NEW SIGNAL
24 SEP 2026 · AI RISK AND RESPONSE REACHES GENERAL AVAILABILITY · PREVENTION REMAINS IN PREVIEW
COMPANY / SECURITY & AITHE BEHAVIOR ISSUE

Gurucul and the
Trouble with Normal

The dangerous login may have the right password. Gurucul has built a business around what happens next - and why a security team should care.

Consider a perfectly ordinary corporate login. The password is correct. The account belongs to an employee. Nothing about that transaction need offend a security rule. Now imagine that the account starts reaching for files it has never touched. Permission has been established; purpose has become interesting. This is the territory Gurucul occupies: the awkward space between being allowed to do something and having a good reason to do it.

THE STORY IN FOUR LINES
  • Gurucul connects behavior, identity and security events to help teams judge risk.
  • Its REVEAL platform combines detection, data management and response workflows.
  • Customers can use their own data lake and augment an existing security stack.
  • The latest expansion watches AI systems as actors with access of their own.

The appeal is easy to grasp. A security department does not need another reason to be anxious. It needs a better way to decide which anxiety deserves the afternoon. Gurucul sells software for that decision, principally to enterprises, government agencies and the providers that run security services for other organizations. Its subject is the activity of people, machines and, increasingly, AI agents. Its raw material is the evidence those actors leave behind.

01 / The password is only the opening sentence

Gurucul’s behavioral roots matter more than the fashionable AI vocabulary around them. User and Entity Behavior Analytics, usually shortened to UEBA, examines activity over time. Identity analytics adds the account and its access rights. A security event gains meaning when it is placed beside the person or system involved, their history and the resources within reach. The question becomes practical: does this activity belong here?

That is useful for compromised accounts, insider activity and data exfiltration. A rule can recognize an already defined condition. Behavioral analysis can flag a departure from an established pattern. Neither observation, by itself, proves malicious intent. A business trip, a new assignment or a legitimate bulk download may also be unusual. The value lies in giving an investigator more to work with than a flashing light.

The founders arrived with relevant experience. CEO Saryu Nayyar had worked in security and identity-related businesses, including Vaau, Sun Microsystems and Oracle, and in EY’s security practice. CTO Nilesh Dherange had helped build a roles-and-compliance product acquired by Sun. He had also developed predictive software for advertising bids. An auction and a compromised account are different problems, but both reward the ability to read patterns without mistaking every fluctuation for a revelation.

Gurucul co-founder and CEO Saryu Nayyar
A familiar face, an unfamiliar login. Co-founder Saryu Nayyar brought an identity-security background to a business concerned with what accounts actually do.

02 / The dashboard nobody trusted

The human test appears in Gurucul’s published Upwork case study. The incumbent SIEM struggled with growing data, false positives and critical alerts delayed by days. Analysts began investigating elsewhere. Upwork ran Gurucul alongside other tools for a year before expanding reliance on it. The reported migration took less than eight weeks, moving more than 100 rules and dashboards. Daily ingestion fell from 1.2 TB to 650 GB, described as roughly 45% lower volume.

“Our previous SIEM felt more like a checkbox than a functional security tool.”Shawn Chakravarty · Upwork, in Gurucul’s case study

Those are vendor-published results, not a universal forecast. The case is revealing because the failure was visible in ordinary work: people stopped trusting the interface. What changed their minds was sustained use, supported migration and an architecture that accommodated Snowflake storage. A smaller stream of data can affect costs, but a 45% volume reduction is not automatically a 45% reduction in the bill.

UPWORK · REPORTED DAILY INGESTION
Before
1.2 TB
After
650 GB

Approximately 45% less data volume. Vendor-published case study; dollars depend on the contract and storage architecture.

03 / The unglamorous advantage: where the logs go

REVEAL, launched in 2024, brings a collection of security functions into one platform. Next-Gen SIEM supplies monitoring and investigation. UEBA supplies behavioral context. SOAR, or security orchestration, automation and response, supplies playbooks that coordinate actions across connected tools. Identity analytics examines access risk; Open XDR connects detection and response across the security environment. Buyers can replace a SIEM or add capabilities beside one.

Gurucul’s position in that market rests partly on an architectural choice: analytics need not dictate the storage destination. Its Snowflake Connected App can analyze data in Snowflake, return alerts and risk scores, and support federated searches using Snowflake syntax. In plainer English, investigators can ask questions of data where it already lives. That gives a buyer with an established data lake a concrete reason to consider the product.

Data Pipeline Management handles the less theatrical work. It filters, deduplicates, normalizes and enriches logs, then routes them to the appropriate destination. Some data belongs in an active detection workflow; some belongs in a searchable archive. Gurucul advertises ingestion-cost savings ranging from 40% to 87%. Treat those as the vendor’s claims about particular optimization opportunities, with the workload and retention requirements doing much of the deciding.

The AWS Marketplace listing describes licensing by user or entity rather than data ingestion, with pricing determined by contract terms. That shifts one part of the commercial calculation. Storage, deployment and integration still belong in a buyer’s budget. The useful procurement exercise is to price the whole operating arrangement and ask which costs move when the telemetry grows.

Alternatives include Splunk, Microsoft Sentinel, Securonix and Exabeam. Gurucul competes on behavioral context, integrated workflows and flexibility over data architecture. A familiar incumbent may still suit a team with working detections and well-established processes. The interesting comparison is the effort required to investigate the same case, retain the same evidence and keep the same coverage.

04 / The new colleague has no pulse

Gurucul added an AI SOC Analyst in 2025, extending automation into triage, investigation and response. The proposition is that evidence gathering and routine case work consume scarce analyst time. Its product materials emphasize transparent workflows and human oversight. “Self-driving SIEM,” the company’s phrase from an April 2025 announcement, is an ambitious label; the operational question is which decisions the software may execute under the customer’s controls.

Then the actor being investigated changed. On September 24, 2026, Gurucul released AI Risk and Response. The announcement targets shadow AI, excessive access and risky agents, linking AI activity with identity and wider security evidence. Detection, investigation and analyst-directed response are generally available. AI Prevention remains in preview. That distinction matters to anyone purchasing a shipped capability rather than a promising direction.

Gurucul AI Risk and Response product dashboard showing AI inventory and threat use cases
The robots have entered the attendance register. Gurucul’s AI Risk and Response dashboard brings agents, models and tools into the investigator’s view. Company product image.

The product uses connected telemetry rather than requiring another endpoint or browser agent. It combines known-pattern detections, behavioral baselines and relationships among users, agents, accounts and endpoints. Its stated limits are practical: visibility depends on the data and fields available; behavioral baselines need history; response depends on integrations, APIs, permissions and approval policies. An agentless design still needs something useful to observe.

This creates a pleasingly uncomfortable symmetry. Gurucul uses AI to help security teams investigate, while selling tools to investigate AI. The underlying subject remains access exercised over time. A software agent can hold credentials, use tools and reach sensitive information. Giving it a friendly name does not answer the security questions that follow.

05 / A school with a security budget

The company takes its name from gurukul, a community of teachers and learners. Gurucul describes its culture in those terms, emphasizing research, customer collaboration and shared practitioner knowledge. It also says it has achieved profitability while prioritizing self-sufficiency. The school metaphor is attractive; the more useful implication is that security models and deployment practices need continuing instruction.

Distribution broadens the audience. Gurucul’s channel program includes resellers, systems integrators and managed security providers. Its October 2025 Blue Mantis partnership puts its SIEM beneath Blue Mantis Protect, a managed service aimed at mid-sized organizations. Customers can obtain the analytics alongside an operating team, instead of assembling every part of a security operations center themselves.

The copyable lesson is modest and valuable. Start with an investigation your team actually performs. Check the identity joins, evidence quality, alert timing and required response permissions. Run a candidate system against that work before committing to a migration. Evaluate data routing alongside detection quality. The software earns its place when an analyst can explain why a case matters and act on it. A successful login is a beginning. So is a successful demo.