Cribl, the security telemetry platform provider, has acquired CardinalOps, adding agentic AI-based detection engineering to its product portfolio. The deal, announced Tuesday, is designed to help customers move beyond collecting and routing telemetry, giving them the tools to act on it. By integrating CardinalOps, Cribl now offers a more complete stack that includes detection capability alongside its established data collection, transformation, routing, and storage offerings.
Cribl's suite of products has gained significant traction among large enterprises, which use it to manage security telemetry across SIEM systems, data lakes, and other tools. The CardinalOps acquisition is a strategic step toward becoming a direct participant in detection engineering and security operations center (SOC) outcomes. The technology will allow Cribl customers to map detection rules and security controls to the MITRE ATT&CK framework, an industry-standard knowledge base of adversary tactics and techniques. This mapping reveals where coverage gaps exist and helps operationalize threat intelligence, turning raw data into actionable security insights.
Closing the Gap Between Telemetry and Action
Nicole Beckwith, Cribl's senior director of security engineering and operations, says CISOs are increasingly being asked difficult questions about their organization's MITRE ATT&CK coverage. Boards and executives want to know whether security controls are aligned with known threat patterns and whether the detection stack is actually capable of identifying adversary behavior. "With mapping to MITRE, you can really see where your gaps in coverage are in visibility," Beckwith says. "They find and fix those broken and noisy rules and then unlock the value of your entire security stack."
CardinalOps will help Cribl customers shift from just collecting telemetry to acting on it, Beckwith adds. The acquisition is not merely about adding more data points; it is about validating detection coverage. "Customers are going to be able to not only see all the telemetry they have but then validate that detection coverage," she says. This validation process is critical because many organizations struggle with thousands of detection rules, many of which are outdated, overly noisy, or fail to align with the actual threat landscape. CardinalOps automates the process of reviewing and optimizing these rules, ensuring that security teams are alerted to genuine threats without being overwhelmed by false positives.
An Alternative to Legacy SIEM
Beckwith believes the CardinalOps acquisition will enhance Cribl's platform enough to make it a credible alternative to legacy SIEM stacks. Many organizations have outgrown their traditional SIEM deployments, which are often expensive, complex, and difficult to scale. "Together, this acquisition is going to help strengthen our platform by adding those really deep detection capabilities to our product," she says. "It gives customers basically an alternative to the SIEM stack that they've outgrown." Instead of relying on a central, monolithic SIEM, Cribl customers can use a more flexible, data-centric approach where telemetry is routed to the best tool for each use case and detection rules are continuously tuned.
The acquisition is "strategically logical," notes Sean Sosnowski, research director at Software Analyst Cyber Research. "Cribl is moving from being primarily the enterprise security and observability data control layer toward becoming a more direct participant in detection engineering and SOC outcomes," he says. This shift reflects a broader market trend where security teams are looking for platforms that go beyond data collection and offer actionable insights. The connection between Cribl and CardinalOps will enhance Cribl's platform by linking data engineering decisions to SOC effectiveness, rather than treating pipeline optimization and detection engineering as separate problems.
"If Cribl can combine telemetry control with detection posture management, it can help customers move from 'we have too much data' to 'we know which data matters for the detections we need,'" Sosnowski explains. That value proposition is compelling because it directly addresses the biggest pain point for modern security teams: data overwhelm. By integrating CardinalOps, Cribl can help customers identify which telemetry is essential for detecting specific threats, route the appropriate data to the right tools, and continuously improve detection coverage without requiring analysts to juggle multiple disconnected consoles.
Executing on the Promise
However, Sosnowski warns that Cribl's ability to deliver on that promise is contingent on effectively integrating the technology. The workflow must be seamless: identify detection gaps, determine the required telemetry, route or transform the right data, and help SOC teams improve coverage—all without adding another disconnected console. "If it becomes a loosely coupled product bundle, the impact will be more limited," he says. The integration challenge is significant, but Cribl has a track record of building products that are designed to interoperate with existing security infrastructure, making it well-positioned to overcome this hurdle.
Cribl's Rapid Growth
San Francisco-based Cribl was founded in 2018 by a team of former Splunk architects who sought to build a scalable telemetry-processing platform. From its inception, the company focused on solving a practical problem: security and IT teams were producing too much telemetry, sending it to too many tools, and paying too much to store and analyze it without sufficient control over data routing. Cribl's approach allowed organizations to collect data from any source, transform it on the fly, and route it to the right destination—whether that be a SIEM, a data lake, or a cloud storage service.
The company has experienced rapid growth since its founding. In its first four years, annual recurring revenue (ARR) increased from $1 million to $100 million, a remarkable trajectory for a security startup. Growth accelerated sharply after that, reaching $200 million in ARR in late 2025 and surpassing $300 million as of February 2026. Cribl has raised more than $600 million in funding and was valued at $3.5 billion after a roughly $320 million Series E round led by GV in 2024. The capital influx has enabled the company to expand its product portfolio and invest in strategic acquisitions like CardinalOps.
Adoption Among Large Enterprises
According to Cribl, more than half of the Fortune 100 and 35% of the Fortune 500 use its platform. This widespread adoption is a testament to the platform's utility and reliability. The company employs more than 1,000 people, and its recent hires reflect its focus on deepening security expertise. One of the latest additions is Nicole Beckwith, who joined Cribl as senior director of security engineering and operations. Beckwith previously served as director of detection and response at Kroger, the US grocery store giant, where she was responsible for the organization's detection program. Kroger uses both Cribl and CardinalOps, giving Beckwith firsthand experience with how the two technologies work together.
Beckwith was brought to Cribl by CISO Myke Lyons, another former security leader who joined the company to help build out its security strategy. "I believe in everything that they're doing and their roadmap," Beckwith says. "So when the opportunity arose to come over here, I jumped at it." Her experience highlights the growing overlap between security operations and security engineering, a trend that the CardinalOps acquisition aims to accelerate.
The acquisition also signals Cribl's ambitions to expand beyond its core telemetry platform. By adding detection engineering capabilities, Cribl is positioning itself as a comprehensive security operations platform. This is particularly relevant in a landscape where organizations are consolidating their security tooling and seeking platforms that can address multiple aspects of the security workflow. The ability to map detection rules to MITRE ATT&CK is a sought-after feature, as it provides a clear framework for understanding how well an organization's security controls align with known threat behaviors.
Implications for the Security Operations Market
The deal comes at a time when security operations teams are under increasing pressure to demonstrate their effectiveness. High-profile breaches and rising regulatory requirements have made it clear that traditional approaches to detection and response are insufficient. Agentic AI—the application of AI agents that can perform tasks autonomously—is emerging as a promising solution to this challenge. CardinalOps has been at the forefront of this trend, using AI to automate the tuning of detection rules and streamline the detection engineering process.
For Cribl, the acquisition is a natural extension of its existing capabilities. The platform already gives organizations control over their data, but that control is only valuable if it translates into better security outcomes. With CardinalOps, Cribl customers can turn their telemetry into actionable intelligence, identifying the most critical threats and ensuring that their detection infrastructure is optimized to catch them. This integration would be particularly valuable for organizations that are dealing with a high volume of alerts and a shortage of skilled analysts.
The move also reflects a broader industry shift toward platform consolidation. Security teams are increasingly looking for tools that can replace multiple point products, reducing complexity and operational overhead. Cribl's expansion into detection engineering is likely to appeal to enterprises that already use its telemetry platform and are looking for ways to derive more value from their security data. By offering a more complete stack, Cribl is positioning itself as a strategic partner for security teams rather than just a utility.
As the security operations market evolves, the boundary between data collection, detection, and response is becoming increasingly blurred. The CardinalOps acquisition is an acknowledgment that these functions are not separate activities but rather part of a continuous loop. Data feeds detection, detection informs response, and response generates new data that needs to be collected and analyzed. By integrating all of these pieces, Cribl aims to close the loop and help organizations build a truly effective security program.
Industry analysts have noted that the success of the acquisition will depend on how well Cribl integrates CardinalOps' technology into its platform. The two companies have complementary products, and their integration could produce significant synergies. However, integration is never a trivial task, and Cribl will need to ensure that its customers can take advantage of the new capabilities without encountering disruptions or added complexity. The company has a strong track record of executing on its roadmap, and the CardinalOps team is expected to bring valuable expertise to the table.
For its customers, the acquisition promises to deliver a more actionable security platform. The ability to map detection rules to MITRE ATT&CK is just the beginning. CardinalOps also helps operationalize threat intelligence, ensuring that the latest intelligence on adversarial tactics is incorporated into detection logic. This is a critical capability in today's threat landscape, where attackers are constantly evolving their methods. By automating this process, Cribl aims to give its customers a measurable improvement in their security posture.
In her new role, Beckwith will be responsible for driving the integration of CardinalOps and ensuring that customers see the value of the combined offering. She brings a pragmatic perspective shaped by her experience on the front lines of security operations. Her appointment is a signal that Cribl is serious about becoming a leader in detection engineering and helping organizations navigate the complexity of modern security operations.
Source: Dark Reading News