
- Automation, AI Agent Builder, AI SOC Pure Play
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.kai.security/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- Funding stage
- Acquired
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.kenzo.security/
Acquired by Rapid7.
Profile last updated 2026-06-26.
- Capabilities
- Automation, AI Agent Builder
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://kindo.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play, Insider Threat / DLP, MDR, Threat Hunting, Threat Intel, SOAR
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.legionsecurity.ai/
Profile last updated 2026-07-08.
LimaCharlie is agentic SecOps infrastructure, purpose-built for AI agents to operate security, not just advise on it. With 100% API coverage, bring-your-own-LLM flexibility, and full auditability, AI agents perceive telemetry, investigate detections, and execute response actions with the same controls as human engineers.
- Capabilities
- SIEM, AI Agent Builder, AI SOC Capability, DFIR / Forensics, Threat Hunting, Detection Engineering, SOAR, Data Ingestion & Processing
- Deployment archetype
- Build it Yourself
- Headquarters
- Covina, United States
- Founded
- 2018
- Funding stage
- Series A
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://limacharlie.io/
Profile last updated 2026-07-06.
A powerful and essential toolkit for modern cybersecurity practices, combining AI-driven automation with deep analytical capabilities.
Seamless Integration
Integrates effortlessly with major platforms like Splunk, Databricks, and Graphistry, enabling a unified view of security and operational data.
Advanced Visualization
Powerful and interactive visualizations allow security teams to identify and analyze threats, patterns, and relationships more effectively.
Automated Detection & Response
Automates the identification of potential threats such as high-risk sign-ins, brute-force attacks, and privilege escalation attempts.
Comprehensive Monitoring
Broad coverage across threat vectors including sign-in attempts, brute-force attacks, privilege escalations, and visual threat hunting.
Enhanced Security Insights
Detailed, technical insights allow IR teams and SOCs to make informed decisions quickly, improving overall security posture.
Proactive Threat Management
Identifies and addresses threats proactively, helping organizations prevent unauthorized access, reduce risks, and maintain security.
- Capabilities
- Data Analytics / UABA, OSS, AI Agent Builder, AI SOC Pure Play
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://louie.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Israel
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.matesecurity.io/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Israel
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.mave.com/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://method.security/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Capability, Data Analytics / UABA, SOAR, SIEM, Data Ingestion & Processing
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel
Profile last updated 2026-06-26.
- Capabilities
- Automation, AI Agent Builder, AI SOC Capability, Threat Intel
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- France
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://mindflow.io/
Profile last updated 2026-07-06.
- Capabilities
- AI SOC Capability, Data Analytics / UABA
- Deployment archetype
- Plug and Play
- Headquarters
- New York, US
- Founded
- 2020
- Funding stage
- Series B
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.mitiga.io/
Profile last updated 2026-06-26.
Orryx AI is an AI-native SOC operating platform that helps security teams investigate, prioritize, and respond to threats faster by combining agentic AI, automation, threat intelligence, threat hunting, and SOC workflows in a single operational layer.
Designed for enterprises and managed security providers (MSSPs), Orryx AI integrates across existing security technologies including SIEM, EDR, identity, cloud, email, and threat intelligence platforms. Rather than replacing existing tools, it unifies investigations across them, normalizing and correlating data to provide analysts with complete operational context.
The platform combines deterministic automation with AI-assisted investigation, threat intelligence, threat hunting, and response support to reduce manual effort while maintaining analyst oversight. Orryx also provides SOC-native case management, risk-based prioritization, detection engineering, detection validation, reporting, and multi-tenant operations.
By connecting investigation, intelligence, hunting, automation, response, and detection engineering into a single workflow with HITL, Orryx AI enables organizations to improve analyst productivity, reduce alert fatigue, accelerate incident response, and scale security operations more effectively across complex environments.
- Capabilities
- AI SOC Pure Play, Automation, Threat Hunting, Threat Intel, CIRM / Case Management, MDR, Detection Engineering
- Deployment archetype
- Plug and Play
- Headquarters
- Hamala, Bahrain
- Founded
- 2022
- Funding stage
- Series A
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.beyoncyber.com/product/orryx-ai
Profile last updated 2026-06-26.
- Capabilities
- AI Agent Builder, AI SOC Capability, Data Analytics / UABA, Detection Engineering, SIEM, SOAR, Threat Intel, MDR
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.paloaltonetworks.com/cortex
Profile last updated 2026-06-26.
Panther is the Complete AI SOC Platform that scales security expertise across the full operations lifecycle. Native AI agents embedded in the data lake, detection engine, and knowledge base investigate alerts and act autonomously, feeding every decision back into a closed-loop system that continuously reduces alert volume while expanding coverage.
- Primary category
- SIEM
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, AI SOC Capability, Threat Intel, Threat Hunting, Data Ingestion & Processing
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- Founded
- 2018
- Funding stage
- Series B
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://panther.com/
Profile last updated 2026-07-10.
The Complete System for the Agentic SOC, combining AI SOC agents with a SIEM core running on an open standards security lakehouse.
- Capabilities
- SIEM, AI SOC Capability, CIRM / Case Management, Data Ingestion & Processing, Detection Engineering, Threat Hunting, Data Analytics / UABA
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Austin, TX, United States
- Founded
- 2024
- Funding stage
- Seed
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.perpetualsystems.com
Profile last updated 2026-07-09.
- Capabilities
- Automation, AI SOC Pure Play
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://presecurity.ai/
Profile last updated 2026-06-26.
Prophet Security’s mission is to be a force multiplier for security teams by delivering a comprehensive Agentic AI SOC Platform that automates the manual processes involved across security operations — from alert triage, investigation and incident response to threat hunting, and detection engineering. Prophet AI reduces mean time to investigate, mean time to respond, and delivers a 10x increase in team productivity. Learn more at prophetsecurity.ai.
- Capabilities
- Detection Engineering, Threat Hunting, AI SOC Pure Play, Threat Intel
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- Founded
- 2023
- Funding stage
- Series A
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.prophetsecurity.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United Kingdom
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.qevlar.com/
Profile last updated 2026-06-26.
- Capabilities
- Data Analytics / UABA, Data Ingestion & Processing, SIEM
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- Funding stage
- Seed
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://www.query.ai/
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://radiantsecurity.ai/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, MDR, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation, Response
- Website
- https://reliaquest.com/
Profile last updated 2026-07-06.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.rilian.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, AI Agent Builder, Data Ingestion & Processing, Threat Hunting, SecOps Resilience, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://runreveal.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Data Ingestion & Processing, AI SOC Capability, Detection Engineering, Data Analytics / UABA
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://scanner.dev/
Profile last updated 2026-06-26.
- Capabilities
- SOAR, AI SOC Pure Play, SIEM
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- India
- SecOps Shift Map coverage
- Data, Triage and Investigation
- Website
- https://secsphere.straightarc.com/
Profile last updated 2026-06-26.
SecureVisio is a unified detection-and-response platform that consolidates SIEM, SOAR, UEBA, vulnerability management, risk analysis (BIA), CMDB, and IT GRC into a single product. Our core differentiator is context: every incident is enriched with business impact, asset owners, dependencies, and attack pathways, and threats are ranked through business-aligned risk scoring so analysts act on what matters first.
An AI assistant supports analysts across the investigation lifecycle — generating incident summaries, classifying alerts, proposing threat-hunting queries, and guiding response. Alongside it, an autonomous AI agent investigates independently: it can call an MCP server and query local or cloud-hosted LLMs (including fully on-prem models). The agent either closes the incident or returns a reasoned verdict explaining what happened with recommendations.
AI runs in a cost-aware cascade. ML models run first and continuously, learning each environment's "normal." Deep Value Learning adds context — which processes spawn others, where users normally log in from — reflecting the organization's real risk profile. Large Reasoning Models are invoked selectively to judge whether a case needs deeper investigation.
- Primary category
- SIEM
- Capabilities
- SIEM, AI SOC Capability, Data Analytics / UABA, SOAR, Detection Engineering, Data Ingestion & Processing, Threat Hunting, Threat Intel
- Deployment archetype
- Build it Yourself
- Headquarters
- Warsaw, Poland
- Founded
- 2010
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://securevisio.com/
Profile last updated 2026-07-10.
Sekoia is the European agentic cybersecurity company building the Cyber Operations Platform for the AI era. Unifying CTI, detection and response, exposure management, and agentic AI, Sekoia is rebuilding cybersecurity from the ground up. Through the Autonomous SOC, machines investigate at scale while security teams govern operations with clarity &control.
- Capabilities
- SIEM, Data Analytics / UABA, SecOps Resilience, Threat Intel, AI SOC Capability, SOAR
- Deployment archetype
- Plug and Play
- Headquarters
- Rennes, France
- Founded
- 2022
- Funding stage
- Series B
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation, Response
- Website
- https://www.sekoia.com/
Profile last updated 2026-07-08.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, Automation, Threat Hunting, MDR, DFIR / Forensics, Threat Intel, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.sentinelone.com/platform/ai-siem/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.sevii.com/
Profile last updated 2026-06-26.
- Capabilities
- Insider Threat / DLP
- Deployment archetype
- Plug and Play
- Headquarters
- Italy
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.sharelock.ai/
Profile last updated 2026-06-26.
- Primary category
- SOAR
- Capabilities
- SOAR, AI SOC Capability, OSS
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://shuffler.io/
Profile last updated 2026-07-10.
- Capabilities
- Threat Hunting, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- India
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://simbian.ai/
Profile last updated 2026-06-26.
- Capabilities
- CIRM / Case Management, AI SOC Capability, OSS
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://sirp.io/
Profile last updated 2026-06-26.
- Capabilities
- OSS, SOAR, DFIR / Forensics, AI SOC Capability
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.cybertriage.com/
Profile last updated 2026-07-06.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, AI SOC Pure Play
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://socprime.com/
Profile last updated 2026-07-10.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Spain
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://socai.eu/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://socjedi.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play, CIRM / Case Management
- Deployment archetype
- Plug and Play
- Headquarters
- Turkey
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.socnova.com/
Profile last updated 2026-06-26.
- Capabilities
- AI Agent Builder, AI SOC Capability, Data Analytics / UABA
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- United States
- Founded
- 2024
- Funding stage
- Series A
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://sola.security/
Profile last updated 2026-06-26.
AI speed. Human judgment. Sophos MDR delivers fully managed, 24/7 threat detection and response through the world's largest Agentic SOC. Designed for organizations with or without dedicated security teams, it integrates with hundreds of existing security tools and neutralizes threats in seconds. AI responds at scale; analysts own the outcomes.
- Capabilities
- Data Ingestion & Processing, Detection Engineering, DFIR / Forensics, ITDR, MDR, SIEM, SOAR, Threat Hunting, Threat Intel, AI SOC Capability
- Headquarters
- Oxford, Oxfordshire, United Kingdom
- Founded
- 1985
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation, Response
- Website
- https://www.sophos.com/en-us/services/managed-detection-and-response
Profile last updated 2026-07-03.
Spacewalk is an agentic AI Security Operations platform that scales with the problem — from a single tier-1 alert to a full multi-host breach, on one system.
For everyday alerts, a team of AI agents led by an autonomous commander investigates and resolves them end to end, fully in control. As a case turns serious, you stay on the same platform: the agents keep working, pull in more of your stack, and escalate into deep, multi-host incident response — no handoff, no tool-switching.
What sets Spacewalk apart is how it reasons. Every case runs a structured Analysis of Competing Hypotheses — weighing benign against malicious — with each finding bound to a re-runnable query, so conclusions are evidence you can inspect, not AI guesswork. Genuine uncertainty resolves to an explicit Indeterminate verdict, never a hand-wavy score.
The agents query your stack in parallel — CrowdStrike, Splunk, Sentinel, Defender, Entra, Google SecOps, Wiz, Sublime and more — correlate across every tool, and rebuild the timeline automatically. When an alert becomes an intrusion, built-in DFIR forensics ingest disk images, Windows event logs, and PCAP. Then Spacewalk writes the report that closes the case — while your analysts stay in command throughout.
- Capabilities
- AI SOC Pure Play, CIRM / Case Management, DFIR / Forensics, Insider Threat / DLP, Threat Hunting
- Deployment archetype
- Plug and Play
- Headquarters
- Irvine, United States
- Founded
- 2024
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://spacewalk.ai/
Profile last updated 2026-07-09.
Spectrum Security is an AI-powered detection platform that automates how organizations identify what they need to detect, build those detections, deploy them, and keep them working - across any SIEM, data lake, or security tool, at machine speed. The platform continuously maps coverage gaps, authors production-grade detections tailored to each environment, and maintains them as threats and infrastructure evolve. Security teams stay in control. Spectrum handles the heavy lifting. In customer environments, detection authoring has been compressed from months to under 30 minutes, with engineering hours reduced by 90%.
- Primary category
- Detection Engineering
- Capabilities
- Detection Engineering, SecOps Resilience
- Deployment archetype
- Plug and Play
- Headquarters
- San Francisco
- Founded
- 2025
- Funding stage
- Seed
- SecOps Shift Map coverage
- Detection Engineering
- Website
- https://www.spectrum.security/
Profile last updated 2026-07-10.
- Capabilities
- Data Analytics / UABA, SIEM, AI SOC Pure Play, SOAR, Threat Hunting, Threat Intel, ITDR
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Hyderabad, India
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://spharaka.com/
Profile last updated 2026-07-06.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.splunk.com/en_us/products/splunk-security-orchestration-and-automation.html
Profile last updated 2026-06-29.
- Capabilities
- SIEM, Data Analytics / UABA, CIRM / Case Management, AI SOC Capability
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://stellarcyber.ai/
Profile last updated 2026-06-26.
Strike48 is the Agentic Security Operations platform, combining complete log visibility with AI agents that work 24/7 to run investigations, automate detection, and orchestrate responses.
The platform provides a no-code custom agent builder and pre-built agent clusters that address security, IT, and compliance use-cases. Bring your logs or query them in place, eliminating blind spots so AI agents can actually do the work, not just assist with it.
- Capabilities
- AI SOC Pure Play, SOAR, AI Agent Builder
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- United States
- Founded
- 2026
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.strike48.com/
Profile last updated 2026-07-06.
- Capabilities
- SIEM, Data Analytics / UABA, Automation, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://strikeready.co/
Profile last updated 2026-06-26.
Sumo Logic makes the digital world secure, fast, and reliable by turning insights into action. With our agentic AI-powered platform, organizations can unify all of their critical data and signals and automate responses to get ahead of business-critical issues and threats.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- Founded
- 2010
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation, Response
- Website
- https://www.sumologic.com
Profile last updated 2026-06-26.
- Capabilities
- SOAR, AI Agent Builder, AI SOC Capability, Threat Hunting
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://swimlane.com/
Profile last updated 2026-06-29.
- Capabilities
- AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Spain
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://tandemtrace.ai/
Profile last updated 2026-06-26.
Tenacium DC is a UK sovereign SME specialising in defence-grade data engineering, Artificial Intelligence (AI), Machine Learning (ML) and secure digital architectures. Tenacium supports Defence Digital, Front Line Commands and Defence Science & Technology Laboratory (Dstl) to design, build and operationalise high-assurance, mission-critical digital capabilities across enterprise, deployed and contested environments.
- Capabilities
- SecOps Resilience, Data Analytics / UABA, AI SOC Capability, SIEM
- Deployment archetype
- Plug and Play
- Headquarters
- London, United Kingdom
- Founded
- 2021
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.tenacium.co.uk/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play, Threat Hunting, SOAR, Threat Intel
- Deployment archetype
- Plug and Play
- Headquarters
- Tel Aviv, Israel
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.tencyle.com/
Profile last updated 2026-07-06.
- Capabilities
- MDR, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://tenex.ai/
Profile last updated 2026-06-26.
- Primary category
- MDR
- Capabilities
- MDR, AI SOC Capability, Data Ingestion & Processing, Threat Hunting, SIEM
- Deployment archetype
- Plug and Play
- Headquarters
- Australia
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://threatdefence.com/
Profile last updated 2026-07-10.
- Capabilities
- AI SOC Pure Play, Data Ingestion & Processing, Automation
- Deployment archetype
- Plug and Play
- Headquarters
- United Arab Emirates
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://thethreatlens.com/
Profile last updated 2026-06-26.
- Primary category
- MDR
- Capabilities
- MDR, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Miami, United States
- Funding stage
- Seed
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://tier4ai.com/
Profile last updated 2026-07-14.
Tines is the intelligent workflow platform trusted by the world's most advanced organizations. With Tines, they’ve built a secure, flexible foundation to operationalize AI agents and intelligent workflows, unlocking productivity, moving faster, and future-proofing how work gets done.
- Capabilities
- SOAR, AI SOC Capability, AI Agent Builder
- Deployment archetype
- Build it Yourself
- Headquarters
- Ireland
- Founded
- 2018
- Funding stage
- Series C
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.tines.com/
Profile last updated 2026-07-06.
- Capabilities
- AI SOC Capability, SOAR, Threat Hunting, AI Agent Builder
- Deployment archetype
- Plug and Play & Customizable, Build it Yourself
- Headquarters
- New York, United States
- Founded
- 2020
- Funding stage
- Series D+
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://torq.io/
Profile last updated 2026-06-29.
Tracecat provides everything busy security teams need to automate work: agents, workflows, cases, and an AI copilot that builds for you.
- Capabilities
- SOAR, OSS, AI SOC Capability, AI Agent Builder
- Deployment archetype
- Build it Yourself
- Headquarters
- United States
- Founded
- 2024
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://tracecat.com/
Profile last updated 2026-07-06.
- Capabilities
- SIEM, Data Ingestion & Processing, SOAR, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- Princeton, United States
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://www.trenchsecurity.ai/
Profile last updated 2026-06-26.
- Capabilities
- Detection Engineering, Threat Hunting, AI SOC Pure Play
- Deployment archetype
- Plug and Play
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.tuskira.ai/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, SecOps Resilience, AI SOC Capability
- Deployment archetype
- Plug and Play
- Headquarters
- Israel
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://vega.io/
Profile last updated 2026-06-26.
Vigil SOC brings together security engineers, researchers, and builders to develop and operate next-generation security systems in the open, through collaborative events, shared infrastructure, and real-world exercises.
Vigil ships with an Auto-Response agent that correlates signals across your stack, scores its own confidence, and contains the threat. Above your configured threshold (0.90 by default) it auto-approves; below, it routes to a human reviewer. Surgical actions (WAF block, Gateway block, session revoke) execute through a full audit trail. You set the boundary. Vigil keeps pace.
- Capabilities
- OSS, AI SOC Pure Play, AI Agent Builder
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- Founded
- 2026
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://vigilsoc.org/
Profile last updated 2026-06-26.
Unified SIEM, NDR, EDR, IDR, AIDR, and CDR powered by AI-driven detection and autonomous response. Built from scratch for speed.
- Primary category
- SIEM
- Capabilities
- SIEM, Threat Hunting, Threat Intel, SOAR, ITDR, Detection Engineering, Data Analytics / UABA, AI SOC Capability, Data Ingestion & Processing
- Deployment archetype
- Plug and Play
- Headquarters
- Stockholm, Sweden
- Founded
- 2026
- Funding stage
- Not disclosed
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation
- Website
- https://voidum.io
Profile last updated 2026-07-07.
What MDR should have always been: onboard in minutes, respond in seconds. Where traditional MDR depends on slow, expensive human analysts, Wirespeed uses a proprietary mix of AI & conditional logic to triage, reach a verdict, and contain threats in milliseconds (median time to verdict: 1,801ms), cutting alert noise by 99.9%.
It connects to your existing stack via 50+ integrations and provides consistent, auditable, and transparent verdicts. Every step is observable, with no black box where logic is hidden from you.
Wirespeed also breaks the fourth wall. When an alert needs context (an unusual login, a suspicious PowerShell command, a risky config change), it reaches out to your users directly over Slack, Teams, email, and SMS to find out what really happened, at any scale. You stay in control: tune every notification, escalation, and containment action, or let Wirespeed handle it automatically.
Backed by Coalition's view across 100k+ cyber insurance policyholders, Wirespeed's algorithms are informed by global scan and incident data.
- Primary category
- MDR
- Capabilities
- MDR, SIEM, AI SOC Pure Play, ITDR
- Deployment archetype
- Plug and Play
- Headquarters
- San Francisco, United States
- Founded
- 2024
- Funding stage
- Acquired
- SecOps Shift Map coverage
- Detection Engineering, Triage and Investigation, Response
- Website
- https://wirespeed.co/
Profile last updated 2026-07-10.
- Capabilities
- AI SOC Pure Play, Data Analytics / UABA
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- United States
- SecOps Shift Map coverage
- Triage and Investigation
- Website
- https://www.wraithwatch.com/
Profile last updated 2026-06-26.
- Capabilities
- SIEM, Detection Engineering, Data Analytics / UABA, Automation, AI SOC Pure Play
- Deployment archetype
- Plug and Play, Plug and Play & Customizable
- Headquarters
- San Francisco, United States
- Founded
- 2024
- SecOps Shift Map coverage
- Data, Detection Engineering, Triage and Investigation
- Website
- https://zaun.ai/
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Capability, Data Analytics / UABA, Insider Threat / DLP, MDR
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- United States
- Funding stage
- Public
- SecOps Shift Map coverage
- Data, Triage and Investigation
- Website
- https://www.zscaler.com/products-and-solutions/security-operations
Profile last updated 2026-06-26.
- Capabilities
- AI SOC Pure Play, Automation, Threat Intel
- Deployment archetype
- Plug and Play & Customizable
- Headquarters
- Barcelona, Spain
- SecOps Shift Map coverage
- Triage and Investigation, Response
- Website
- https://www.zynap.com/
Profile last updated 2026-06-26.