When Your SOC Sleeps, Israelis Are Hunting

The American SOC has a math problem. Alert volume rises. Headcount does not. The companies most aggressively re-engineering that math — Cybereason, Hunters, Dream, Torq, Coralogix, Cyera, Sygnia — are Israeli.
The American security operations center has a math problem. Alert volume keeps rising. Headcount does not. Mean time to detect a real breach inside a Fortune 500 SOC still measures in days, not minutes, despite a decade of SIEM, SOAR, EDR, XDR, MDR, and every other three-letter acronym sold against the gap.
The companies most aggressively re-engineering that math are Israeli.
The Israeli SOC stack
Cybereason — XDR platform founded in 2012 by Lior Div, Yossi Naar, and Yonatan Striem-Amit, all Unit 8200 alumni. ~$850 million total funding (SoftBank, Liberty Strategic Capital, Lockheed Martin Ventures). Restructured in 2023; continues as a focused XDR vendor with strength in nation-state threat detection.
Hunters — Next-generation SIEM founded in 2018 in Tel Aviv by Uri May and Tomer Levy. Backers include Stripes, YL Ventures, M12 (Microsoft), Bessemer, and Snowflake Ventures. Widely regarded as a credible structural challenger to Splunk and Microsoft Sentinel.
Dream — AI-native SOC platform founded by Shalev Hulio and Gil Dolev. Reported $100 million Series A from Group 42 and Thiel Capital in 2024. Targeting national-security-grade SOC automation for governments and critical infrastructure.
Torq — Hyperautomation and SOAR platform. Reported $122 million Series C in 2024 at unicorn valuation. Founded by ex-Luminate (acquired by Symantec) veterans.
Coralogix — Observability with embedded security analytics. ~$142 million through Series E.
Cyera — Data security posture management. Reported $300 million Series D in 2025 at $1.4 billion valuation.
Sygnia — Incident response, majority-acquired by Temasek in 2018, later sold to ION Group. One of the highest-end IR practices in the world for nation-state-grade breaches — competing directly with Mandiant and CrowdStrike Services.
What the math actually changes
Three structural shifts: telemetry pricing collapses (Hunters and Torq both architected against Splunk pricing); detection content shifts from rules to behavior (Cybereason, Dream, and Hunters built on behavior graphs rather than rule libraries); and AI agents are entering the SOC (Dream is the most explicit, but Torq, Hunters, and Cybereason all shipped AI-analyst workflows in 2025).
Why Israel, again
Unit 8200's offensive divisions ran one of the largest SIGINT collection programs per capita through the 2010s. The defensive translation of that telemetry expertise — what to retain, how to correlate, where the signal lives — moved into the private sector at scale starting around 2015. Cybereason, Hunters, and Torq are the leading edges of that translation. The American SOC will keep buying from them.
Related — Israeli Cybersecurity
- The Israeli AI Economy: The Complete Map
- The Israeli Cyber 50: Q1 2026 Ranking
- Israel Just Cashed $57 Billion in Cyber. What Comes Next?
- Unit 8200: The $50 Billion Founder Factory
- Check Point: The Longest-Tenured Israeli Nasdaq Listing
- Israel's Red Teams Hit You Before the Hackers Do
- America's Login Screen Is an Israeli Product
- Israeli Code Locks America's Cloud and AI Stack
- Spyware Pays in Billions — and Israel Owns the Market
- The Mossad Cyber Pipeline
- Shalev Hulio
- Israeli Cybersecurity in 2026: The Olam Guide

