Nebulock
10 known investors
Nebulock is an agentic security analytics platform that continuously hunts for threats by ingesting telemetry across sources, building a behavioral context graph, and deploying validated detection rules. It serves security operations teams (SOC/SOAR workflows) to detect human and AI-agent insider threats, close detection coverage gaps, and accelerate investigations.
Also known as Nebulock, Inc.
Investors Β· 10
Also in the syndicate Β· 7
Company profile
researched Aug 2026Nebulock is a cybersecurity company that sells an agentic, "hunt-first" security operations platform. It ingests telemetry across endpoint, identity, cloud, network and SaaS sources, normalizes raw events and resolves them to single entities on a shared timeline, and maintains a continuously updated behavioral context graph (referred to in company material as the TRACE Graph) that acts as a behavioral system of record for a customer environment. A swarm of AI agents runs the threat hunting lifecycle end to end: forming and testing hypotheses, cross-referencing external threat intelligence, documentation, governance data, past hunts and allowlists against the graph, and producing findings with stated reasoning plus durable detection rules.
The platform's stated outcomes are closing detection coverage gaps, detecting credentialed human and AI-agent insider threats (including shadow AI), preventing detection drift through automated rule refinement, baselining normal human and agentic behavior, and accelerating investigations with remediation guidance. Findings and detections are pushed into customers' existing SOC and SOAR workflows. Named product components include Vespyr, an autonomous hunting agent that monitors global intelligence and scopes and executes hunts without a user directive; the Command Center dashboard; Helix, which queries vulnerability management tools on demand rather than pre-ingesting their data (shipping with Qualys, Tenable, Rapid7, Axonius, CrowdStrike and Microsoft Defender); insider risk management, which collapses a person's or AI agent's accounts, identities and hosts into a single "Actor"; and correlation rules that combine cross-domain signals into one detection with an evidence chain. Nebulock also publishes open material, including the open source Agentic Detection Engineering Framework (ADEF) and coreSigma, a macOS detection framework released via its GitHub repository.
Founding story
Founder and CEO Damien Lewke spent over a decade (described as 12 years) in cybersecurity across Northrop Grumman, CrowdStrike (early integrations engineering, from Series C to IPO) and Arctic Wolf, where he held product roles in AI, threat intelligence and detection. One source also references a master's thesis at MIT CSAIL. Lewke concluded that threat hunting remained manual, single-threaded and reactive even at well-resourced organizations, and that reactive alert triage could not keep pace with machine-speed attackers. After pressure-testing the problem with security leaders and practitioners, he founded the company on the thesis that effective hunting requires agentic AI grounded in contextual security analytics.
Business model
Nebulock sells a software platform to enterprise security organizations, marketed through demo requests on its website. The company describes API-driven integrations with existing security tooling (EDR, SIEM, IAM, CrowdStrike, Okta, Splunk) and onboarding measured in minutes. One source describes scaling ARR and growing deal sizes, and a customer quote characterizes the product as "another teammate working without impacting our budget," but no pricing structure is disclosed in the sources.
Sources indicate recurring revenue (ARR) from enterprise customers but do not disclose pricing, packaging or contract terms.
Traction
By June 2026, nine months after emerging from stealth, the company reported customers among Fortune 500 enterprises and organizations in financial services, healthcare and technology, naming Cribl, HealthEdge and Bain Capital. It reported more than 300 million agentic investigations run and over 4,000 high-confidence findings. During the OpenClaw incident it said it observed over 50,000 related events within a week across 40% of its customer base. Earlier material (2025) cited a double-digit production customer base, scaling ARR and monthly growth in deal sizes, and cited customer outcomes such as identifying a malicious insider who downloaded and ran malware despite a best-of-breed security stack. A February 2026 product update lists SOC 2 Type 2.
Latest developments
Following the June 2026 Series A, Nebulock shipped insider risk management, correlation rules and the Command Center; launched Helix, an on-demand query layer over vulnerability management tools, and the open source Agentic Detection Engineering Framework in late July 2026; hired Alex Hurtado as Head of Detection Strategy in July 2026; and published material on the TRACE Graph behavioral system of record in August 2026. Stated uses of the new funding are expanding platform capabilities, deepening cross-telemetry correlation and the behavioral context graph, and hiring in engineering and go-to-market.
βΈFull profile β market position, technology, go-to-market, geography, history, risks & controversies
Market position
Nebulock positions itself as a hunt-first, vendor-agnostic alternative to alert-driven security operations and to SIEM/agent-centric architectures, arguing that a behavioral system of record must sit above any single vendor sensor. It described itself at launch as the first platform to run fully autonomous, vendor-agnostic, intelligence-driven threat hunts. Company material cites third-party research (Verizon DBIR 2026, CardinalOps, Gravitee) on SIEM coverage gaps and AI-agent incidents to frame the market need. Sources do not name direct competitors.
Stated differentiators are: autonomous, continuously running hunts rather than reactive alert triage; a persistent behavioral context graph that carries memory across hunts and investigations; vendor-agnostic operation on telemetry the customer already owns rather than a proprietary sensor; behavior/TTP-based detection instead of indicator-based matching; transparent reasoning and evidence citations with each finding; and automatic generation, validation and refinement of durable detection rules deployed into existing SOC/SOAR pipelines.
Technology
Core technical elements are telemetry ingestion and normalization across endpoint, identity, cloud, network and SaaS; entity resolution onto a shared timeline; a continuously updated behavioral context graph that carries memory and context across hunts; and multi-threaded/agentic AI that generates hypotheses, executes parallel hunts, cites evidence, and emits validated detection rules. The company emphasizes behavior and TTP-based hunting over IOC matching. Company engineering posts describe using a deterministic classical machine learning model rather than an LLM for shadow-AI detection to reduce cost, and an open source framework (ADEF) that stores a machine-readable rationale and tuning history for detection rules. Natural language querying ("Scopes") is described as replacing manual SQL queries.
Go-to-market
Direct enterprise sales supported by website demo requests, a technical content program (Hunt Mode threat-hunting breakdowns, research posts, product release notes), open source releases (ADEF, coreSigma) and named customer references. The company said Series A proceeds would fund hiring across engineering and go-to-market, and an earlier source references adding a Head of Marketing.
Enterprise security operations teams: threat hunters, detection engineers, SOC analysts and security leaders (CISOs). One source describes mid-to-large enterprises with 1,000-5,000+ employees, including VC-backed technology firms, IPO candidates, financial institutions and retail organizations. The company states it has customers among Fortune 500 enterprises and in financial services, healthcare and technology, naming Cribl, HealthEdge and Bain Capital.
Geography
Headquartered in Boston, Massachusetts (an address of 131 Dartmouth St, Floor 3, Boston, MA 02116 is listed by one source). One source describes a hybrid workplace with roughly half the team local. No other offices or regions are named.
History
Sources disagree on the founding year: one page states 2023 in its quick facts and 2024 in its narrative. The company worked with enterprise security leaders and ran stealth trials across health tech, finance and VC-backed technology firms before emerging from stealth on 29 July 2025 with $8.5 million in total funding, including a seed round led by Bain Capital Ventures. Product and research output continued through late 2025 and 2026 (Vibe Hunting, the Agentic Threat Hunting Framework, coreSigma, Vespyr, Command Center). On 25 June 2026 the company announced a $25 million Series A led by FirstMark, bringing total funding to more than $33 million, and expanded from autonomous threat hunting into a broader hunt-first security analytics platform. Subsequent 2026 releases included Helix, ADEF and the TRACE Graph.
Risks & controversies
No controversies are reported in the sources. Data reliability is a concern for third-party aggregator information: one source lists conflicting founding years (2023 and 2024), an employee band of 1001-5000 alongside a statement that the company has 14 employees, and a single $6.0M seed round with a long investor list that conflicts with the company's own account of an $8.5M total raise led by Bain Capital Ventures with Decibel, Zetta Venture Partners and In-Q-Tel. The company's marketing statistics and customer outcome claims are self-reported.
Compiled by commissioned research from 8 cited public sources β announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed β not independently audited.
Timeline Β· 11
launches, deals, and filingsTRACE Graph is described as Nebulock's behavioral system of record for a customer environment.
Helix queries vulnerability management tools on demand without pre-ingestion, shipping with Qualys, Tenable, Rapid7, Axonius, CrowdStrike and Microsoft Defender integrations.
Open source framework giving detection rules an agent-readable journal of why they exist and how they were tuned.
Series A of $25 million led by FirstMark (David Waltcher), with participation from Bain Capital Ventures, Decibel, Zetta Venture Partners and Step Function Ventures; brings total raised to over $33 million. Funds are earmarked for platform capabilities, cross-telemetry correlation and behavioral context graph work, and engineering/go-to-market hiring.
$25M source β
Insider risk management consolidates a person's or AI agent's accounts, identities and hosts into a single monitored Actor; correlation rules combine signals across endpoint, identity and cloud into one detection with an evidence chain.
A single view surfacing the most critical finding, recommended hunt and actionable intelligence, including coverage gaps in the customer's SIEM.
Vespyr monitors global intelligence, determines relevance to the customer environment, and scopes and executes hunts without a user directive.
A February 2026 product update lists SOC 2 Type 2 among recent additions alongside insights, integrations and additional detection.
coreSigma, a macOS detection framework pipeline, was made publicly available in the Nebulock GitHub repository.
Nebulock publicly launched its autonomous threat hunting platform and announced $8.5 million in total funding, including a seed round led by Bain Capital Ventures with Decibel VC, Zetta Venture Partners, In-Q-Tel and angel investors.
$8.5M source β
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
βΈResearch sources Β· 8
primary sources listed
- Nebulocknebulock.io Β· web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Nebulock do?
- Boston-based Nebulock builds an agentic, hunt-first security analytics platform that continuously hunts threats and deploys detections.
- Who are Nebulock's investors?
- Nebulock's investors include Aviso Ventures, Decibel Partners, Bain Capital Ventures.
