Nebulock
Nebulock is an agentic, contextual security-analytics platform built for hunt-first security operations. A swarm of AI agents continuously hunts across cloud, SaaS, network, endpoint, and identity telemetry, maintaining a behavioral Context Graph to surface endpoint- and identity-based threats, close detection coverage gaps, and catch human and agentic insider threats before they escalate into incidents. The platform runs hypothesis-driven investigations, writes and deploys detection rules (Sigma and scheduled SQL), retrohunts historical data, simulates attacks, and maps coverage against MITRE ATT&CK. Nebulock exposes a customer-facing public API for Findings, Entities (actors/users/hosts correlation), Hunts, hunt suggestions and reports, and detection Rules, authenticated with per-organization API keys. The company raised a $25M Series A and is backed by Bain Capital Ventures.
Nebulock publishes 4 APIs on the APIs.io network, including Entities API, Findings API, Hunts API, and 1 more. Tagged areas include Company, Security, Threat Hunting, Threat Detection, and Security Operations.
Nebulock’s developer surface includes documentation, API reference, getting-started guide, engineering blog, support, authentication, and 18 more developer resources.
Kin Score
APIs 4
Individual APIs this provider publishes, each with its own machine-readable definition.
Nebulock Entities API
Actors, users, and hosts — the identity/asset correlation graph.
Nebulock Findings API
Retrieve and manage security findings and their comments.
Nebulock Hunts API
Threat hunts, hunt suggestions, and hunt reports.
Nebulock Rules API
Create, validate, and run detection rules (Sigma / scheduled SQL).
Arazzo Workflows 3
Multi-step API workflows described with the Arazzo specification.
_Index
ARAZZORun a Nebulock hunt and generate a report
Create a hunt, add a follow-up directive, then generate and fetch its report.
ARAZZOValidate and deploy a Nebulock detection rule
Validate rule content, create it inactive, then activate it.
ARAZZOMCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
nebulock-mcp.yml
MCP SERVERSecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 3
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 7
Pagination, idempotency, versioning, errors, and events
Scroll for all 7
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type