Category · 26 models

SOC Alert Triage & Investigation

Cut a 10,000-alert day down to the handful that actually matter.

What it is

Security models cluster alerts, pull in context from EDR + SIEM + identity, and write the first draft of an incident timeline so Tier-1 analysts can decide in seconds, not hours.

Real-world examples

  • ·De-duplicate 8,000 EDR alerts to 12 real incidents
  • ·Auto-draft an IR timeline from raw log evidence
  • ·Recommend containment actions with reasoning

What to look for

  • ·Native SIEM / XDR integration
  • ·MITRE ATT&CK mapping
  • ·Human-in-the-loop guardrails

26 models in this category

Cisco AI Defense

Cisco

AIDB88

Security platform that protects AI applications from misuse and attacks.

Agents
SecurityProprietary

CrowdStrike Charlotte AI

CrowdStrike

AIDB93

Generative AI security analyst built into the Falcon platform.

Agents
SaaSProprietary

Microsoft Security Copilot

Microsoft

AIDB92

Generative AI assistant for SOC analysts and IT admins.

Agents
SaaSProprietary

Palo Alto AI Access Security

Palo Alto Networks

AIDB93

Discovery and protection for employee use of generative AI apps.

Agents
SaaSProprietary

Cisco AI Assistant

Cisco

AIDB94

Cross-portfolio AI assistant for security, networking and collaboration.

Agents
SaaSProprietary

Cisco Hypershield

Cisco

AIDB91

AI-native distributed security fabric for data centers and clouds.

Agents
PlatformProprietary

F5 AI Gateway

F5

AIDB82

Application-delivery and security AI gateway for LLM apps.

Agents
GatewayProprietary

Fortinet FortiAI

Fortinet

AIDB91

GenAI security analyst across the Fortinet Security Fabric.

Agents
SaaSProprietary

Zscaler ZDX Copilot

Zscaler

AIDB94

Generative-AI copilot for digital experience and zero-trust operations.

Agents
SaaSProprietary

Palo Alto Strata Copilot

Palo Alto Networks

AIDB95

GenAI copilot for network security across the Strata portfolio.

Agents
SaaSProprietary

Palo Alto Cortex XSIAM

Palo Alto Networks

AIDB93

AI-driven SOC platform unifying SIEM, EDR and SOAR.

Agents
PlatformProprietary

Check Point Infinity AI Copilot

Check Point

AIDB87

Generative-AI assistant for security administration and threat analysis.

Agents
SaaSProprietary

SentinelOne Purple AI

SentinelOne

AIDB88

Generative-AI threat-hunting analyst across the Singularity platform.

Agents
SaaSProprietary

Darktrace ActiveAI

Darktrace

AIDB87

Self-learning AI platform for autonomous response across email, network and cloud.

Agents
PlatformProprietary

Vectra AI Platform

Vectra AI

AIDB86

AI-driven threat detection and response across hybrid cloud.

Agents
PlatformProprietary

Veeam Data Intelligence

Veeam

AIDB91

AI-powered data resilience, anomaly detection and recovery analytics.

Agents
PlatformProprietary

Commvault Cloud Arlie

Commvault

AIDB92

GenAI assistant for cyber resilience, recovery and data protection.

Agents
SaaSProprietary

Rubrik Ruby

Rubrik

AIDB90

Generative-AI assistant for cyber recovery investigations and remediation.

Agents
SaaSProprietary

Elastic AI Assistant

Elastic

AIDB88

GenAI assistant across Elastic Search, Observability and Security.

AgentsEmbeddings
PlatformProprietary

Splunk AI Assistant

Splunk (Cisco)

AIDB92

GenAI assistant for SPL, observability and security operations.

Agents
SaaSProprietary

Datadog Bits AI

Datadog

AIDB89

Generative-AI assistant across Datadog observability and security.

Agents
SaaSProprietary

AI Agents (ServiceNow)

ServiceNow

AIDB95

Autonomous AI agents for IT, HR, customer service and security operations.

Agents
SaaSProprietary

Cisco AI Assistant

Cisco

AIDB94

Cross-portfolio AI assistant for security, networking and collaboration.

Agents
SaaSProprietary

Symantec AI for DLP

Broadcom / Symantec

AIDB87

AI-driven data loss prevention classifying sensitive content across cloud, email and endpoints.

Agents
PlatformProprietary

Prisma AIRS

Palo Alto Networks

AIDB93

AI Runtime Security — protects models, agents and data across enterprise AI deployments.

Agents
PlatformProprietary

Cortex Cloud

Palo Alto Networks

AIDB91

Unified AI-driven CNAPP + CDR converging Prisma Cloud and Cortex into one platform.

Agents
PlatformProprietary

Explore other categories