How Artemis helps security teams cut incident resolution time by 96%

Try Claude
Contact sales
Industry:
Cybersecurity
Company size:
Startup
Product:
Claude Platform
Partner:
AWS
Location:
North America
90% increase in detection coverage
with environment-specific detections built and tuned from day one
300+ custom Claude skills powering internal development
creating a flywheel between engineering velocity and product capability

Artemis is a cybersecurity startup building an AI-native protection platform that delivers real-time detection and automated response for enterprise security teams. Artemis deeply integrated Claude into its platform, from the core reasoning that powers its security agents to the engineering workflows that build and maintain them.

With Claude, Artemis delivers:

  • 90% increase in detection coverage, with environment-specific detections auto built and tuned from day one
  • 96% reduction in mean time to resolution, eliminating multi-hour investigations and producing structured, evidence-cited attack reports and response options in under five minutes
  • 300+ custom Claude skills powering Artemis’ internal development, creating a flywheel between engineering velocity and product capability
  • Environment-specific intelligence within 24 hours of initial integration, highlighting security posture gaps and cloud spend optimization opportunities
  • Detection building and threat hunting in English, no specialized query skills required

The challenge

How security teams use Claude

Claude helps security teams investigate threats, validate findings, and resolve issues faster.

Read more
How security teams use Claude
Next

Claude helps security teams investigate threats, validate findings, and resolve issues faster.

Next
How security teams use Claude

Claude helps security teams investigate threats, validate findings, and resolve issues faster.

The gap between threats and defenses

AI-powered threats can now run from initial access to data exfiltration with minimal human intervention, outpacing an entire generation of defensive technology. Traditional security stacks, built on static rule sets and manual investigation workflows, weren't built for this. 

The problem runs deep. A skilled detection engineer in any security organization might write a few rules per week, each requiring intimate knowledge of the log source, the attack technique, and careful tuning to minimize false positives. When new SaaS tools get adopted or configurations change, those rules fall behind. And when a detection does fire, what follows is hours of manual work: copying IP addresses into threat intelligence tools, pulling cloud logs, cross-referencing across disconnected systems. Most alerts turn out to be benign. 

"You can't bolt intelligence onto a fundamentally static architecture," says Dan Shiebler, co-founder and CTO, at Artemis. "You have to start over, with AI as the reasoning engine, not an add-on."

The solution

Claude on Amazon Bedrock

Build innovative AI applications with safer systems from Anthropic, supported by secure infrastructure from AWS.

Claude on Amazon Bedrock
Next

Build innovative AI applications with safer systems from Anthropic, supported by secure infrastructure from AWS.

Next
Claude on Amazon Bedrock

Build innovative AI applications with safer systems from Anthropic, supported by secure infrastructure from AWS.

Why Artemis chose Claude

Artemis evaluated multiple model providers before building its platform on Claude, using Opus 4.7, Sonnet 4.6, and Haiku 4.5 within the platform. Security workflows demand something specific: following complex multi-step instructions with precision, reasoning across large volumes of evidence, and producing structured output where every conclusion cites specific supporting data. 

"The depth of Claude's reasoning capability, combined with Anthropic's commitment to safety and the enterprise trust of Amazon Bedrock, has been a fundamental piece in how we designed Artemis' platform," says Shachar Hirshberg, co-founder and CEO at Artemis. Every customer runs in a SOC2-compliant dedicated single-tenant environment. Customer data is never shared across tenants and is never used to train models. 

"The depth of Claude's reasoning capability, combined with Anthropic's commitment to safety, has been a fundamental piece in how we designed Artemis' platform."
Shachar Hirshberg
Co-founder and CEO, Artemis

Next

Next

The outcome

How Artemis uses Claude to protect customers

Rather than applying generic rules, Claude-powered agents build a living model of each customer's environment: every entity, asset, behavioral baseline, and cross-source relationship. That context is what makes detections effective. When a new event arrives, Artemis evaluates it against the full context of the user, system, and organization, not just a static set of rules. Integration takes less than an hour, and customers begin receiving environment-specific intelligence within minutes of connecting their first data source. 

When a detection fires, Claude-powered investigation agents take over: formulating hypotheses, querying across log sources, correlating signals, and producing reports with severity assessments and clear chains of reasoning. Deep domain expertise for each log type (Okta, AWS CloudTrail, Entra ID, Crowdstrike) is encoded into each investigation, regardless of which analyst is on shift. Before Artemis, one enterprise customer's security team averaged two hours per investigation. The same cases now produce structured, evidence-cited reports and response actions in less than five minutes. A global financial services customer went from initial integration to over a hundred environment-specific detections within the first week, covering credential access, lateral movement, and persistence techniques their previous tool missed entirely.

"The investigation backlog for our customers didn't shrink. It disappeared," says Hirshberg. "We help them go from triaging a fraction of alerts, hoping the ones we skipped were benign, to having every single alert investigated with the same analytical rigor. We also use Artemis internally to protect the company."

Analysts can also query their security data in English, asking to see suspicious commercial VPN usage across their organization, then follow up to review a detailed report, maintaining context across the interaction. They can build new detections through conversation and investigate specific alerts without having to know SPL, SQL, KQL, or any other domain specific language.

Looking to the future

What's less visible but equally important: Artemis uses Claude not just in the product, but to build the product. 100% of the engineers work with Claude Code as a core part of their development workflow. Over 300 custom Claude skills encode the team's operational playbook, from creating new detectors to managing infrastructure and reviewing code. Internal tools become product features. The engineering team ships faster the more it builds.

"We help them go from triaging a fraction of alerts to having every single alert investigated with the same analytical rigor."
Shachar Hirshberg
Co-founder and CEO, Artemis