Defants
French DFIR startup building a collaborative, semantic incident-response and threat-hunting platform for resource-constrained security teams.
Visit Website ↗ + Add to CompareOverview
Defants is a French cybersecurity startup that builds an automated, collaborative digital forensics and incident response (DFIR) platform. Its flagship product, Defants vSIRT (also marketed as Defants AIR), applies a semantic-investigation approach to threat hunting and incident response, letting security analysts collaborate in real time on a single case rather than passing evidence between disconnected tools like SIEMs, EDR consoles, and spreadsheets.
The core pitch is speed and consistency in incident response: a no-code investigation interface that captures artifacts, timelines, and analyst reasoning in one place, aimed at helping thinly staffed security teams at SMEs and mid-caps respond to incidents without needing a dedicated, expensive DFIR specialist on staff. Defants also sells Defants Continuum, a continuous network monitoring service layered with IDS/IPS, and a professional service called Threat Check that assesses an organization’s historical and current threat exposure.
Founded in 2021 in Rennes and recognized by Gartner as a Cool Vendor shortly after its pre-seed raise, Defants is still an early-stage company competing against much larger, well-resourced DFIR and SOAR incumbents. Its differentiation rests on collaborative, semantic case-building rather than raw detection breadth, and its customer base and public case studies remain limited at this stage.
Innovation Matrix Assessment
Defants ships a focused DFIR product with continuous updates as a young company, but as a ~12-person startup its release cadence and platform breadth cannot yet be independently verified against larger SOAR/DFIR vendors.
The platform is delivered as a no-code case-management layer that integrates with existing SIEM/EDR tooling rather than replacing it, which lowers operational overhead for adopters, though real-world deployment friction at scale is not yet documented.
Defants raised roughly .1-2.3M in seed funding (Region Bretagne, Auriga Cyber Ventures, Cyber Impact Ventures, Breizh Up, business angels) in 2023 and earned a Gartner Cool Vendor mention, which is meaningful early traction but far short of proof of durable growth.
Semantic, collaborative case-building for DFIR is a genuinely different workflow model than legacy ticket-based incident response tools, targeting a real gap for under-resourced security teams, which supports a moderate disruption score despite the company's small size.
No independent, third-party test results (e.g., MITRE ATT&CK evaluations) or named enterprise case studies were found; efficacy claims are currently vendor-stated only, which caps this score until independent verification exists.
Faster, more collaborative incident response is directly relevant to CISOs facing analyst shortages, but Defants' relevance is currently concentrated in the French/European SME and mid-cap market rather than demonstrated globally.
Why CISOs Should Care
CISOs running lean security teams get a way to compress incident investigation time and standardize DFIR workflow without hiring specialized forensic staff.
What Makes It Different
Unlike ticket-based SOAR tools, Defants centers the workflow on real-time, semantic collaboration across a single investigation case rather than siloed alerts and playbooks.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
A promising but unproven early-stage DFIR platform; worth evaluating for resource-constrained security teams, but buyers should ask for reference customers and independent validation before relying on it for critical incident response.
Editorial Note: Claims vs. Verified Findings
Funding figures, Gartner Cool Vendor recognition, and product description are corroborated across multiple independent outlets (Gartner, Bretagne Economique, EU-Startups, Crunchbase). Performance/efficacy claims about investigation speed come only from Defants' own materials and have not been independently tested.
Sources
Alternatives to Defants
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…