Stellar Cyber

Stellar Cyber is a private cybersecurity company focused on AI-native security operations for MSSPs and lean enterprise security teams. Its platform is built to unify SIEM, NDR, Open XDR, identity, behavioral analytics, and threat intelligence workflows so analysts can detect, investigate, and respond from one operating environment rather than a fragmented security stack.

The company frames its value around a human-augmented autonomous SOC, combining Multi-Layer AI™, automation, and open integrations to reduce alert noise, improve context, and speed response. Stellar Cyber supports cloud, on-premises, and OT environments and emphasizes modernization without rip-and-replace, making it relevant for organizations that want stronger SecOps outcomes while preserving existing tools, data sources, and operating models.

Offerings, Capabilities, and Integrations

Stellar Cyber delivers an open, integration-first security operations platform that brings together telemetry, alerts, and contextual data from existing security and IT tools. Its capabilities span detection, investigation, case correlation, threat hunting, and response, with a design that supports both enterprise SOC teams and multi-tenant service-provider operations.

The platform uses log forwarders, API-based connectors, built-in threat intelligence ingestion, and automated response workflows to extend visibility across cloud, endpoint, network, SaaS, and identity environments. Stellar Cyber also provides data streaming to external storage or SIEM environments, REST APIs for third-party workflows, and architecture features such as multi-tier, multi-tenant, and multi-site support for scalable deployments and partner-led service delivery.

Products and Services

  • Human-Augmented Autonomous SOC Platform: AI-native SecOps platform that unifies detection, investigation, triage, and response for MSSPs and lean enterprise security teams across hybrid environments.
  • Multi-Layer AI™: Layered AI framework that applies machine learning, GraphML, LLM-based assistance, agentic AI, and automation to improve threat detection, case correlation, investigation, and response.
  • AI-Native Next-Gen SIEM: AI-driven SIEM capability for ingesting logs, telemetry, and cloud API data, normalizing and enriching events, correlating detections into cases, and supporting manual or automated response.
  • Open XDR Architecture: Open, API-driven architecture that correlates signals across third-party tools and supports automated response, data sharing, and workflow integration without vendor lock-in.
  • Network Detection & Response (NDR): Network detection and response capability, delivered as NDR+, that extends visibility across IT, OT, and cloud environments and supports earlier detections and faster investigations.
  • Identity Threat Detection & Response (ITDR): Embedded identity security capability that correlates identity activity with other telemetry to detect credential abuse, login anomalies, privilege misuse, and related attacks.
  • Behavioral & Entity Analytics (UEBA): Behavioral analytics capability that uses adaptive modeling to surface anomalous user and entity activity and strengthen correlation across identity, endpoint, and network signals.
  • Threat Intelligence Platform (TIP): Built-in threat intelligence capability that aggregates multiple intelligence feeds, supports customer-owned and third-party feeds, and enriches detections during data processing.
  • MITRE ATT&CK Coverage Analyzer: Web-based analyzer that maps detections and data sources to the MITRE ATT&CK framework, helping teams identify coverage gaps and model the impact of telemetry changes.

Target Customers

Stellar Cyber primarily targets MSSPs, MDR providers, and enterprises that run lean internal security teams. Its value proposition is strongest for organizations that need broad detection and response coverage without building a large analyst bench or managing multiple disconnected consoles.

The platform is also suited to buyers modernizing legacy SIEM programs, deploying NDR, extending EDR into XDR, or building next-generation SOC services. Service providers benefit from multi-tier, multi-tenant, and multi-site architecture for delivering SOC-as-a-Service and MDR-as-a-Service, while enterprise teams benefit from support for cloud, on-premises, and OT environments and an open model that preserves existing investments.

Cloud Integrations and Marketplace

  • Microsoft Azure Marketplace: Stellar Cyber has verified Microsoft Azure Marketplace presence and also supports Azure-centric integrations such as Azure Event Hub ingestion and Microsoft Entra ID connectivity for identity and access use cases.
  • Amazon Web Services (AWS): Stellar Cyber documents AWS integration support, including AWS traffic and port mirroring workflows for monitoring VPC traffic within AWS environments.

Key People

  • Changming Liu: Chief Executive Officer & Co-Founder
  • Aimei Wei: Chief Technical Officer (CTO) & Founder
  • David P. McKeough: Chief Revenue Officer (CRO)
  • Mayuresh Ektare: Senior Vice President Product Management
  • Albert Zhichun Li: Senior Vice President of Engineering
  • Tony Chou: Senior Vice President of Customer Success
  • Andrew Homer: Senior Vice President Strategic Alliances
  • Snehal Contractor: Senior Vice President Global Sales Engineering
  • Steve Garrison: Senior Vice President of Marketing
  • Paul Levasseur: SVP Customer & Partner Enablement

Key Facts

  • Headquarters: San Jose, California, USA
  • Employees: 147
  • Annual Revenue: $35M
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Private

Analyst Recognitions

  • Gartner: 2025 Gartner Magic Quadrant for Network Detection and Response – Challenger. 2023 Gartner Peer Insights Voice of the Customer for Network Detection and Response – Strong Performer.
Stellar Cyber

Enter a search