SANDSLab
SANDSLab is a Korean AI cybersecurity company providing the CTX threat intelligence platform, MNX network detection, and proprietary profiling technologies (DBP, DDP). It serves Korean government agencies, financial institutions, and large enterprises, with Japan as its first overseas market.
- Company typePublic
- Founded2004
- HeadquartersSeoul, South Korea
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What SANDSLab does
SANDSLab (주식회사 샌즈랩) is a South Korea-based AI cybersecurity company specializing in cyber threat intelligence. Founded in 2003-2004 by CEO Kim Ki-hong following the January 25 cyber attack incident and incorporated in 2004, the company has been listed on KOSDAQ (ticker 411080) since February 2022 via a technology-specialized listing and operates as a subsidiary of KSign (KSAIN). Its headquarters relocated from Seoul to Gwacheon-si, Gyeonggi-do in October 2023. The company processes more than 2 million malware samples daily and maintains a database exceeding 30 billion threat intelligence records, positioning itself as a Korea and Asia #1 threat intelligence provider serving government agencies (KISA, Ministry of Science and ICT), financial institutions, and large enterprises in Korea and Japan.
The product portfolio is organized around the CTX (Cyber Threat X) platform, an AI-driven threat intelligence hub that aggregates IoC data, attacker profiles, and malware analysis into a knowledge graph and integrates with Microsoft Sentinel, VirusTotal, AlienVault OTX, and Criminal IP. Underlying core technologies include DBP (Deep Binary Profiler), a binary reverse engineering engine for attacker profiling, and DDP (Deep Document Profiler), a non-executable malware detection technology; both carry NET (New Excellent Technology) certification from the Ministry of Trade, Industry and Energy. MNX delivers AI-based Network Detection and Response with lossless 100 Gbps collection and quantum-resistant cryptography inspection, MDX targets document-type malware with a stated 99.4% average detection rate, and an On-Premise sLLM plus GLX (LLM Guard) extend the stack into generative AI security. The company has filed over 95 patents and registered 48, including US patents for AI-based predictive threat response and generative AI security automation.
Revenue is generated through a mix of subscription-based threat intelligence services (CTX), one-time or perpetual licenses (MNX, MDX), data monetization (cybersecurity AI datasets), and professional services (government project contracts, including a KRW 45 billion KISA-led cybersecurity AI dataset consortium in which SANDSLab holds 90% of scope). Distribution combines direct enterprise sales, government consortia, a Japanese distribution partner for MNX exports (1,000 units in December 2025), and Microsoft Azure marketplace integration. The headcount is small (11-50 employees, with 84% in R&D roles), which both signals a research-dense organization and represents a scaling constraint as contract volume grows.
SANDSLab firmographics
Firmographics- Name
- SANDSLab
- Legal name
- 주식회사 샌즈랩
- Website
- https://sandslab.io
- Company type
- Public
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SANDSLab is a Korean AI cybersecurity company providing the CTX threat intelligence platform, MNX network detection, and proprietary profiling technologies (DBP, DDP). It serves Korean government agencies, financial institutions, and large enterprises, with Japan as its first overseas market.
- Ownership category
- akta.pro rank
SANDSLab industry classification
Industry- Product category
- Cybersecurity Threat Intelligence Software
- NAICS
- Security Systems Services (56162), Computer Systems Design and Related Services (54151), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Network Analytics, AIOps & Root-Cause Correlation (HDAFAGAM)
- akta.pro secondary industries
- Vulnerability Management, Pen Testing & Attack Surface Management (ASM) (HLACAJAN), Endpoint Deception & Anti-Ransomware (HDADAEAL)
Keywords
Where SANDSLab is headquartered
LocationHeadquarters
- HQ city
- Seoul
- HQ country
- South Korea
- HQ region
- Asia
Offices1 record
Markets served
SANDSLab business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Operations, Infrastructure, Marketing or Sales
Revenue model
- CTX Threat Intelligence Service: Subscription-based threat intelligence platform providing IoC information, attack group identification, and malware analysis. Includes API access, datasets, and feed services.
- MNX NDR Solution: One-time license or subscription sale of Network Detection and Response hardware/software solution for enterprise security infrastructure.
- MDX Solution: Document-type malware detection solution sold as enterprise license.
- Cybersecurity AI Dataset Sales: Sale of curated cybersecurity training datasets to enterprises and research institutions. First-of-its-kind in Korean cybersecurity market.
- Government Project Contracts: Revenue from KISA and government agency projects including AI dataset construction, threat intelligence development, and security technology R&D.
- Deepfake Detection Service: Fakecheck service for deepfake image and video detection, available to general public.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | One time/ perpetual license | MNX NDR Solution promotional pricing |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels10 records
SANDSLab product offering
Product offeringCore offering
SANDSLab builds and sells AI and big data-based cybersecurity software, centered on the CTX threat intelligence platform, MNX network detection and response (NDR) solution, and MDX malware detection solution. Its proprietary DBP and DDP profiling technologies power automated attacker profiling and malware analysis, while complementary services include cybersecurity AI datasets, an on-premise small language model (sLLM), and the FakeCheck deepfake detection service.
Product overview
SANDSLab (주식회사 샌즈랩) is an AI and big data-based cybersecurity company specializing in cyber threat intelligence. The product portfolio centers on the CTX (Cyber Threat X) platform as the core intelligence engine, supported by hardware/software security solutions (MNX NDR, MDX malware detection, SI security intelligence) and proprietary AI profiling technologies (DBP, DDP). The architecture follows a platform-plus-modules model where CTX serves as the central threat intelligence hub that can be accessed via API, integrated with external platforms (Microsoft Sentinel, VirusTotal, AlienVault, Criminal IP), or extended through add-on services including on-premise AI models (sLLM), cybersecurity datasets, and specialized tools (IDPW breach notification, FakeCheck deepfake detection). MNX provides network-level threat detection at up to 100 Gbps with ML-based anomaly detection, while MDX focuses on document-type malware and zero-day attacks. DBP and DDP provide the underlying binary and document profiling technologies that power the intelligence platform. The company processes over 2 million malware samples daily and maintains a database of over 30 billion threat intelligence records.
Differentiator
Problem solved
Functional benefit
Brands
- CTX: Cyber Threat eXchange - AI-based next-generation threat intelligence platform providing IoC information, attack technique analysis, threat actor profiling. Replaced Malwares.com in November 2023.
- CTX for GPT
- MNX
- MDX
- SI
- DBP (Deep Binary Profiler)
- DDP (Deep Document Profiler)
- IDPW
- Fakecheck
Products and services
- CTX (Cyber Threat X) AI-based next-generation cyber threat intelligence platform providing real-time threat actor profiling, IoC (Indicator of Compromise) lookup, and attack technique analysis. Aggregates intelligence into a knowledge graph structure for security teams, enterprise security operations, and government agencies. Offers API access and integrates with Microsoft Sentinel, VirusTotal, AlienVault OTX, and Criminal IP.
- MNX (Network Threat X) AI-based Network Detection and Response (NDR) solution for IT/OT traffic analysis and APT attack detection in enterprise and government environments. Provides lossless 100 Gbps network traffic collection, machine learning-based new and variant malware identification, and protocol-specific anomaly event detection. Pre-loaded with quantum-resistant cryptography inspection technology.
- MDX (Malware Detection X) Machine learning-based APT attack response and document-type malware detection solution for enterprise security teams. Uses AI to detect zero-day attack codes and identifies new malware faster than traditional anti-virus solutions, with data science-based document feature extraction achieving 99.4% average detection rate for document-type malware.
- SI (Security Intelligence) Security intelligence solution providing integrated security monitoring and response capabilities for enterprise customers. Complements NDR and malware detection products with centralized security intelligence aggregation and reporting.
- DBP (Deep Binary Profiler) Binary reverse engineering-based attacker profiling technology that disassembles executable malware files and identifies attack groups and techniques (MITRE ATT&CK T-ID) automatically using AI. NET-certified with 30+ patents registered in Korea and 10+ patents filed in the US. Offered to security teams and government agencies for malware attribution.
- DDP (Deep Document Profiler) Multidimensional metadata extraction analysis-based non-executable malware profiling and detection technology. Analyzes document files and non-executable content to identify APT attack vectors and document-type malware for enterprise and government security teams. NET-certified in 2022.
- Cybersecurity AI Training Dataset Curated cybersecurity AI training dataset containing malware samples, threat profiles, and attack group data. Available for purchase by enterprises, research institutions, and AI developers for cybersecurity AI model training and R&D.
- On-Premise sLLM (Small Language Model) On-Premise cybersecurity-specialized small Language Model for enterprise deployment. Provides domain-specific AI capabilities for security operations within enterprise infrastructure for data sovereignty, privacy, and AI governance requirements without cloud dependency.
- IDPW (Personal Data Breach Notification) Personal data breach notification service that alerts users when their credentials appear in data leaks. Partnership with Toss (Kakao T) enables nationwide breach notifications through the AppInToss service, reaching Korean consumers directly.
- FakeCheck (Deepfake Detection) Deepfake detection service that identifies AI-generated images and videos using computer vision AI. FakeCheck 2.0 (released May 2025) expanded from image-only to include video analysis for synthetic media detection used in fraud prevention and disinformation defense.
- CTX for GPT Integration of CTX threat intelligence capabilities within the OpenAI GPT environment. Allows security analysts to access and query CTX threat data directly through the ChatGPT interface for enriched threat context and automated intelligence lookup.
Quantifiable outcome
- 99.4% average detection rate for document-type malware
- +3 more outcomes
Companies that use SANDSLab
Customer profileNamed customers6 records
Segments4 records
Ideal customer profiles3 records
SANDSLab technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability11 records
Feature7 records
SANDSLab partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered core, strategic and minor.
- KISA (Korea Internet & Security Agency)coreSANDSLab-led consortium selected for KISA's 2026 New Information Security Technology Support Program. The 12 billion won program supports 50 companies across 18 projects. SANDSLab leads development of AI-driven integrated security platform.
- Chei Medical University (차의과학대)strategicJoint development of AI-based next-generation medical and healthcare security technology. Expanding AI security technology application to healthcare sector.
- DSO National Research Institute (Singapore)strategicPartnership for cutting-edge cybersecurity technology development with Singapore's defense research organization.
- LogpressocoreAI-based XDR (Extended Detection and Response) development partnership. Security operations platform specialist collaborating on automated security operations using AI agents. SANDSLab invested as strategic investor in Logpresso's KRW 16B Series B round.
- Microsoft KoreacoreStrategic MOU for Azure-based cybersecurity technology development. Joint seminar 'SANDS Lab on Azure' held showcasing CTX integration with Azure cloud infrastructure. Collaboration on domain-specific generative AI cybersecurity model development.
- LG Uplus and FortiToo (포티투마루)coreThree-party consortium for building cybersecurity-specialized LLM. SANDSLab provides dataset development for enterprise internal infrastructure. LG Uplus handles LLM development and customer data protection. FortiToo provides cybersecurity-domain LLM modeling and RAG technology.
- Fraunhofer FKIE (Germany)strategicTechnology exchange and cooperation agreement with Europe's largest applied research institution. Focus on deep malware analysis, reverse tracking capability enhancement, and AI-based new technology system development. Collaboration on Malpedia open malware search service integration.
- Kudo CommunicationminorKudo Communication-led consortium in KISA program building unified physical security monitoring system.
- Japanese Distribution PartnercoreExclusive distribution agreement for MNX NDR solution in Japan. First large-scale overseas revenue - 1,000 units exported. Overseas general distributor partnership.
- Logpresso ConsortiumcoreSANDSLab-led consortium for KISA KRW 45 billion cybersecurity AI dataset project. SANDSLab handles 90% of project scope focusing on latest malware and threat profiling dataset construction.
- KSAIN (케이사인)coreParent company relationship. KSAIN holds SANDSLab as subsidiary. Strategic support for COSDAQ listing and ongoing corporate governance.
- Kakao T (Toss partnership for IDPW)strategicIDPW personal information leak notification service partnership with Kakao T (Toss) to provide breach alerts to nationwide users through 'AppInToss' service.
Scale indicators11 records
Recent moves6 records
Expansion highlights6 records
SANDSLab competitors and assessment
Company assessmentBroad incumbents
- AhnLab: Korea's largest domestic cybersecurity vendor offering endpoint, network, and threat intelligence solutions. Most directly comparable as a Korean incumbent with broad security portfolio, though AhnLab is significantly larger and more diversified across consumer and enterprise security.
- Recorded Future: Global threat intelligence platform owned by Mastercard. Closely comparable on threat intelligence product category and AI-augmented intelligence approach, serving similar enterprise and government customers at significantly larger global scale.
- CrowdStrike: Global cybersecurity leader in endpoint detection, threat intelligence, and security operations. Comparable as a competitor in NDR/threat intelligence space (CrowdStrike Falcon Intelligence) with significantly broader platform and global enterprise scale.
- Mandiant: Threat intelligence and incident response leader (now part of Google Cloud). Comparable on threat intelligence and APT analysis capabilities, though operates at significantly larger scale with global government and enterprise customer base.
Direct peers
- S2W (S2WLAB): Korean AI-based threat intelligence company specializing in dark web monitoring and cyber threat analysis. Closely comparable as a Korea-headquartered AI-driven threat intelligence peer with similar customer profile (government, enterprise) and overlapping technology stack (AI/ML for malware and threat analysis).
- Anomali: Threat intelligence platform vendor offering threat aggregation, analysis, and integration with SIEM/SOAR. Directly comparable as a standalone threat intelligence platform with similar product-market fit to SANDSLab's CTX, including integrations with SIEM ecosystems.
- EclecticIQ: European threat intelligence platform vendor serving enterprise SOC teams and MSSPs. Comparable as a pure-play threat intelligence platform competitor with similar CTI/STM functionality and integration approach as SANDSLab's CTX.
Regional players
- Igloo Security: Korean cybersecurity vendor with threat intelligence and security operations capabilities. Comparable as a Korean regional cybersecurity player targeting similar enterprise and government customers, though with broader traditional security portfolio.
Emerging players
- Logpresso: Korean cloud SIEM specialist in which SANDSLab invested as a strategic investor in the KRW 16B Series B (December 2025). Directly comparable as a Korean security operations partner, with the two companies co-developing XDR ecosystem — overlap in security analytics and SOC automation.
Others
- VirusTotal: Google-owned malware analysis and threat intelligence aggregation platform that SANDSLab integrates with and partnered with as early as 2013. Comparable as a foundational threat data infrastructure layer, though operating as an open community service rather than commercial competitor.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat7 records
Key risks6 records
Key highlights7 records
Customer concentration
SANDSLab social profiles
Digital presenceSANDSLab compliance and trust
Trust signalCompliance3 records
SANDSLab financial estimates
Financial estimateRevenue estimate
Valuation estimate
SANDSLab leadership team
Management profileNumber of profiles
Profiles8 records
SANDSLab funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SANDSLab M&A and investment
M&A and investmentM&A
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SANDSLab
What does SANDSLab do?
SANDSLab builds and sells AI and big data-based cybersecurity software, centered on the CTX threat intelligence platform, MNX network detection and response (NDR) solution, and MDX malware detection solution. Its proprietary DBP and DDP profiling technologies power automated attacker profiling and malware analysis, while complementary services include cybersecurity AI datasets, an on-premise small language model (sLLM), and the FakeCheck deepfake detection service.
Is SANDSLab a public or private company?
SANDSLab is a public company. It is classified as public and is currently operating.
When was SANDSLab founded?
SANDSLab was founded in 2004. It employs 11 to 50 people.
Where is SANDSLab based?
SANDSLab is headquartered in Seoul, South Korea, in the Asia region.
How does SANDSLab make money?
Six revenue lines are on record. CTX Threat Intelligence Service is the primary driver. The others are MNX NDR Solution, MDX Solution, cybersecurity AI Dataset Sales, government Project Contracts and deepfake Detection Service.
Who are SANDSLab's main competitors?
Broad incumbents on record are AhnLab, Recorded Future, CrowdStrike and Mandiant. Direct peers are S2W (S2WLAB), Anomali and EclecticIQ. Igloo Security is listed as a regional player. Logpresso is listed as an emerging player. VirusTotal is listed as an others.
Does SANDSLab have an API?
Yes. CTX provides a customer-exclusive API that allows clients to access threat intelligence data directly. Customers can query threat indicators (IoCs), attack group profiles, and related analysis without requiring manual processing or development work. The API delivers curated intelligence tailored to the customer's specific environment and requirements. The service is positioned as a value-added offering where SANDSLab customizes the API output to each customer's needs rather than requiring customers to process raw data themselves.
What industry is SANDSLab in?
SANDSLab's product category is Cybersecurity Threat Intelligence Software. Its primary akta.pro industry code is HDAFAGAM, Network Analytics, AIOps & Root-Cause Correlation, with a secondary code of HLACAJAN, Vulnerability Management, Pen Testing & Attack Surface Management (ASM). Its NAICS code is 56162 and its SIC code is 7370.