Corma is back out of stealth with a new defensive cybersecurity AI-model and a fresh round of funding totaling $60 million. The company deliberately doesn’t position itself as “general-purpose AI,” but as a foundation for defense against attacks that are becoming faster and more sophisticated.
Development focuses on analyzing large volumes of security data, so deviations in behavior and chains of events become clearer over time. At the same time, Corma aims to translate this into practical support for teams working in operational security environments.
What Corma is building
Corma was founded in 2025 and has headquarters in Tel Aviv and San Francisco. Alon Pluda is one of the co-founders and serves as CEO. In the seed round, the company raised $60 million from, among others, Sequoia Capital, Khosla Ventures, and Coatue.
The core product is a foundation model designed for defensive cybersecurity operations. That means the model processes security telemetry such as system events, audit logs, and network traffic. It then looks for subtle signals of anomalies—especially when those patterns only “start to add up” over longer periods.
Security telemetry as fuel for longer-term detection
While many detection approaches rely on individual signals, Corma focuses on connecting clues from multiple sources. The approach centers on recognizing complex threat evaluations: not just “is something suspicious?”, but also “how does this fit into a broader chain?”.
This time dimension matters because multi-stage attacks often consist of several steps that—on their own—may be less noticeable. By combining events and context for longer, the model can better identify when a sequence of actions together forms an attack.
Agents that work alongside your existing security infrastructure
A second pillar is real-world usability day to day. Corma pairs the model with automated agents that can operate directly alongside existing security infrastructure. The agents are meant to take over or support defensive tasks, while human staff remain actively engaged in their roles.
According to Corma, this works iteratively: because the environment where the agents operate is continuously fed into the learning process, they can adapt to the specified enterprise context. The system therefore targets detection and neutralization of threats, including multi-stage intrusions.
Why Corma emphasizes that it’s built for defense
The company says it has run tests with OpenAI and Anthropic AI models. In those experiments, the models would be able to carry out end-to-end attacks, but they failed when it came to defending against the same types of attacks.
This point is at the heart of the company’s message: attacks can gain speed and sophistication through AI in ways that teams and general tooling don’t always keep up with. That’s why, CEO Pluda says, Corma believes a AI-driven defensive force is needed—built from the start for cyber defense, with comparable speed and generalization to what attackers are already using.
What this could mean for SOCs and incident response
If the workflow Corma describes works in practice, the gains for security teams mainly come down to two things: faster translation of signals into actions and better context, since the model brings together time series and multiple telemetry sources.
Agents that can automatically collaborate with your security stack can also help speed up routine work—ranging from assembling context around suspicious events to supporting next steps during potential incidents. Human oversight remains crucial, but it may reduce pressure during peak moments.
For organizations that already invest in modern analytics capabilities, the practical question remains: how well does an AI system align with existing processes, tooling, and logging? Corma’s claim is that the agents can integrate into today’s infrastructure—that’s exactly what teams need to deliver value without rebuilding everything from scratch.
AI attacks vs. AI defense: the bigger picture
Corma’s move fits into a broader trend: attacks are increasingly being supported by AI and automated workflows. As a result, the conversation shifts from “can we detect something?” to “can we respond effectively too?”.
It also helps to look at recent examples of how attackers misuse technology—and how defenders need to organize themselves. Curious how AI attack techniques relate to concrete risks? Read also: AI attacks, Metabase 0-day, and backdoors.
Practical points to consider when adopting defensive AI
Even with a strong foundation, there are always practical considerations. Organizations would do well to focus on data quality and data coverage when evaluating a defensive AI model. If certain logs are missing or inconsistent, it becomes harder to correctly interpret anomalies over time.
In addition, it’s important to define how the agents behave: do they mainly support detection and triage, or can they also take actions toward systems? The more autonomy you give them, the higher the requirements for auditing, evaluation, and alignment with incident response procedures.
Finally, it’s worth checking how the system performs against the types of threats that match your own environment. Corma’s approach to learning from the environment may be valuable, but the outcome always depends on implementation and management.
Conclusion
Corma is betting on a defensive cybersecurity AI-model with a defense-first approach that analyzes security telemetry and turns it into automated agents that collaborate with SOC teams. With $60 million in seed funding, the company wants to bring speed and sophistication in defense closer to the level attackers currently operate at.
For organizations, the core remains: integration with existing infrastructure, sufficient and correct logging, and clear agreements on how the agents help with detection and response. If Corma delivers on these promises, this could be an interesting step in the race between attack technology and defensive capability.
Related reading: AI attacks, Metabase 0-day, and backdoors
Source: https://www.securityweek.com/corma-raises-60-million-for-defensive-cybersecurity-ai-model/
