Fundraising Fox

Nebulock

10 known investors

nebulock.io β†—

Nebulock is an agentic security analytics platform that continuously hunts for threats by ingesting telemetry across sources, building a behavioral context graph, and deploying validated detection rules. It serves security operations teams (SOC/SOAR workflows) to detect human and AI-agent insider threats, close detection coverage gaps, and accelerate investigations.

Also known as Nebulock, Inc.

AI & Machine LearningCybersecuritySaaS

Investors Β· 10

Also in the syndicate Β· 7

Andrew MorrisAndrew PetersonDecibelDecibel VCJosh KamdjouNick GalbreathWilliam Lehmann

Company profile

researched Aug 2026

Nebulock is a cybersecurity company that sells an agentic, "hunt-first" security operations platform. It ingests telemetry across endpoint, identity, cloud, network and SaaS sources, normalizes raw events and resolves them to single entities on a shared timeline, and maintains a continuously updated behavioral context graph (referred to in company material as the TRACE Graph) that acts as a behavioral system of record for a customer environment. A swarm of AI agents runs the threat hunting lifecycle end to end: forming and testing hypotheses, cross-referencing external threat intelligence, documentation, governance data, past hunts and allowlists against the graph, and producing findings with stated reasoning plus durable detection rules.

The platform's stated outcomes are closing detection coverage gaps, detecting credentialed human and AI-agent insider threats (including shadow AI), preventing detection drift through automated rule refinement, baselining normal human and agentic behavior, and accelerating investigations with remediation guidance. Findings and detections are pushed into customers' existing SOC and SOAR workflows. Named product components include Vespyr, an autonomous hunting agent that monitors global intelligence and scopes and executes hunts without a user directive; the Command Center dashboard; Helix, which queries vulnerability management tools on demand rather than pre-ingesting their data (shipping with Qualys, Tenable, Rapid7, Axonius, CrowdStrike and Microsoft Defender); insider risk management, which collapses a person's or AI agent's accounts, identities and hosts into a single "Actor"; and correlation rules that combine cross-domain signals into one detection with an evidence chain. Nebulock also publishes open material, including the open source Agentic Detection Engineering Framework (ADEF) and coreSigma, a macOS detection framework released via its GitHub repository.

Founding story

Founder and CEO Damien Lewke spent over a decade (described as 12 years) in cybersecurity across Northrop Grumman, CrowdStrike (early integrations engineering, from Series C to IPO) and Arctic Wolf, where he held product roles in AI, threat intelligence and detection. One source also references a master's thesis at MIT CSAIL. Lewke concluded that threat hunting remained manual, single-threaded and reactive even at well-resourced organizations, and that reactive alert triage could not keep pace with machine-speed attackers. After pressure-testing the problem with security leaders and practitioners, he founded the company on the thesis that effective hunting requires agentic AI grounded in contextual security analytics.

Business model

Nebulock sells a software platform to enterprise security organizations, marketed through demo requests on its website. The company describes API-driven integrations with existing security tooling (EDR, SIEM, IAM, CrowdStrike, Okta, Splunk) and onboarding measured in minutes. One source describes scaling ARR and growing deal sizes, and a customer quote characterizes the product as "another teammate working without impacting our budget," but no pricing structure is disclosed in the sources.

Sources indicate recurring revenue (ARR) from enterprise customers but do not disclose pricing, packaging or contract terms.

Traction

By June 2026, nine months after emerging from stealth, the company reported customers among Fortune 500 enterprises and organizations in financial services, healthcare and technology, naming Cribl, HealthEdge and Bain Capital. It reported more than 300 million agentic investigations run and over 4,000 high-confidence findings. During the OpenClaw incident it said it observed over 50,000 related events within a week across 40% of its customer base. Earlier material (2025) cited a double-digit production customer base, scaling ARR and monthly growth in deal sizes, and cited customer outcomes such as identifying a malicious insider who downloaded and ran malware despite a best-of-breed security stack. A February 2026 product update lists SOC 2 Type 2.

Latest developments

Following the June 2026 Series A, Nebulock shipped insider risk management, correlation rules and the Command Center; launched Helix, an on-demand query layer over vulnerability management tools, and the open source Agentic Detection Engineering Framework in late July 2026; hired Alex Hurtado as Head of Detection Strategy in July 2026; and published material on the TRACE Graph behavioral system of record in August 2026. Stated uses of the new funding are expanding platform capabilities, deepening cross-telemetry correlation and the behavioral context graph, and hiring in engineering and go-to-market.

β–ΈFull profile β€” market position, technology, go-to-market, geography, history, risks & controversies

Market position

Nebulock positions itself as a hunt-first, vendor-agnostic alternative to alert-driven security operations and to SIEM/agent-centric architectures, arguing that a behavioral system of record must sit above any single vendor sensor. It described itself at launch as the first platform to run fully autonomous, vendor-agnostic, intelligence-driven threat hunts. Company material cites third-party research (Verizon DBIR 2026, CardinalOps, Gravitee) on SIEM coverage gaps and AI-agent incidents to frame the market need. Sources do not name direct competitors.

Stated differentiators are: autonomous, continuously running hunts rather than reactive alert triage; a persistent behavioral context graph that carries memory across hunts and investigations; vendor-agnostic operation on telemetry the customer already owns rather than a proprietary sensor; behavior/TTP-based detection instead of indicator-based matching; transparent reasoning and evidence citations with each finding; and automatic generation, validation and refinement of durable detection rules deployed into existing SOC/SOAR pipelines.

Technology

Core technical elements are telemetry ingestion and normalization across endpoint, identity, cloud, network and SaaS; entity resolution onto a shared timeline; a continuously updated behavioral context graph that carries memory and context across hunts; and multi-threaded/agentic AI that generates hypotheses, executes parallel hunts, cites evidence, and emits validated detection rules. The company emphasizes behavior and TTP-based hunting over IOC matching. Company engineering posts describe using a deterministic classical machine learning model rather than an LLM for shadow-AI detection to reduce cost, and an open source framework (ADEF) that stores a machine-readable rationale and tuning history for detection rules. Natural language querying ("Scopes") is described as replacing manual SQL queries.

Go-to-market

Direct enterprise sales supported by website demo requests, a technical content program (Hunt Mode threat-hunting breakdowns, research posts, product release notes), open source releases (ADEF, coreSigma) and named customer references. The company said Series A proceeds would fund hiring across engineering and go-to-market, and an earlier source references adding a Head of Marketing.

Enterprise security operations teams: threat hunters, detection engineers, SOC analysts and security leaders (CISOs). One source describes mid-to-large enterprises with 1,000-5,000+ employees, including VC-backed technology firms, IPO candidates, financial institutions and retail organizations. The company states it has customers among Fortune 500 enterprises and in financial services, healthcare and technology, naming Cribl, HealthEdge and Bain Capital.

Geography

Headquartered in Boston, Massachusetts (an address of 131 Dartmouth St, Floor 3, Boston, MA 02116 is listed by one source). One source describes a hybrid workplace with roughly half the team local. No other offices or regions are named.

History

Sources disagree on the founding year: one page states 2023 in its quick facts and 2024 in its narrative. The company worked with enterprise security leaders and ran stealth trials across health tech, finance and VC-backed technology firms before emerging from stealth on 29 July 2025 with $8.5 million in total funding, including a seed round led by Bain Capital Ventures. Product and research output continued through late 2025 and 2026 (Vibe Hunting, the Agentic Threat Hunting Framework, coreSigma, Vespyr, Command Center). On 25 June 2026 the company announced a $25 million Series A led by FirstMark, bringing total funding to more than $33 million, and expanded from autonomous threat hunting into a broader hunt-first security analytics platform. Subsequent 2026 releases included Helix, ADEF and the TRACE Graph.

Risks & controversies

No controversies are reported in the sources. Data reliability is a concern for third-party aggregator information: one source lists conflicting founding years (2023 and 2024), an employee band of 1001-5000 alongside a statement that the company has 14 employees, and a single $6.0M seed round with a long investor list that conflicts with the company's own account of an $8.5M total raise led by Bain Capital Ventures with Decibel, Zetta Venture Partners and In-Q-Tel. The company's marketing statistics and customer outcome claims are self-reported.

Compiled by commissioned research from 8 cited public sources β€” announcements, filings, and press listed under research sources below.

Key figures

latest reported
Agentic investigations runJun 2026300,000,000 investigations
EmployeesJan 202514 people
High-confidence findings producedJun 20264,000 findings
OpenClaw-related events observedJun 202650,000 events
Total funding raisedJun 2026$33M

Company-reported or press-reported figures, each dated to when it was claimed β€” not independently audited.

Timeline Β· 11

launches, deals, and filings
Aug 2026
TRACE Graph introduced

TRACE Graph is described as Nebulock's behavioral system of record for a customer environment.

source β†—

Jul 2026
Alex Hurtado joins as Head of Detection Strategy

source β†—

Jul 2026
Nebulock Helix launched

Helix queries vulnerability management tools on demand without pre-ingestion, shipping with Qualys, Tenable, Rapid7, Axonius, CrowdStrike and Microsoft Defender integrations.

source β†—

Jul 2026
Agentic Detection Engineering Framework (ADEF) released

Open source framework giving detection rules an agent-readable journal of why they exist and how they were tuned.

source β†—

Jun 2026
Nebulock raises $25M Series A led by FirstMark

Series A of $25 million led by FirstMark (David Waltcher), with participation from Bain Capital Ventures, Decibel, Zetta Venture Partners and Step Function Ventures; brings total raised to over $33 million. Funds are earmarked for platform capabilities, cross-telemetry correlation and behavioral context graph work, and engineering/go-to-market hiring.

$25M source β†—

Jun 2026
Insider risk management and correlation rules shipped

Insider risk management consolidates a person's or AI agent's accounts, identities and hosts into a single monitored Actor; correlation rules combine signals across endpoint, identity and cloud into one detection with an evidence chain.

source β†—

Jun 2026
Command Center released

A single view surfacing the most critical finding, recommended hunt and actionable intelligence, including coverage gaps in the customer's SIEM.

source β†—

Mar 2026
Vespyr autonomous hunting agent introduced

Vespyr monitors global intelligence, determines relevance to the customer environment, and scopes and executes hunts without a user directive.

source β†—

Feb 2026
SOC 2 Type 2 noted in product update

A February 2026 product update lists SOC 2 Type 2 among recent additions alongside insights, integrations and additional detection.

source β†—

Jan 2026
coreSigma macOS endpoint security framework published publicly

coreSigma, a macOS detection framework pipeline, was made publicly available in the Nebulock GitHub repository.

source β†—

Jul 2025
Nebulock emerges from stealth with $8.5M in total funding

Nebulock publicly launched its autonomous threat hunting platform and announced $8.5 million in total funding, including a seed round led by Bain Capital Ventures with Decibel VC, Zetta Venture Partners, In-Q-Tel and angel investors.

$8.5M source β†—

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

β–ΈResearch sources Β· 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Nebulock do?
Boston-based Nebulock builds an agentic, hunt-first security analytics platform that continuously hunts threats and deploys detections.
Who are Nebulock's investors?
Nebulock's investors include Aviso Ventures, Decibel Partners, Bain Capital Ventures.