Skip to content

Cotool

llms.txt snapshot

Captured by Entropy on 9/6/2026. This is the content Entropy fetched at scan time — not a live view of cotool.ai’s file, which may have changed since.

llms.txt

fetched from https://cotool.ai/llms.txt

# Cotool

> AI for the blue team. Scale detection, response, and threat hunting beyond headcount. Build AI agents across your entire security stack.

Every page on this site is available as Markdown: append `.md` to any URL,
or request it with `Accept: text/markdown`.

## Pages

- [Cotool — AI for the blue team.](https://www.cotool.ai/index.md): Scale detection, response, and threat hunting beyond headcount. Build AI agents across your entire security stack.
- [About Cotool](https://www.cotool.ai/about.md): Cotool is our vision of how security work should be: faster, simpler, and less exhausting.
- [Blog](https://www.cotool.ai/blog.md): Engineering, research, and company updates from Cotool.
- [Detect](https://www.cotool.ai/detect.md): Purpose-built to detect threats your SIEM is missing. Cotool detects threats using natural language intent, and automatically suggests new detections to cover gaps.
- [Hunt](https://www.cotool.ai/hunt.md): Monitor threat intel from your feeds and the public web, surfacing only what is relevant to your environment.
- [Respond](https://www.cotool.ai/respond.md): Create any response agent in natural language. Tailor it to your team's workflows and processes.
- [Partner with Cotool](https://www.cotool.ai/partners.md): Cotool is partner-first. Bring agentic detection, response, and threat hunting to your customers as a reseller, MSSP, integration partner, or strategic advisor.
- [Meet the Cotool Team at Black Hat USA 2026](https://www.cotool.ai/blackhat-2026.md): Meet the Cotool team during Black Hat USA 2026 in Las Vegas. Book time with our founders and get invites to our events during the week.
- [AI Research in Security Operations](https://www.cotool.ai/research.md): Pushing the frontier of AI agents for real security work. Benchmarks evaluating AI models on security tasks.
- [Request a demo](https://www.cotool.ai/request-demo.md): Request a Cotool demo.
- [License](https://www.cotool.ai/license.md): Cotool license terms.
- [Privacy policy](https://www.cotool.ai/privacy-policy.md): Cotool privacy policy.
- [Subprocessors](https://www.cotool.ai/subprocessors.md): Cotool Inc uses the following subprocessors to support its product offerings.

## Research benchmarks

- [Impact & Exfiltration](https://www.cotool.ai/research/bluebench-simulation-003.md): BlueBench-Simulation-003: Three simulated end-of-intrusion investigations (ransomware impact, backup sabotage, and data exfiltration) scored against complete hidden ground truth
- [Identity & Active Directory Attacks](https://www.cotool.ai/research/bluebench-simulation-002.md): BlueBench-Simulation-002: Four simulated Windows identity-tier attacks (password spray, domain persistence, credential-attack detection, and a hands-on-keyboard operator) scored against complete hidden ground truth
- [Initial Access & Command-and-Control](https://www.cotool.ai/research/bluebench-simulation-001.md): BlueBench-Simulation-001: Five simulated investigations covering a mail-borne endpoint compromise, a DMZ webshell, and DGA botnet beaconing, scored against complete hidden ground truth
- [AWS Cloud Intrusion](https://www.cotool.ai/research/aws-cloud-intrusion.md): BlueBench-Intrusion-003: Real AWS intrusion through leaked CI credentials, scored on open-ended incident response reporting
- [Windows Enterprise Intrusion](https://www.cotool.ai/research/windows-enterprise-intrusion.md): BlueBench-Intrusion-002: Real multi-host Windows Active Directory intrusion spanning detection engineering, malware analysis, and open-ended incident reporting
- [macOS Threat Investigation](https://www.cotool.ai/research/macos-threat-investigation.md): BlueBench-Intrusion-001: Real macOS infostealer intrusion spanning incident response, threat hunting, and detection engineering
- [NYU CTF Bench](https://www.cotool.ai/research/nyu-ctf.md): Real CTF challenges from CSAW competitions covering reverse engineering, forensics, and miscellaneous problem-solving
- [Cybench (Defensive Subset)](https://www.cotool.ai/research/cybench.md): Defensive security CTF challenges testing forensics, reverse engineering, and miscellaneous security skills
- [BOTSv3 Blue Team CTF](https://www.cotool.ai/research/botsv3.md): Blue team CTF scenarios testing incident response and threat hunting
- [Sigma Detection Classification](https://www.cotool.ai/research/sigma.md): Multi-label classification of MITRE ATT&CK tactics and techniques from Sigma rules
- [CyberMetric](https://www.cotool.ai/research/cybermetric.md): Multiple-choice cybersecurity knowledge evaluation across 10,000 questions

## Blog posts

- [Introducing Cotool Router](https://www.cotool.ai/blog/introducing-cotool-router.md): Cotool Router gives security teams automatic cross-provider fallback, access to open-weight models, and evaluation-informed model selection for any security task.
- [Agents as Software](https://www.cotool.ai/blog/agents-as-software.md): What does security look like in a world where intelligence is everywhere?
- [Beyond CTFs: Evaluating AI Agents on Real Intrusion Data](https://www.cotool.ai/blog/beyond-ctfs-evaluating-ai-agents-on-real-intrusion-data.md): We benchmarked frontier models on a real macOS infostealer intrusion. This is not a CTF, which tend to test narrow, artificial scenarios. Tasks spanned incident response, threat hunting, and detection engineering.
- [The Security Infrastructure Powering EliseAI's Rapid Scale](https://www.cotool.ai/blog/case-study-eliseai.md): How EliseAI uses Cotool to automate investigations, expand detection coverage, and defend customer data across housing and healthcare
- [Announcing our $7.4m seed fundraising to build the AI Operating system for security teams](https://www.cotool.ai/blog/announcing-our-seed-round.md): Cotool announces $7.4m seed round led by Andreessen Horowitz to build the AI Operating System for security teams
- [Evaluating AI Agents in Security Operations (December 2025)](https://www.cotool.ai/blog/evaluating-gpt-5-1-claude-opus-4-5-and-gemini-3-pro-ai-agents-in.md): Which frontier model should you use for SecOps automation? We added the latest cohort of frontier models to our benchmark to find out.
- [Evaluating AI Agents in Security Operations](https://www.cotool.ai/blog/evaluating-gpt-5-1-claude-opus-4-5-and-gemini-3-pro-ai-agents-in-security-operations.md): We benchmarked frontier AI models on realistic security operations (SecOps) tasks using Cotool’s agent harness and the Splunk BOTSv3 dataset. GPT-5 achieved the highest accuracy (63%), while Claude Haiku-4.5 completed tasks the fastest with strong accuracy. GPT-5 variants dominated the performance-cost frontier. These results provide practical guidance for model selection in enterprise SecOps automation.
- [Context Management for Agentic Security](https://www.cotool.ai/blog/context-management.md): How we are solving the LLM Security Data problem
- [Security without the Spectacle](https://www.cotool.ai/blog/security-without-the-spectacle.md): Why would anyone want to start an AI security company? 

AI models mentioned in this file

  • GPT-5 (OpenAI) — “- [Evaluating AI Agents in Security Operations (December 2025)](https://www.cotool.ai/blog/evaluating-gpt-5-1-claude-opus-4-5-and-gemini-3-pro-ai-agents-in.md): Which frontier model should you use for…(llms.txt)
  • Claude (Anthropic) — “- [Evaluating AI Agents in Security Operations (December 2025)](https://www.cotool.ai/blog/evaluating-gpt-5-1-claude-opus-4-5-and-gemini-3-pro-ai-agents-in.md): Which frontier model should you use for…(llms.txt)
  • Gemini (Google) — “- [Evaluating AI Agents in Security Operations (December 2025)](https://www.cotool.ai/blog/evaluating-gpt-5-1-claude-opus-4-5-and-gemini-3-pro-ai-agents-in.md): Which frontier model should you use for…(llms.txt)