Disclaimer: Opinions expressed are solely my own and do not reflect the views or opinions of my employer or any other affiliated entities. Any sponsored content featured on this blog is independent and does not imply endorsement by, nor relationship with, my employer or affiliated organisations.
AI SOC, or Agentic SOC as some call it now, went through an interesting evolution in the last 3 years. I has a chance to implement it in an enterprise in the early days when no one trusted it will be a thing, I advised most of the AI SOC vendors as a consultant, I tracked and analyzed almost every vendor in the space as an analyst, and now I build and market in it. So I've seen it from most of the angles that matter.
Enough bragging. The point is the space changed in a very short period of time. What started as a product category is now commoditized and used across the majority of SecOps tooling in some shape or form.
And that's not a bad thing. But let's first understand why it happened.
Product Updates Section !
Spacewalk handles the full investigation depth, from pre-L1 triage to L3+ incident work. It runs agentic investigations inside your SIEM and EDR, and when the case needs it, goes down to forensics: disk images, event logs, even PDFs. What caught my attention is how it handles complexity. The deeper the investigation, the more rigor it applies. It uses Analysis of Competing Hypotheses: benign versus malicious hypotheses, blind-evaluated, and the evidence has to actually discriminate between them. Not just a confidence score slapped on a verdict. The end result: verdicts you can audit, at whatever depth the investigation went.
AI tools are becoming part of the enterprise attack surface, but most SOCs still have limited visibility into what users, agents, and connected tools are doing. Daylight now provides managed AI security for Claude Enterprise as part of its MDR service. They build and continuously refine detection coverage for AI-native threats across Claude activity, including malicious or unauthorized MCPs, risky Skills and Plugins, prompt injection attempts, and more. Daylight’s agentic MDR investigates each signal, using context from identity, endpoint, cloud, SaaS, and business systems. Daylight other cool product features are the agentic threat hunting and a security data lake.
The SecOps Shift Map
To track the space, I created the SecOps Shift Map. It explains the areas where SecOps tooling is developing. Soon is making 1 year since I first published it and now we have version 2.
Here's how is structured.. On the far left you have the data pipeline and log ingestion. To get alerts, you first need visibility. Then you have the detection layer, plus what I now call SecOps resilience: monitoring your SecOps pipeline itself. You got the alerts, now you need to get alerted when something is malicious or suspicious.
Then you get into triage. This is where you do the analysis and decide how to handle an alert. If it's a false positive or benign, figure out what needs fixing. If it's a true positive, you continue to remediation.
Quick note on terminology: I try to use "response" less these days. For some people, response means you started analyzing an alert. For others, it means remediation, mitigation, containment. Too confusing.
(The map is still work in progress. I haven't figured out where to place attack simulation/emulation or deception tech yet. My current thinking is attack simulation sits under SecOps resilience, because you're testing your pipeline.)
Here's the kicker
Most AI SOC vendors started in the middle of the map. Triage. And to some extent, that's how the product category got shaped.
In my mind, that was never going to be enough. Something that just does triage will get commoditized. And it did. Most SIEM, EDR, SOAR, XDR, or whatever tech SecOps teams use, added some form of autonomous triage. Some of it is simple, mainly throwing stuff at an LLM. Some of it is complex agentic systems with RAG and automations.
I won't argue about what "true AI SOC" is, because we're not there yet. When I speak with practitioners, no two give me the same definition. It means different things to different people. So I stick with AI SOC as we know it: AI/LLM and agents used for autonomous alert investigation. Based on that definition, it got commoditized.
The prediction that played out
What I said last year: because of this, it won't be enough for AI SOC vendors to sell just triage. They will move either left or right on the Shift Map.
Right means the SOAR route. Add response, some level of automation builders. Left means threat hunting, detection engineering, or even building a SIEM.
And exactly that happened. You can see how the Shift Map looked last year versus how it looks now.
Ah, and one more shift I almost forgot. Some vendors will go into service offerings and add MDR. We have that as a separate highlight on the Shift Map, since that one is services rather than tech.
The analysts are catching up
This connects to something I covered in a recent Friday SIEM post: the movement isn't only coming from the AI SOC side. Data pipeline vendors are moving into SIEM and adding AI SOC on top. Cribl acquiring CardinalOps is the latest example. The AI SOC piece is what makes them compelling. In the past you needed SOAR-like capabilities to offer the investigation piece, now the agents cover that.
And the demand explains why everyone converges. Many orgs looking into AI SOC don't just want triage. They want to replace or consolidate their SIEM, MDR and SOAR costs. Every AI SOC conversation is a consolidation conversation.
The analyst firms see it too. Gartner even created a new category for it, called ISOC (Integrated Security Operations Center) Solutions. Forrester took a different route. In their latest XDR Wave they kept the XDR name but added AI agents and agentic systems as a separate evaluation criteria, and SIEM replacement went from experimental to reality. So basically, XDR with agents.
In my view, this is where many of today's players around SecOps will evolve.
Will it change the name? Not so sure. Gartner invented a new one, Forrester stuck with XDR. And even XDR failed to replace SIEM as a term.
How I see this playing out
Three types of implementations:
Platform play. This is where the ISOC category is getting stronger. The usual large players that offer everything.
Point solutions and decoupled SIEM. Many smaller solutions added to the stack, a combo of vendors plus build it yourself.
Existing stack plus MDR and/or AI SOC on top. For those that want minimal tech disruption. And here I think the demand is high: AI SOC with MDR, or MDR with AI SOC capabilities.
So, pure play or add-on?
You might be wondering what the advantages are of pure play vendors versus the ones offering AI SOC as an add-on capability.
Well, it depends what you're looking for. As in many markets, you'll always have niche pure play players versus the big ones that have a bit of everything. Some capabilities are there just to tick a box, others are full blown.
For pure play, I think the advantage is focus. They concentrate on that one thing, so they put a lot of effort into developing the autonomous investigation. For the vendors adding it as a capability, it might be a checkbox, or it might be a full blown capability. You have to check.
I won't share my view on which is better. Some might say I have bias here, so I won't say one beats the other. That's the whole point of SecOps Unpacked: we give you all the tools to evaluate, and you tell us which one you find better and why.
The plot twist I didn't predict
Vendors that were not AI SOC rebranded as AI SOC. And on the other side, AI SOC vendors rebranded as something else, like SIEM.
We track that too. One insight into how we map vendors: if a vendor was founded before Gen AI, so before 2022, they get classified as AI SOC as a capability add-on. That way you know the underlying tech is something else and there was a shift in technology. I think this is fair for everyone.
On top of all this, there are teams building AI SOC in house. Too early for success stories there.
Do we have too many vendors doing AI SOC?
Maybe. But compared to vendors doing security for AI, it's about 3 times less. So I wouldn't call it crowded just yet.
Where to go from here
On the SecOps Unpacked vendor tracker we have close to 140 vendors, all mapped to the Shift Map, so we can track the changes live year over year. Go check it out and let me know what you think.
The full mapping of all vendors per category will be released in our AI for SecOps Market Research coming in November.
SecOps Unpacked is built by practitioners for practitioners. If our articles, frameworks, and research have helped you make better decisions or solve real-world security challenges, we’d love your support.
By pledging, you’re helping us dedicate more time to independent research, in-depth content, and new resources that stay free for the community.
Thank you for being part of the journey.




