LLMs performance on AI SOC LLM Leaderboard
Across 100 full-kill-chain SOC scenarios, the 7 frontier LLMs tested on the Simbian AI SOC Benchmark scored between 61.4% and 67.6%. Sonnet 3.5 (Anthropic) led at 67.6%, ahead of Gemini 2.5 Pro Preview (Google) at 66.4% and Opus 4 (Anthropic) at 65.7%. No model tested cleared 70%, which is why autonomous alert triage needs an orchestration layer around the model rather than a model alone.
| Rank | Model | Provider | Benchmark score |
|---|---|---|---|
| 1 | Sonnet 3.5 | Anthropic | 67.6% |
| 2 | Gemini 2.5 Pro Preview | 66.4% | |
| 3 | Opus 4 | Anthropic | 65.7% |
| 4 | GPT 4.1 | OpenAI | 63.0% |
| 5 | Sonnet 4 | Anthropic | 62.1% |
| 6 | Sonnet 3.7 | Anthropic | 61.9% |
| 7 | DeepSeek R1 | DeepSeek | 61.4% |
Our AI Agents work 24x7x365 to automatically investigate and respond to alerts, conduct threat hunts, prioritize and patch vulnerabilities, and more
Our benchmark is built on the automated investigation of 100 full-kill chain scenarios that realistically mirror what human SOC analysts face every day. The created attack scenarios have known ground truth of malicious activity, allowing AI agents to investigate and be assessed against a clear baseline. The used scenarios are even based on historical behavior of well-known APT groups and cybercriminal organizations covering a wide range of MITRE ATT&CK™ Tactics and Techniques, with a focus on prevalent threats like ransomware and phishing.




