D3 Security Morpheus
Agentic SOC platform doing autonomous triage, attack-path investigation and response execution
ToolTier 2 SOC AutomationCloud, Self-hosted
Pricing: Not published. The vendor describes a fixed annual subscription tied to a daily alert volume tier, from 500 to 10,000 alerts per day with custom pricing above that, plus named user licences and no per-alert fees.
Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings
What is D3 Security Morpheus?
D3 Security is a Vancouver-based automation vendor that built SOAR products before launching Morpheus, which it describes as an accountable agentic SOC platform. The vendor states that Morpheus autonomously handles both first-line triage and second-line work: full attack path investigation, blast radius assessment and playbook generation, without analyst intervention. An Attack Path Discovery engine produces an attack narrative, horizontal and vertical attack paths, MITRE ATT&CK mapping and a timeline, and Morpheus generates and executes response playbooks at runtime. It claims more than 800 integrations and supports cloud, on-premise, hybrid and air-gapped deployment. Named customers on the vendor site include PwC, Scotiabank and S&P Global.
Best for: Enterprise SOCs and MSSPs that want autonomous second-line investigation and response execution, including teams that need on-premise or air-gapped deployment.
Pros
- The vendor FAQ states second-line investigation, blast radius assessment and runtime response playbooks explicitly (d3security.com/faq)
- Offers cloud, on-premise, hybrid and air-gapped deployment, which most agentic SOC vendors do not (d3security.com/faq)
- SOC 2 Type II stated by the vendor
- Rated 4.2 out of 5 across 69 reviews on G2 (g2.com/products/d3-security/reviews)
Things to check
- Performance claims, including investigating 95% of alerts in under two minutes, are vendor-stated and unaudited
- Independent coverage of Morpheus is largely syndicated vendor content rather than analyst evaluation
- The vendor FAQ does not mention threat hunting; that capability is claimed only on the vendor blog
- SOC 2 Type II only; no ISO 27001 or FedRAMP authorisation found
Reported in public reviews and vendor documentation. See sources below.
Key Features
Do you work at D3 Security Morpheus? to confirm the details or send us a correction.
Add the Cyber Vendor Guide badge to your site
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent D3 Security Morpheus? Request a correction.
Key facts
- Pricing
- Not published. The vendor describes a fixed annual subscription tied to a daily alert volume tier, from 500 to 10,000 alerts per day with custom pricing above that, plus named user licences and no per-alert fees.
- Model
- Annual subscription by alert volume tier plus named users; quote-based
- Founded
- 2002
- Cloud
- Yes
- Self-hosted
- Yes
D3 Security Morpheus Alternatives
- ExaforceAgentic SOC platform with separate agents for detection, tri...
- Legion SecurityAgentic security operations platform that learns analyst wor...
Certifications
SOC 2 Type II (vendor-stated), Microsoft Intelligent Security Association member (vendor-stated)