D3 Security (Morpheus)
Also known as: D3 Security, D3 Morpheus, Morpheus AI, Smart SOAR, Attack Path Discovery
Autonomous AI SOC platform from SOAR vendor D3 Security: full L2-depth Attack Path Discovery on every alert, bespoke response playbooks generated at runtime, and a structured case file in under two minutes, with up to 95% of alerts triaged and L2-investigated in that window. Runs bounded agentic reasoning on a purpose-built Cybersecurity Triage Reasoning Graph inside deterministic governance with autonomy modes and approval gates, producing one unified regulator-ready audit trail per incident. Self-healing integrations across 800+ tools, Azure plus four-region data residency plus on-prem, published testing results (87% attack path revelation, 94% closure).
D3 Morpheus is an autonomous AI SOC platform from D3 Security, the established SOAR vendor behind Smart SOAR. Morpheus investigates and responds to security alerts without human intervention for routine work: it ingests alerts from the entire security stack, performs full L2-depth Attack Path Discovery on every alert, generates a bespoke response playbook at runtime, and delivers a structured case file ready for analyst review, all in under two minutes, with up to 95% of alerts triaged and L2-investigated in that window. Attack Path Discovery hunts horizontally across identities, endpoints, cloud, and email (lateral movement) and vertically through time (privilege escalation, persistence), reconstructing the complete attack path rather than examining alerts in isolation. Underneath sits the Cybersecurity Triage Reasoning Graph, a domain-specific reasoning architecture encoding how a senior SOC analyst reasons: nodes are security entities and concepts, edges are reasoning patterns, and the graph constrains what the LLM considers at every step so it never reasons about irrelevant telemetry. D3 explicitly positions this unified-engine design against multi-agent platforms (Torq, Dropzone, Prophet, CrowdStrike), arguing message-bus coordination fragments context and audit trails; Morpheus instead runs bounded agentic reasoning inside one deterministic playbook with explicit iteration, cost, tool-scope, and approval-gate bounds. Six capabilities (triage, investigation, response and orchestration, self-healing integrations, agentic task, autonomy modes) run on one reasoning engine producing one unified audit trail per incident, designed to read identically to a US examiner, an EU supervisor, or a critical-infrastructure regulator, with accountability framed under SEC, NYDFS, NIS2, DORA, and the EU AI Act. Autonomy modes provide graduated autonomy with remediation recommendations routed to analysts for approval. D3 continuously tests Morpheus against simulated attacks and adversarial inputs, publishing an 87% attack path revelation rate and 94% investigation closure rate. Deployment runs on Azure with four-region data residency and on-premises for regulated industries. Sold as an annual platform subscription sized to the SOC with an included envelope of AI investigations, and a strong MSSP channel for MDR/MXDR delivery. Morpheus is the lane's SOAR-incumbent-gone-AI-SOC entrant and its compliance-architecture benchmark.
Vendor details
Canonical URL
https://d3security.com
Category
Security / SOC agent
Funding status
Established independent SOAR vendor (Smart SOAR) that pivoted into the AI SOC category with Morpheus, announced March 2025 and generally available August 2025; President Gordon Benoit; Microsoft Intelligent Security Association (MISA) member; strong MSSP channel enabling MDR and MXDR service delivery
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Sits on top of any security stack, ingesting from SIEM, SOAR, EDR, NDR, identity, authentication, email, DLP, CSP, and 800+ tools, with self-healing integrations that maintain connectivity automatically when APIs change. Includes a built-in SOAR engine and integrated case management. The same Attack Path Discovery engine also triages AI-discovered vulnerability findings from sources like Anthropic Mythos and OpenAI Codex Security, treating them as a second input class.
Sources & related URLs
Capability coverage
10.0 / 14 capabilities · 71%
| Integrations & Tool Calling800+ integrations across SIEM, SOAR, EDR, NDR, identity, email, DLP, and CSP with self-healing integrations that maintain connectivity automatically, D3 Morpheus FAQ and MSSP Alert 2026-07-22 | Full |
|---|---|
| Workflow OrchestrationAutonomous L2-depth investigation on every alert with bespoke response playbooks generated at runtime, a built-in SOAR engine, and response orchestration across the stack, D3 Morpheus product pages and FAQ 2026-07-22 | Full |
| Knowledge Grounding & RAGThe Cybersecurity Triage Reasoning Graph is a purpose-built domain knowledge architecture encoding senior-analyst reasoning as entity nodes and reasoning-pattern edges, constraining the LLM's context at every investigation step, D3 Morpheus triage and investigation pages 2026-07-22 | Full |
| Human Oversight & GuardrailsAutonomy modes provide graduated autonomy with explicit iteration, cost, tool-scope, and approval-gate bounds on agentic reasoning, and remediation recommendations are routed to human analysts for approval, D3 Morpheus product pages 2026-07-22 | Full |
| Security, Identity & GovernanceCompliance is structural: bounded reasoning inside deterministic governance with accountability framed under SEC, NYDFS, NIS2, DORA, and the EU AI Act, and audit trails designed for regulators; formal attestations not retrieved, D3 Morpheus triage page 2026-07-22 | Full |
| Observability & AuditabilityOne unified audit trail per incident with visible, auditable reasoning behind every triage decision and structured case files, designed to read identically to US, EU, and critical-infrastructure regulators, D3 Morpheus product pages 2026-07-22 | Full |
| Memory & State PersistenceIntegrated case management persists incident state with structured case files per investigation and timeline reconstruction across events, D3 Morpheus FAQ and investigation pages 2026-07-22 | Partial |
| Deployment & Data ResidencyRuns on Azure infrastructure with data residency choice across four global regions, and on-premises deployment is available for regulated industries, D3 Morpheus product page 2026-07-22 | Full |
| Prebuilt Agents, Templates & PacksThe prebuilt Reasoning Graph and six console elements ship consistently across every customer tenant; playbooks are generated at runtime by design rather than from a template library, D3 Morpheus pages 2026-07-22 | Partial |
| Triggers & Channel CoverageEvery alert from the entire stack is autonomously investigated in under two minutes, with AI-discovered vulnerability findings handled as a second input class through the same engine, D3 Morpheus product pages 2026-07-22 | Full |
| Model Flexibility & RoutingA cybersecurity-specific threat LLM is internal to the platform; no customer-facing model choice or routing documented, D3 Morpheus materials 2026-07-22 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityBuilt-in SOAR engine and integration framework provide workflow extensibility atop any stack; a public API, SDK, or MCP surface was not retrieved, D3 Morpheus FAQ 2026-07-22 | Partial |
| Testing, Debugging & OptimizationContinuous testing against simulated attacks, adversarial inputs, and novel threat patterns with published results (87% attack path revelation rate, 94% investigation closure rate), D3 agentic SOC page 2026-07-22 | Partial |
| Browser & Computer UseNo browser or computer-use capability documented; Morpheus operates on ingested alert and telemetry data through integrations, D3 Morpheus materials 2026-07-22 | Unable to verify |
Pricing
Contact sales
annual platform subscription sized to the SOC, with an included envelope of AI investigations
What is public
The pricing structure is public (flat-rate annual subscription sized to the SOC, including platform, named analyst access, integrations, and an AI-investigation envelope) but no dollar amounts are disclosed.
Variable cost rationale
Flat-rate annual subscription with an included investigation envelope is explicitly designed to cap variable exposure for normal SOC operations; overage beyond the envelope is the main variable.
Sales call required
Yes — required for paid access
Free / trial
Not published
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Assail — Autonomous red teaming platform (Ares) whose AI agents discover,…
- Astelia — AI native exposure management platform from Israeli National Red…