State of the space ·

Alert Triage and Investigation Agents

The AMS Map plots 10 roster vendors in alert triage and investigation agents across three axes - agent independence, job width, and output to cost - with each chip labeled by its pricing metric.
The quadrant, Aug 2026 ·open full page →· this file does not change after publish

All eight still price by coverage

Alert triage and investigation agents pull alerts from any security stack, decide which ones are real, work each real alert into a finished case, and hand that case to a human analyst or a response system. Vendors in this category range from independent AI SOC analyst products to agents built into an established platform's own console. Dropzone AI reports its agent autonomously investigates and closes a majority of tier-one alerts for managed security customers, according to the company's own published case data, and most vendors in this roster now charge by the alert or by a consumption credit rather than by analyst seat.

1Consumption-based alert creditsPositions: Monetizely analysisPublic data only
10 / 15
Roster vendors versus total tracked vendors in this category
6 of 10
Roster vendors pricing on alert volume or consumption credits instead of per-seat licenses
2024
Year the first standalone AI SOC analyst products shipped commercially

Who is on this map

No items found.

The roster splits between independent AI SOC analyst products built specifically for alert triage and investigation, and agents shipped inside an established security platform's existing console. Dropzone AI, Prophet Security, Radiant Security, Simbian, Exaforce, and Conifers built their businesses around this single job, and each has published funding, customer, or revenue evidence supporting emerging or established status. D3 Security, Microsoft, CrowdStrike, and SentinelOne route their triage agents through platforms that already carry large installed customer bases, which qualifies those agent-level products for the roster under the platform routing rule in this charter.

Several additional vendors ship agentic triage work but sit below the roster bar on public evidence today. Qevlar AI and Palo Alto Networks' AgentiX carry credible shipped announcements but thinner public customer or revenue disclosure as of this edition. ReliaQuest, Expel, and Red Canary appear as service-attribute candidates, meaning their triage agents operate inside a managed detection and response service rather than as a standalone purchasable product; each is tracked rather than rostered pending clearer usage-based pricing disclosure.

Tracked but off-roster in this edition: Qevlar AI, Palo Alto Networks AgentiX, ReliaQuest, Expel, and Red Canary. Each has a shipped or credibly announced triage agent but currently lacks the funding, customer count, or revenue evidence this charter requires for roster placement.

What this category does

Products in this category ingest alerts from endpoint, network, identity, cloud, and email tools regardless of vendor origin, apply a decision layer that separates real threats from noise, and then investigate each confirmed alert by pulling logs, correlating related events, and reconstructing what happened. The output is a concluded case file with a recommended verdict, handed to a human analyst for sign-off or passed directly into a response system for containment action.

Tier-one and tier-two security operations center analysts still approve final verdicts on high-impact cases, tune detection logic when an agent's investigation surfaces a gap, and handle escalations that require judgment calls outside an agent's trained scope, such as legal exposure or executive notification. Analysts also remain responsible for building and running the response playbooks that execute after a case closes, work that this charter assigns to response automation agents rather than to triage and investigation agents.

The task list agents can take over
  1. Ingest - pull alerts from endpoint, network, identity, cloud, and email tools into one queue regardless of source vendor.
  2. Triage - separate real threats from false positives using correlated evidence rather than static rules alone.
  3. Investigate - reconstruct the full chain of events behind each confirmed alert, pulling logs and related activity end to end.
  4. Conclude - hand a finished case with a verdict and evidence trail to a human analyst or a response system.

The agentic shift

From alert queues to concluded cases

Alert triage moved from static correlation rules to agent-driven investigation in stages tied to specific product launches. Dropzone AI shipped its AI SOC analyst product in 2023 and expanded managed service partnerships through 2024, according to company blog posts, establishing the independent AI SOC analyst as a distinct product category. Radiant Security and Simbian followed with their own investigation agents in 2024, each raising early venture rounds to fund the shift from rule-based triage to agent-led case building.

Platform vendors followed roughly a year later. CrowdStrike introduced Charlotte AI detection triage inside the Falcon platform, and Microsoft announced a set of Security Copilot agents including a phishing and alert triage agent in March 2025, according to Microsoft's own security blog. SentinelOne extended Purple AI toward more autonomous triage behavior across the same period, and Exaforce entered the market in 2025 with a combined detection and investigation agent backed by a large seed round, moving the independent segment toward broader job width rather than narrower point tools.

Pricing in this category has shifted away from flat per-analyst-seat licensing toward metering tied to alert volume or agent work performed. Dropzone AI and Radiant Security both structure commercial terms around the number of alerts an agent investigates rather than the number of human seats accessing a dashboard, according to each vendor's public product and partner materials. Microsoft prices its Security Copilot agents, including its triage agent, through Security Compute Units, a consumption meter billed on agent activity rather than named users, as described in Microsoft's own Security Copilot pricing documentation.

Independent vendors earlier in their funding lifecycle, including Simbian and Conifers, list pricing as not public and instead route prospective buyers to a sales conversation, a common pattern for vendors still finalizing packaging around a new agentic product. CrowdStrike and SentinelOne bundle their triage agents into existing platform subscription tiers rather than metering separately, keeping the underlying alert-volume economics inside a broader platform contract. Across the roster, the dominant emerging meter is consumption tied to alert volume or compute units rather than seat count. Sources: dropzone.ai; radiantsecurity.ai; microsoft.com/security-copilot; crowdstrike.com; sentinelone.com; simbian.ai; conifers.ai

Sources:category analysis,NDR comparison,Vendr

Observed monetization patterns
  1. Alert-volume consumption - Dropzone AI and Radiant Security meter commercial terms on the number of alerts an agent investigates rather than per-seat access.
  2. Compute-unit metering - Microsoft bills Security Copilot agents, including its triage agent, through Security Compute Units consumed during agent activity.
  3. Platform bundling - CrowdStrike's Charlotte AI and SentinelOne's Purple AI ship inside existing platform subscription tiers rather than as separately metered products.
  4. Pricing not public - Simbian and Conifers route buyers to direct sales conversations while their packaging around agentic triage work remains unpublished.

This quarter

May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital

Cloud packaging

On July 20, AWS put the Amazon GuardDuty investigation agent into public preview for investigating GuardDuty findings across AWS environments. AWS made the preview free but capped usage at 10 investigations per account per day and 100 cumulative investigations per account. The move attaches on-demand agent investigation to a managed cloud-detection service, exposing a quota-controlled adoption model instead of a standalone analyst-seat purchase.

Source: AWS Security Blog, GuardDuty investigation agent announcement

Platform pressure

On July 31, Elastic announced an expanded Attack Discovery capability as part of its push toward Alert Zero, with the product investigating and validating threats to reduce a raw alert queue to a smaller set of attacks. Elastic subsequently described Elastic 9.5 as generally available with AI-driven first-pass alert triage and investigation. The release brings attack-level validation into a broader security-data platform, increasing competitive pressure on standalone AI SOC offerings.

Source: Elastic investor-relations announcement, Elastic 9.5 general-availability announcement

Managed triage

On August 24, Expel introduced its Ruxie AI rapid triage agent for first-pass investigations of high-volume identity and AWS cloud alerts. Expel says the agent tests competing benign and attack hypotheses before setting severity, while its expert human analysts remain the sole decision-makers for final alert disposition. The launch preserves a managed-service human approval boundary while moving evidence gathering and prioritization into an autonomous agent.

Source: Expel product announcement

Edition packaging

On September 10, Gravwell announced version 5.10 with an Alert Triage Agent that reviews alerts, runs supporting queries, gathers context, and prepares an initial investigation report. Its AI Agent Preview kit is available across Gravwell editions, including Community Edition, and the product documentation describes prebuilt automated agents for alert triage, audit, and daily summaries. The release packages agent access as an edition-level platform capability rather than reserving it for a separate premium AI tier.

Source: Gravwell 5.10 announcement, Gravwell 5.10 AI agent documentation

The long arc

2023 to 2026: from static correlation rules to agent-led case conclusion

2021
PLAYBOOK BASELINE

The category's predecessor was deterministic SOC automation: Tines described integrations that collect context to determine alert severity and remediation, while CrowdStrike added notification workflows and real-time-response automation for known situations. Buyers were procuring integrations, playbooks, and response workflow capacity rather than autonomous investigation agents.

2023
COPILOT ARRIVAL

Microsoft announced Security Copilot on March 28 to help defenders correlate activity and investigate incidents, and CrowdStrike introduced Charlotte AI on May 30 as a generative-AI cybersecurity analyst for Falcon users. The category shifted toward natural-language analyst assistance embedded in major security platforms.

2024
METERED AVAILABILITY

CrowdStrike made Charlotte AI generally available in February, and Microsoft made Security Copilot generally available on April 1 with a provisioned, pay-as-you-go model. AI-assisted investigation gained a repeatable procurement path through platform capacity consumption rather than bespoke deployment projects.

2025
AUTONOMOUS VERDICTS

Google introduced an alert triage agent that performs dynamic investigations, gathers context, renders a verdict, and records its evidence and decisions, while Microsoft announced Security Copilot agents for high-volume tasks including phishing triage. The category definition expanded from prompted assistance to background workflows that could investigate, classify, and explain an alert disposition.

2026
PLATFORM AGENT ECONOMICS

By the September 15 cutoff, Google's Triage and Investigation agent was generally available, while SentinelOne opened Purple AI Agentic Investigation to customers with a complimentary trial and Singularity Credits. Commercial models now vary across Microsoft's provisioned and overage SCUs, CrowdStrike's monthly AI credits, and platform-specific credit programs. Alert triage agents had become a metered or included platform capability, but without a standardized economic unit.

Vendor by vendor

Journalist first, analyst second

Method:we work journalist first and analyst second. We document the agentic products each vendor actually ships, with sources a reader can check, and the AMS placement follows from that documented capability. Vendors with no shipped agentic product stay on the quadrant and out of this section. We report how each vendor charges today, and we do not use this page to advise vendors on what to charge.
No items found.

Not covered

Corelight builds the evidence pipeline that most of the other tools on this page depend on, on top of  Zeek, one of the most widely used network analysis frameworks in security. When we went looking for a shipped  product that triages, investigates, or responds on its own, we did not find one, so Corelight stays on the quadrant and out of the breakdown section. The same finding applies to Netography, which provides flow observability at scale. If either company ships an agentic product, it enters this section in the edition that documents it.

About this data

Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.