All Cribl and Radiant Security claims on this page are sourced to Cribl’s August 19, 2026 announcement and same-day coverage. Nothing here asserts what happens to Radiant’s customers, contracts, or standalone platform beyond what has been publicly stated. Characterizations of third-party products reflect their vendors’ public positioning as of August 19, 2026.
Contents: What Happened · Asset vs. Company Acquisition · Five Questions to Ask This Week · The Bigger Shift · The Shortlist You’re Rebuilding · What to Demand · Where Morpheus Fits · Mid-Evaluation or Switching · FAQ
On August 19, 2026, Cribl announced it has acquired technology assets from Radiant Security’s AI SOC product, including the intellectual property behind autonomous alert triage and investigation. Cribl says it is adapting the technology to run as an application on its telemetry data platform. If you run Radiant today, or had it on your shortlist, your AI SOC roadmap now runs through a data pipeline vendor.
What Happened
Cribl, the telemetry pipeline company, announced this morning that it acquired technology assets from Radiant Security. Per the press release, the deal covers the IP behind Radiant’s AI-native SOC product: software that autonomously triages, investigates, and resolves security alerts. Terms were not disclosed.
This is Cribl’s second security acquisition of 2026, following CardinalOps in July. Cribl says it will adapt the AI SOC technology to run as an application on its telemetry platform, with more platform additions to be shared at CriblCon on September 28, 2026.
Radiant Security raised a $15 million Series A led by Next47 in 2023 and built a real product with real customers. Their team earned a place in nearly every AI SOC analyst report of the last two years. What changed today is who owns that technology and where it lives next.
An Asset Acquisition Is Not a Company Acquisition
The distinction matters. Cribl bought technology assets and IP. The announcement describes the technology’s future home: an application running on Cribl’s telemetry data platform, working against data that platform collects and routes. What the announcement does not describe: the future of Radiant’s standalone platform, existing customer contracts, support commitments, or the integration roadmap for the 120+ connectors Radiant publicly lists.
Those answers will come from account teams and from CriblCon. Until they arrive, every Radiant customer is operating on assumptions.
If You’re a Radiant Customer, Ask These Five Questions This Week
- Who honors my current contract through term, and who owns my support SLA today?
- Will the standalone platform keep receiving detection logic updates, integration fixes, and model improvements while the technology is adapted for Cribl’s platform?
- Does the AI SOC capability eventually require adopting Cribl’s telemetry platform? If so, on what timeline?
- What happens to my existing connections to Splunk, Microsoft Sentinel, Datadog, Exabeam, CrowdStrike, and the rest of my stack?
- If any answer above is unclear, what is my exit and migration path, and who pays for it?
Get these answers in writing. Renewal conversations after an asset acquisition are the one moment you have maximum leverage and minimum information. Fix the information half first.
The Bigger Shift: Your AI SOC Just Became a Data Architecture Decision
Cribl’s announcement is explicit about the strategy. The AI SOC technology will run as an application on Cribl’s telemetry platform, operating on data that platform already collects and routes. For Cribl, that is a coherent play: own the pipeline, then own the intelligence on top of it.
For a SOC buyer, it inverts the evaluation. Most enterprises made their data layer decisions years ago. You run Splunk, or Sentinel, or Datadog, or Exabeam, or Microsoft end to end, or more likely several of these at once. You chose an AI SOC layer to sit on top of that reality, not to renegotiate it. An investigation platform that performs best, or eventually only, on a specific telemetry pipeline turns an investigation-layer purchase into a data-architecture commitment.
Some teams will want that. Cribl is a strong company with a large installed base, and if you were already planning to route your telemetry through Cribl, this consolidation may work in your favor. But if you evaluated Radiant precisely because it connected to the tools you already own, the calculus changed this morning.
The Shortlist You’re About to Rebuild
Teams restarting an AI SOC evaluation this quarter are choosing between three routes. Hyperautomation platforms, with Torq as the best-known example, give your engineers a powerful automation engine and AI agents to operate it; your team builds the investigation logic, per their public positioning. AI triage agents, with Dropzone AI as the best-known example, ship a pre-trained analyst that investigates Tier 1 alerts and hands findings to the rest of your stack, per their public positioning. AI SOC platforms run the investigation itself, end to end, with orchestration and case management on the same engine. That third route is what Radiant customers bought, and it is where Morpheus lives.
We published a full three-way comparison of these routes, including Radiant vs. Torq vs. Morpheus and Radiant vs. Dropzone AI vs. Morpheus tables: Radiant Security Alternatives in 2026.
What to Demand From an AI SOC Platform That Stays Independent of Your Data Stack
Whether you are a Radiant customer reassessing or an evaluator restarting a shortlist, these are the criteria that protect you from repeating this situation:
- Investigates across your existing stack. The platform should pull evidence from your SIEM, EDR, identity, email, cloud, and network tools wherever that data already lives, straight over API.
- Runs L1 and L2 investigation end to end, with you in control. Full investigation depth on every alert, with you deciding what the AI is allowed to do at every step. If the platform stops at a triage summary, your analysts still own the hard part.
- SOAR and case management built in. If response orchestration and case management are separate purchases, you are assembling three vendors, and consolidation risk applies to each of them.
- Integrations that survive vendor API changes. When a vendor changes an API, does the platform detect the drift and repair the connector, or does your team find out when a playbook fails?
- Deploys where you need it. Cloud, on-premises, hybrid, and multi-tenant for MSSPs. Regulated environments and OT-adjacent SOCs need all four options on the table.
- A vendor whose only business is your SOC. The roadmap should serve security operations and nothing else. Every other business model eventually asks your SOC to fund it.
Where Morpheus Fits
Morpheus is D3 Security’s AI SOC platform with SOAR and case management built in. It was built for exactly the buyer this acquisition leaves exposed: a SOC that wants autonomous investigation on top of the stack it already owns.
Morpheus connects to your environment through 800+ self-healing integrations covering every major SIEM, EDR, identity, email, cloud, and ticketing platform: Splunk, Microsoft Sentinel, Datadog, Exabeam, CrowdStrike, Elastic, and the rest of the stack you already run. Self-healing means Morpheus detects vendor API drift and generates corrective code autonomously, keeping integration maintenance off your engineers’ plates. Your data layer stays exactly where it is. Morpheus investigates against your tools, where your data lives, from day one.
On every alert, Attack Path Discovery investigates the environment around the alert: north-south ingress, east-west lateral movement, MITRE ATT&CK alignment on every finding. Morpheus runs L1 and L2 investigation end to end, and you control what it is allowed to do through four autonomy modes: Deterministic, AI-Assisted, AI-Led, and Autonomous. Same engine, same audit trail format across all four, so you can start supervised and expand autonomy at your own pace. In production, Morpheus investigates up to 95% of alerts in under 2 minutes at L2+ depth.
Commercially, Morpheus is an annual subscription sized to your alert volume envelope, and D3 absorbs all AI token costs. There are no per-investigation fees, which means connecting your full alert stream is the intended use of the platform, not a billing event.
If You’re Mid-Evaluation or Considering a Switch
Moving off an AI triage layer is lighter than moving off a SIEM. Integrations reconnect through APIs. Morpheus generates deterministic playbooks from your existing SOPs, so codified response logic carries forward. A proof of concept runs on your own alerts, in your own environment, and you judge investigation output on your real traffic.
D3 has run structured migrations from SOAR and triage platforms for years. If you have remaining term on a contract and an unclear roadmap, that is a solvable commercial conversation. Bring it to us.
Frequently Asked Questions
Did Cribl acquire Radiant Security?
Cribl announced on August 19, 2026 that it acquired technology assets from Radiant Security’s AI SOC product, including the IP for autonomous alert triage, investigation, and resolution. The announcement describes an acquisition of technology assets, not a full company acquisition. Terms were not disclosed.
What happens to Radiant Security’s standalone platform?
The announcement does not say. Cribl states it is adapting the technology to run as an application on its telemetry data platform, with more detail expected at CriblCon on September 28, 2026. Existing Radiant customers should confirm support, roadmap, and contract commitments with their account teams in writing.
Will Radiant’s AI SOC technology require Cribl’s platform?
Per the announcement, the technology is being adapted to run as an application on Cribl’s telemetry platform, operating on data that platform collects and routes. Whether any standalone availability continues has not been publicly stated.
What is a good Radiant Security alternative?
It depends on your stack and your appetite for adopting a telemetry pipeline. If you want an AI SOC platform that runs on the tools you already own, with SOAR and case management built in, not sold separately, D3 Morpheus is built for that requirement: 800+ self-healing integrations, Attack Path Discovery on every alert, four autonomy modes, and cloud, on-premises, hybrid, and MSSP deployment.
Does Morpheus work with my existing SIEM?
Yes. Morpheus is multi-SIEM by design and runs on top of Splunk, Microsoft Sentinel, Datadog, Exabeam, Elastic, Google SecOps, and others, including several at once. It investigates against your data where it lives, and your data layer stays put.
How fast can we evaluate Morpheus?
A proof of concept connects to your environment through APIs and runs on your own alerts. Most teams see full L2-depth investigation output on their real alert stream within days, which makes side-by-side comparison against any incumbent straightforward.
See It on Your Own Alerts
The fastest way to pressure-test any of this is to watch Morpheus investigate your alerts, in your environment, against your stack. Book a demo and bring your hardest alert source.
Request a demo → · Radiant Security alternatives compared → · Coming off a contract with an unclear roadmap? Migrate for free →
D3 Security is not affiliated with Cribl, Radiant Security, Torq, Dropzone AI, or the other third-party vendors named above. All trademarks are the property of their respective owners. Statements about the Cribl and Radiant Security transaction are drawn from Cribl’s August 19, 2026 announcement; characterizations of other third-party products reflect their vendors’ public positioning as of August 19, 2026. Vendor-stated figures are the vendor’s claims, not independent audits.

