Nebulock, Inc.’s cover photo
Nebulock, Inc.

Nebulock, Inc.

Computer and Network Security

Brookline, Massachusetts 1,390 followers

Agentic threat hunting for everyone. Always-on, autonomous behavioral detections.

About us

Nebulock is the first agentic threat hunting platform; autonomously surfacing behaviors, not just IOCs, from your existing data. Nebulock acts like a new teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through your telemetry, and learns from your environment. Whether you’re a two-person SOC or a global enterprise, we scale your threat hunting—and give your team superpowers. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings—often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry—identifying the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections—automatically. No new agents
No alert regurgitation No workflow disruption Just high-fidelity, explainable findings—delivered directly to your SIEM, API, or Slack.

Website
http://nebulock.io
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Brookline, Massachusetts
Type
Privately Held

Locations

Employees at Nebulock, Inc.

Updates

  • Nebulock, Inc. reposted this

    View profile for Stuart Mitchell

    Founder and CEO @ Hampton North

    "AI has lowered the barrier to entry for sophisticated attacks..." "The line between nation state hacker and script kiddy has become blended..." Last week, Conor Sherman and I were fortunate enough to have Damien Lewke, Founder and CEO of Nebulock, Inc. on the Zero Signal Podcast. We talked all things Threat Hunting in the new AI led world... If you haven't been following Damien, you absolutely should be. Damien founded Nebulock to democratize threat hunting, making it accessible to all enterprises, not just those who can afford it or have the requisite talent in-house. This is a company and founder I'm incredibly bullish on. Links to the episode in the comments. Like, subscribe, tell your friends, and as we round out season one of Zero Signal, we truly welcome all feedback.

  • We’re excited to share that Nebulock, Inc. has been nominated for Emerging Company of the Year in Cyber Security at the #NEVYs25! New England Venture Capital Association For this year's #NEVYsthe13th event, we'll be joining a group of 80+ scary-good nominees who brought terrifying feats of innovation to 2025. We're proud to be part of this esteemed group in Tech, Healthcare, and Tough Tech! Check out the full nominee list here: https://bit.ly/nevy25 #NEVCA #Innovation

    • No alternative text description for this image
  • Nebulock, Inc. reposted this

    View profile for Damien Lewke

    Founder & CEO @ Nebulock | MIT CSAIL | Threat Hunting | Marathoner

    If attackers now get agency, defenders need it too. Anthropic’s latest report on disrupting the first-ever AI-orchestrated cyber espionage campaign is immutable proof of the speed and scale of adversaries today. My initial takes: 1. Insider threats aren’t just humans anymore, they’re the agents we use. If a model can follow complex instructions, write tooling, chain actions, and make decisions autonomously…it’s effectively an internal operator. Most organizations aren’t prepared for that shift. 2. The barrier to launching sophisticated attacks is now lower than the barrier to detecting them. Agentic models can do the work of entire hacker teams: analyze infrastructure, generate exploits, iterate, and operate at scale. Meanwhile, most defenders still wait for alerts that show up too late. 3. Defense can’t be reactive when the adversary moves first…and moves continuously. Attackers now get 24/7 initiative…they don’t pause, don’t fatigue and iterate. This is exactly why we built Nebulock, Inc. We can’t defend against autonomous offense with reactive detections. Modern cyber defense requires continuous, proactive visibility to surface & respond to these new threat vectors. That’s what vibe hunting is: always-on, hypothesis-driven agents that hunt behaviors, surface weak signals, and turn them into actionable detections before they become an incident. Join the hunt.

    • No alternative text description for this image
  • A new era of threat hunting starts today. 🏹 Introducing Vibe Hunting: where human intuition meets machine reasoning. Whether you're a seasoned threat hunter or aspire to have a dedicated threat hunter on your team, Vibe Hunting allows you to ask natural language questions and get clear, context-driven outcomes that guide your next move. No query languages. No tool juggling. Just insight. Vibe Hunting is available to customers, but you can take it for a spin in our playground: https://lnkd.in/gP9sZuMW Learn more on our blog: https://lnkd.in/gUKD_yjV

    • No alternative text description for this image
  • 🍎 macOS has long been underrepresented in threat detection with organizations relying on limited telemetry or propriety enterprise tools. Even with the community-driven advances via Sigma, the currently supported macOS types for Sigma rule coverage is still relatively low compared to Windows and Linux. This current Sigma gap leaves defenders blind to almost 85% of the MITRE ATT&CK techniques applicable to macOS. We've developed coreSigma, a macOS endpoint telemetry collection, detection, and analysis app built with the primary goal of extending Sigma's capabilities for macOS ESF and UL logs. Read the full post from Lead Detection Engineer Eric Brown to learn how coreSigma expands visibility and ways take a more proactive approach to macOS threat detection and response: https://lnkd.in/gRAm4fpN

    • No alternative text description for this image
  • Something we forget as we implement AI is recognizing the value of the human and our ability to reason. If there’s an attacker that can automate sophisticated kill chains at speed, what are the tell-tale signs of automation? Speed, time of day, verbiage, etc. To counter elements like compressed timelines, you need to: - use data you already have to create real-time detections - go one step further with continuous hunting, where every hunt is event-driven and every action is transparent Listen to Founder & CEO Damien Lewke on this week's episode of Risky Business Media on countering adversary use of AI with AI to truly know what's happening in real-time: https://lnkd.in/gbrHD7sQ

    • No alternative text description for this image
  • Nebulock, Inc. reposted this

    Day 6 of #Ones2Watch is Nebulock, Inc. 🔍🧠 Nebulock, Inc. is a cybersecurity startup that makes what’s invisible, visible and automates real-time threat hunting so SOCs stop sorting noise from nuance and starts anticipating the next move. From the very first line of code, they knew detection can’t wait until alerts pile up and adversaries move sideways, abuse credentials, and probe quietly. Their mission is to surface those patterns automatically, with minimal noise, maximum context, and disciplined efficiency. 💡 Why They Rock: Founded by Damien Lewkeand and a team of seasoned detection engineers, Nebulock emerged from stealth with $8.5 million in funding led by Bain Capital Ventures (BCV). Their approach is to rethink the detection stack, plug into your existing EDR, IAM, and log pipelines, then enable their autonomous AI agents to baseline, hunt, and stress-test your environment continuously. What makes it stand out is how seamlessly it fuses data science with human tradecraft. 🧩🤔 What Sets Them Apart: Their real strength lies in its design discipline. Its AI agents operate in parallel threads and catch lateral movement, insider missteps, and credential abuse in near real time. Each detection is context-aware, validated, and built to highlight signal, not spectacle. Investigations are no longer reactive hunts through endless noise, thankfully, and are precise, explainable, and fast enough to keep pace with the threat. Nebulock reminds us that in detection engineering, progress isn’t about making more noise but rather understanding the signals. We're evolving, and Nebulock is clearly leading in this space. That’s why they’re today’s #Ones2Watch. 💙 #Ones2Watch #Cybersecurity #ThreatHunting #AIsecurity #DetectionEngineering #InsiderThreat #AutonomousSecurity #Infosec #SentinelBlue

    • No alternative text description for this image
  • Great week in Tennessee with the team!

    View profile for Damien Lewke

    Founder & CEO @ Nebulock | MIT CSAIL | Threat Hunting | Marathoner

    Great week with team Nebulock in Tennessee! From building agents to hack (and hunt)athons, we’re excited to drive towards our goal of delivering world-class threat hunting to everyone (#vibehunting). We’ve been shipping some great new features (and yes, our UI has a dark mode enabled) Grateful for this team P.S. we’re hiring! Please DM me if you’re interested in building the future of threat hunting …stay tuned… Emily DannGabe HonigsbergJustin S.Alexandre SfezEric BrownJoshua HinesRyan ZecJustin CarlsonConnor WhelanRon CahlonSam Nguyen

    • No alternative text description for this image
  • If you're in Boston October 1, come join us and our friends over at Natoma for a great evening of demos, discussions and dinner!

    View profile for Damien Lewke

    Founder & CEO @ Nebulock | MIT CSAIL | Threat Hunting | Marathoner

    Back by popular demand...Nebulock, Natoma and Step Function are teaming up for the fall security speakeasy! If you're interested in Boston's growing cybersecurity ecosystem, want to see some great tech (I'm biased), and meet some amazing practitioners, please register using the link in comments.

    • No alternative text description for this image

Similar pages

Funding