Company Overview
Cybereason is an AI-driven cybersecurity company headquartered in Boston, MA, USA, with its R&D center in Tel Aviv, Israel. Founded in 2012 by Lior Div and Yonatan Striem-Amit, Cybereason is a pioneer in extended detection and response (XDR), known for its proprietary "malop" (malicious operation) detection engine that correlates seemingly isolated security events into complete attack chains for automated response. In November 2025, Cybereason was acquired by LevelBlue.
Core Products
| Product | Category | Description |
|---|---|---|
| Cybereason XDR | Extended Detection & Response | Unified detection and response platform across endpoints, network, and cloud workloads |
| Cybereason EDR | Endpoint Detection & Response | Endpoint threat capture and automated analysis powered by the malop engine |
| Cybereason NGAV | Next-Gen Antivirus | AI-driven malware protection against known and unknown threats |
| Cybereason Ransomware Protection | Ransomware Defense | Behavioral analysis-driven real-time ransomware blocking and recovery |
| Cybereason MDR | Managed Detection & Response | 24/7 expert-led threat monitoring, investigation, and response services |
| Cybereason Deception | Deception Defense | Distributed traps and honeypot technologies for proactive attacker engagement |
Technical Strengths
| Capability | Description |
|---|---|
| Malop Engine | Correlates low-level alerts into complete Malicious Operations, presenting the full attack picture |
| Agentless Sensing | Endpoint sensors collect full telemetry data, detecting behavioral anomalies without signature dependency |
| AI Behavioral Analysis | Machine learning models distinguish normal from malicious behavior, detecting zero-day and fileless attacks |
| Automated Response Orchestration | Automatically executes isolation, process termination, and rollback upon malop detection |
| Nocturnus Threat Research | Professional security research team; first to discover vaccines for NotPetya and Bad Rabbit attacks |
Key Milestones
| Year | Event |
|---|---|
| 2012 | Founded by Lior Div and Yonatan Striem-Amit in Israel |
| 2014 | Completed $4.6M Series A funding; moved headquarters to Boston, MA |
| 2017 | Received $100M Series D from SoftBank; launched Malicious Life security podcast |
| 2019 | Reported "Operation Soft Cell" nation-state espionage campaign; raised $200M |
| 2021 | Completed $325M Series F round; cumulative funding exceeded $713M |
| 2025 | Acquired by LevelBlue, becoming part of their XDR security portfolio |
Market Position
Cybereason competes with the following major vendors in the XDR, EDR, and endpoint security markets:
- CrowdStrike: Direct competitor in EDR/XDR with the Falcon platform
- SentinelOne: Competes in AI-driven autonomous endpoint protection
- Microsoft Defender: Competes in endpoint protection and SMB markets
- Palo Alto Networks (Cortex XDR): Rival in XDR security analytics
- Trend Micro: Competes in endpoint protection and XDR domains
- Sophos: Competes in endpoint security and MDR services