Anomali
Anomali provides an AI-native Security Operations platform combining a unified security data lake, ThreatStream threat intelligence, and agentic AI for autonomous triage, investigation, and response. It sells via subscription to Fortune 500 enterprises, government agencies, MSSPs, and financial institutions.
- Company typePrivate
- Founded2013
- HeadquartersRedwood City, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Anomali does
Anomali is a privately held cybersecurity software company founded in 2013 and headquartered in Redwood City, California. It sells an Intelligence-Native Agentic SOC Platform that unifies three layers: a Unified Security Data Lake that ingests and retains petabyte-scale security telemetry (cloud, endpoint, network, identity), the ThreatStream Next-Gen threat intelligence platform built on a curated intelligence graph, and an Agentic AI operations layer that drives autonomous triage, scoring, investigation, and response. The platform is exposed to analysts through Anomali Copilot AI (natural-language querying) and a Model Context Protocol that lets AI agents reason over data lake and intelligence context. An additional Anomali Marketplace packages third-party threat intelligence feeds, integrations, and SDKs; an Underground Threat Intelligence module (powered by RedSense) provides dark web, credential, and C2 feeds. A free STIX/TAXII tool (STAXX) anchors the bottom of the funnel.
The company monetizes primarily through subscription SaaS contracts (annual or multi-year, quote-based, tiered by data volume and features) supplemented by a Customer Success Organization that delivers professional services, training, and RFI support. Its go-to-market is hybrid: a direct enterprise field-sales motion targeting Fortune 500 and government accounts layered with an expanding channel network of value-added distributors (ABP Securite in APAC, Solid8 in Africa) and an MSSP program (launched in ANZ in late 2025). It targets four customer segments: large enterprise SOC/CTI teams (primary), MSSPs, government agencies, and financial services institutions, with named users including Air Canada, Bank of Hope, RAKBANK, Blackhawk Network, College Board, Paysafe, and Oklahoma OMES. The company holds EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework certifications and a triple-win at the Global InfoSec Awards (SIEM, SecOps, TIP).
Anomali firmographics
Firmographics- Name
- Anomali
- Legal name
- Anomali Inc.
- Website
- https://anomali.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Anomali provides an AI-native Security Operations platform combining a unified security data lake, ThreatStream threat intelligence, and agentic AI for autonomous triage, investigation, and response. It sells via subscription to Fortune 500 enterprises, government agencies, MSSPs, and financial institutions.
- Ownership category
- akta.pro rank
Anomali industry classification
Industry- Product category
- Security Operations Platform / Threat Intelligence Platform
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design Services (541512), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- SOAR & Security Automation (HDADAGAB)
Keywords
Where Anomali is headquartered
LocationHeadquarters
- HQ city
- Redwood City
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Anomali business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription SaaS: Annual or multi-year subscription licenses for the Agentic SOC Platform, Unified Security Data Lake, and ThreatStream Next-Gen. Subscription fees charged for platform access with tiered pricing based on data volume and features.
- Professional Services: Customer Success Organization provides professional services including workflow services, RFI services, training, and support/management of Anomali software solutions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform with personalized demos and tailored deployments |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels6 records
Anomali product offering
Product offeringCore offering
Anomali sells an Intelligence-Native Agentic SOC Platform that unifies a cloud-native security data lake, a curated threat intelligence platform (ThreatStream Next-Gen), and agentic AI into a single subscription software offering for enterprise SOC and CTI teams. The platform enables autonomous threat detection, investigation, and response across petabyte-scale security telemetry, complemented by an online marketplace for third-party threat intelligence feeds and security system integrations.
Product overview
Anomali delivers an Intelligence-Native Agentic SOC Platform that unifies a fully-featured Security Data Lake, threat intelligence, and agentic AI into a single modern experience. The platform architecture consists of three layers built on a Unified Security Data Lake: (1) the Agentic SOC Platform as the main orchestration layer, (2) ThreatStream Next-Gen as the Intelligence Graph layer providing curated threat intelligence, and (3) Agentic AI as the operations layer enabling autonomous investigation and response. Additional offerings include the Anomali Marketplace for third-party integrations and feeds, Anomali Copilot AI for natural language querying, and specialized products like Anomali Underground Threat Intelligence for dark web monitoring. The platform accelerates detection, investigation, and response while delivering earlier insights, faster action, and scalable modernization across any environment.
Differentiator
Problem solved
Functional benefit
Brands
- ThreatStream®: Industry-leading threat intelligence platform (TIP) providing curated access to the world's largest repository of curated threat intelligence. Registered trademark of Anomali Inc.
- Anomali Match™
- Anomali Lens™
- Anomali University
- Agentic SOC Platform
- Unified Security Data Lake
Products and services
- Agentic SOC Platform The main unified platform that integrates threat intelligence, security data lake, and agentic AI to enable SOC and CTI teams to collaborate seamlessly, providing context and AI-guided workflows to detect hidden threats, prioritize high-risk incidents, and respond faster. Targeted at enterprise security operations teams.
- Unified Security Data Lake The foundational layer of the Agentic SOC Platform that centralizes and retains massive volumes of security telemetry (cloud, endpoint, network, identity) without the performance limits or cost penalties of legacy SIEMs, providing always-on, always-searchable data for real-time and historical analysis at scale. Targeted at enterprise SOC teams replacing legacy SIEMs.
- ThreatStream Next-Gen An industry-leading threat intelligence platform (TIP) providing curated access to the world's largest repository of curated threat intelligence, with AI-driven autonomous triage, scoring, investigation, and operationalization across detection, investigation, and response. Targeted at enterprise CTI and SOC teams.
- Agentic AI Advanced AI and natural language processing capabilities that bring agency to the SOC, enabling AI-driven agents to reason over data and intelligence context to guide investigations, recommend actions, and automate response workflows. Targeted at enterprise security operations teams adopting AI-driven SOC transformation.
- Anomali Underground Threat Intelligence Five high-fidelity intelligence feeds powered by RedSense integrated into ThreatStream Next-Gen, including Dark Web Intelligence, Early Warning Alerts, C2 Detection, Credential Monitoring, and Threat Briefings for comprehensive underground threat visibility. Targeted at enterprise CTI teams needing dark web and underground threat coverage.
- Anomali Marketplace Cybersecurity marketplace providing instant access to third-party threat intelligence feeds, threat analysis tools and enrichments, security system partner integrations, and SDKs for extending platform capabilities. Targeted at enterprise security teams and integrators building on Anomali.
- STAXX Free STIX/TAXII solution for consuming and managing threat intelligence feeds in standard formats. Targeted at security practitioners and the broader threat intelligence community to support ecosystem adoption.
Quantifiable outcome
- 300x faster detection and investigation validated across 50 enterprise deployments
- +3 more outcomes
Companies that use Anomali
Customer profileNamed customers10 records
Segments4 records
Ideal customer profiles4 records
Anomali technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration21 records
AI capability9 records
Feature5 records
Anomali partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- RedSensecoreCollaboration with RedSense to power Anomali Underground Threat Intelligence with five high-fidelity intelligence feeds integrated into ThreatStream Next-Gen. Feeds include Dark Web Intelligence, Early Warning Alerts, C2 Detection, Credential Monitoring, and Threat Briefings for comprehensive underground threat coverage.
- Solid8 TechnologiescoreSouth African cybersecurity distributor partnership for showcasing Anomali solutions at ITWeb Security Summit 2026. Solid8 showcases threat detection platforms including Anomali's threat intelligence capabilities as part of their cybersecurity vendor portfolio in Africa.
- ABP SecuritecoreStrategic partnership with Singapore-based value-added distributor specializing in cybersecurity and network performance solutions. ABP Securite distributes and supports Anomali's Agentic SOC Platform across key Asia Pacific markets, providing technical enablement, partner training, solution integration, and pre- and post-sales support to strengthen access to intelligence-led detection, investigation, and response capabilities.
- MSSPs Australia/New ZealandcoreMSSP Program launched for Australian and New Zealand managed security service providers to enhance security service delivery using a unified platform based on open security data lake architecture. Provides multi-tenant management, threat intelligence integration, and AI-enhanced analytics for improved operational efficiency and scalability.
- Integration Partners EcosystemcoreExtensive integration ecosystem including ServiceNow, Palo Alto Networks, Cisco, Zscaler, CrowdStrike, Splunk, Microsoft Azure Sentinel, Check Point, Fortinet, Deloitte, Qualys, Tenable, and 200+ additional integrations enabling seamless data flows and unified security operations.
Scale indicators6 records
Expansion highlights6 records
Anomali competitors and assessment
Company assessmentDirect peers
- LogRhythm: LogRhythm is a SIEM platform with integrated SOAR and threat intelligence features targeting mid-market and enterprise SOC teams, directly comparable to Anomali's intelligence-led detection and response capabilities.
- Splunk: Splunk (now part of Cisco) is the leading SIEM/log analytics platform and a direct competitor to Anomali's Unified Security Data Lake and ThreatStream capabilities. Splunk's scale, installed base, and bundled Cisco security stack make it the primary incumbent Anomali displaces with its SIEM cost-savings narrative.
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM that competes directly with Anomali's Unified Security Data Lake, offering bundled threat intelligence, SOAR, and AI capabilities within the Microsoft enterprise ecosystem. Anomali even integrates with Sentinel, reflecting overlapping positioning.
- Palo Alto Networks Cortex XSIAM: Palo Alto Networks' Cortex XSIAM is an AI-driven SOC platform combining SIEM, XDR, and SOAR with threat intelligence — a near-direct competitive match to Anomali's Agentic SOC Platform, backed by Palo Alto's firewall-installed base.
- CrowdStrike Falcon Platform: CrowdStrike Falcon is an endpoint-led XDR platform that has expanded into SIEM, identity threat detection, and agentic AI workflows — directly competing with Anomali's SOC and threat intelligence offerings, particularly among Falcon-anchored enterprise customers.
- Exabeam: Exabeam is a cloud-native SIEM with UEBA and SOAR capabilities that competes head-to-head with Anomali in the security operations and threat intelligence market for mid-to-large enterprises.
- Securonix: Securonix offers a SIEM platform built on UEBA and security analytics with threat intelligence integration, closely mirroring Anomali's positioning as an intelligence-native SOC platform for enterprise and MSSP customers.
- Recorded Future (Mastercard): Recorded Future is a leading threat intelligence platform now owned by Mastercard, directly competing with ThreatStream as a primary TIP and increasingly overlapping with Anomali's agentic SOC integrations and threat intel feeds.
Emerging players
- Swimlane: Swimlane is a low-code SOAR platform with growing agentic AI capabilities, competing with Anomali's automation and orchestration layer in the SOC and offering an alternative for buyers prioritizing playbook-centric automation.
- Devo Technology: Devo Technology is a cloud-native SIEM and analytics platform competing with Anomali's Unified Security Data Lake, particularly among security teams seeking petabyte-scale telemetry retention with real-time analytics.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Anomali social profiles
Digital presenceAnomali compliance and trust
Trust signalCompliance3 records
Anomali financial estimates
Financial estimateRevenue estimate
Valuation estimate
Anomali leadership team
Management profileNumber of profiles
Profiles13 records
Anomali funding detail
Funding detailFunding overview
Funding rounds6 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Anomali M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Anomali
What does Anomali do?
Anomali sells an Intelligence-Native Agentic SOC Platform that unifies a cloud-native security data lake, a curated threat intelligence platform (ThreatStream Next-Gen), and agentic AI into a single subscription software offering for enterprise SOC and CTI teams. The platform enables autonomous threat detection, investigation, and response across petabyte-scale security telemetry, complemented by an online marketplace for third-party threat intelligence feeds and security system integrations.
Is Anomali a public or private company?
Anomali is a private company. It is classified as venture growth investor backed and is currently operating.
When was Anomali founded?
Anomali was founded in 2013. It employs 251 to 500 people.
Where is Anomali based?
Anomali is headquartered in Redwood City, United States, in the North America region.
How does Anomali make money?
Two revenue lines are on record. Subscription SaaS are the primary driver. The others are professional Services.
Who are Anomali's main competitors?
Direct peers on record are LogRhythm, Splunk, Microsoft Sentinel, Palo Alto Networks Cortex XSIAM, CrowdStrike Falcon Platform, Exabeam, Securonix and Recorded Future (Mastercard). Emerging players are Swimlane and Devo Technology.
Does Anomali have an API?
Yes. Anomali offers SDKs through its Marketplace for developers to build integrations and extend the platform's capabilities. The Anomali Marketplace provides access to threat intelligence feeds, threat analysis tools and enrichments, security system partner integrations, and SDKs for custom development. Developer documentation is at www.anomali.com/marketplace.
What industry is Anomali in?
Anomali's product category is Security Operations Platform / Threat Intelligence Platform. Its primary akta.pro industry code is HDADAGAB, SOAR & Security Automation. Its NAICS code is 5182 and its SIC code is 7372.