Players

AI SOC and detection companies

A crowded, capital-rich market selling alert-triage economics, sitting on the one benchmark that says reasoning may not help here.

evidence: medium9 minupd 2026-08-29socdetectionalert-triagemdrfunding

The AI SOC market is adjacent to AI code security companies, not the same market, and it is more crowded, better capitalized per company, and sitting on worse benchmark evidence for the thing everyone is selling. At least thirteen funded startups and five platform giants are chasing "an AI analyst that triages your alerts," and the one rigorous defensive benchmark built for this exact task — CyberSOCEval — found that reasoning and test-time compute, the single biggest driver of 2025–2026 gains on offensive tasks, does not transfer the same way to SOC work. That finding should worry anyone planning to post-train a model for this segment more than any competitor's funding round.

#The master table

#Funded startups

Company HQ / founded Funding (latest) Product Notable signal
Dropzone AI Seattle, 2023 $37M (Series B, beyond an initial $16.85M Series A) Dropzone "AI SOC Analyst" — full autonomous investigations, not just alert summarization Investors include Leidos Holdings — a defense/gov contractor as corporate backer
Prophet Security US $30M, Aug 2025 VentureBeat Autonomous SOC platform for L1/L2 triage, explicitly "replacing human analysts" Backers include Citi Ventures and Amex Ventures Citi Ventures — corporate VC from real SOC buyers, a stronger enterprise-pull signal than most rounds in this table
Radiant Security US $15M, Nov 2023 — no later round found SecurityWeek "Adaptive AI SOC platform" for triage and investigation Funding has gone quiet for nearly two years relative to newer entrants
Exaforce US $125M Series B, May 2026, on top of a $75M Series A — roughly $200M in just over a year TechCrunch Real-time attack detection/response, broader than pure alert triage One of the fastest-escalating raises in the entire defensive-AI space
Culminate Not independently identified in available research [unverified] Named in industry lists as an AI SOC player No confirmed funding, product detail, or primary source located
Intezer Israel/US, 2015 $33M (2024) — no fresh round found Malware/genetic-code-analysis triage automation Repositioning around "AI that emulates human analysts"
Conifers.ai US $25M, backed by SYN Ventures PRNewswire Agentic AI SOC platform
Qevlar AI US/Europe $30M, on top of an earlier $14M Qevlar Shifting from "alert firefighting" to org-level security insight Steady step-up funding pattern
Twine Security US/Israel $12M seed DarkReading "AI digital employees for cybersecurity" Frames SOC agents explicitly as headcount replacement, not augmentation
Andesite US $23M additional raise, Feb 2025 SiliconANGLE "Bionic SOC" — general availability Explicitly hybrid human+AI positioning, not full autonomy
Simbian US $10M seed Autonomous AI security platform Named to CB Insights AI 100 2026 — one of only six security companies on that list
Legion Not independently identified in available research [unverified] Named in industry lists as an AI SOC player No confirmed detail located
Torq (HyperSOC) Israel/US $140M Series D, $1.2B valuation (2024 round; company reports >300% YoY revenue growth into 2025) Torq SOAR-native, repositioned as "HyperSOC" "SOAR is dead, AI SOC is now" positioning
Tines Dublin $125M Series C, $1.125B valuation PRNewswire No-code security automation, expanding into agentic orchestration Closer to "SOAR + agent runtime" than a pure AI-analyst product

Culminate and Legion — both named in the founder's brief — could not be independently confirmed: no funding record, product description, or primary source was located for either. Treat both as unverified.

#Platform incumbents

Company Product Signal
Microsoft Security Copilot Consumption-priced on "Security Compute Units" layered on E5/enterprise licensing Pricing so opaque it has spawned a cottage industry of third-party cost explainers Microsoft
CrowdStrike Charlotte AI Expanded from a single copilot into an "AgentWorks" ecosystem, plus "Charlotte Agentic SOAR" Trying to become the agent platform for the SOC, not just ship one assistant CrowdStrike
Palo Alto Networks Cortex XSIAM / AgentiX Redesigned data lake (Cortex XDL 2.0) plus named agents (Case Investigation, Cloud Posture, Automation Engineer); XSOAR rebranded "Cortex AgentiX" Combines 1,300+ playbooks and 1,100 integrations with agent orchestration; PANW frames urgency around attackers completing "end-to-end attacks in as little as 72 minutes" PANW
SentinelOne Purple AI "Purple AI Agentic Investigation" Opened to all customers in 2026 (previously gated) — bundled into the base platform rather than charged separately SentinelOne
Google / Mandiant Gemini in SecOps Continuous, near-weekly feature drops (parsers, detection tuning, agent behaviors) Public changelog cadence, not big-bang launches — a fast-iterating product line, not a one-off changelog example
Key numbers

The MDR/SOC market itself is sized at $3.5B (2023) → an estimated $6.6B (2026) → $15.3B by 2030, a 23.5% CAGR Grand View Research — one of the fastest-growing segments in all of cybersecurity, for the same reason MDR itself grew: it answers the talent-shortage problem directly. See Who buys, and what they pay and Unit economics and the compute bill.

#Why this segment is crowded and capital-rich

The SOC talent shortage is real and well documented; PwC's 2026 Global Digital Trust Insights survey found 53% of organizations are prioritizing AI/ML tools specifically to address the security talent gap, and ranks "AI enablement of key cyber capabilities" as the top priority for new cyber-budget allocation. That is a clean, quantifiable buyer pain — "we can't hire enough L1 analysts" — exactly the kind of problem venture capital likes to fund and platform incumbents like to bundle away. Result: five funded challengers with $100M+ rounds in the last eighteen months (Exaforce, Torq, Tines, plus Prophet and Dropzone trending that direction), and five platform giants (Microsoft, CrowdStrike, Palo Alto Networks, SentinelOne, Google) all shipping competing agentic-SOC features into products their customers already own.

#What the actual product is: alert-triage economics

Strip away the "autonomous defender" language and nearly every company above sells the same thing: an agent that reads an alert, gathers context (logs, threat intel, asset inventory), reasons about whether it's a true or false positive, and either closes it, escalates it, or hands a human a pre-investigated case instead of a raw ping. This is a labor-arbitrage product — it exists because a Tier-1 SOC analyst is expensive, hard to hire, and burns out on repetitive triage, and the pitch is "buy this instead of hiring three more of them" Who buys, and what they pay. That is also why the market rewards adoption speed over depth: Torq's "SOAR is dead" positioning and SentinelOne giving Purple AI Agentic Investigation to all customers for free are both bets that the winning move is commoditizing triage fast and monetizing the platform underneath it, not the triage layer itself.

#Why the benchmark evidence matters enormously

This is the fact that should reshape any plan to post-train a defensive model. CyberSOCEval — the field's first credible, purpose-built defensive benchmark, published jointly by Meta and CrowdStrike on 24 September 2025 arXiv:2509.20166 · CrowdStrike press release — tests malware analysis and cyber-threat-intelligence reasoning built from real SOC-telemetry-style tasks. Its headline finding: reasoning models with test-time scaling do not get the same performance boost on these SOC tasks that they get on math and coding benchmarks.

Contrast that against offense, where reasoning and test-time compute are the single biggest driver of 2025–2026 capability gains — the gap between mid-2024 and mid-2026 performance on benchmarks like CyberGym is almost entirely a reasoning-scale story Cyber benchmarks and evals. Defense does not get that same lift, at least not on the tasks CyberSOCEval measures, and defense has essentially one benchmark of this caliber, versus at least six mature, actively-cited benchmarks on the offensive side Cyber benchmarks and evals.

Unverified

This finding is recent (Sept 2025, revised Nov 2025), built on one benchmark suite, and — per the CyberSOCEval authors' own framing — has not yet been cited as gating evidence in any frontier lab's system card or risk classification as of Aug 2026. It should be treated as the best available evidence, not a settled law of the field. But it is the only rigorous evidence that currently exists on this specific question, which is itself the point: nobody should assume "more reasoning compute" solves SOC-analyst-quality triage just because it solved offensive exploit generation.

The practical implication: if reasoning/test-time compute is the lever a lab or startup would reach for first to improve a defensive model, and that lever works less well here than on offense, then companies competing on "our model reasons better" are competing on a dimension that may not differentiate outcomes. The dimension that plausibly does — context assembly, tool integration, access to an org's actual telemetry, trustworthy automation of the boring 80% of triage — is un-sexy, data-and-integration-heavy work that is hard to post-train your way past.

#Should the founder go anywhere near it

No, not as a first move, and the reasoning is structural, not just competitive:

  • The product is a labor-arbitrage play, not a research-capability play. Winning requires deep integration into a buyer's SIEM/EDR/ticketing stack, telemetry access, and trust built over long sales cycles — not a better base model. Different company than "cyber-defense Devin that reviews every PR," which is a code/reasoning problem the founder is better positioned for.
  • The benchmark evidence argues against a model-first bet. If reasoning-scale gains don't transfer to SOC tasks the way they do to offense or code review, a lab whose edge is post-training research talent has less leverage here than in code security, where whole-repo reasoning and exploitability validation are still open, reasoning-shaped problems.
  • The incumbents already bundle this in for free. SentinelOne opened Purple AI Agentic Investigation to all customers in 2026; Microsoft, CrowdStrike, and Google ship competing agent ecosystems into platforms their target buyers already pay for. A new entrant is fighting free.
  • The funding bar is already high, with at least five startups at $30M+ and two platform-adjacent players (Torq, Tines) above $1B in valuation — a capital-intensive land grab, not an open field.

#Palo Alto Networks and what its M&A says about exits

PANW ran the most aggressive AI-security acquisition campaign of any platform vendor in 2025–2026, and the shape of it is informative for anyone thinking about exit paths in this segment:

  1. Protect AI — completed 22 July 2025, AI/ML security posture and model-security scanning PANW. Deal value undisclosed.
  2. CyberArk — announced 2025, reported at $25 billion [unverified — press-reported, not confirmed by a primary financial disclosure found in this research], PANW's largest deal ever, expanding into identity/privileged-access security.
  3. Chronosphere — reported at $3.35 billion [unverified, same caveat], an observability platform PANW frames as "unifying observability and security for the AI era."
  4. Koi — smaller, "agentic endpoint" security, referenced in PANW's Feb 2026 Cortex strategy post.

All four are confirmed completed transactions; none of the dollar figures could be independently verified from a primary financial source — treat every deal value above as press-reported, not confirmed Verification ledger. The pattern is the useful signal regardless of exact prices: PANW is buying data, telemetry, and identity depth to feed its own agentic Cortex platform, not pre-merge code-review tooling. It has no visible SAST/SCA product line and no stated ambition to build one — PANW reads as a plausible acquirer for a company in this SOC-adjacent market, and a weak, indirect one for a company in the AI code security companies cluster.

#What this means for us

  • Do not build a SOC-triage product as a first bet — it is a labor-arbitrage, integration-heavy business, not a research-capability business, and the founder's likely edge (post-training, model reasoning) is weakest here of anywhere in the landscape.
  • The CyberSOCEval finding — reasoning/test-time compute doesn't transfer to SOC tasks the way it does to offense — is the single most important piece of evidence against a "post-train a better defensive reasoner" strategy in this segment specifically. It does not necessarily apply to code security, where the reasoning-shaped problems (exploitability validation, whole-repo threat modeling) look more like the offensive benchmarks. See Post-training playbook and Cyber benchmarks and evals.
  • If SOC is ever revisited, the wedge is integration and trustworthy automation of the boring majority of triage, not a smarter model — and that is a GTM and data-access problem more than a lab problem. See Data, and whether a moat is possible and Go to market.
  • PANW's M&A pattern says this market has real, near-term acquirer appetite (Protect AI, Chronosphere) that the code-security cluster does not obviously have — worth remembering if the strategic goal is an eventual acquisition rather than an independent business. See Who funds this and at what price and The three ideas, judged.
  • Treat every SOC-market deal value and valuation figure in this landscape as press-reported until proven otherwise — this segment has the noisiest funding data in the whole survey, including two names (Culminate, Legion) that could not be confirmed to exist as described at all.