Home
Tech Grid
News Room
Interviews
Think Stack
Articles
  • AI

Nebulock Raises $25M Series A for Hunt-First Contextual Security Platform


Nebulock Raises $25M Series A for Hunt-First Contextual Security Platform
  • by: Business Wire
  • |
  • June 29, 2026

Nebulock, the AI-native contextual security platform, today announced it has raised $25 million in Series A financing led by FirstMark, with participation from existing investors Bain Capital Ventures, Decibel, Zetta Venture Partners, and Step Function. The new financing comes less than a year after Nebulock emerged from stealth, underscoring both the company's rapid momentum and a fast-evolving threat landscape. In that time, Nebulock has earned the trust of Fortune 500 enterprises, leading organizations in highly targeted sectors like financial services and healthcare, and fast-growing companies.

Quick Intel

  • Nebulock raises $25M Series A led by FirstMark, less than a year after stealth.

  • Performed 300M+ agentic investigations generating 4,000+ high-confidence findings.

  • Uncovered threats including undetected remote actor, insider copying source code, and malicious browser extensions.

  • Observed 50,000+ OpenClaw-related events across 40% of customer base within a week.

  • Founded by former CrowdStrike, Palo Alto Networks, and Arctic Wolf leaders.

  • 2026 Verizon DBIR found threat actors used AI across 15-50 attack techniques.

Real-World Impact and Threat Detection

Nebulock's platform has already demonstrated significant real-world impact, performing more than 300 million agentic investigations and generating over 4,000 high-confidence findings to prevent incidents. Examples of what Nebulock has uncovered in customer environments include a malicious remote actor operating undetected for months at a digital retailer, an insider copying 748 source code files to USB at a Fortune 1000 retailer, credentials exposed in CLI arguments at a healthcare technology company, and a malicious browser extension downloaded at a Fortune 500 food and beverage company.

Addressing Agentic Insider Threats

The company is also on the front lines of a new category of "agentic" insider threats driven by the rapid adoption of AI tools in the workplace. When OpenClaw went viral earlier this year, employees across multiple organizations began downloading and experimenting with it, often bypassing corporate controls. Within a week, Nebulock observed more than 50,000 related events across 40% of its customer base and rapidly deployed detections across all environments, proactively preventing incidents tied to this emerging form of shadow AI risk.

Customer Perspective

Myke Lyons, CISO of Cribl, stated: "Security teams need to understand not just what looks suspicious, but what looks ordinary for the wrong reasons. Bringing on Nebulock changed the math on how quickly we can detect and act. When threat intel hits our feeds, the window between awareness and evidence used to be the hardest part to manage. Now that the hunt is run, we have a clear read on exposure and can remediate before our other tools send us an alert. That shift from assumption to evidence is what a proactive posture actually looks like."

The Challenge of AI-Enabled Attacks

As attackers increasingly use AI to mimic legitimate users, blend into normal workflows, and operate with valid credentials, the challenge for defenders is no longer just finding red flags. It is about identifying the green flags that should look fine, but are not. According to the 2026 Verizon Data Breach Investigations Report, the typical threat actor researched or used AI assistance in 15 different documented techniques, while more advanced actors are already operationalizing AI across 40 to 50 different attack vectors. Nebulock addresses that challenge by correlating telemetry across endpoint, identity, cloud, network, and SaaS silos to surface subtle behavioral patterns that legacy alerting and black-box anomaly scoring often miss.

Founder and Investor Perspectives

Damien Lewke, founder and CEO of Nebulock, stated: "AI is changing both sides of the security equation. The attacker has become more agentic faster than defenders have become proactive. Breaches used to take months; now they take tokens. That's why Nebulock was built to help security teams move beyond reactive-by-default workflows and toward context-rich, always-on protection that shows them what their stack can't see. Over time, our vision is much bigger than agentic threat hunting alone—we want to do for SIEM what EDR did for endpoint."

David Waltcher, Partner at FirstMark, added: "The entire security market is at an inflection point. From our earliest conversations, it was clear that Damien is the definition of founder market fit, combining deep domain expertise with a rare ability to translate that insight into product. As attacks become faster, more credentialed, and more autonomous, enterprises need a new security layer built around context, behavior, and continuous reasoning."

About Nebulock

Nebulock is an AI-native contextual security platform that helps security teams proactively find, convict, and attribute threats across your security stack. Backed by top venture capital firms including Bain Capital Ventures, FirstMark, and Decibel, Nebulock combines contextual security analytics, a behavioral graph, and agentic hunting workflows across endpoint, identity, cloud, network, and SaaS environments to help enterprises uncover threats others miss entirely.

  • CybersecurityThreat HuntingAgentic AIEnterprise Security
News Disclaimer
Want to reach B2B tech decision-makers through TechIntelPro? Get our Media Kit
  • Share
Enterprise Tech News