Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models

Proofpoint’s SOC Analyst Agent uses OpenAI Daybreak models to help security teams investigate threats, connect signals, and automate recurring analysis.

Written By
Luis Millares
Luis Millares
Sep 8, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Proofpoint has launched its SOC Analyst Agent, an agentic AI capability that uses OpenAI Daybreak models to help security teams investigate threats, connect signals across Proofpoint products, and automate recurring analysis.

Currently in private preview, the agent is designed to reduce the manual work involved in SOC investigations while keeping consequential remediation decisions in human hands. General availability is expected by the end of Q3 2026.

Proofpoint SOC Analyst Agent connects security signals

According to Proofpoint, the SOC Analyst Agent was built to address the “prioritization challenge” security teams currently face. 

Citing its 2025 Data Security Landscape report, the company said 54% of organizations already use AI-enhanced capabilities to triage and investigate alerts, but SOC teams still need to connect signals across security systems and determine what deserves attention next.

“The challenge for security teams is to cut through the noise to quickly identify which signals matter and reach a defensible decision fast enough to act,” said Daniel Rapp, chief data and AI officer at Proofpoint. 

“The Proofpoint SOC Analyst Agent brings together our security expertise and data with advanced AI reasoning from OpenAI to give analysts a faster path from investigation to action, while keeping people in control of consequential security decisions.”

The SOC Analyst Agent plans investigations and draws context from connected Proofpoint security data, including alerts, logs, data loss prevention (DLP) events, and user risk signals.

Natural-language investigations target SOC alert overload

Instead of switching between consoles or writing individual queries, Proofpoint says that with SOC Analyst Agent, analysts can use natural language to investigate security events and synthesize findings across connected Proofpoint products.

The agent is designed around three core capabilities:

  • Accelerate investigations: Analysts can investigate security events using natural language across connected Proofpoint products, reducing the manual work needed to assemble context.
  • Automate recurring analysis: Teams can configure scheduled workflows for threat hunts, data security investigations, and escalation reporting, with results routed to appropriate analysts.
  • Keep analysts in control: Findings are traceable to the underlying source data, allowing analysts to validate recommendations. The agent does not independently make account changes, contain threats, or initiate other consequential remediation actions.
Advertisement

Proofpoint expands its use of OpenAI Daybreak models

Proofpoint joined the OpenAI Daybreak Defense Network in June 2026, with plans to apply OpenAI’s cyber-focused models across its products, services, and security workflows.

The company is now exploring additional uses for the models across threat research, data security, and AI security. Potential applications include helping threat researchers trace confirmed malicious findings across networks and supporting workflows that move from detection and investigation to recommended fixes for human review.

“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, head of global cyber partnerships at OpenAI.

“Proofpoint’s SOC Analyst Agent shows how frontier AI can help defenders move faster without giving up control. By combining Proofpoint’s security data and human-behavior expertise with OpenAI’s Daybreak models, analysts can turn fragmented signals into clearer findings, faster investigations, and recommended next steps they can trust.”

Proofpoint recently launched a new OEM Program for security vendors and MSPs looking to embed its threat intelligence and detection capabilities into their own offerings. Read more about the program and what it offers security providers, vendors, and MSPs.

Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.