Cybereason AI

AI-driven endpoint protection and threat hunting platform — correlates attacker operations, not just individual alerts.

Security & Safety Enterprise Has API
Researched · Published · Reviewed
RECATOOLS Score
7.3 / 10
Capability
8
Value for money
6
Ease of use
6
ASEAN readiness
6
API quality
5
Founded
2012
HQ
Boston, Massachusetts
Users
900+ enterprise customers
Launched
Jul 2026
Developer
Liberty Strategic Capital

Overview

Cybereason is an EDR/XDR vendor whose MalOp engine correlates individual security events into complete attack stories; founded in 2012 by Unit 8200 veterans, it was acquired by managed-security giant LevelBlue in November 2025.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Enterprise
Custom
Prevention-focused protection for SMEs
  • NGAV, AV & threat intel
  • Anti-ransomware
  • Endpoint controls & EDR
  • Optional MDR Essentials
Enterprise Advanced
Custom
Prevent, detect & respond for SMEs
  • Everything in Enterprise
  • MDR Essentials included
  • Extended response (XR)
Enterprise Complete
Custom
Full SOC toolkit for large enterprises
  • Everything in Advanced
  • DFIR & threat hunting
  • Cyber posture assessment
  • Mobile threat defense

Use cases

Correlating fragmented attack indicators into complete kill-chain narratives for incident response Proactive threat hunting using MITRE ATT&CK technique queries across endpoint telemetry Detecting multi-stage ransomware operations before encryption begins
Advertisement

ASEAN Perspective

Cybereason AI in Southeast Asia

ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).

RECATOOLS Verdict

Cybereason's MalOp engine — correlating scattered alerts into one attack story — is still a genuinely good idea, and the EDR/XDR technology remains respected, especially in Japan, its strongest market. But buy with eyes open: after a terminated Trustwave merger, a CEO exit amid investor litigation in March 2025, and repeated layoffs, Cybereason was acquired by MSSP giant LevelBlue in November 2025. That stabilises the finances but folds the product into a managed-services portfolio alongside Trustwave and Stroz Friedberg. Suits SOC-equipped enterprises and MDR customers; pricing is quote-based, tuning needs expertise, and it competes against CrowdStrike, SentinelOne and Microsoft. Ask hard questions about roadmap and support continuity under the new owner.

Independent AI-assisted assessment by RECATOOLS.

What people say

The last eighteen months at Cybereason read like a corporate thriller: a merger with Trustwave announced in November 2024, then terminated; CEO Eric Gan suing his own top investors over blocked financing plans, then resigning in March 2025; an emergency $120 million from SoftBank and Liberty Strategic Capital; and finally, in November 2025, acquisition by LevelBlue, the AT&T-cybersecurity spinout assembling the world's largest pure-play MSSP. Cybereason the independent company — once headed for a $5 billion IPO — is gone.

The technology deserved better. The MalOp engine remains one of the smarter ideas in endpoint security: instead of firing thousands of disconnected alerts, it correlates events across machines and time into a single narrative attack operation, which measurably cuts analyst triage. The behavioural detection is well regarded, and Cybereason is among the leading security providers in Japan, its strongest market.

Under LevelBlue, the product folds into a managed-services portfolio alongside Trustwave and forensics firm Stroz Friedberg, with Cybereason's researchers merged into the SpiderLabs team. For MDR customers that's arguably good news — more scale, more forensics depth. For customers who bought the EDR/XDR platform as a product, it raises the usual post-acquisition questions: roadmap continuity, support quality, contract terms at renewal. Three rounds of layoffs between 2022 and 2024 had already thinned the bench.

Evaluate it now as a LevelBlue capability, not a standalone vendor. Get written commitments on the product roadmap, check local partner support in your region, and benchmark against CrowdStrike, SentinelOne and Microsoft Defender — all of which offer more certainty about who owns them next year.

Summary of public user & expert reviews, compiled by RECATOOLS.

Notable facts

  • Cybereason's three founders all served in Israel's Unit 8200, the elite intelligence and cyber unit — making it one of the highest-pedigree cybersecurity teams in the industry.
  • The Malop engine can correlate an attack operation spread across 100 different endpoints over 72 hours and present it as a single, unified attack story.
  • Cybereason's AI processes 9 million endpoint events per second across its customer base — more real-time security telemetry than any national intelligence agency processes.

Frequently asked questions

What is a Malop?
A Malicious Operation — Cybereason's AI-assembled attack narrative that correlates related security events into a complete attack story.
How does Cybereason compare to CrowdStrike?
Both are leading EDR platforms. Cybereason differentiates with attack operation correlation; CrowdStrike has a larger threat intelligence database.
Does Cybereason protect cloud workloads?
Yes. Cloud workload protection for AWS, Azure, and GCP is available alongside endpoint protection.
What is the MITRE ATT&CK integration?
Cybereason maps detected behaviours to ATT&CK techniques, enabling standardised threat hunting and reporting.
Is Cybereason free?
No. Enterprise pricing only with free trial evaluation.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Cybereason AI's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Cybereason AI unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Cybereason AI directly →

Spotted something out of date? Suggest an update →

Advertisement