State of the space ·
All eight still price by coverage
The roster splits between independent AI SOC analyst products built specifically for alert triage and investigation, and agents shipped inside an established security platform's existing console. Dropzone AI, Prophet Security, Radiant Security, Simbian, Exaforce, and Conifers built their businesses around this single job, and each has published funding, customer, or revenue evidence supporting emerging or established status. D3 Security, Microsoft, CrowdStrike, and SentinelOne route their triage agents through platforms that already carry large installed customer bases, which qualifies those agent-level products for the roster under the platform routing rule in this charter.
Several additional vendors ship agentic triage work but sit below the roster bar on public evidence today. Qevlar AI and Palo Alto Networks' AgentiX carry credible shipped announcements but thinner public customer or revenue disclosure as of this edition. ReliaQuest, Expel, and Red Canary appear as service-attribute candidates, meaning their triage agents operate inside a managed detection and response service rather than as a standalone purchasable product; each is tracked rather than rostered pending clearer usage-based pricing disclosure.
Tracked but off-roster in this edition: Qevlar AI, Palo Alto Networks AgentiX, ReliaQuest, Expel, and Red Canary. Each has a shipped or credibly announced triage agent but currently lacks the funding, customer count, or revenue evidence this charter requires for roster placement.
Products in this category ingest alerts from endpoint, network, identity, cloud, and email tools regardless of vendor origin, apply a decision layer that separates real threats from noise, and then investigate each confirmed alert by pulling logs, correlating related events, and reconstructing what happened. The output is a concluded case file with a recommended verdict, handed to a human analyst for sign-off or passed directly into a response system for containment action.
Tier-one and tier-two security operations center analysts still approve final verdicts on high-impact cases, tune detection logic when an agent's investigation surfaces a gap, and handle escalations that require judgment calls outside an agent's trained scope, such as legal exposure or executive notification. Analysts also remain responsible for building and running the response playbooks that execute after a case closes, work that this charter assigns to response automation agents rather than to triage and investigation agents.
From alert queues to concluded cases
Alert triage moved from static correlation rules to agent-driven investigation in stages tied to specific product launches. Dropzone AI shipped its AI SOC analyst product in 2023 and expanded managed service partnerships through 2024, according to company blog posts, establishing the independent AI SOC analyst as a distinct product category. Radiant Security and Simbian followed with their own investigation agents in 2024, each raising early venture rounds to fund the shift from rule-based triage to agent-led case building.
Platform vendors followed roughly a year later. CrowdStrike introduced Charlotte AI detection triage inside the Falcon platform, and Microsoft announced a set of Security Copilot agents including a phishing and alert triage agent in March 2025, according to Microsoft's own security blog. SentinelOne extended Purple AI toward more autonomous triage behavior across the same period, and Exaforce entered the market in 2025 with a combined detection and investigation agent backed by a large seed round, moving the independent segment toward broader job width rather than narrower point tools.
Pricing in this category has shifted away from flat per-analyst-seat licensing toward metering tied to alert volume or agent work performed. Dropzone AI and Radiant Security both structure commercial terms around the number of alerts an agent investigates rather than the number of human seats accessing a dashboard, according to each vendor's public product and partner materials. Microsoft prices its Security Copilot agents, including its triage agent, through Security Compute Units, a consumption meter billed on agent activity rather than named users, as described in Microsoft's own Security Copilot pricing documentation.
Independent vendors earlier in their funding lifecycle, including Simbian and Conifers, list pricing as not public and instead route prospective buyers to a sales conversation, a common pattern for vendors still finalizing packaging around a new agentic product. CrowdStrike and SentinelOne bundle their triage agents into existing platform subscription tiers rather than metering separately, keeping the underlying alert-volume economics inside a broader platform contract. Across the roster, the dominant emerging meter is consumption tied to alert volume or compute units rather than seat count. Sources: dropzone.ai; radiantsecurity.ai; microsoft.com/security-copilot; crowdstrike.com; sentinelone.com; simbian.ai; conifers.ai
Sources:category analysis,NDR comparison,Vendr
May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital
On July 20, AWS put the Amazon GuardDuty investigation agent into public preview for investigating GuardDuty findings across AWS environments. AWS made the preview free but capped usage at 10 investigations per account per day and 100 cumulative investigations per account. The move attaches on-demand agent investigation to a managed cloud-detection service, exposing a quota-controlled adoption model instead of a standalone analyst-seat purchase.
Source: AWS Security Blog, GuardDuty investigation agent announcement
On July 31, Elastic announced an expanded Attack Discovery capability as part of its push toward Alert Zero, with the product investigating and validating threats to reduce a raw alert queue to a smaller set of attacks. Elastic subsequently described Elastic 9.5 as generally available with AI-driven first-pass alert triage and investigation. The release brings attack-level validation into a broader security-data platform, increasing competitive pressure on standalone AI SOC offerings.
Source: Elastic investor-relations announcement, Elastic 9.5 general-availability announcement
On August 24, Expel introduced its Ruxie AI rapid triage agent for first-pass investigations of high-volume identity and AWS cloud alerts. Expel says the agent tests competing benign and attack hypotheses before setting severity, while its expert human analysts remain the sole decision-makers for final alert disposition. The launch preserves a managed-service human approval boundary while moving evidence gathering and prioritization into an autonomous agent.
Source: Expel product announcement
On September 10, Gravwell announced version 5.10 with an Alert Triage Agent that reviews alerts, runs supporting queries, gathers context, and prepares an initial investigation report. Its AI Agent Preview kit is available across Gravwell editions, including Community Edition, and the product documentation describes prebuilt automated agents for alert triage, audit, and daily summaries. The release packages agent access as an edition-level platform capability rather than reserving it for a separate premium AI tier.
Source: Gravwell 5.10 announcement, Gravwell 5.10 AI agent documentation
2023 to 2026: from static correlation rules to agent-led case conclusion
The category's predecessor was deterministic SOC automation: Tines described integrations that collect context to determine alert severity and remediation, while CrowdStrike added notification workflows and real-time-response automation for known situations. Buyers were procuring integrations, playbooks, and response workflow capacity rather than autonomous investigation agents.
Microsoft announced Security Copilot on March 28 to help defenders correlate activity and investigate incidents, and CrowdStrike introduced Charlotte AI on May 30 as a generative-AI cybersecurity analyst for Falcon users. The category shifted toward natural-language analyst assistance embedded in major security platforms.
CrowdStrike made Charlotte AI generally available in February, and Microsoft made Security Copilot generally available on April 1 with a provisioned, pay-as-you-go model. AI-assisted investigation gained a repeatable procurement path through platform capacity consumption rather than bespoke deployment projects.
Google introduced an alert triage agent that performs dynamic investigations, gathers context, renders a verdict, and records its evidence and decisions, while Microsoft announced Security Copilot agents for high-volume tasks including phishing triage. The category definition expanded from prompted assistance to background workflows that could investigate, classify, and explain an alert disposition.
By the September 15 cutoff, Google's Triage and Investigation agent was generally available, while SentinelOne opened Purple AI Agentic Investigation to customers with a complimentary trial and Singularity Credits. Commercial models now vary across Microsoft's provisioned and overage SCUs, CrowdStrike's monthly AI credits, and platform-specific credit programs. Alert triage agents had become a metered or included platform capability, but without a standardized economic unit.
Journalist first, analyst second
About this data
Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.