Singapore – Proofpoint has launched the Proofpoint SOC Analyst Agent, an agentic AI tool designed to help security operations teams investigate threats more quickly across the company’s security data.
According to Proofpoint, the tool is the first capability to emerge from its collaboration with the OpenAI Daybreak Defense Network, bringing OpenAI’s Daybreak cyber-tuned models into Proofpoint’s investigation workflows.
The company says the SOC Analyst Agent converts natural-language questions into structured, traceable findings and recommended next steps, while keeping consequential security decisions with human analysts.
The launch comes as security teams contend with a mounting prioritisation challenge, with alerts and security data multiplying across tools and workflows.
Citing its 2025 Data Security Landscape report, Proofpoint says more than half of organisations (54%) already use AI-enhanced capabilities to triage and investigate alerts.
However, the company notes that SOC teams still need to connect signals across security systems, establish context, and determine what deserves attention next.
Proofpoint says the SOC Analyst Agent is intended to reduce this investigative burden, giving defenders a faster path from fragmented signals to informed action.
“The challenge for security teams is to cut through the noise to quickly identify which signals matter and reach a defensible decision fast enough to act,” said Daniel Rapp, Chief Data and AI Officer at Proofpoint.
“The Proofpoint SOC Analyst Agent brings together our security expertise and data with advanced AI reasoning from OpenAI to give analysts a faster path from investigation to action, while keeping people in control of consequential security decisions,” Rapp added.
Meanwhile, McCall McIntyre, Head of Global Cyber Partnerships at OpenAI, framed the launch within the broader aims of the Daybreak Defense Network.
“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” McIntyre said.
“Proofpoint’s SOC Analyst Agent shows how frontier AI can help defenders move faster without giving up control. By combining Proofpoint’s security data and human-behavior expertise with OpenAI’s Daybreak models, analysts can turn fragmented signals into clearer findings, faster investigations, and recommended next steps they can trust,” McIntyre further explained.
In terms of functionality, the SOC Analyst Agent plans investigations and draws context from connected Proofpoint security data, including alerts, logs, data loss prevention events, and user risk signals.
Rather than switching between consoles or writing individual queries, Proofpoint says analysts can use natural language to synthesise findings and resolve issues faster.
The agent is built around three core capabilities, according to Proofpoint.
First, it aims to accelerate investigations, allowing analysts to investigate security events using natural language across connected Proofpoint products and reducing the manual work required to assemble context.
Second, it is designed to automate recurring analysis, enabling teams to configure scheduled workflows for activities such as threat hunts, data security investigations, and escalation reporting, with results routed to the appropriate analysts.
Third, Proofpoint says the tool is built to keep analysts in control, with findings traceable to underlying source data so analysts can validate recommendations.
Notably, the company states that the agent does not independently make account changes, contain threats, or initiate other consequential remediation actions.
The SOC Analyst Agent marks the first capability Proofpoint has brought to market through the Daybreak Defense Network, which it joined in June 2026 to apply OpenAI’s cyber-tuned models across its products, services, and workflows.
Looking ahead, Proofpoint says it is also exploring how OpenAI’s Daybreak models could support additional defensive security workflows across its portfolio, including threat research, data security, and AI security.
Future work, the company suggests, could include using AI reasoning to help threat researchers trace confirmed malicious findings across the network, strengthening detection coverage.
Proofpoint also points to the possibility of building a closed-loop approach to data and AI security that moves from detection to investigation to a recommended fix for human review.

