ABOUT US
An Entire Company Focused on Security Automation
No matter what tools you use, or at what scale you operate, we can automate your security operations and incident response. No organization is too big for D3. That’s why clients like Disney, London Stock Exchange Group, and the Government of Ontario rely on D3 to streamline their security.
Powering the World’s Best SecOps Teams
Tested and trusted by the largest and most targeted enterprises, governments, and MSSPs

Our Mission:
To Help  Cybersecurity Pros Give, and Get, More
We believe that automation can help analysts, engineers, and team leaders get more from their work. When security pros get to spend their time on the important stuff—not repetitive busywork—they are engaged with their work and less likely to burn out. That’s what we strive to enable.
More Confidence
A strong, confident view of cyber threats, with a unified alert data model that is free of false positives.
More Speed
Faster alert processing and triage. Faster incident response playbooks and integrations.
More Clarity
Designed to keep users focused on their priority tasks and intelligence, with streamlined workflows and minimal manual coordination.
Our Innovation Story
In 2015, our founder Gordon Benoit built the first incident response automation solution. Dynamic incident forms, alert grouping, and link analysis helped analysts respond faster. At RSA 2016, D3 demoed integrations with ArcSight, Qradar, and Splunk. Gartner would soon use the term “security orchestration, automation and response (SOAR)” to describe D3 and the emerging category.
- Security automation, incident response, and case management innovator
- Making SOAR since before the term existed
- The first SIEM and TIP integrations for incident response
From 2017 through 2021, D3 scaled up its development to continue innovating and meet the growing worldwide demand for SOAR. In this period, D3 launched NIST- and SANS-based playbook libraries, a codeless playbook editor, MITRE ATT&CK features including a dashboard still used today, and MITRE D3FEND-based playbooks and automations.
- NIST and SANS libraries
- MITRE ATT&CK TTP tracking
- MITRE D3FEND playbooks
In 2022, D3 decided to focus on SOC teams’ biggest challenge: the volume of alerts. The Event Pipeline minimizes the impact of benign alerts on SOC teams by de-duplicating, enriching, correlating and normalizing alerts upon their ingestion, reducing alert assignments by up to 99%.
- Solving the big problem
- Unified data model
- 99% real-world improvement
In 2023, D3 launched Smart SOAR™, the world’s most effective incident response automation solution. Combining the Event Pipeline with drag-and-drop playbooks, vendor-maintained integrations, and three levels of automation (alerts, incidents, and scheduled), Smart SOAR brings all of D3’s innovations together in one proven platform.
- The culmination of years of innovation
- Battle-tested platform for high-availability security operations
- SOAR industry’s best in-house support team
In 2024, D3 became one of a handful of independent software vendors invited by Microsoft to the Microsoft Security Copilot Partner Private Preview, giving D3 unique access to cutting-edge AI security innovation. D3’s proprietary AI research led to Morpheus, which delivers:
- AI-powered triage and response
- AI-generated incident summaries
- Prompt-based playbook generation
In The News
Top MITRE ATT&CK Techniques and How to Defend Against Them—New Research from D3 Security

Is Automated Triage of 100% of Alerts Possible with Today’s Tools?

D3 Security is a proud participant in the Microsoft Security CoPilot Partner Private Preview

Explaining the Big Strides in Security Automation Even Before GenAI Became a Thing

D3 Security Brings Smart SOAR™ to the SentinelOne® Singularity™ Marketplace

Dedicated to the World of Cyber Security
Join D3
If you’re ready to grow your career and help thousands of cyber security professionals, you’ve come to the right place. We’re always looking for the best and brightest (and most organized!) to join our team across the globe.
We invest in our people as they create original research at D3 Labs.
Sponsors of Black Hat, RSA, SecTor, it-sa, and many more!
We can’t wait to share the details.
Leadership Team










Learn More About What Makes D3 Different
Check out these resources to dive deeper into D3’s unique approach to cyber security.
- 
Morpheus: AI-Driven Autonomous Investigation, Triage, and ResponseUncover how Morpheus’s AI-driven investigation capabilities transform alert handling from hours to seconds while keeping humans strategically positioned.   
- 
The CISO’s Guide to Autonomous SecOpsExplore how Morpheus powers autonomous SecOps with complete alert coverage and lightning-fast triage—no stack replacement required. Real case studies included.   
- 
The State of the Autonomous SOC: Drivers, Risks, and OpportunitiesExplore how autonomous security operations and AI-driven response are reshaping enterprise defense.   
- 
Introducing Morpheus: Autonomous Investigation, Triage, and Response for SOC TeamsLearn how Morpheus ASOC brings AI-driven autonomy to security operations, enabling 100% alert coverage and faster investigations. 
- 
Inside the Morpheus AI-Assisted Workspace: Bridging the Gap Between Complex Data and Rapid ResponseMorpheus’s AI-augmented SOC workspace streamlines Jinja transformations, automates Python scripts, and uncovers deep incident insights. 
- 
One AI Analyst, Infinite Scale: The New Security Operations ModelThe age of throwing more analysts at the problem is over. The future belongs to teams that recognize AI isn’t just a helper—it’s a force multiplier for security operations.