Dossier · Private startup · 1 independent source

Hunters

Cybersecurity Dual-Use Technology Priority Signal Founded 2018

Last updated: Jul 31, 2026

Hunters is a private Israeli cybersecurity company building a next-generation SIEM and SOC platform that automates security telemetry normalization, detection, alert triage, investigation, and response. Its current product positioning combines an open security data lake with human-curated detection expertise and AI-assisted or agentic investigation workflows.

Visit Website

Company Overview

Hunters sells security operations software for teams that need broad visibility without building and maintaining a large detection-engineering function. The core platform ingests telemetry from endpoint, identity, cloud, network, email, SaaS, and other security sources; normalizes data to OCSF; correlates signals into attack stories; and prioritizes incidents using detection logic, enrichment, risk or confidence scoring, and automated investigation. The product has evolved from the company's earlier XDR positioning into a broader SOC platform and next-generation SIEM. Current public materials describe Pathfinder AI as an intelligence layer for alert and attack-activity summaries, natural-language querying, guided investigations, and more autonomous classification and root-cause analysis. These are operationally meaningful capabilities when they preserve evidence and auditability rather than merely generating plausible text.

The commercial problem is persistent: small and mid-sized SOCs face too many alerts, fragmented tools, expensive data ingestion, and a shortage of experienced analysts. Hunters targets that gap with pre-built detections, integrations, automation, and a deployment model intended to produce value faster than a traditional SIEM implementation. It also markets a multi-tenant version to MSSPs and MDR providers, where standardized ingestion, case workflows, and analyst efficiency can affect margins across many customers. Public customer references and case-study materials name organizations including Booking.com, Snowflake, Cimpress, TheRealReal, and Pennymac; these are useful traction signals, but they do not by themselves establish current revenue, retention, deployment scale, or referenceability beyond the published material.

Hunters has credible category and commercialization signals for a growth-stage startup. The company announced a $68 million Series C led by Stripes in January 2022, bringing publicly reported total funding to approximately $118 million at that point, and said it had crossed 100 employees when the round was announced. LinkedIn currently describes the company as privately held, headquartered in Tel Aviv, and in the 51–200 employee range. No later financing or liquidity event is treated here as confirmed. The company also publishes security and compliance materials, including a stated SOC 2 Type II report available to prospects and a historical ISO/IEC 27001 certificate, which may reduce enterprise procurement friction but should be checked for current scope and validity during diligence.

Competition is intense. Hunters must win against Microsoft Sentinel, Splunk, Google SecOps, Elastic Security, Securonix, Exabeam, Panther, and MDR or managed-SOC substitutes. Its plausible edge is a combination of open data-lake architecture, detection content and threat research from Team Axon, graph-based correlation, and automation that reduces repetitive analyst work. The risk is that large platforms can bundle SIEM and AI features, while specialist vendors can offer stronger depth in endpoint, cloud, identity, or managed detection. Durable differentiation therefore depends on measured alert-reduction and investigation-time outcomes, integration breadth, deployment economics, model quality, and customer retention rather than on the words AI or next-generation alone.

The national-security relevance is real but adjacent. The same functions used by commercial SOCs—cross-domain telemetry collection, anomaly and threat detection, incident reconstruction, analyst decision support, and response orchestration—are useful to government, critical-infrastructure, and defense cyber-defense teams. Hunters is not presented as a weapons company, defense prime, or confirmed government supplier, and the public evidence reviewed does not establish classified deployment or a government contract. Its strategic relevance is consequently that of a cyber-defense software infrastructure company whose commercial product could support high-value network defense, subject to procurement, data-residency, assurance, and operational-resilience requirements.

Dual-Use Assessment

Military & Commercial Applications

Hunters has substantive but adjacent dual-use relevance. Its core SOC capabilities—heterogeneous telemetry ingestion, normalization, detection, correlation, threat investigation, and response workflow automation—are directly useful for commercial cyber defense and potentially for government, critical-infrastructure, and defense-network security operations. Public evidence does not establish a defense-specific product, classified deployment, or government contract, so the dual-use case should be treated as cyber-infrastructure adjacency rather than as a defense-native thesis.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Hunters is a credible strategic-priority signal for a dual-use cybersecurity database because it addresses a persistent operational bottleneck and its technology maps to defensive cyber missions as well as enterprise security. Evidence supporting the case includes the company's private growth-stage status, a publicly announced $68M Series C, named enterprise customers or references, a broad integration footprint, and a product architecture aimed at reducing analyst workload rather than only storing logs. This is a strategic diligence assessment, not an investment recommendation. The central diligence questions are current recurring revenue and retention, deployment success, gross-margin impact of ingestion, customer concentration, proof that automated investigations improve outcomes without unsafe false negatives, and the ability to defend against bundled SIEM offerings from much larger vendors.

Strategic Value to U.S.-Israel Alliance

Hunters could provide strategic value as a vendor-neutral security-operations layer for organizations with fragmented telemetry and limited detection-engineering capacity. OCSF normalization, open data-lake positioning, graph correlation, and human-reviewed automation can improve visibility across heterogeneous environments and are relevant to enterprise, critical-infrastructure, and public-sector cyber defense. The value is strongest where teams need faster time to detection and investigation without replacing every existing security control. Strategic assessment should remain conditional on current product assurance, data residency, resilience, integration depth, and evidence that AI workflows are explainable, auditable, and safe for high-consequence response decisions.

Key Technologies

  • OCSF-oriented security telemetry normalization
  • Open security data lake architecture
  • Graph-based cross-source attack correlation
  • AI-assisted and agentic alert triage and investigation
  • Pre-built detection engineering and threat-hunting content
  • Risk and confidence scoring with alert clustering
  • Multi-tenant SOC and MDR workflow automation

Use Cases & Applications

  • Alert triage and prioritization for small and mid-sized SOCs
  • Cross-cloud, endpoint, identity, network, email, and SaaS threat detection
  • Automated incident enrichment, investigation, and root-cause analysis
  • Detection engineering and continuous security-content maintenance
  • Security data consolidation with predictable ingestion economics
  • MSSP and MDR multi-tenant monitoring and case operations
  • Critical-infrastructure cyber monitoring and incident response support
  • Government or defense-network defensive cyber operations, subject to assurance and procurement requirements

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.