---
title: "A Proactive System of Intelligence for Security"
description: "Theory Ventures invests in Artemis's $70M Series A to build the AI-native detection engine for the next era of security operations."
categories: ["AI","cybersecurity"]
keywords: ["Artemis","SIEM","Theory Ventures","cybersecurity","AI security","agentic detection","security operations"]
date: 2026-04-14
lastmod: 2026-08-27
canonical_url: https://www.tomtunguz.com/artemis/
author: "Tomasz Tunguz"
---


At the heart of every security team, there's a database. That database records each time a user logs in, every packet of inbound traffic, & each attempted attack. Architected before AI, these SIEM systems are wooden shields in an era of autonomous attackers.

The consequences are mounting. Deepfake scams have stolen tens of millions. AI-generated phishing bypasses legacy filters. As [Mythos](https://tomtunguz.com/mythos-glasswing/) has shown, the sophistication of attacks will only increase.

[Shachar Hirshberg](https://www.linkedin.com/in/shachar-hirshberg/) & [Dan Shiebler](https://www.linkedin.com/in/dan-shiebler-10219b42/) saw this opportunity. Shachar led the Amazon GuardDuty product, scaling the business to over 80,000 customers. Dan built & led the 60-person AI/ML team at Abnormal Security. Together, they started [Artemis](https://artemissecurity.com/) to build a database to power defenses for modern security teams. Within a few months, they have more than a dozen production enterprise deployments & are processing over a billion events per hour. We are excited to partner with them at the Series A, along with our friends at Felicis, Brightmind, & First Round.

{{< email_image src="kbwalimy5vuwszjff8yf" alt="Screenshot 2026-04-15 at 7.34.47 AM" width="540" height="360" >}}

At the core of this new SIEM are three technologies :

**Semantic understanding.** To a traditional SIEM, a log is just a string of text. It has no understanding that "jdoe" in Okta & "john.doe" in AWS are the same person, or that a sequence of individually benign actions might constitute an attack. Artemis turns raw logs into a living model of the customer's environment : users, assets, relationships, & security posture.

**Agentic detection.** Legacy platforms rely on brittle, hand-written rules. An engineer writes a detection rule : "if events A, B, & C happen in sequence, fire an alert." It works for a couple months. Then a new service gets added, log formats change, & the rule breaks. Artemis' detections include multi-step reasoning agents that dynamically query data, perform aggregations, & reason about context to confirm a threat before ever surfacing an alert.

**Closed-loop learning.** Legacy platforms get worse over time : static detections degrade with changing data & behaviors. Artemis gets better : with each incident or proactive threat hunt, the system identifies new patterns. These are converted into permanent detections that are researched, validated, & maintained fully autonomously.

The result is a platform that doesn't just store & search data, but _reasons_ about it autonomously.

If you're interested in learning more or joining this mission, check out the [open roles at Artemis](https://artemissecurity.com/careers/) & [Shachar's post](https://www.linkedin.com/posts/shachar-hirshberg_seven-months-ago-dan-shiebler-and-i-started-activity-7450170298982678528-rxzy/)
