Proofpoint has launched its SOC Analyst Agent, an agentic AI capability that uses OpenAI Daybreak models to help security teams investigate threats, connect signals across Proofpoint products, and automate recurring analysis.
Currently in private preview, the agent is designed to reduce the manual work involved in SOC investigations while keeping consequential remediation decisions in human hands. General availability is expected by the end of Q3 2026.
Proofpoint SOC Analyst Agent connects security signals
According to Proofpoint, the SOC Analyst Agent was built to address the “prioritization challenge” security teams currently face.
Citing its 2025 Data Security Landscape report, the company said 54% of organizations already use AI-enhanced capabilities to triage and investigate alerts, but SOC teams still need to connect signals across security systems and determine what deserves attention next.
“The challenge for security teams is to cut through the noise to quickly identify which signals matter and reach a defensible decision fast enough to act,” said Daniel Rapp, chief data and AI officer at Proofpoint.
“The Proofpoint SOC Analyst Agent brings together our security expertise and data with advanced AI reasoning from OpenAI to give analysts a faster path from investigation to action, while keeping people in control of consequential security decisions.”
The SOC Analyst Agent plans investigations and draws context from connected Proofpoint security data, including alerts, logs, data loss prevention (DLP) events, and user risk signals.
Natural-language investigations target SOC alert overload
Instead of switching between consoles or writing individual queries, Proofpoint says that with SOC Analyst Agent, analysts can use natural language to investigate security events and synthesize findings across connected Proofpoint products.
The agent is designed around three core capabilities:
- Accelerate investigations: Analysts can investigate security events using natural language across connected Proofpoint products, reducing the manual work needed to assemble context.
- Automate recurring analysis: Teams can configure scheduled workflows for threat hunts, data security investigations, and escalation reporting, with results routed to appropriate analysts.
- Keep analysts in control: Findings are traceable to the underlying source data, allowing analysts to validate recommendations. The agent does not independently make account changes, contain threats, or initiate other consequential remediation actions.
Proofpoint expands its use of OpenAI Daybreak models
Proofpoint joined the OpenAI Daybreak Defense Network in June 2026, with plans to apply OpenAI’s cyber-focused models across its products, services, and security workflows.
The company is now exploring additional uses for the models across threat research, data security, and AI security. Potential applications include helping threat researchers trace confirmed malicious findings across networks and supporting workflows that move from detection and investigation to recommended fixes for human review.
“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, head of global cyber partnerships at OpenAI.
“Proofpoint’s SOC Analyst Agent shows how frontier AI can help defenders move faster without giving up control. By combining Proofpoint’s security data and human-behavior expertise with OpenAI’s Daybreak models, analysts can turn fragmented signals into clearer findings, faster investigations, and recommended next steps they can trust.”
Proofpoint recently launched a new OEM Program for security vendors and MSPs looking to embed its threat intelligence and detection capabilities into their own offerings. Read more about the program and what it offers security providers, vendors, and MSPs.





