Cybereason AI
AI-driven endpoint protection and threat hunting platform — correlates attacker operations, not just individual alerts.
Overview
Cybereason is an EDR/XDR vendor whose MalOp engine correlates individual security events into complete attack stories; founded in 2012 by Unit 8200 veterans, it was acquired by managed-security giant LevelBlue in November 2025.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- NGAV, AV & threat intel
- Anti-ransomware
- Endpoint controls & EDR
- Optional MDR Essentials
- Everything in Enterprise
- MDR Essentials included
- Extended response (XR)
- Everything in Advanced
- DFIR & threat hunting
- Cyber posture assessment
- Mobile threat defense
Use cases
ASEAN Perspective
Cybereason AI in Southeast Asia
ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).
Cybereason's MalOp engine — correlating scattered alerts into one attack story — is still a genuinely good idea, and the EDR/XDR technology remains respected, especially in Japan, its strongest market. But buy with eyes open: after a terminated Trustwave merger, a CEO exit amid investor litigation in March 2025, and repeated layoffs, Cybereason was acquired by MSSP giant LevelBlue in November 2025. That stabilises the finances but folds the product into a managed-services portfolio alongside Trustwave and Stroz Friedberg. Suits SOC-equipped enterprises and MDR customers; pricing is quote-based, tuning needs expertise, and it competes against CrowdStrike, SentinelOne and Microsoft. Ask hard questions about roadmap and support continuity under the new owner.
What people say
The last eighteen months at Cybereason read like a corporate thriller: a merger with Trustwave announced in November 2024, then terminated; CEO Eric Gan suing his own top investors over blocked financing plans, then resigning in March 2025; an emergency $120 million from SoftBank and Liberty Strategic Capital; and finally, in November 2025, acquisition by LevelBlue, the AT&T-cybersecurity spinout assembling the world's largest pure-play MSSP. Cybereason the independent company — once headed for a $5 billion IPO — is gone.
The technology deserved better. The MalOp engine remains one of the smarter ideas in endpoint security: instead of firing thousands of disconnected alerts, it correlates events across machines and time into a single narrative attack operation, which measurably cuts analyst triage. The behavioural detection is well regarded, and Cybereason is among the leading security providers in Japan, its strongest market.
Under LevelBlue, the product folds into a managed-services portfolio alongside Trustwave and forensics firm Stroz Friedberg, with Cybereason's researchers merged into the SpiderLabs team. For MDR customers that's arguably good news — more scale, more forensics depth. For customers who bought the EDR/XDR platform as a product, it raises the usual post-acquisition questions: roadmap continuity, support quality, contract terms at renewal. Three rounds of layoffs between 2022 and 2024 had already thinned the bench.
Evaluate it now as a LevelBlue capability, not a standalone vendor. Get written commitments on the product roadmap, check local partner support in your region, and benchmark against CrowdStrike, SentinelOne and Microsoft Defender — all of which offer more certainty about who owns them next year.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- Cybereason's three founders all served in Israel's Unit 8200, the elite intelligence and cyber unit — making it one of the highest-pedigree cybersecurity teams in the industry.
- The Malop engine can correlate an attack operation spread across 100 different endpoints over 72 hours and present it as a single, unified attack story.
- Cybereason's AI processes 9 million endpoint events per second across its customer base — more real-time security telemetry than any national intelligence agency processes.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including Cybereason AI's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Cybereason AI unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Cybereason AI directly →
Spotted something out of date? Suggest an update →
Cybereason AI in the news
Cybersecurity
AWS Confirms First Production Prompt-Injection Compromise in Bedrock Agents — Enterprise C...
Cybersecurity
EchoLeak: Zero-Click Prompt Injection in Microsoft 365 Copilot Quietly Exfiltrates Enterpr...
Cybersecurity
Hackers Reach Anthropic's Restricted Mythos Model Through a Vendor Environment as FSB Call...
More in Security & Safety