D3 Security Morpheus

Agentic SOC platform doing autonomous triage, attack-path investigation and response execution

ToolTier 2 SOC AutomationCloudSelf-hosted

Pricing: Not published. The vendor describes a fixed annual subscription tied to a daily alert volume tier, from 500 to 10,000 alerts per day with custom pricing above that, plus named user licences and no per-alert fees.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is D3 Security Morpheus?

D3 Security is a Vancouver-based automation vendor that built SOAR products before launching Morpheus, which it describes as an accountable agentic SOC platform. The vendor states that Morpheus autonomously handles both first-line triage and second-line work: full attack path investigation, blast radius assessment and playbook generation, without analyst intervention. An Attack Path Discovery engine produces an attack narrative, horizontal and vertical attack paths, MITRE ATT&CK mapping and a timeline, and Morpheus generates and executes response playbooks at runtime. It claims more than 800 integrations and supports cloud, on-premise, hybrid and air-gapped deployment. Named customers on the vendor site include PwC, Scotiabank and S&P Global.

Best for: Enterprise SOCs and MSSPs that want autonomous second-line investigation and response execution, including teams that need on-premise or air-gapped deployment.
Pros
  • The vendor FAQ states second-line investigation, blast radius assessment and runtime response playbooks explicitly (d3security.com/faq)
  • Offers cloud, on-premise, hybrid and air-gapped deployment, which most agentic SOC vendors do not (d3security.com/faq)
  • SOC 2 Type II stated by the vendor
  • Rated 4.2 out of 5 across 69 reviews on G2 (g2.com/products/d3-security/reviews)
Things to check
  • Performance claims, including investigating 95% of alerts in under two minutes, are vendor-stated and unaudited
  • Independent coverage of Morpheus is largely syndicated vendor content rather than analyst evaluation
  • The vendor FAQ does not mention threat hunting; that capability is claimed only on the vendor blog
  • SOC 2 Type II only; no ISO 27001 or FedRAMP authorisation found

Reported in public reviews and vendor documentation. See sources below.

Key Features

Autonomous first-line triage and second-line attack path investigation
Blast radius assessment, lateral movement mapping and full-stack timeline reconstruction
MITRE ATT&CK mapping per incident
Runtime response playbook generation and execution, positioned as a SOAR replacement
More than 800 integrations with drift detection
Cloud, on-premise, hybrid and air-gapped deployment

Are you D3 Security Morpheus? Improve this listing with screenshots, case studies and more.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent D3 Security Morpheus? Request a correction.

Quick Info
PricingNot published. The vendor describes a fixed annual subscription tied to a daily alert volume tier, from 500 to 10,000 alerts per day with custom pricing above that, plus named user licences and no per-alert fees.
ModelAnnual subscription by alert volume tier plus named users; quote-based
Founded2002
CloudYes
Self-HostedYes

Last updated: Aug 20, 2026

Certifications
SOC 2 Type II (vendor-stated)Microsoft Intelligent Security Association member (vendor-stated)