Bricata
Bricata built a Network Detection & Response platform combining signature inspection, anomaly detection, and machine learning for SOCs and MSSPs, with SmartPCAP full-packet capture and native integrations into Splunk, QRadar, Sentinel, CrowdStrike, and Palo Alto Cortex. The product is now sold as OpenText Network Detection & Response.
- Company typePrivate
- Founded2014
- HeadquartersColumbia, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Bricata does
Bricata was a Columbia, Maryland-based network security company founded in 2014 that built a Network Detection & Response (NDR) platform combining signature inspection, anomaly detection, and machine learning to deliver real-time threat detection across encrypted and unencrypted traffic. The platform's core technical differentiators were SmartPCAP (full packet capture directly linked to alerts), adaptive Smart Sensors for cloud-hybrid deployments, an encrypted traffic analysis engine that operates on flow and metadata without payload decryption, and a long-term session-based metadata repository for historical threat hunting. Native integrations with Splunk, IBM QRadar, Microsoft Sentinel, CrowdStrike, and Palo Alto Networks Cortex XSOAR positioned the product as a complementary telemetry source within existing SOC stacks rather than a standalone console.
The company generated revenue through an enterprise subscription model with multi-year contracts and quote-based pricing, selling direct to Security Operations Centers and indirectly through Managed Security Service Providers (MSSPs). Distribution combined a direct enterprise sales motion, an inside sales team, a partner/reseller channel, and listings on the AWS, Google Cloud, and Microsoft Azure marketplaces. Named reference customers include MSSPs MAD Security and MegaplanIT and a major consumer goods corporation's security team.
Bricata's product is now sold and marketed as OpenText Network Detection & Response within the OpenText Cybersecurity portfolio, distributed via OpenText's global enterprise sales, partner, and cloud channels. The original Bricata entity remains listed as a privately held firm with 11–50 employees and a Columbia, MD footprint; its disclosed funding history shows six rounds totaling approximately $15.4M between 2014 and 2020, including a $8.0M round led by Edison Partners in 2017.
Bricata firmographics
Firmographics- Name
- Bricata
- Legal name
- Bricata
- Website
- https://bricata.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Bricata built a Network Detection & Response platform combining signature inspection, anomaly detection, and machine learning for SOCs and MSSPs, with SmartPCAP full-packet capture and native integrations into Splunk, QRadar, Sentinel, CrowdStrike, and Palo Alto Cortex. The product is now sold as OpenText Network Detection & Response.
- Ownership category
- akta.pro rank
Bricata industry classification
Industry- Product category
- Network Detection and Response (NDR)
- NAICS
- Software Publishers (513210), Software Publishers (5132)
- akta.pro primary industry
- Network Detection & Response (NDR) (HDADABAI)
Keywords
Where Bricata is headquartered
LocationHeadquarters
- HQ city
- Columbia
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Bricata business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Network Detection & Response Platform: Enterprise security software subscription model providing real-time network monitoring, threat detection, and incident response capabilities with flexible deployment options including cloud, on-premises, and hybrid configurations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Enterprise subscription with flexible deployment options |
Distribution channels4 records
Marketing channels6 records
Bricata product offering
Product offeringCore offering
Bricata provides a Network Detection and Response (NDR) platform that monitors network traffic in real time to detect intrusions, surface threats, and enable threat hunting across hybrid enterprise environments. The platform unifies signature inspection, anomaly detection, and machine learning with full packet capture (SmartPCAP) and integrates with SIEM, SOAR, and EDR tools, sold today as OpenText Network Detection & Response via enterprise subscriptions.
Product overview
OpenText Network Detection & Response is a unified platform that delivers 100% complete network threat detection and visibility. The platform combines detection, forensics, and response in one scalable solution to strengthen security posture. Key capabilities include SmartPCAP for threat context, adaptive sensors for hybrid network detection, seamless SIEM/SOAR/EDR integrations (Splunk, QRadar, Sentinel, CrowdStrike, Palo Alto Networks Cortex), and cloud-hybrid deployment support. The platform uses machine learning and behavioral analysis for anomaly detection and threat hunting.
Differentiator
Problem solved
Functional benefit
Products and services
- OpenText Network Detection and Response (formerly Bricata NDR) A network security platform that combines signature inspection, anomaly detection, and machine learning to provide complete visibility across networks with real-time monitoring, full packet capture (SmartPCAP), and automated response capabilities for Security Operations Centers and Managed Security Service Providers.
Quantifiable outcome
- 50% reduction in SLA times for managed security services
- +2 more outcomes
Companies that use Bricata
Customer profileNamed customers3 records
Segments2 records
Ideal customer profiles2 records
Bricata technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability3 records
Feature6 records
Bricata partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and flagship.
- SplunkcoreNative integration partnership enabling NDR alerts and context to feed into Splunk SIEM platform for unified security operations.
- IBM QRadarcoreNative integration enabling NDR to push threat intelligence and alerts to IBM QRadar for incident response workflows.
- Microsoft SentinelcoreIntegration with Microsoft Sentinel SIEM for unified threat detection and response across enterprise environments.
- CrowdStrikecoreIntegration with CrowdStrike endpoint detection and response for comprehensive security coverage across network and endpoints.
- Palo Alto Networks Cortex XSOARcoreIntegration with Palo Alto Networks SOAR platform for automated incident response workflows and orchestration.
- Amazon Web ServicesflagshipStrategic cloud partnership enabling NDR deployment and optimization on AWS cloud infrastructure.
- Google CloudflagshipStrategic cloud partnership enabling deployment and optimization on Google Cloud Platform.
- Microsoft AzureflagshipStrategic cloud partnership enabling deployment and optimization on Microsoft Azure with secure and compliant public cloud operations.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Bricata competitors and assessment
Company assessmentDirect peers
- Darktrace: Darktrace is a leading AI-driven NDR and cybersecurity platform focused on anomaly-based threat detection across enterprise networks. It directly competes with Bricata on behavioral detection, ML, and SOC use cases.
- ExtraHop: ExtraHop provides Reveal(x), a network detection and response platform that uses machine learning and full-stream analysis to identify threats. Directly comparable to Bricata's NDR/SmartPCAP approach and SOC buyer profile.
- Vectra AI: Vectra AI focuses on AI-driven network threat detection and response for hybrid and multi-cloud environments. Overlaps directly with Bricata on NDR analytics, encrypted traffic analysis, and SOC workflows.
- Corelight: Corelight delivers an open NDR platform built on Zeek, combining signatures, behavioral analytics, and full PCAP for threat hunting—directly aligned with Bricata's combination of packet capture and ML detection.
- IronNet Cybersecurity: IronNet offers network detection and collective defense solutions focused on behavioral analytics for enterprise and government SOCs. Comparable to Bricata on NDR analytics and SOC use cases.
- Plixer (now part of Ivanti): Plixer provides network detection, response, and analytics platforms targeted at SOC teams and MSSPs. Directly comparable in functionality, customer segment, and detection-engine approach to Bricata.
Broad incumbents
- Cisco (Secure Network Analytics / Stealthwatch): Cisco's Secure Network Analytics/Stealthwatch is an enterprise NDR offering that competes with Bricata in large enterprise SOCs. As a much larger incumbent, Cisco bundles NDR into a broader networking and security portfolio.
- Palo Alto Networks (Cortex XDR / XSIAM): Palo Alto Networks is both a Bricata integration partner (Cortex XSOAR) and a broad incumbent whose XDR/XSIAM offerings increasingly absorb NDR functionality, creating competitive pressure on standalone NDR vendors.
- RSA NetWitness Network: RSA NetWitness Network is a network detection, monitoring, and forensics offering within RSA's broader security analytics portfolio. As an incumbent SIEM-adjacent platform, it competes with Bricata for enterprise SOC spend.
Emerging players
- IronNet-level specialist (e.g., Tidal Cyber / Stellar Cyber): Stellar Cyber is an open XDR/NDR platform geared to MSSPs and mid-market SOCs with packet capture, ML detection, and SIEM/SOAR integrations—comparable to Bricata in target segments and delivery model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Bricata social profiles
Digital presenceBricata financial estimates
Financial estimateRevenue estimate
Valuation estimate
Bricata leadership team
Management profileNumber of profiles
Profiles4 records
Bricata funding detail
Funding detailFunding overview
Funding rounds6 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Bricata M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Bricata
What does Bricata do?
Bricata provides a Network Detection and Response (NDR) platform that monitors network traffic in real time to detect intrusions, surface threats, and enable threat hunting across hybrid enterprise environments. The platform unifies signature inspection, anomaly detection, and machine learning with full packet capture (SmartPCAP) and integrates with SIEM, SOAR, and EDR tools, sold today as OpenText Network Detection & Response via enterprise subscriptions.
Is Bricata a public or private company?
Bricata is a private company. It is classified as corporate owned and is currently operating.
When was Bricata founded?
Bricata was founded in 2014. It employs 11 to 50 people.
Where is Bricata based?
Bricata is headquartered in Columbia, United States, in the North America region.
How does Bricata make money?
One revenue line is on record: network Detection & Response Platform.
Who are Bricata's main competitors?
Direct peers on record are Darktrace, ExtraHop, Vectra AI, Corelight, IronNet Cybersecurity and Plixer (now part of Ivanti). Broad incumbents are Cisco (Secure Network Analytics / Stealthwatch), Palo Alto Networks (Cortex XDR / XSIAM) and RSA NetWitness Network. IronNet-level specialist (e.g., Tidal Cyber / Stellar Cyber) is listed as an emerging player.
Does Bricata have an API?
Yes. OpenText Network Detection and Response offers APIs and syslog capabilities to feed alerts and context into external security tools. The developer portal at developer.opentext.com provides API technical documentation for building custom applications. Developer documentation is at developer.opentext.com.
What industry is Bricata in?
Bricata's product category is Network Detection and Response (NDR). Its primary akta.pro industry code is HDADABAI, Network Detection & Response (NDR). Its NAICS code is 513210.