Prophet AI Launches Detection Engineer to Close SOC Blind Spots and Cut Alert Noise
- Jul 30
- 2 min read
New AI security tool maps MITRE ATT&CK coverage, writes and tests detection rules, and works with existing SIEM platforms
Security operations teams have spent years trying to investigate alerts faster. Prophet Security now wants artificial intelligence to improve the detections that generate those alerts in the first place.
The company has introduced Prophet AI Detection Engineer, an AI-powered detection engineering system designed to identify security coverage gaps, create and tune detection rules, and test changes before they reach production.
The product extends Prophet Security’s existing AI SOC platform. Its Prophet AI SOC Analyst investigates alerts and determines whether activity is malicious. The new detection engineering agent uses those investigation results to evaluate whether an organization’s detection program is finding meaningful threats or merely maintaining a large inventory of enabled rules.
That distinction matters because a security alert can only be investigated if a detection exists and fires. Missing or ineffective rules can allow attacker activity to pass through a security environment without triggering a response.
Prophet AI Detection Engineer creates a continuously updated MITRE ATT&CK coverage map based on an organization’s detections, telemetry, and previous investigations. Techniques are categorized as observed, covered, or uncovered.
Observed techniques have generated meaningful investigations. Covered techniques have detections in place but have not produced investigative evidence. Uncovered techniques have no active monitoring.
The system then ranks recommended actions based on potential security impact. It can author new detections in the language required by a customer’s security platform, tune noisy rules, suggest suppressions, identify missing telemetry, and create threat-hunting priorities for areas with limited coverage.
Prophet Security is positioning backtesting as a central safeguard. Proposed rules are evaluated against the customer’s historical data so security teams can estimate alert volume, detection effectiveness, and false-positive risk before deployment.
Changes are delivered as version-controlled recommendations that include supporting evidence, testing results, rationale, and confidence assessments. Human approval remains the default, although customers can increase automation for selected detection engineering activities.
The platform initially supports Splunk, Sumo Logic, and Microsoft Sentinel. Prophet says detections remain portable rather than being locked into a proprietary analytics platform, allowing customers to improve their existing security information and event management systems without replacing them.
The larger goal is to create a feedback loop across detection, investigation, and threat hunting. Alert investigations reveal weak or noisy rules. Those findings improve future detections, while threat hunting searches for activity that existing rules missed.
Prophet AI Detection Engineer is available to customers using Prophet AI SOC Analyst.


