An AI SOC built on the open agent platform
Cotool is AI SOC without the black box. Agents triage, investigate, and resolve every alert, and hunt for what your detections miss. You control the models, tools, instructions, and every action they take.
95% faster investigation
Agents pick up every alert the moment it lands, gather context across your tools, and close or escalate it with the evidence attached.
Coverage that compounds
Agents hunt from fresh intel and your threat model, turn what they find into detections, and tune out the noise, so coverage grows instead of drifting.
80% lower SIEM ingest costs
Agents query your tools and data lake directly, so you only send the SIEM what your detections need, not everything you might want to investigate.
Cotool vs. the alternatives
Most teams choose between black-box, legacy AI SOC and a harness they must build and maintain themselves. Cotool gives you the control of the second without the upkeep.
Model choice
Availability
Agents and customizability
Integrations
Extended functionality
Log storage
| Traditional AI SOC | Cotool | Build your own | |
|---|---|---|---|
| Model choice | Opaque, black box | All frontier and open-weight models, configurable per agent, backed by public security evaluations | A single model family, or multi-provider support and failover you build yourself |
| Availability | You wait on the vendor | Rerouted automatically, with 100% task completion on routed defensive workloads | Multi-provider failover and harness support, on call for infra and reliability |
| Agents and customizability | A fixed number and configuration | Unlimited agents with sane defaults out of the box, managed in the UI or in Git | Build everything |
| Integrations | Built-in, with limited flexibility | Over 100 built-in integrations, plus custom MCP and CLI tools | Build everything |
| Extended functionality | Proprietary and opaque | Common standards like skills and agent filesystems | Build everything |
| Log storage | Legacy SIEM | Built-in pipelines to any legacy SIEM or data lake, or use Cotool's SIEM | Integrate and optimize it yourself |
Everything your team does, run by agents you control
Open on both ends
Any model, including your own, and any tool, including your own MCP server. Nothing is locked in.
Agents that get better over time
Analyst feedback becomes instruction changes you review, and Cotool suggests improvements on its own.
A SOC you can engineer
Agents and skills live in Git as YAML, with pull-request review and rollback, not click-ops.
Extended Features
Sandboxed compute
Each agent gets an isolated Linux sandbox with cloud CLIs ready to go, so it parses logs and decodes payloads itself. Outbound traffic is restricted per agent.
Persistent workspace
Files and working state carry over between runs, and agents hand back finished deliverables: reports, PDFs, and spreadsheets.
Global memory
Every run teaches every agent. Cotool keeps what agents learn about your environment in shared files you can inspect, so no one relearns it.
Model choice
Anthropic, OpenAI, Google, xAI, open-weight models, or your own endpoint, set per agent. Frontier models for hard cases, cheaper ones for volume.
Multi-agent support
Agents hand work to investigator and reviewer subagents, or call other agents as tools, for parallel investigations and built-in peer review.
Evals on every run
An AI judge grades every run against your acceptance criteria and flags a broken integration the moment it fails, not weeks later.
Skills
Versioned packages of runbooks, reference docs, and scripts that every agent can use. Tribal knowledge becomes an auditable asset.
Human-in-the-loop
State-changing actions can require approval in the app or Slack, and one click makes an agent read-only. Run autonomously from day one, safely.
GitOps
Agents and skills sync from GitHub as YAML, with every change versioned for review and rollback. Import existing workflows from Tines.
Getting Started
Connect your alert sources
Native integrations, webhooks, email, Jira, Linear, or the API.
Start with built-in agents
Triage and investigation work out of the box.
Make them yours
Edit the prompt, attach your playbooks as skills, or move agents into Git.
Add Cotool as your SIEM when you're ready
Store logs, run detections as code, and close the loop from alert back to detection.
SIEM“Cotool blew me out of the water — it saves us meaningful time every single week, and without it, we'd immediately have to hire more people.”

“Other AI SOC tools felt pretty black box. Cotool gives us control over the system prompt, how we tune it, what it connects to. I like being that close to the configuration of the agent.”

FAQ
- Do I have to replace my SIEM?
- No. Cotool investigates alerts from any source, whether or not Cotool stores the logs.
- Can Cotool triage alerts automatically?
- Yes. Route alerts from any source to a response agent, and it investigates each one as it arrives, gathers context across your tools, and closes or escalates it with the evidence attached.
- Which models can I use?
- Anthropic, OpenAI, and open-weight models, chosen per agent, with the same data residency and zero-data-retention guarantees. Cotool routes and fails over across providers, or you can bring your own keys.
- How do I know which model to use?
- Start with the model Cotool recommends for the agent's job, based on BlueBench, our public benchmark on real intrusions. Every run is evaluated, so if you switch models you can see whether it helped.Research
- What if an agent gets it wrong?
- Every verdict shows the evidence and reasoning behind it, and you can reopen any investigation and ask follow-up questions. Every run is evaluated so mistakes show up in the numbers. Feedback on a run feeds suggested fixes to the agent.
- What happens when a model refuses security work?
- Frontier providers' safety filters sometimes refuse legitimate defensive work, because an investigation can look like an attack. When that happens, or a provider goes down, Cotool Router moves the task to another provider or an open-weight model without interrupting the agent.Introducing Cotool Router
- Can I investigate past incidents?
- Yes. Ask questions in chat, and Cotool searches across your connected tools and Cotool logs. Turn any investigation into an always-on agent with one click.
- What can Cotool do besides triage?
- Agents hunt from threat intel and a threat model of your environment, and propose detections for what they find. Detections that run in Cotool tune themselves: each false-positive or benign disposition feeds autotuning, which tests a change against the current version before applying it or sending it for review.
Attackers are scaling with tokens. Your SOC can too.
Book a demo