FIELD NOTES / NEBULOCKSEP 2026: GATES METHOD PUBLISHEDJUN 2026: $25M SERIES AHUNT FIRST. KEEP THE EVIDENCE.

Company / Cybersecurity 01 / The quiet intrusion

Nebulock hunts the threats that look perfectly ordinary

An approved tool. A valid login. A very quiet intrusion. Nebulock builds its security platform around the awkward possibility that the most dangerous activity in your network looks like business as usual.

The computer was running an approved remote-access tool. That was the comfort. It was also, in Nebulock’s account of an August 2026 investigation, the camouflage. ScreenConnect belonged in the environment. An attacker had learned to belong inside ScreenConnect.

The useful bits
  • Nebulock hunts across existing security data, including activity that never triggers an alert.
  • Its agents keep investigation context and help turn findings into behavioral detections.
  • Humans review the evidence. Open-source frameworks make parts of the method available to anyone.

The approved tool with three identities

On one endpoint, the company reported, there were three distinct ScreenConnect instances. A service spawned command interpreters. A second client arrived through a silent installer. A registry setting hid an installation from the ordinary software list. These details were individually explainable, which is often how trouble obtains its invitation.

The lead was a scheduled task running with SYSTEM privileges. It executed, slept, then deleted itself. Nebulock’s own detection scored it as moderate. Agents followed the thread, queried surrounding activity and raised the finding to critical. According to the published account, standard endpoint alerts had missed the intrusion.

This is the company’s proposition in miniature. A security operations center has an inbox of alerts. A threat hunter asks what might be happening outside that inbox. Nebulock sells software for the second question, with agents doing much of the collection, correlation and follow-up.

A skeptic, a founder and a memory problem

Founder and CEO Damien Lewke had spent more than a decade in cybersecurity, including roles at Northrop Grumman, CrowdStrike and Arctic Wolf. His account of the problem is recognizably practical: fragmented tools, too little time to hunt, and additional people who did not automatically make the fragments fit.

One recruit, principal security architect Justin Swisher, was initially suspicious. He described his former attitude toward AI as an “old man who yells at the cloud.” Fifteen years in security had furnished him with a respectable collection of technologies supposedly about to make other technologies obsolete.

What changed his mind was working with the tools and customers. Agents could collect and summarize unfamiliar data, preserve context and shorten the journey from an idea to detection coverage. His enthusiasm depended on keeping hunters involved. A machine that takes minutes off preparation gives an experienced person more room to think.

Nebulock founder and CEO Damien Lewke, standing with his arms crossed
Damien Lewke: a decade among security tools, then a company devoted to the spaces between them. Photograph: Nebulock.

The technical expression of that argument is TRACE Graph, short for Threat Research and Context Engine. It records behavior, entities, investigations and feedback specific to an environment. A dismissed finding can teach the next hunt what legitimate activity looks like. A hunt that finds nothing still leaves a record.

“Agents propose, humans approve.”Nebulock’s stated operating principle

The hunt that starts itself

Vespyr, introduced in March 2026, takes the initiating step. It monitors intelligence, decides what is relevant to the customer’s environment, scopes a hunt and delivers findings. Earlier Vibe Hunting let a person express a hypothesis in plain language. Vespyr can begin without that prompt. The analyst reviews, validates and acts.

The platform connects hunting with investigation and detection engineering. Command Center gathers findings and suggested hunts into one workspace. The intended buyers are security leaders and teams that have telemetry but insufficient time or specialist capacity to investigate it continuously. Named customers include Cribl, HealthEdge and Bain Capital.

Nebulock emerged publicly in July 2025 with $8.5 million in total funding. A $25 million Series A, announced June 25, 2026 and led by FirstMark, brought disclosed funding to $33.5 million. Returning investors included Bain Capital Ventures, Decibel, Zetta Venture Partners and Step Function Ventures.

300M+agentic investigations reported by Nebulock by June 2026An activity count, not a count of attacks stopped.

That announcement also reported more than 4,000 high-confidence findings. These are company figures; they describe its claimed operating scale. Funding pays for expansion, while findings are evidence of product activity. Neither number tells a buyer what a deployment will cost or how well it will work in their own network.

The bill for keeping everything

The enterprise software business runs through a demo-led sales process. For a buyer, the useful comparison includes analyst hours, data preparation, integration and upkeep alongside the software contract. Nebulock competes for work performed through manual hunting programs, managed services and AI-assisted security investigations.

Its positioning emphasizes hunts that can begin before an alert and memory that survives a closed investigation. Existing endpoint and SIEM products remain part of the stack. The company’s argument is that their data can support a different workflow, without requiring every tool to be replaced.

Helix, launched in July 2026, addresses another expense: collecting enrichment data before anybody needs it. It queries authoritative tools on demand, starting with vulnerability management. Initial support includes Qualys, Tenable, Rapid7, Axonius, CrowdStrike and Microsoft Defender. Core endpoint, identity and cloud telemetry is still centralized; the just-in-time approach concerns additional context.

There is a pleasingly unglamorous choice elsewhere in the product. For identifying AI-related endpoint processes, Nebulock describes a gradient-boosted machine using behavioral features rather than tool names. Repeatable outputs, interpretable decisions and token-free inference make classical machine learning useful here. An AI company can exercise taste in machinery.

Five questions worth stealing

In September, Nebulock published GATES, a checklist for deciding whether a hunt deserves a permanent detection. Its team developed and checked the method against 350 hunts. Some findings belonged in recurring hunts instead. Keeping everything switched on can simply manufacture another maintenance problem.

Before a finding becomes a rule

G Generalizable Does the behavior repeat?

A Additive Does it close a coverage gap?

T Tunable Can attack and routine work be separated?

E Exposure-tested Have bypasses been examined?

S Sustainable Can you see it and maintain it?

Readers can copy the discipline: document one hunt, preserve the reasoning, test the five questions. ATHF supplies hunt structure and memory; ADEF keeps a detection’s history. Both are public projects. They offer methods and scaffolding rather than the entire commercial service.

The limits appear in Nebulock’s own insider-risk case study. During a restructuring, agents connected file collection, archiving and movement. In one sequence, telemetry could not confirm that files left the organization. That required follow-up. Legitimate activity was downgraded, including an employee preserving personal employment records.

Missing telemetry cannot become proof through eloquent reasoning. Rare legitimate behavior takes time to learn, and a rule nobody can maintain belongs elsewhere. Nebulock’s most useful promise is a better question asked with more context. Sometimes the answer is an intrusion. Sometimes it is a person doing their job.