
Nebulock raises $25M to expand hunt-first autonomous threat hunting platform
Published by AINave Editorial • Reviewed by Ramit
Nebulock Inc. has raised $25 million in Series A funding to expand its autonomous, vendor-agnostic threat hunting platform, which turns enterprise telemetry into a behavioral system of record to detect hidden threats that traditional tools miss.
What happened
Nebulock announced a $25 million Series A round led by FirstMark Capital, with participation from Bain Capital Ventures, Decibel Partners, Zetta Venture Partners, and Step Function Ventures. The company has now raised about $33.5 million total after an $8.5 million seed round in July 2025 Techmeme.
The platform has run more than 300 million agentic investigations and produced over 4,000 high-confidence findings since its public launch less than a year ago. Customers include Cribl Inc., HealthEdge Software Inc., and Bain Capital LP across financial services, healthcare, and technology.
Alongside the funding, Nebulock shipped new tooling. Insider-risk consolidation pulls a person's or an AI agent's scattered accounts, identities, and hosts into a single entity for monitoring. Cross-signal correlation connects unrelated signals from endpoint, identity, and cloud into one detection with a full evidence chain. A Command Center view tells teams where to hunt, what to investigate, and which coverage gaps matter most, including those buried in existing SIEM deployments.
Nebulock calls hidden threats "green flags" -- malicious activity that looks routine on the surface, such as an attacker using valid stolen credentials or a sanctioned AI agent doing something unauthorized. When the OpenClaw vulnerability went viral earlier this year, the company logged more than 50,000 related events across 40% of its customer base within a week and issued detections before those events turned into incidents.
Why AI builders should care
Enterprise AI adoption is creating new attack surfaces. AI agents, whether sanctioned or rogue, can operate with valid credentials and authorized access, making them hard to detect with rule-based tools. Nebulock's approach of treating telemetry as a behavioral system of record is designed to catch these scenarios by reasoning across systems rather than chasing individual alerts.
For security teams building or deploying AI products, Nebulock offers a vendor-agnostic layer that integrates with existing endpoint, identity, cloud, network, and SaaS telemetry. This reduces the need to add more point tools or hire more analysts. As founder and CEO Damien Lewke put it, "Expert threat hunting should not demand endless headcount, months of integration, or a pile of tools that never talk to each other" SiliconANGLE.
Practical implications
Teams can use Nebulock to fill coverage gaps in their SIEM deployments. The Command Center prioritizes hunts based on risk, and the insider-risk consolidation feature is particularly useful for monitoring both human users and AI agents. Cross-signal correlation with full evidence chains reduces investigation time and false positives.
The platform's autonomous nature means it can run continuous hunts without manual intervention, which is valuable for lean security teams managing complex environments. The vendor-agnostic design also avoids lock-in, allowing teams to keep their existing telemetry sources.
Caveats
Nebulock's metrics are self-reported and the platform has been publicly available for less than a year, so independent validation is limited. The "green flags" concept is proprietary and may not cover all attack types. Pricing and deployment details are not fully disclosed in the announcement. The funding will be used to scale engineering and expand coverage, but product maturity is still evolving. Teams evaluating Nebulock should test it against their own threat scenarios and compare with other autonomous hunting options.
Sources
- Nebulock raises $25M to expand hunt-first security platform - SiliconANGLE
- Duncan Riley's Profile | SiliconANGLE Journalist | Muck Rack
- Techmeme: Nebulock, which helps security teams proactively ...
- Nebulock: Elite Agentic Threat Hunting for All - Decibel
- Nebulock - 2025 Company Profile & Team - Tracxn
- Proactive by Default: How Nebulock Rethinks Threat Hunting
- Nebulock Raises $25 Million Series A to Bring a Hunt-First Context to the Enterprise
- Nebulock Launches to Redefine Threat Hunting with AI-Powered ...
- Nebulock | AI Threat Hunting & Detection Platform



















