Skip to main content

An AI SOC built on the open agent platform

Cotool is AI SOC without the black box. Agents triage, investigate, and resolve every alert, and hunt for what your detections miss. You control the models, tools, instructions, and every action they take.

Trusted by security teams at

95% faster investigation

Agents pick up every alert the moment it lands, gather context across your tools, and close or escalate it with the evidence attached.

Coverage that compounds

Agents hunt from fresh intel and your threat model, turn what they find into detections, and tune out the noise, so coverage grows instead of drifting.

80% lower SIEM ingest costs

Agents query your tools and data lake directly, so you only send the SIEM what your detections need, not everything you might want to investigate.

Cotool vs. the alternatives

Most teams choose between black-box, legacy AI SOC and a harness they must build and maintain themselves. Cotool gives you the control of the second without the upkeep.

Model choice

Traditional AI SOCOpaque, black box
CotoolAll frontier and open-weight models, configurable per agent, backed by public security evaluations
Build your ownA single model family, or multi-provider support and failover you build yourself

Availability

Traditional AI SOCYou wait on the vendor
CotoolRerouted automatically, with 100% task completion on routed defensive workloads
Build your ownMulti-provider failover and harness support, on call for infra and reliability

Agents and customizability

Traditional AI SOCA fixed number and configuration
CotoolUnlimited agents with sane defaults out of the box, managed in the UI or in Git
Build your ownBuild everything

Integrations

Traditional AI SOCBuilt-in, with limited flexibility
CotoolOver 100 built-in integrations, plus custom MCP and CLI tools
Build your ownBuild everything

Extended functionality

Traditional AI SOCProprietary and opaque
CotoolCommon standards like skills and agent filesystems
Build your ownBuild everything

Log storage

Traditional AI SOCLegacy SIEM
CotoolBuilt-in pipelines to any legacy SIEM or data lake, or use Cotool's SIEM
Build your ownIntegrate and optimize it yourself

Everything your team does, run by agents you control

Open on both ends

Any model, including your own, and any tool, including your own MCP server. Nothing is locked in.

Agents that get better over time

Analyst feedback becomes instruction changes you review, and Cotool suggests improvements on its own.

A SOC you can engineer

Agents and skills live in Git as YAML, with pull-request review and rollback, not click-ops.

Extended Features

Sandboxed compute

Each agent gets an isolated Linux sandbox with cloud CLIs ready to go, so it parses logs and decodes payloads itself. Outbound traffic is restricted per agent.

Persistent workspace

Files and working state carry over between runs, and agents hand back finished deliverables: reports, PDFs, and spreadsheets.

Global memory

Every run teaches every agent. Cotool keeps what agents learn about your environment in shared files you can inspect, so no one relearns it.

Model choice

Anthropic, OpenAI, Google, xAI, open-weight models, or your own endpoint, set per agent. Frontier models for hard cases, cheaper ones for volume.

Multi-agent support

Agents hand work to investigator and reviewer subagents, or call other agents as tools, for parallel investigations and built-in peer review.

Evals on every run

An AI judge grades every run against your acceptance criteria and flags a broken integration the moment it fails, not weeks later.

Skills

Versioned packages of runbooks, reference docs, and scripts that every agent can use. Tribal knowledge becomes an auditable asset.

Human-in-the-loop

State-changing actions can require approval in the app or Slack, and one click makes an agent read-only. Run autonomously from day one, safely.

GitOps

Agents and skills sync from GitHub as YAML, with every change versioned for review and rollback. Import existing workflows from Tines.

Getting Started

01

Connect your alert sources

Native integrations, webhooks, email, Jira, Linear, or the API.

02

Start with built-in agents

Triage and investigation work out of the box.

03

Make them yours

Edit the prompt, attach your playbooks as skills, or move agents into Git.

04

Add Cotool as your SIEM when you're ready

Store logs, run detections as code, and close the loop from alert back to detection.

SIEM
“Cotool blew me out of the water — it saves us meaningful time every single week, and without it, we'd immediately have to hire more people.”
Jake Skinner
Jake Skinner
Senior Security Engineer
“Other AI SOC tools felt pretty black box. Cotool gives us control over the system prompt, how we tune it, what it connects to. I like being that close to the configuration of the agent.”
Antoinette Stevens
Antoinette Stevens
Principal Security Engineer
Case study
The Security Infrastructure Powering EliseAI's Rapid Scale

FAQ

Do I have to replace my SIEM?
No. Cotool investigates alerts from any source, whether or not Cotool stores the logs.
Can Cotool triage alerts automatically?
Yes. Route alerts from any source to a response agent, and it investigates each one as it arrives, gathers context across your tools, and closes or escalates it with the evidence attached.
Which models can I use?
Anthropic, OpenAI, and open-weight models, chosen per agent, with the same data residency and zero-data-retention guarantees. Cotool routes and fails over across providers, or you can bring your own keys.
How do I know which model to use?
Start with the model Cotool recommends for the agent's job, based on BlueBench, our public benchmark on real intrusions. Every run is evaluated, so if you switch models you can see whether it helped.Research
What if an agent gets it wrong?
Every verdict shows the evidence and reasoning behind it, and you can reopen any investigation and ask follow-up questions. Every run is evaluated so mistakes show up in the numbers. Feedback on a run feeds suggested fixes to the agent.
What happens when a model refuses security work?
Frontier providers' safety filters sometimes refuse legitimate defensive work, because an investigation can look like an attack. When that happens, or a provider goes down, Cotool Router moves the task to another provider or an open-weight model without interrupting the agent.Introducing Cotool Router
Can I investigate past incidents?
Yes. Ask questions in chat, and Cotool searches across your connected tools and Cotool logs. Turn any investigation into an always-on agent with one click.
What can Cotool do besides triage?
Agents hunt from threat intel and a threat model of your environment, and propose detections for what they find. Detections that run in Cotool tune themselves: each false-positive or benign disposition feeds autotuning, which tests a change against the current version before applying it or sending it for review.

Attackers are scaling with tokens. Your SOC can too.

Book a demo