Skip to main content
frontier

Nebulock’s $25M Series A Fuels AI Threat‑Hunting Surge

By Priya Nair

The Federal Pivot to Behavior-Based Detection

Nebulock closed a $25 million Series A in June 2026, less than a year after an $8.5 million seed round, and the capital is flowing because the federal government has codified behavior-based detection as the new baseline for adequate security. The company's autonomous AI threat hunting platform is attracting significant investment and driving product enhancements, prompting rivals such as Darktrace to adjust their competitive strategies.

The federal government has stopped trusting signatures. After years of watching adversaries slip past static rules, CISA and OMB rewrote the baseline for adequate detection — and the new baseline is behavior. Executive Order 14028, issued in May 2021, directed civilian agencies to adopt Zero Trust Architecture. OMB's M-22-09 followed in January 2022 with specific goals organized around the Zero Trust Maturity Model. Version 2.0 arrived in April 2023 after feedback from agencies, vendors, consultants, academia, and foreign partners. The framework organizes implementation across five pillars and three cross-cutting capabilities, with Visibility and Analytics at the center. That pillar demands health, status, performance, behavioral, and threat insights across infrastructure by observing real-time communications and security-relevant activities across every network component.

The documentation makes the shift explicit: "Evolving from traditional signature-based approaches, detection and response capabilities are increasingly adopting behavior-based methodologies to combat the sophistication of modern cyber threats." User and Entity Behavior Analytics, previously confined to the user pillar, now expands across visibility, using traditional and machine learning approaches to analyze enormous sets of network activities and pick out aberrations that may indicate malicious activity. Single or limited log sources often fail to detect actors hiding in the noise of normal network fluctuations.

Four maturity stages define the progression. Traditional: manual configuration, response, and mitigation; static and siloed policies. Initial: starting automation; initial cross-pillar solutions; aggregated visibility for internal systems. Advanced: automated controls where applicable; cross-pillar policy enforcement; least-privilege changes based on risk and posture. Optimal: fully automated, just-in-time, self-reporting; dynamic least privilege access; cross-pillar interoperability with continuous monitoring and centralized visibility. CISA itself operates a capability to detect and prevent cybersecurity risks in agency network traffic, and each agency head must apply and continue using CISA's intrusion detection and prevention capabilities.

For enterprise buyers, the signal is clear: the federal government, the largest buyer in the market, has established it as the standard. Agencies must develop plans for log collection prioritizing firewalls, EDR, Active Directory, switches, and routers within a common SIEM using open industry-standard formats. They must develop analytics and detection capabilities within that SIEM, augment with external threat intelligence, and incorporate AI/ML to improve scale, scope, and efficiency. The maturity model's "Optimal" stage describes fully automated, dynamic, cross-pillar interoperability — a description that maps directly to the autonomous threat hunting capabilities now entering the commercial market.

Nebulock's Architecture: Built for the Mandate

CISA's behavior-based detection mandate asks security teams to move beyond signature matching and identify anomalous activity across identity, network, and cloud telemetry. Nebulock's architecture was built for that exact shift. The platform runs multi-threaded, agentic hunts continuously across raw telemetry — no agents, no workflow disruption, and it correlates signals across CrowdStrike, Okta, Splunk, and other tools via API. That cross-telemetry correlation engine is the technical backbone of behavior-based detection: it stitches together identity anomalies, lateral movement, and credential misuse that single-layer tools miss.

The platform's "start with hunts, not alerts" philosophy maps directly to the government's push for proactive detection. Instead of waiting for a rule to fire, Nebulock's AI agents, branded Vespyr, execute hundreds of concurrent hunt hypotheses 24/7. In early deployments, those hunts surfaced dormant persistent threats and credential misuse that had evaded existing EDR and SIEM detection rules. The company reports true positive rates above 90 percent and more than 300 million agentic investigations producing over 4,000 high-confidence findings. Each finding includes a natural-language explanation and suggested response, closing the gap between hypothesis and actionable detection that CISA's guidance highlights as a critical operational shortfall.

Natural language detection engineering is another alignment point. Analysts can write, test, and iterate detections in plain English — "who RDP'd into finance servers?" — without SQL or proprietary query languages. That capability addresses the workforce gap the government has repeatedly identified: most organizations lack dedicated threat hunters, and detection engineers spend weeks triaging alerts rather than creating new hypotheses. Nebulock's feedback loops use LLMs to refine detection quality over time; every analyst decision trains the system to reduce false positives and adapt to the environment in real time. The result is a continuously learning threat engine that improves without manual rule maintenance.

Insider threat and credentialed attack detection, both explicit priorities in federal zero-trust guidance, are native to the platform. Nebulock flags anomalous human and agentic activity, identifies shadow AI usage, and surfaces lateral movement and attacker pre-positioning before escalation. The company notes that 95 percent of breaches are fully credentialed and adversary breakout time is now measured in minutes. Its agentic hunts are designed to catch deviation at that speed, not days later.

The investment from In-Q-Tel, the CIA's strategic venture arm, signals that the intelligence community sees technical alignment. In-Q-Tel participated in the $8.5 million seed round alongside Bain Capital Ventures, Decibel, Zetta Venture Partners, Step Function, and Aviso Ventures. That capital is funding expanded cross-telemetry coverage, deeper SIEM/EDR/IAM integrations, and engineering scale to meet demand from financial services, healthcare, and technology enterprises already deploying the platform.

Nebulock's approach does not replace existing controls; it validates them. Customers describe the platform as an always-on machine-driven hunting companion that provides a critical layer of validation for detective controls. That framing, augmentation over rip-and-replace, matches the pragmatic adoption path federal agencies have encouraged for behavior-based detection.

Incumbents Scramble to Match the New Baseline

The government's behavior-based detection mandate didn't just create demand — it forced incumbents to move. Darktrace, which holds a significant federal footprint, has recalibrated product and channel strategy over the past year to align with the new buyer requirements.

Darktrace's response is the most visible. In July 2024 the company launched the Darktrace Defenders Partner Program, a ground-up rewrite of its Global Partner Organization. The new program introduces three tiers, Elite, Premier, Preferred, with distinct entry requirements and benefit structures. It adds a Services Authorized Partner track that lets MSSPs deliver managed detection and response for network and email using Darktrace's ActiveAI Security Platform, backed by mandatory certification and a 30-day proof-of-value at no charge. The company tripled its GPO headcount across sales operations, marketing, and technical enablement, deployed a new partner portal, and added a commission accelerator for direct sellers who close through partners. Denise Walter, Darktrace's chief revenue officer, framed the overhaul as a response to customer unpreparedness: the company's 2024 State of AI Cybersecurity report found three in four security professionals believe AI-augmented threats already have significant impact, yet 60 percent feel unprepared to defend against them. Partners, Walter said, are critical to closing that gap. The program's deal-registration mechanics offer the highest available discounts on qualifying transactions, and market development funds operate on a co-investment model where Darktrace reimburses up to 100 percent of pre-approved costs.

CrowdStrike, the largest pure-play endpoint vendor in the federal market, has absorbed the behavior-based shift into its Falcon platform evolution. Damien Lewke, Nebulock's founder, spent his pre-Nebulock career at CrowdStrike and at Arctic Wolf, giving him direct visibility into how the incumbent translates federal requirements into product roadmap priorities.

The competitive dynamic is compressing. Darktrace is investing in channel depth to reach mid-market and enterprise buyers who lack the staff to run autonomous hunting themselves. All three are fighting for the same federal and regulated-enterprise budgets that Nebulock's Series A now targets. The market is increasingly binary: vendors either secure AI systems or use AI to deliver measurable security outcomes. The government's behavior-based mandate just made the second category a funded requirement.

Capital Follows the Mandate

Nebulock's $25 million Series A, closed in June 2026 and led by FirstMark partner David Waltcher, arrived less than twelve months after the company emerged from stealth. Existing seed investors doubled down. The speed of the follow-on round reflects a broader pattern: venture funding in cybersecurity is concentrating into fewer companies with larger rounds and higher valuations.

FirstMark's conviction stems from what the firm calls founder-market fit. Damien Lewke built detection pipelines at the DoD, took CrowdStrike through its IPO, and led product at Arctic Wolf before founding Nebulock in 2024. "From our earliest conversations, it was clear that Damien is the definition of founder market fit, combining deep domain expertise with a rare ability to translate that insight into product," the firm said in the Series A announcement. Bain Capital Ventures, which led the seed, cited Nebulock's ability to surface threats that legacy tools discard: insider threats, detection drift, and the new category of agentic insider risk created by workplace AI adoption.

The capital is earmarked for three levers: expanding the platform's cross-telemetry correlation engine, deepening its behavioral context graph, and scaling engineering and go-to-market teams to meet enterprise demand. Nebulock says its platform has already run that many agentic investigations across customers that include Cribl, HealthEdge, and Bain Capital itself, plus Fortune 500 enterprises in financial services and healthcare.

Those customer wins are landing in a market that multiple research firms size differently but agree is expanding fast.

Research firm 2024/2025 base CAGR Forecast year Forecast value
Grand View Research 16.3% 2033 $16.25 billion
PS Market Research $3.5 billion (2024) 15.2% 2030 $8.1 billion
MarketsandMarkets (threat intelligence) $11.6 billion (2025) 14.7% 2030 $23.0 billion
Mordor Intelligence $3.4 billion (2025) 14.4% 2030 $6.6 billion

The spread reflects definitional differences, threat hunting versus threat intelligence, pure-play versus platform, but the vector is consistent. Mordor Intelligence lists IBM, Cisco, Google, CrowdStrike, and Palo Alto Networks as key competitors in the threat hunting space. The concentration of capital into Nebulock's Series A suggests investors are betting on a handful of platforms that can collapse the SIEM-EDR-XDR stack the way EDR collapsed endpoint complexity — a vision Lewke articulated explicitly: "Over time, our vision is much bigger than agentic threat hunting alone, we want to do for SIEM what EDR did for endpoint."

The next funding test will be whether Nebulock's hunt-first architecture converts pilot velocity into recurring revenue at a pace that justifies the step-up in valuation. The mandates have created a procurement tailwind; the market now waits for the revenue inflection that turns tailwind into trajectory.

Why Autonomy Remains a Spectrum, Not a Switch

Gartner places AI-SOC agents in the Innovation Trigger phase with only 1 to 5 percent market adoption as of early 2026, and over 100 vendors now claim autonomous security operations capabilities. That gap between marketing claims and deployed reality defines the first barrier: buyers cannot distinguish signal from noise in a crowded field where every vendor promises self-learning models and autonomous response.

Integration hurdles compound the confusion. Nearly all IT leaders report that integration challenges impede AI implementation, according to Defy Security's readiness research. The problem is not API connectivity — it is context. Human analysts spend up to a quarter of their time on false positives because they must perform "swivel chair" operations, manually pulling data from multiple tools to understand whether an alert matters. Autonomous agents lack that contextual access unless security teams invest months wiring telemetry sources, normalizing schemas, and building the enrichment pipelines that human intuition navigates instinctively.

The organizational readiness gap runs deeper than most vendors acknowledge. AI-SOC does not just automate alert triage; it fundamentally changes what SOC analysts do. Analysts need training in data science principles, prompt engineering for LLM interactions, and critical analysis of AI-generated narratives. Surveys indicate most employees are comfortable working alongside AI agents, but only if they understand what the AI is doing and why. That transparency requirement forces vendors to build explainability into every investigation path, not just the happy path.

Adversarial deception exploits a structural weakness in current LLM-based hunters. Threat actors cheat; deception is the medium in which they operate throughout the attack lifecycle. Security telemetry is typically trustworthy, but the activity it reports may be threat-actor influenced — accurate telemetry accurately reporting a lie. AIs are not good at subtlety; they are trained to take input data at face value. This creates what threat hunting framework architect David Bianco calls the hunter's paradox: organizations need AI to hunt at scale, yet cannot fully trust the automation they depend on.

Technical overhead adds friction. LLM inference latency introduces non-trivial delay in detection workflows, and the cost model of frontier agent operations warrants careful consideration. Extended multi-turn investigations with large context windows incur significant token costs on platforms like Amazon Bedrock. Prompt injection risk forces every external data ingested by agents to be treated as potentially adversarial input, processed through content filtering guardrails, adding latency and architectural complexity.

Governance requirements stretch deployment timelines. A phased approach, shadow SOC observation, targeted augmentation for off-hours coverage, then autonomous operations, typically spans six to nine months from initial planning to production. Teams must define error tolerance upfront, accepting that AI agents will have an error rate, perhaps two percent on critical alerts, and build validation processes around that reality. Each specialist agent needs dedicated machine identities, least-privilege IAM permissions, and comprehensive audit trails captured in immutable storage. Tiered remediation actions require non-negotiable governance controls with human escalation SLAs, 15-minute veto windows for Tier 2, four-hour approval deadlines for Tier 3, and automatic default actions on SLA breach. The AI system itself must undergo regular adversarial red-teaming.

The human creative advantage remains the final barrier. Inherent limitations of current LLM technology mean humans will likely retain the creative edge indefinitely. AI can only do what it sees in its training data; attackers innovate beyond that boundary. Humans must still pick what is worth hunting, even if AI figures out how to execute those hunts within set bounds.

The federal mandate that rewrote detection baselines is now rewriting the vendor landscape. Nebulock's hunt-first architecture, the incumbents' channel overhauls, the capital concentration — all trace to that one pivot. The Series A buys Nebulock time to prove its architecture turns pilot velocity into recurring revenue. The mandate guarantees a procurement tailwind; the market watches for the inflection that turns it into trajectory. If it arrives, the autonomous hunting category graduates from innovation trigger to budget line item. If not, the incumbents' channel depth and endpoint incumbency will absorb the demand.


Working in frontier tech? Zero G Talent tracks the openings: see every open ASML role, browse frontier tech jobs, openings at Stripe, and the people building the field.

Ready to Start Your Space Career?

Browse frontier jobs and find your next opportunity.

View frontier Jobs