Dropzone AI launches threat hunter for security teams
Fri, 31st Jul 2026 (Today)
Dropzone AI has launched general availability of its AI Threat Hunter product, aimed at enterprises, managed security service providers and government agencies.
The product is designed to make threat hunting a routine security operations task rather than an occasional specialist exercise. It runs scheduled hunts across security systems and produces findings for analysts to review and act on.
Threat hunting sits alongside conventional alerting in cybersecurity operations. Alerts are built to flag activity that matches known rules or suspicious patterns, while hunting looks for threats, risks and gaps that may not trigger those alerts.
That work has often been difficult to sustain. Security teams typically need experienced staff, tailored queries and long blocks of analyst time to carry out a single hunt, which can limit how often the work is done or stop it altogether.
AI Threat Hunter uses a library of more than 270 prebuilt hunt packs mapped to attacker behaviour and the MITRE ATT&CK framework. Each pack contains between five and 10 hunts, and the system can return results in around one to two hours for tasks that previously took far longer.
The product is already being used to run federated hunts across platforms including Splunk, Microsoft Sentinel, CrowdStrike NG-SIEM, Elastic and Panther. It also highlights visibility gaps, policy violations, misconfigurations and potential detection opportunities alongside active threats, according to Dropzone AI.
Broader push
The release extends Dropzone AI's effort to build a broader set of automated security tools for security operations centres. More than 300 enterprises and managed security providers already use its platform, according to the company.
Among the customer examples it cited, Zapier reduced triage time from 10 to 15 minutes to under two minutes, UiPath saved more than 700 analyst hours and cut false positives by 86%, and Assala Energy achieved full alert investigation and faster response times with a smaller team.
Dropzone AI said beta use of AI Threat Hunter automated the equivalent of 200 years of hunting work. Further additions are planned, including custom hypothesis-based hunts, support for more data sources and closer links with its AI SOC Analyst product.
Cybersecurity vendors have increasingly focused on automation as defenders face growing alert volumes, broader attack surfaces and persistent staffing shortages. That has led many suppliers to pitch systems that can take on parts of triage, investigation and response that were previously handled manually.
Dropzone AI is positioning AI Threat Hunter for the less visible part of that workload. Rather than reacting to what detection rules already surface, the tool is intended to help teams systematically search for signs of compromise or weak points that might otherwise remain unnoticed.
Edward Wu, Founder and Chief Executive Officer of Dropzone AI, described the launch as a response to the imbalance between attackers and defenders.
"Attackers already operate at machine speed. Compute, not skill, is their bottleneck now, and defenders can't out-hire that gap. AI Threat Hunter lets any team proactively identify undetected intrusions at the same speed, turning hunting from a once-a-year luxury into an operational habit and levelling a field that's been tilting toward attackers for years. Analysts can now stay focused on the judgment only they can give rather than the mechanics of building and running hunts," Wu said.
The company also pointed to feedback from early use in operational settings.
"AI Threat Hunter ran this without pulling a single person off their queue, and by the end of it we had a clear, evidence-backed finding we could take straight to leadership. That's the kind of leverage a security team actually needs," Spillman said.