
Work Here?
Red Canary provides managed detection and response (MDR) cybersecurity services for a wide range of industries. It collects high-fidelity telemetry to continuously monitor environments, using endpoint detection and response (EDR) and security operations to detect threats, with behavioral analytics, 24/7 expert threat investigation, and automated playbooks to accelerate response. It differentiates itself by aiming for measurable outcomes—reducing risk over time and improving security quickly—through constant monitoring and expert analysis. Its goal is to help clients strengthen their security posture with a subscription-based service that delivers ongoing protection and risk reduction.
Industries
Enterprise Software
Cybersecurity
Company Size
201-500
Company Stage
Series C
Total Funding
$129.9M
Headquarters
Denver, Colorado
Founded
2013
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$129.9M
Above
Industry Average
Funded Over
5 Rounds
Industry standards
Health Insurance
Dental Insurance
Vision Insurance
Mental Health Support
Unlimited Paid Time Off
Parental Leave
Health Savings Account/Flexible Spending Account
Remote Work Options
Stock Options
Train, triage, repeat: The AI agent changing how Red Canary Inc. fight phishing. Learn how Red Canary engineered a super agent - blending ML, a rules engine, similarity, agentic AI, and LLMs - to classify phishing emails. With 94% accuracy, it makes the case for what a hybrid AI SOC can achieve. June 30, 2026 Red Canary Inc. has already established that artificial intelligence is raising the bar for adversaries. This is especially the case when it comes to crafting phishing messages. These days, an AI tool can make personal and well-formatted phishing emails that seem legit, even to a trained analyst. Advances in adversarial deception and the sheer volume of potential phishing emails have pushed defenders to innovate. The Anti-Phishing Working Group (APWG) observed over 3.8 million phishing attacks in 2025 - with Q2 alone accounting for more than 1.1 million, the highest quarterly total in two years. At that scale, no team can tackle triage unaided. That's why Red Canary has equipped its phishing analysts with an AI triage agent built to handle the bulk of the triage work at scale. How does it work? Red Canary Inc. has learned that using one catch-all agent that is ok at doing many tasks is not very reliable or scalable. For this reason, Red Canary Inc. assembled a team of orchestrated subagents, integrated as a complex graph workflow that manages each of the agentic loops, chains and deterministic nodes. Each subagent is tightly scoped to specific subtasks of an email investigation and the whole agentic workflow, paired with a feedback loop, gives Red Canary Inc. accuracy of 94%. Email parsing and enrichment. The first subagent to see a reported email is its parsing and enrichment agent. Starting with the raw email, the subagent parses it into a standard data object to streamline analysis in the workflow. The subagent enriches the metadata with external services giving domain reputation, abuse levels and flagging other indicators from past phishing campaigns. Traditional and AI-powered feature extraction. The next subagent in the workflow is its feature extraction agent. This subagent analyzes the parsed email and produces a set of true/false features that drive the triage process. Features come from two sources: traditional code checks that follow classic boolean logic, where a feature is true if a condition is met, and AI-powered checks where the subagent uses carefully crafted prompting to return true/false values along with reasoning. Leveraging AI for feature extraction enables much richer signals powered by Natural Language Processing (NLP), capturing sentiment, intent, and emotion, all distilled into simple true/false features. Rules engine and deterministic outcomes. Before information reaches the classification subagent, it is first run through its rules engine. While its triage agent is highly accurate overall, AI is not perfect; the rules engine ensures deterministic outcome. Rules support both raw email data and extracted features, enabling TTP-level detection that pairs rich NLP features with atomic indicators from the email metadata. The rules engine can also be fine-tuned to fit specific customer environments, which is essential since each environment has unique characteristics that influence false positive rates. Rules can also be created from intelligence on emerging campaigns, eliminating the chance of the classification subagent missing novel phishing threats. Hybrid AI/ML classification. When no rule matches are found, its classification subagent makes the final decision. Extracted features are used to train a classical ML model on emails previously assessed by its analysts. The model is trained exclusively on true/false feature value, no customer data or email content is ever used in training. The feature importance weights from the trained model are then added to the classification prompt, allowing the subagent to factor them into its assessment, creating a hybrid AI/ML approach. After reaching a final classification, the subagent, a reasoning deep agent, generates a summary and explanation detailing the reasoning behind its decision. Transparent by design. Regardless of where the classification takes place, all classifications will have a category, a high level summary and a deeper explanation of the classification. The feature values and feature explanations can also be seen for those who want a deeper understanding of how the agent actually makes its decision. Always learning. As this is a new technology, Red Canary Inc. is constantly reviewing and refining its agent with analyst-driven feedback loops. These feedback loops not only improve the agent but maintain its adaptability - with analysts at the helm, continuously shaping new features and capabilities. A hybrid approach is the great enabler in the cat and mouse game of phishing technologies, allowing the analysts to focus on the more nuanced, bespoke phishing techniques while the agent does the bulk of the work. The dual-use dilemma: Rethinking detection for remote access tool abuse. How threat hunting evolves at scale. Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents. * Threat detection Investigating suspicious AI workflows in Microsoft Entra Agent ID: Agent's user account. You'll receive a weekly email with its new blog posts. See Red Canary in action. Watch the 10-minute demo now. Security gaps? Red Canary Inc. got you.
That is why Red Canary Inc. is so excited to announce Managed Phishing Response, its new solution that provides AI-powered triage, rapid expert analysis, and tailored feedback for every user-reported phishing email.
Red Canary named a leader in g2's summer 2025 MDR reports - #1 in enterprise customer satisfaction.
Red Canary named a leader in MDR.
Red Canary has been recognised for its contributions to managed detection and response, being named a Leader in the Forrester Wave: Managed Detection and Response for the third year running and featured in the Gartner Market Guide for MDR for the past seven years.
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
201-500
Company Stage
Series C
Total Funding
$129.9M
Headquarters
Denver, Colorado
Founded
2013
Find jobs on Simplify and start your career today