AI for SecOps vendor directory · SecOps Unpacked

All 140 vendor profiles in full

Independent, practitioner-run research directory. Generated 2026-07-26. Each heading links to the vendor's own page, which is the canonical citation URL. Also available as plain text; site guide at llms.txt.

7AI

Capabilities
AI SOC Pure Play, MDR
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://7ai.com/

Profile last updated 2026-06-26.


Above Security

Above turns scattered telemetry into defensible stories of intent, not just isolated events. Instead of flooding teams with alerts or relying on blunt blocking, Above detects risky human behavior in real time to prevent it from becoming an incident. Above is an insider risk management platform built around narrative intelligence: it continuously observes how employees interact with data, apps, identities, and AI tools. Those signals get stitched into clear, human-readable timelines that explain what happened, why it happened, and how risk evolved over time. Humans are at the center of everything we do. With in-the-moment coaching, and automatically produced investigation-ready narratives that security, legal, and HR can actually use.

Primary category
Insider Threat / DLP
Capabilities
Insider Threat / DLP, Data Analytics / UABA, SecOps Resilience
Deployment archetype
Plug and Play
Headquarters
Wilmington, United States
Founded
2025
Funding stage
Series A
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.above.security/

Profile last updated 2026-07-10.


Abstract Security

A security-native SIEM built for how modern SOCs actually work. Composable architecture means your data stays in your environment, routes anywhere, and isn't held hostage by a single vendor's pricing model. Streaming pipelines, AI-assisted detection, and scalable retention that bends to your stack.

Capabilities
SIEM, AI SOC Capability, Data Analytics / UABA, Detection Engineering
Deployment archetype
Plug and Play
Headquarters
Palo Alto, United States
Founded
2023
Funding stage
Series A
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.abstract.security/

Profile last updated 2026-06-26.


AirMdr

Primary category
MDR
Capabilities
MDR, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
http://www.airmdr.com/

Profile last updated 2026-07-10.


Airrived

Capabilities
Automation, AI Agent Builder, AI SOC Pure Play
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://airrived.ai/

Profile last updated 2026-06-26.


AiStrike

AiStrike delivers an AI-native approach to modern security operations by covering the full lifecycle of detection, investigation, and response. The platform stands out for its ability to operate across both the “left side” and “right side” of the incident response lifecycle, combining detection engineering, threat intelligence operations, automated triage, investigation, response, and remediation into a unified operational model. On the left side, AiStrike focuses on improving detection coverage, operational visibility, and threat intelligence utilization. The platform helps organizations continuously refine detections, enrich security context, and identify emerging threats before they escalate into incidents. This positions AiStrike beyond traditional alert-handling solutions by addressing the upstream operational challenges that often create investigation bottlenecks inside the SOC. In the middle of the lifecycle, AiStrike accelerates triage and investigation workflows through AI-driven analysis, correlation, and operational automation. The platform reduces manual investigation effort while helping analysts prioritize high-fidelity threats and reduce alert fatigue. On the right side, AiStrike extends into response and remediation, enabling organizations to operationalize findings and automate corrective actions across their environment. Combined with its MDR offering, AiStrike provides organizations with both AI-driven automation and human-led expertise, supporting a more proactive and continuously adaptive security operations model.

Capabilities
AI SOC Pure Play, Detection Engineering, Automation, Threat Intel, MDR
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
Funding stage
Seed
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.aistrike.com/

Profile last updated 2026-06-26.


AlphaLevel

Capabilities
Data Analytics / UABA, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering
Website
https://www.alphalevel.ai/

Profile last updated 2026-06-26.


Andesite

Andesite, the Human-AI SOC, puts humans at the helm, empowering cyber defenders to oversee AI-driven workflows, assess threats, respond immediately, reduce risk, and focus on prevention. Our product enables SOC teams to configure their agents and playbooks, oversee and guide AI-driven automated triage, enrichment, investigation, and response. Using Andesite, cyber defenders work at machine speed while validating evidence and making the critical decisions they are accountable for. Built for the high-complexity, high-risk world of enterprise and national security, Andesite's architecture adapts to customers' tools, workflows, and use cases. It connects silos, reduces inefficiencies, and uses contextual awareness to analyze risk and exposure, offering CISOs a future-proof, flexible product that evolves with their ecosystem.

Capabilities
AI Agent Builder, AI SOC Pure Play, Threat Intel, Threat Hunting, Data Analytics / UABA
Deployment archetype
Plug and Play & Customizable
Headquarters
McLean, United States
Founded
2024
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://andesite.ai/

Profile last updated 2026-07-13.


Anomali

Capabilities
AI SOC Capability, Data Analytics / UABA, SIEM, Threat Intel, Threat Hunting
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.anomali.com/

Profile last updated 2026-06-26.


Anvilogic

At a glance AI SOC platform that unifies detection engineering, AI triage, and workflow automation across existing SIEMs (Splunk, Sentinel) and cloud data lakes (Snowflake, Databricks, Azure). Runs on your data — no rip-and-replace required. Deployment model SaaS — BYOD (Bring Your Own Data Lake) Anvilogic is a cloud-hosted platform that connects to the customer's own data environment.

Capabilities
SIEM, Detection Engineering, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
Palo Alto, CA, USA
Founded
2019
Funding stage
85M - Series C
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://anvilogic.com/

Profile last updated 2026-06-26.


AquilaI

Capabilities
AI SOC Pure Play, Data Analytics / UABA
Deployment archetype
Plug and Play
Headquarters
India
SecOps Shift Map coverage
Triage and Investigation
Website
https://aquilai.io/

Profile last updated 2026-06-26.


Arcanna AI

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.arcanna.ai/

Profile last updated 2026-06-26.


Arctic Wolf

Primary category
MDR
Capabilities
MDR, SIEM, Data Analytics / UABA, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://arcticwolf.com/

Profile last updated 2026-07-10.


Artemis

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, Threat Hunting, Threat Intel, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://artemissecurity.com/

Profile last updated 2026-06-26.


Axoflow

Primary category
Data Ingestion & Processing
Capabilities
Data Ingestion & Processing, Data Analytics / UABA
Deployment archetype
Plug and Play & Customizable
Headquarters
Hungary
SecOps Shift Map coverage
Data
Website
https://axoflow.com/

Profile last updated 2026-07-10.


Beacon Security

Capabilities
SIEM, Automation, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://beacon.security/

Profile last updated 2026-06-26.


Binalyze

Binalyze is an Investigation Automation and Response platform that makes a SOC complete. Built for security operations and incident response teams, Binalyze AIR transforms alerts into actionable understanding through automated investigation and forensic-level visibility across endpoint, cloud, and hybrid environments. By integrating with existing SIEM, EDR, XDR, and SOAR technologies, AIR enables organizations to investigate threats faster, uncover root cause with confidence, and respond with clarity and precision. Trusted by enterprises, MSSPs, and incident response providers worldwide, Binalyze helps defenders reduce complexity, strengthen cyber resilience, and turn fragmented signals into conclusive answers. Learn more at binalyze.com.

Primary category
DFIR / Forensics
Capabilities
DFIR / Forensics, Automation, Threat Hunting, CIRM / Case Management, AI SOC Capability, AI Agent Builder
Deployment archetype
Plug and Play & Customizable
Headquarters
Tallinn, Estonia
Founded
2018
Funding stage
Series A
SecOps Shift Map coverage
Triage and Investigation, Response
Website
www.binalyze.com

Profile last updated 2026-07-10.


Binary Defense

Binary Defense is one of the most trusted names in MDR, founded by offensive security operators who built the company on a simple idea: the best defense thinks like the attacker. That legacy lives on in our Agentic MDR, where human instinct and AI speed work together to help organizations.

Primary category
MDR
Capabilities
MDR, Threat Hunting, AI SOC Capability, Automation, CIRM / Case Management, Data Ingestion & Processing, DFIR / Forensics
Deployment archetype
Plug and Play
Headquarters
Cleveland, United States
Founded
2012
Funding stage
Not disclosed
SecOps Shift Map coverage
Triage and Investigation
Website
https://binarydefense.com/

Profile last updated 2026-07-10.


BlinkOps

BlinkOps is an Agentic Security Operations Platform built for enterprise-scale security teams that need to operate faster than manual processes and point solutions allow. The platform is built around a composable agent architecture that combines deterministic agents for high-volume, known patterns with reasoning agents for complex, evolving threats. Security teams can deploy across every major security function, including SOC, threat hunting, vulnerability management, IAM, GRC, cloud security, and asset management, from a single platform rather than stitching together disconnected tools. Where most AI SOC vendors operate as black boxes, BlinkOps gives teams full visibility into agent logic, execution, and decisions. Human-in-the-loop controls are built in, not bolted on. Every action is auditable. Deployment starts with pre-built solutions like Agentic SOC, then scales through 30,000+ integrations to fit any existing stack. For teams that need faster time-to-value, AI-as-a-Service provides forward-deployed engineers who assess, design, and build customized agentic solutions from day one. BlinkOps is purpose-built for enterprises that want to replace fragmented, manual security operations with a single platform that agents can run at scale, without giving up control of how decisions get made..

Primary category
AI Agent Builder
Capabilities
AI Agent Builder, SOAR, Threat Hunting, Threat Intel, AI SOC Capability
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
Austin, United States
Founded
2021
Funding stage
Series B
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.blinkops.com/?utm_campaign=44388369-chnl-influencer-secops-unpacked&utm_source=blog&utm_content=learn_more

Profile last updated 2026-07-10.


Bricklayer AI

Bricklayer AI enables organizations to deploy specialized AI agents that share investigative context, collaborate through structured procedures, and operate under defined governance and human oversight. Built around the architectural principles of Context, Coordination, and Control, Bricklayer enables security teams to reduce noise, accelerate investigations, and scale security operations.

Capabilities
Threat Hunting, Threat Intel, AI SOC Pure Play
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
Arlington, United States
Founded
2023
Funding stage
Seed
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.bricklayer.ai/

Profile last updated 2026-06-26.


Cantina

Capabilities
Automation, AI Agent Builder, AI SOC Pure Play
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.cantina.security/

Profile last updated 2026-06-26.


Caver

Five layers. One lakehouse. Land your security data as OCSF Parquet on any S3-compatible storage. Query it in seven languages, SPL, SQL, KQL, Sigma, PromQL, natural language, or the native Caver UI, over one lake you own. Caver is the enterprise SIEM you run on top: no per-GB ingest tax

Capabilities
AI SOC Capability, SIEM, Data Ingestion & Processing, Data Analytics / UABA, SOAR, Threat Intel, Threat Hunting, DFIR / Forensics
Deployment archetype
Plug and Play
Headquarters
Nashville , United States
Founded
2026
Funding stage
Bootstrapped
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://etairos.ai/caver/

Profile last updated 2026-06-26.


Cognna

Capabilities
MDR, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Saudi Arabia
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.cognna.com/

Profile last updated 2026-06-26.


Command Zero

Command Zero is the autonomous and AI-assisted SOC platform built for complex enterprise environments. The platform combines an expert-encoded knowledge base, controlled AI agents, and human-led investigation tools to deliver consistent, auditable analysis at scale. Through a federated data model, Command Zero connects directly to your existing data sources—identity systems, EDR, cloud platforms, SIEM—without data ingestion or migration. Analysts and AI agents work from the same encoded knowledge base, ensuring predictable outcomes across all tiers. AI agents handle high-volume tier-1 tasks and standard investigations, then pass their work—tools, context, and findings—to human analysts for complex cases. The result: Faster mean time to understand and respond, with best practices that scale through both AI automation and human expertise.

Capabilities
AI SOC Pure Play, Threat Hunting, CIRM / Case Management, Automation, Insider Threat / DLP
Deployment archetype
Plug and Play & Customizable
Headquarters
Austin, United States
Founded
2022
Funding stage
Seed
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.cmdzero.io/

Profile last updated 2026-06-26.


Conifers

Capabilities
CIRM / Case Management, Detection Engineering, SecOps Resilience, Threat Hunting, Threat Intel, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.conifers.ai/

Profile last updated 2026-06-26.


Cotool

Capabilities
AI Agent Builder, AI SOC Pure Play
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.cotool.ai/

Profile last updated 2026-06-26.


CounterShadow

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://countershadow.com/

Profile last updated 2026-06-26.


Cribl

Capabilities
SIEM, Data Analytics / UABA, Data Ingestion & Processing, Detection Engineering, AI SOC Capability
Deployment archetype
Build it Yourself
Headquarters
San Francisco, United States
Funding stage
Series D+
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://cribl.io/solutions/initiatives/investigations/

CriticalStart

Primary category
MDR
Capabilities
MDR, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.criticalstart.com/

Profile last updated 2026-07-10.


Crogl

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.crogl.com/

Profile last updated 2026-06-26.


CrowdStrike

Capabilities
SIEM, Data Analytics / UABA, SOAR, Threat Hunting, MDR, DFIR / Forensics, Threat Intel, AI SOC Capability, AI Agent Builder
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.crowdstrike.com/en-us/platform/charlotte-ai/agentic-soar/

Profile last updated 2026-07-06.


Culminate

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.culminatesecurity.com/

Acquired by Datadog.

Profile last updated 2026-06-26.


Cyber Defence

Capabilities
Data Analytics / UABA, DFIR / Forensics, SIEM, Threat Hunting, AI SOC Capability, Automation
Deployment archetype
Plug and Play & Customizable
Headquarters
United Kingdom
Founded
2009
Website
https://emilyai.io/#platform

Profile last updated 2026-06-26.


CyberProof

Capabilities
AI SOC Capability, Data Analytics / UABA
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.cyberproof.com/defense-management/

Profile last updated 2026-06-26.


Cydarm

Capabilities
CIRM / Case Management, AI SOC Capability
Deployment archetype
Build it Yourself
Headquarters
Australia
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.cydarm.com/

Profile last updated 2026-06-26.


Cylerian

Next Generation SaaS Security Platform - One unified cloud platform to achieve your security, compliance, and operational objectives.

Primary category
SIEM
Capabilities
SIEM, AI SOC Capability, SOAR, MDR, Data Ingestion & Processing, Detection Engineering, Threat Hunting, Data Analytics / UABA
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://cylerian.com/

Profile last updated 2026-06-26.


Cymph

Cymph is an Incident Response Readiness platform that gives security teams continuous visibility into their response coverage: which threats they are ready to address, where the gaps are, and the tools to close those gaps.

Capabilities
SecOps Resilience
Deployment archetype
Plug and Play & Customizable
Headquarters
Tallinn, Estonia
Founded
2023
Funding stage
Bootstrapped
SecOps Shift Map coverage
Detection Engineering
Website
https://www.cymph.io

Profile last updated 2026-07-10.


Cyware

Capabilities
CIRM / Case Management, Threat Intel, AI SOC Capability
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://cyware.com/

Profile last updated 2026-06-26.


D3 Security

D3 Security builds Morpheus, an AI-autonomous SOC platform. Running on one purpose-built reasoning engine, it performs L2-depth Attack Path Discovery on every alert across your existing security stack—triaging up to 95% in under two minutes—then orchestrates governed response through a built-in SOAR engine and case management, delivering end-to-end alert investigation and incident response on a single platform. Where most agentic SOC vendors ship a fleet of separate agents—each with its own logic and log format, each requiring its own governance review—Morpheus inverts that. Triage, investigation, AI-augmented playbook building, and response are surfaces of the same engine, sharing one per-tenant context and producing one unified audit trail per incident. That trail reads identically to a SEC examiner, a NIS2 competent authority, or a DORA supervisor. Four selectable autonomy modes—from fully deterministic to end-to-end autonomous—are configurable per workflow, per tenant, per regulator, and migration between them is a configuration change, not a rebuild. Self-healing integrations adapt automatically when vendor APIs change, so the alert pipeline never goes dark. Morpheus is built to scale—for large enterprises, multi-tenant MSSP deployments, and SOC teams moving from SOAR to AI SOC who still require a full, governable, accountable incident response solution.

Primary category
AI SOC Capability
Capabilities
AI SOC Capability, SOAR, SecOps Resilience, Threat Hunting
Deployment archetype
Build it Yourself
Headquarters
Vancouver, Canada
Founded
2012
Funding stage
Not disclosed
SecOps Shift Map coverage
Triage and Investigation, Response
Website
http://www.d3security.com/

Profile last updated 2026-07-06.


DarkTrace

Capabilities
AI SOC Capability, Data Analytics / UABA, DFIR / Forensics
Deployment archetype
Plug and Play
Headquarters
United Kingdom
SecOps Shift Map coverage
Data, Triage and Investigation
Website
https://www.darktrace.com/

Profile last updated 2026-06-26.


Databricks

Capabilities
SIEM, Automation, AI Agent Builder
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://www.databricks.com/product/lakewatch

Profile last updated 2026-06-26.


Datadog

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI Agent Builder, AI SOC Capability
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.datadoghq.com/product/ai/bits-ai-security-analyst/

Profile last updated 2026-06-26.


Daylight Security

Daylight is a security services company delivering Managed Agentic Security Services (MASS), including MDR, threat hunting, security data lake, and more, through a fundamentally different architecture than traditional security services providers. Daylight's architecture combines an agentic platform that runs the full cycle from detection to response with security experts from IR and threat hunting backgrounds. The platform integrates deeply across your environment - cloud, identity, SaaS, endpoints - and collects identity and business context to investigate alerts the way a senior analyst would. It continuously learns your environment to make better decisions over time. Security experts validate decisions, feed insights into the platform, optimize detections, and take over in case of an incident. The result: security teams move from firefighting mode to strategic work that improves their security posture.

Capabilities
AI SOC Pure Play, MDR, Threat Hunting
Deployment archetype
Plug and Play
Headquarters
United States
Founded
2024
Funding stage
Series A
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://daylight.ai/

Profile last updated 2026-06-26.


DeepTempo

Capabilities
Data Analytics / UABA, AI SOC Pure Play, Threat Hunting
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.deeptempo.ai/

Profile last updated 2026-06-26.


DeepWatch

Capabilities
MDR, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.deepwatch.com/

Profile last updated 2026-06-26.


Detections AI

Capabilities
Detection Engineering, SecOps Resilience, AI SOC Capability
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering
Website
https://www.detections.ai/

Profile last updated 2026-06-26.


Digital Hands

Digital Hands is an AI SOC cybersecurity company that helps enterprise businesses achieve world class security without the constraints. Our approach centers on Unified Security Posture Management, bringing identities (human & non-human), data, cloud, applications, AI, and OT into one continuously assessed, continuously improved posture.

Capabilities
MDR, AI SOC Capability, Threat Hunting, ITDR, Data Ingestion & Processing
Deployment archetype
Plug and Play & Customizable
Headquarters
Tampa, Florida, United States
Founded
2001
Funding stage
Not disclosed
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.digitalhands.com/

Profile last updated 2026-07-13.


dndx AI

Dndx AI Agentic SOC Platform

Primary category
Automation
Capabilities
Automation, AI SOC Pure Play, MDR
Deployment archetype
Plug and Play & Customizable
Headquarters
İstanbul, Turkey
Founded
2022
Funding stage
Not disclosed
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://dndx.com.tr/

Profile last updated 2026-07-14.


Dropzone AI

Dropzone AI weaponizes LLMs for cyber defenders, delivering the Agentic SOC: AI agents that collaborate 24/7 to beat attackers at scale. Dropzone is ready to go on Day 1 and integrates into your existing tools. AI agents start work immediately to investigate alerts, respond to emerging threats, and proactively hunt attackers. Dropzone works with enterprises and MSSPs including ECS, Avalara, UiPath, and Zapier, and is actively protecting over 300 companies. Self-guided demo available (live environment) here: https://www.dropzone.ai/self-guided-demo

Capabilities
AI SOC Pure Play, Threat Hunting, Threat Intel
Deployment archetype
plug_and_play
Headquarters
Seattle, United States
Founded
2023
Funding stage
Series B
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://hubs.li/Q04q5kp90

Profile last updated 2026-06-26.


Elastic

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI Agent Builder, AI SOC Capability, Data Ingestion & Processing, Threat Hunting, Threat Intel
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.elastic.co/security/ai

Profile last updated 2026-07-03.


Embed Security

Embed Security is focused on security noise cancellation® for demanding SecOps environments. Embed’s AI SOC agentic security platform reduces alert fatigue and accelerates threat response across multiple attack surfaces by autonomously triaging and investigating security alerts, so teams can focus on real threats. Founded in 2024 by experienced security practitioners.

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
Founded
2024
Funding stage
Seed
SecOps Shift Map coverage
Triage and Investigation
Website
https://embedsecurity.com/

Profile last updated 2026-06-26.


Exabeam

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI SOC Capability
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.exabeam.com/platform/exabeam-nova/

Profile last updated 2026-06-26.


Exaforce

Exaforce is an AI-native agentic SOC platform built to transform how security teams detect, triage, investigate, and respond to threats. Rather than applying AI to isolated pieces of SOC optimization, Exaforce delivers AI-native capabilities across the entire security operations lifecycle, supporting analysts, detection engineers, DevOps teams, and threat hunters. At the core is a real-time knowledge graph and Multi-Model AI engine combining data semantics, behavioral baselining, machine learning, and large language models to deliver fast, precise, and trustworthy security decisions, avoiding the hallucination risks of standalone LLMs. AI agents called Exabots deliver 24/7 tier-1 to tier-3 analyst coverage without extra headcount, reviewing 100% of alerts in real time and surfacing hidden threats at lower TCO. The platform is available as SaaS or a fully managed MDR service, helping teams work faster and more accurately than with traditional SOC tooling. Exaforce has raised $200 million across funding rounds, led by Mayfield, Khosla Ventures, Harbourvest, Peak XV, and others, with a founding team drawing on experience from Google, F5, and Palo Alto Networks.

Capabilities
AI SOC Pure Play, SIEM, Data Analytics / UABA, Detection Engineering, SOAR, Threat Hunting, Threat Intel, MDR, Data Ingestion & Processing
Deployment archetype
Plug and Play
Headquarters
San Jose, CA
Founded
2023
Funding stage
200M - Series B
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.exaforce.com/

Profile last updated 2026-06-26.


Expel

Primary category
MDR
Capabilities
MDR, AI SOC Capability, Threat Hunting, CIRM / Case Management
Deployment archetype
Plug and Play
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://expel.com/

Profile last updated 2026-07-10.


Fig

Fig leads Security Operations Resilience, keeping detection and response working through constant change. The Fig platform delivers the full SecOps engineering lifecycle: build, ship, and observe every change, on any infrastructure, with confidence. Founded by veterans of Google SecOps and Siemplify, and backed by Team8 and Ten Eleven Ventures, Fig serves some of the world’s largest and most complex SOCs from offices in New York and Tel Aviv. With Fig, change powers the SOC instead of breaking it.

Capabilities
SecOps Resilience, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
New York, United States
Founded
2025
Funding stage
Series A
SecOps Shift Map coverage
Detection Engineering
Website
https://www.fig.security/

Profile last updated 2026-07-20.


Fortinet

Capabilities
AI SOC Capability, SOAR, SIEM, MDR, Data Analytics / UABA, Detection Engineering, Data Ingestion & Processing
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.fortinet.com/solutions/soc-platform

Profile last updated 2026-06-26.


Ghost Security

Capabilities
AI Agent Builder, AI SOC Capability
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
Founded
2022
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://ghostsecurity.ai/

Profile last updated 2026-06-26.


Google SecOps

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, Threat Intel, AI SOC Capability, Data Ingestion & Processing
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://cloud.google.com/security/products/security-operations

Profile last updated 2026-07-06.


GuarDDoG AI

Capabilities
Data Analytics / UABA, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://guarddog.ai/

Profile last updated 2026-06-26.


Gurucul

Capabilities
SIEM, Data Analytics / UABA, SOAR, AI SOC Capability
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://gurucul.com/

Profile last updated 2026-06-26.


HarkX

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
India
SecOps Shift Map coverage
Triage and Investigation
Website
https://harkx.ai/

Profile last updated 2026-06-26.


Hawkeye AI

Capabilities
AI SOC Capability, Data Analytics / UABA, SOAR, Threat Hunting, Threat Intel, Detection Engineering, Data Ingestion & Processing
Deployment archetype
Plug and Play & Customizable
Headquarters
United Arab Emirates
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://hawk-eye.io/

Profile last updated 2026-06-26.


Huntbase

Capabilities
Threat Hunting, AI SOC Pure Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.huntbase.io/

Profile last updated 2026-06-26.


Hunters

Capabilities
AI SOC Capability, SIEM, Data Analytics / UABA
Deployment archetype
Plug and Play
Headquarters
Israel
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://www.hunters.security/

Profile last updated 2026-06-26.


HydraNexus

HydraNexus is an AI-driven threat analysis platform for SOC teams and MSSPs. Six parallel LLM analysis heads evaluate security events with evidence-gated reasoning, synthesized into a single auditable verdict by an arbiter layer — reducing false positives and hallucinated findings compared to single-model AI security tools.

Capabilities
Threat Intel, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
Naperville, Illinois, United States
Founded
2016
Funding stage
Bootstrapped
SecOps Shift Map coverage
Triage and Investigation
Website
https://hydranexus.io/

Profile last updated 2026-07-07.


Imperum

Capabilities
SOAR, DFIR / Forensics, AI SOC Pure Play, AI Agent Builder
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
Netherlands
Founded
2023
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation, Response
Website
https://imperum.io/

Profile last updated 2026-07-06.


Intezer

Intezer crosses the trust threshold by combining forensic depth with agentic AI to accurately determine what really happened. This enables enterprise customers to safely offload Tier 1 and Tier 2 investigation work, shifting humans from investigating alerts to supervising outcomes.

Capabilities
AI SOC Pure Play, Threat Hunting, DFIR / Forensics, Threat Intel
Deployment archetype
Plug and Play & Customizable
Headquarters
New York, United States
Founded
2015
Funding stage
Series C
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://intezer.com/

Profile last updated 2026-06-26.


Jazz

Capabilities
Insider Threat / DLP, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
New York, United States
Founded
2024
Funding stage
Series A
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.jazz.security/

Profile last updated 2026-06-26.


Joon

Capabilities
AI Agent Builder, AI SOC Pure Play
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://joon.co/

Profile last updated 2026-06-26.


Kai Security

Capabilities
Automation, AI Agent Builder, AI SOC Pure Play
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.kai.security/

Profile last updated 2026-06-26.


Kenzo Security

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
Funding stage
Acquired
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.kenzo.security/

Acquired by Rapid7.

Profile last updated 2026-06-26.


Kindo

Capabilities
Automation, AI Agent Builder
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://kindo.ai/

Profile last updated 2026-06-26.


Legion Security

Capabilities
AI SOC Pure Play, Insider Threat / DLP, MDR, Threat Hunting, Threat Intel, SOAR
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.legionsecurity.ai/

Profile last updated 2026-07-08.


LimaCharlie

LimaCharlie is agentic SecOps infrastructure, purpose-built for AI agents to operate security, not just advise on it. With 100% API coverage, bring-your-own-LLM flexibility, and full auditability, AI agents perceive telemetry, investigate detections, and execute response actions with the same controls as human engineers.

Capabilities
SIEM, AI Agent Builder, AI SOC Capability, DFIR / Forensics, Threat Hunting, Detection Engineering, SOAR, Data Ingestion & Processing
Deployment archetype
Build it Yourself
Headquarters
Covina, United States
Founded
2018
Funding stage
Series A
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://limacharlie.io/

Profile last updated 2026-07-06.


Louie AI

A powerful and essential toolkit for modern cybersecurity practices, combining AI-driven automation with deep analytical capabilities. Seamless Integration Integrates effortlessly with major platforms like Splunk, Databricks, and Graphistry, enabling a unified view of security and operational data. Advanced Visualization Powerful and interactive visualizations allow security teams to identify and analyze threats, patterns, and relationships more effectively. Automated Detection & Response Automates the identification of potential threats such as high-risk sign-ins, brute-force attacks, and privilege escalation attempts. Comprehensive Monitoring Broad coverage across threat vectors including sign-in attempts, brute-force attacks, privilege escalations, and visual threat hunting. Enhanced Security Insights Detailed, technical insights allow IR teams and SOCs to make informed decisions quickly, improving overall security posture. Proactive Threat Management Identifies and addresses threats proactively, helping organizations prevent unauthorized access, reduce risks, and maintain security.

Capabilities
Data Analytics / UABA, OSS, AI Agent Builder, AI SOC Pure Play
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://louie.ai/

Profile last updated 2026-06-26.


Mars Security

Attackers have automated everything. The research, the campaign design, the execution. Most security teams are still writing detection rules by hand. That gap is where breaches live. Mars Security is an autonomous threat hunting and detection engineering platform built to close it. Mars connects directly to your existing security stack via API: SIEM, EDR, identity systems, cloud telemetry, and security data lakes - and performs federated search across all of it without ingesting a single log. No data migration. No tool replacement. No additional headcount. The platform continuously pulls global threat intelligence, extracts attacker TTPs, maps them to your environment, and generates validated hunts and production-ready detections tailored to your telemetry. Automatically. Continuously. Before the alert fires. Mars also delivers detection coverage intelligence, showing you exactly which active campaigns your stack can detect today, and which ones it cannot. Then it closes the gaps. The result: security teams move from reactive alert triage to proactive attacker detection. What used to take weeks takes minutes. Your team goes from five hunts a month to fifty.

Primary category
Detection Engineering
Capabilities
Detection Engineering, AI SOC Pure Play, Threat Hunting
Deployment archetype
Plug and Play & Customizable
Headquarters
Tel Aviv, Israel
Founded
2025
Funding stage
Seed
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://marssec.ai/

Profile last updated 2026-07-10.


Mate Security

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Israel
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.matesecurity.io/

Profile last updated 2026-06-26.


Mave

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Israel
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.mave.com/

Profile last updated 2026-06-26.


Method Security

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://method.security/

Profile last updated 2026-06-26.


Microsoft Sentinel

Capabilities
AI SOC Capability, Data Analytics / UABA, SOAR, SIEM, Data Ingestion & Processing
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel

Profile last updated 2026-06-26.


Mindflow

Capabilities
Automation, AI Agent Builder, AI SOC Capability, Threat Intel
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
France
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://mindflow.io/

Profile last updated 2026-07-06.


Mitiga

Capabilities
AI SOC Capability, Data Analytics / UABA
Deployment archetype
Plug and Play
Headquarters
New York, US
Founded
2020
Funding stage
Series B
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.mitiga.io/

Profile last updated 2026-06-26.


Orryx AI

Orryx AI is an AI-native SOC operating platform that helps security teams investigate, prioritize, and respond to threats faster by combining agentic AI, automation, threat intelligence, threat hunting, and SOC workflows in a single operational layer. Designed for enterprises and managed security providers (MSSPs), Orryx AI integrates across existing security technologies including SIEM, EDR, identity, cloud, email, and threat intelligence platforms. Rather than replacing existing tools, it unifies investigations across them, normalizing and correlating data to provide analysts with complete operational context. The platform combines deterministic automation with AI-assisted investigation, threat intelligence, threat hunting, and response support to reduce manual effort while maintaining analyst oversight. Orryx also provides SOC-native case management, risk-based prioritization, detection engineering, detection validation, reporting, and multi-tenant operations. By connecting investigation, intelligence, hunting, automation, response, and detection engineering into a single workflow with HITL, Orryx AI enables organizations to improve analyst productivity, reduce alert fatigue, accelerate incident response, and scale security operations more effectively across complex environments.

Capabilities
AI SOC Pure Play, Automation, Threat Hunting, Threat Intel, CIRM / Case Management, MDR, Detection Engineering
Deployment archetype
Plug and Play
Headquarters
Hamala, Bahrain
Founded
2022
Funding stage
Series A
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.beyoncyber.com/product/orryx-ai

Profile last updated 2026-06-26.


PaloAlto

Capabilities
AI Agent Builder, AI SOC Capability, Data Analytics / UABA, Detection Engineering, SIEM, SOAR, Threat Intel, MDR
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.paloaltonetworks.com/cortex

Profile last updated 2026-06-26.


Panther

Panther is the Complete AI SOC Platform that scales security expertise across the full operations lifecycle. Native AI agents embedded in the data lake, detection engine, and knowledge base investigate alerts and act autonomously, feeding every decision back into a closed-loop system that continuously reduces alert volume while expanding coverage.

Primary category
SIEM
Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, AI SOC Capability, Threat Intel, Threat Hunting, Data Ingestion & Processing
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
Founded
2018
Funding stage
Series B
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://panther.com/

Profile last updated 2026-07-10.


Perpetual Systems

The Complete System for the Agentic SOC, combining AI SOC agents with a SIEM core running on an open standards security lakehouse.

Capabilities
SIEM, AI SOC Capability, CIRM / Case Management, Data Ingestion & Processing, Detection Engineering, Threat Hunting, Data Analytics / UABA
Deployment archetype
Plug and Play & Customizable
Headquarters
Austin, TX, United States
Founded
2024
Funding stage
Seed
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.perpetualsystems.com

Profile last updated 2026-07-09.


PRE Security

Capabilities
Automation, AI SOC Pure Play
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://presecurity.ai/

Profile last updated 2026-06-26.


Prophet Security

Prophet Security’s mission is to be a force multiplier for security teams by delivering a comprehensive Agentic AI SOC Platform that automates the manual processes involved across security operations — from alert triage, investigation and incident response to threat hunting, and detection engineering. Prophet AI reduces mean time to investigate, mean time to respond, and delivers a 10x increase in team productivity. Learn more at prophetsecurity.ai.

Capabilities
Detection Engineering, Threat Hunting, AI SOC Pure Play, Threat Intel
Deployment archetype
Plug and Play
Headquarters
United States
Founded
2023
Funding stage
Series A
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.prophetsecurity.ai/

Profile last updated 2026-06-26.


Qevlar

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United Kingdom
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.qevlar.com/

Profile last updated 2026-06-26.


Query

Capabilities
Data Analytics / UABA, Data Ingestion & Processing, SIEM
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
Funding stage
Seed
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://www.query.ai/

Radiant Security

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://radiantsecurity.ai/

Profile last updated 2026-06-26.


ReliaQuest

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, MDR, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation, Response
Website
https://reliaquest.com/

Profile last updated 2026-07-06.


Rilian

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.rilian.com/

Profile last updated 2026-06-26.


RunReveal

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, AI Agent Builder, Data Ingestion & Processing, Threat Hunting, SecOps Resilience, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://runreveal.com/

Profile last updated 2026-06-26.


Scanner

Capabilities
SIEM, Data Ingestion & Processing, AI SOC Capability, Detection Engineering, Data Analytics / UABA
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://scanner.dev/

Profile last updated 2026-06-26.


SecsphereSOC

Capabilities
SOAR, AI SOC Pure Play, SIEM
Deployment archetype
Plug and Play & Customizable
Headquarters
India
SecOps Shift Map coverage
Data, Triage and Investigation
Website
https://secsphere.straightarc.com/

Profile last updated 2026-06-26.


SecureVisio

SecureVisio is a unified detection-and-response platform that consolidates SIEM, SOAR, UEBA, vulnerability management, risk analysis (BIA), CMDB, and IT GRC into a single product. Our core differentiator is context: every incident is enriched with business impact, asset owners, dependencies, and attack pathways, and threats are ranked through business-aligned risk scoring so analysts act on what matters first. An AI assistant supports analysts across the investigation lifecycle — generating incident summaries, classifying alerts, proposing threat-hunting queries, and guiding response. Alongside it, an autonomous AI agent investigates independently: it can call an MCP server and query local or cloud-hosted LLMs (including fully on-prem models). The agent either closes the incident or returns a reasoned verdict explaining what happened with recommendations. AI runs in a cost-aware cascade. ML models run first and continuously, learning each environment's "normal." Deep Value Learning adds context — which processes spawn others, where users normally log in from — reflecting the organization's real risk profile. Large Reasoning Models are invoked selectively to judge whether a case needs deeper investigation.

Primary category
SIEM
Capabilities
SIEM, AI SOC Capability, Data Analytics / UABA, SOAR, Detection Engineering, Data Ingestion & Processing, Threat Hunting, Threat Intel
Deployment archetype
Build it Yourself
Headquarters
Warsaw, Poland
Founded
2010
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://securevisio.com/

Profile last updated 2026-07-10.


Sekoia

Sekoia is the European agentic cybersecurity company building the Cyber Operations Platform for the AI era. Unifying CTI, detection and response, exposure management, and agentic AI, Sekoia is rebuilding cybersecurity from the ground up. Through the Autonomous SOC, machines investigate at scale while security teams govern operations with clarity &control.

Capabilities
SIEM, Data Analytics / UABA, SecOps Resilience, Threat Intel, AI SOC Capability, SOAR
Deployment archetype
Plug and Play
Headquarters
Rennes, France
Founded
2022
Funding stage
Series B
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation, Response
Website
https://www.sekoia.com/

Profile last updated 2026-07-08.


SentinelOne

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, Automation, Threat Hunting, MDR, DFIR / Forensics, Threat Intel, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.sentinelone.com/platform/ai-siem/

Profile last updated 2026-06-26.


Sevii

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.sevii.com/

Profile last updated 2026-06-26.


Sharelock

Capabilities
Insider Threat / DLP
Deployment archetype
Plug and Play
Headquarters
Italy
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.sharelock.ai/

Profile last updated 2026-06-26.


Shuffle

Primary category
SOAR
Capabilities
SOAR, AI SOC Capability, OSS
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://shuffler.io/

Profile last updated 2026-07-10.


Simbian

Capabilities
Threat Hunting, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
India
SecOps Shift Map coverage
Triage and Investigation
Website
https://simbian.ai/

Profile last updated 2026-06-26.


SIRP

Capabilities
CIRM / Case Management, AI SOC Capability, OSS
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://sirp.io/

Profile last updated 2026-06-26.


Sleuth Kit Labs

Capabilities
OSS, SOAR, DFIR / Forensics, AI SOC Capability
Deployment archetype
Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.cybertriage.com/

Profile last updated 2026-07-06.


SOC Prime

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, AI SOC Pure Play
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://socprime.com/

Profile last updated 2026-07-10.


SOCAI

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Spain
SecOps Shift Map coverage
Triage and Investigation
Website
https://socai.eu/

Profile last updated 2026-06-26.


Socjedi AI

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://socjedi.ai/

Profile last updated 2026-06-26.


SOCNova

Capabilities
AI SOC Pure Play, CIRM / Case Management
Deployment archetype
Plug and Play
Headquarters
Turkey
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.socnova.com/

Profile last updated 2026-06-26.


Sola

Capabilities
AI Agent Builder, AI SOC Capability, Data Analytics / UABA
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
United States
Founded
2024
Funding stage
Series A
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://sola.security/

Profile last updated 2026-06-26.


Sophos

AI speed. Human judgment. Sophos MDR delivers fully managed, 24/7 threat detection and response through the world's largest Agentic SOC. Designed for organizations with or without dedicated security teams, it integrates with hundreds of existing security tools and neutralizes threats in seconds. AI responds at scale; analysts own the outcomes.

Capabilities
Data Ingestion & Processing, Detection Engineering, DFIR / Forensics, ITDR, MDR, SIEM, SOAR, Threat Hunting, Threat Intel, AI SOC Capability
Headquarters
Oxford, Oxfordshire, United Kingdom
Founded
1985
Funding stage
Not disclosed
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation, Response
Website
https://www.sophos.com/en-us/services/managed-detection-and-response

Profile last updated 2026-07-03.


Spacewalk AI

Spacewalk is an agentic AI Security Operations platform that scales with the problem — from a single tier-1 alert to a full multi-host breach, on one system. For everyday alerts, a team of AI agents led by an autonomous commander investigates and resolves them end to end, fully in control. As a case turns serious, you stay on the same platform: the agents keep working, pull in more of your stack, and escalate into deep, multi-host incident response — no handoff, no tool-switching. What sets Spacewalk apart is how it reasons. Every case runs a structured Analysis of Competing Hypotheses — weighing benign against malicious — with each finding bound to a re-runnable query, so conclusions are evidence you can inspect, not AI guesswork. Genuine uncertainty resolves to an explicit Indeterminate verdict, never a hand-wavy score. The agents query your stack in parallel — CrowdStrike, Splunk, Sentinel, Defender, Entra, Google SecOps, Wiz, Sublime and more — correlate across every tool, and rebuild the timeline automatically. When an alert becomes an intrusion, built-in DFIR forensics ingest disk images, Windows event logs, and PCAP. Then Spacewalk writes the report that closes the case — while your analysts stay in command throughout.

Capabilities
AI SOC Pure Play, CIRM / Case Management, DFIR / Forensics, Insider Threat / DLP, Threat Hunting
Deployment archetype
Plug and Play
Headquarters
Irvine, United States
Founded
2024
Funding stage
Not disclosed
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://spacewalk.ai/

Profile last updated 2026-07-09.


Spectrum Security

Spectrum Security is an AI-powered detection platform that automates how organizations identify what they need to detect, build those detections, deploy them, and keep them working - across any SIEM, data lake, or security tool, at machine speed. The platform continuously maps coverage gaps, authors production-grade detections tailored to each environment, and maintains them as threats and infrastructure evolve. Security teams stay in control. Spectrum handles the heavy lifting. In customer environments, detection authoring has been compressed from months to under 30 minutes, with engineering hours reduced by 90%.

Primary category
Detection Engineering
Capabilities
Detection Engineering, SecOps Resilience
Deployment archetype
Plug and Play
Headquarters
San Francisco
Founded
2025
Funding stage
Seed
SecOps Shift Map coverage
Detection Engineering
Website
https://www.spectrum.security/

Profile last updated 2026-07-10.


Spharaka

Capabilities
Data Analytics / UABA, SIEM, AI SOC Pure Play, SOAR, Threat Hunting, Threat Intel, ITDR
Deployment archetype
Plug and Play & Customizable
Headquarters
Hyderabad, India
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://spharaka.com/

Profile last updated 2026-07-06.


Splunk

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.splunk.com/en_us/products/splunk-security-orchestration-and-automation.html

Profile last updated 2026-06-29.


Stellar Cyber

Capabilities
SIEM, Data Analytics / UABA, CIRM / Case Management, AI SOC Capability
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://stellarcyber.ai/

Profile last updated 2026-06-26.


Strike48

Strike48 is the Agentic Security Operations platform, combining complete log visibility with AI agents that work 24/7 to run investigations, automate detection, and orchestrate responses. The platform provides a no-code custom agent builder and pre-built agent clusters that address security, IT, and compliance use-cases. Bring your logs or query them in place, eliminating blind spots so AI agents can actually do the work, not just assist with it.

Capabilities
AI SOC Pure Play, SOAR, AI Agent Builder
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
United States
Founded
2026
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.strike48.com/

Profile last updated 2026-07-06.


StrikeReady

Capabilities
SIEM, Data Analytics / UABA, Automation, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://strikeready.co/

Profile last updated 2026-06-26.


Sumo Logic

Sumo Logic makes the digital world secure, fast, and reliable by turning insights into action. With our agentic AI-powered platform, organizations can unify all of their critical data and signals and automate responses to get ahead of business-critical issues and threats.

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SOAR, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
United States
Founded
2010
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation, Response
Website
https://www.sumologic.com

Profile last updated 2026-06-26.


Swimlane

Capabilities
SOAR, AI Agent Builder, AI SOC Capability, Threat Hunting
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://swimlane.com/

Profile last updated 2026-06-29.


TandemTrace

Capabilities
AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Spain
SecOps Shift Map coverage
Triage and Investigation
Website
https://tandemtrace.ai/

Profile last updated 2026-06-26.


Tenacium DC

Tenacium DC is a UK sovereign SME specialising in defence-grade data engineering, Artificial Intelligence (AI), Machine Learning (ML) and secure digital architectures. Tenacium supports Defence Digital, Front Line Commands and Defence Science & Technology Laboratory (Dstl) to design, build and operationalise high-assurance, mission-critical digital capabilities across enterprise, deployed and contested environments.

Capabilities
SecOps Resilience, Data Analytics / UABA, AI SOC Capability, SIEM
Deployment archetype
Plug and Play
Headquarters
London, United Kingdom
Founded
2021
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.tenacium.co.uk/

Profile last updated 2026-06-26.


Tencyle

Capabilities
AI SOC Pure Play, Threat Hunting, SOAR, Threat Intel
Deployment archetype
Plug and Play
Headquarters
Tel Aviv, Israel
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.tencyle.com/

Profile last updated 2026-07-06.


Tenex AI

Capabilities
MDR, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://tenex.ai/

Profile last updated 2026-06-26.


ThreatDefence

Primary category
MDR
Capabilities
MDR, AI SOC Capability, Data Ingestion & Processing, Threat Hunting, SIEM
Deployment archetype
Plug and Play
Headquarters
Australia
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://threatdefence.com/

Profile last updated 2026-07-10.


ThreatLens

Capabilities
AI SOC Pure Play, Data Ingestion & Processing, Automation
Deployment archetype
Plug and Play
Headquarters
United Arab Emirates
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://thethreatlens.com/

Profile last updated 2026-06-26.


Tier4 AI

Primary category
MDR
Capabilities
MDR, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Miami, United States
Funding stage
Seed
SecOps Shift Map coverage
Triage and Investigation
Website
https://tier4ai.com/

Profile last updated 2026-07-14.


Tines

Tines is the intelligent workflow platform trusted by the world's most advanced organizations. With Tines, they’ve built a secure, flexible foundation to operationalize AI agents and intelligent workflows, unlocking productivity, moving faster, and future-proofing how work gets done.

Capabilities
SOAR, AI SOC Capability, AI Agent Builder
Deployment archetype
Build it Yourself
Headquarters
Ireland
Founded
2018
Funding stage
Series C
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.tines.com/

Profile last updated 2026-07-06.


Torq

Capabilities
AI SOC Capability, SOAR, Threat Hunting, AI Agent Builder
Deployment archetype
Plug and Play & Customizable, Build it Yourself
Headquarters
New York, United States
Founded
2020
Funding stage
Series D+
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://torq.io/

Profile last updated 2026-06-29.


TraceCat

Tracecat provides everything busy security teams need to automate work: agents, workflows, cases, and an AI copilot that builds for you.

Capabilities
SOAR, OSS, AI SOC Capability, AI Agent Builder
Deployment archetype
Build it Yourself
Headquarters
United States
Founded
2024
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://tracecat.com/

Profile last updated 2026-07-06.


TrenchSecurity

Capabilities
SIEM, Data Ingestion & Processing, SOAR, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
Princeton, United States
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://www.trenchsecurity.ai/

Profile last updated 2026-06-26.


Tuskira

Capabilities
Detection Engineering, Threat Hunting, AI SOC Pure Play
Deployment archetype
Plug and Play
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.tuskira.ai/

Profile last updated 2026-06-26.


Vega

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, SecOps Resilience, AI SOC Capability
Deployment archetype
Plug and Play
Headquarters
Israel
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://vega.io/

Profile last updated 2026-06-26.


Vigil

Vigil SOC brings together security engineers, researchers, and builders to develop and operate next-generation security systems in the open, through collaborative events, shared infrastructure, and real-world exercises. Vigil ships with an Auto-Response agent that correlates signals across your stack, scores its own confidence, and contains the threat. Above your configured threshold (0.90 by default) it auto-approves; below, it routes to a human reviewer. Surgical actions (WAF block, Gateway block, session revoke) execute through a full audit trail. You set the boundary. Vigil keeps pace.

Capabilities
OSS, AI SOC Pure Play, AI Agent Builder
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
Founded
2026
SecOps Shift Map coverage
Triage and Investigation
Website
https://vigilsoc.org/

Profile last updated 2026-06-26.


Voidum AB

Unified SIEM, NDR, EDR, IDR, AIDR, and CDR powered by AI-driven detection and autonomous response. Built from scratch for speed.

Primary category
SIEM
Capabilities
SIEM, Threat Hunting, Threat Intel, SOAR, ITDR, Detection Engineering, Data Analytics / UABA, AI SOC Capability, Data Ingestion & Processing
Deployment archetype
Plug and Play
Headquarters
Stockholm, Sweden
Founded
2026
Funding stage
Not disclosed
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation
Website
https://voidum.io

Profile last updated 2026-07-07.


Wirespeed

What MDR should have always been: onboard in minutes, respond in seconds. Where traditional MDR depends on slow, expensive human analysts, Wirespeed uses a proprietary mix of AI & conditional logic to triage, reach a verdict, and contain threats in milliseconds (median time to verdict: 1,801ms), cutting alert noise by 99.9%. It connects to your existing stack via 50+ integrations and provides consistent, auditable, and transparent verdicts. Every step is observable, with no black box where logic is hidden from you. Wirespeed also breaks the fourth wall. When an alert needs context (an unusual login, a suspicious PowerShell command, a risky config change), it reaches out to your users directly over Slack, Teams, email, and SMS to find out what really happened, at any scale. You stay in control: tune every notification, escalation, and containment action, or let Wirespeed handle it automatically. Backed by Coalition's view across 100k+ cyber insurance policyholders, Wirespeed's algorithms are informed by global scan and incident data.

Primary category
MDR
Capabilities
MDR, SIEM, AI SOC Pure Play, ITDR
Deployment archetype
Plug and Play
Headquarters
San Francisco, United States
Founded
2024
Funding stage
Acquired
SecOps Shift Map coverage
Detection Engineering, Triage and Investigation, Response
Website
https://wirespeed.co/

Profile last updated 2026-07-10.


Wraithwatch

Capabilities
AI SOC Pure Play, Data Analytics / UABA
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
United States
SecOps Shift Map coverage
Triage and Investigation
Website
https://www.wraithwatch.com/

Profile last updated 2026-06-26.


Zaun

Capabilities
SIEM, Detection Engineering, Data Analytics / UABA, Automation, AI SOC Pure Play
Deployment archetype
Plug and Play, Plug and Play & Customizable
Headquarters
San Francisco, United States
Founded
2024
SecOps Shift Map coverage
Data, Detection Engineering, Triage and Investigation
Website
https://zaun.ai/

Profile last updated 2026-06-26.


Zscaler

Capabilities
AI SOC Capability, Data Analytics / UABA, Insider Threat / DLP, MDR
Deployment archetype
Plug and Play & Customizable
Headquarters
United States
Funding stage
Public
SecOps Shift Map coverage
Data, Triage and Investigation
Website
https://www.zscaler.com/products-and-solutions/security-operations

Profile last updated 2026-06-26.


Zynap

Capabilities
AI SOC Pure Play, Automation, Threat Intel
Deployment archetype
Plug and Play & Customizable
Headquarters
Barcelona, Spain
SecOps Shift Map coverage
Triage and Investigation, Response
Website
https://www.zynap.com/

Profile last updated 2026-06-26.