Team Cymru
Team Cymru is a private threat intelligence firm operating the Pure Signal platform, which observes ~90% of global internet traffic via 800+ ISP partnerships, and serves 500+ enterprise customers across telecom, financial services, retail, government, and cybersecurity sectors.
- Company typePrivate
- Founded2005
- HeadquartersLake Mary, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Team Cymru does
Team Cymru is a privately held cybersecurity threat intelligence firm headquartered in Lake Mary, Florida, founded in 2005 and backed by Audax Private Equity since August 2021. The company operates the Pure Signal platform, which delivers real-time external threat intelligence grounded in direct first-party observation of IP-to-IP traffic through 800+ ISP partnerships. The platform processes over 1.3 billion daily events and observes approximately 90% of global internet traffic, combining NetFlow data, passive DNS, WHOIS, X.509 certificates, and behavioral intelligence to produce products spanning threat infrastructure analysis (Scout), threat hunting (Recon), attack surface management (Orbit), passive asset discovery (Radar), botnet analysis (BARS), and the newer machine-readable Total Insights Feed and Pure Signal MCP Server integrations.
Team Cymru monetizes primarily through annual and monthly subscriptions to its threat intelligence platform, data feeds, and APIs, supplemented by professional services for customer support and training. It reaches the market through direct enterprise field sales (including a dedicated federal sales motion via Carahsoft), the Red Dragon Technology Alliance Program for technology integrations (Splunk, Microsoft, Palo Alto Networks, Google SecOps, ThreatQuotient, Cyware, Anomali, OpenCTI), and MSSP/reseller channels. Named customers include AT&T, Cisco, Akamai, CrowdStrike, FireEye/Mandiant, Microsoft, Walmart, Deloitte, FS-ISAC, and Carahsoft, spanning telecommunications, cybersecurity platforms, financial services, retail, consulting, and government.
Following the 2021 Audax investment and the acquisition of attack-surface-management firm Amplicy, Team Cymru is undergoing a leadership and commercial transition under CEO Joe Sander (appointed April 2025). The company has rebuilt its executive team with a new CFO, CCO, CTO, and CMO, added experienced board members, launched multiple new products (RADAR in late 2025; Total Insights Feed and the Pure Signal MCP Server in April 2026), and established a Sydney APJ regional hub in June 2026 to extend its commercial footprint into Asia-Pacific and Japan.
Team Cymru firmographics
Firmographics- Name
- Team Cymru
- Legal name
- Team Cymru, Inc.
- Website
- https://team-cymru.com
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Team Cymru is a private threat intelligence firm operating the Pure Signal platform, which observes ~90% of global internet traffic via 800+ ISP partnerships, and serves 500+ enterprise customers across telecom, financial services, retail, government, and cybersecurity sectors.
- Ownership category
- akta.pro rank
Team Cymru industry classification
Industry- Product category
- Cybersecurity Threat Intelligence
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
Keywords
Where Team Cymru is headquartered
LocationHeadquarters
- HQ city
- Lake Mary
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
Team Cymru business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales
Revenue model
- Threat Intelligence Platform Subscriptions: Subscription-based access to Pure Signal platform including Scout, Recon, Radar, and Orbit products. Tiered configurations available with varying capability levels.
- Data Feeds: Machine-readable threat intelligence feeds including Total Insights Feed, IP Reputation Feed, Controller Feed, Botnet Analysis & Reporting Service. Updated hourly with near-real-time threat data.
- API Access: Scout API access for developers and technology partners through Red Dragon Alliance Program. Scout Ultimate API for advanced capabilities with 300+ billion daily records.
- Professional Services: Customer support, training, and enablement services. Includes incident management, compliance, and commercial support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Scout Insight - Basic API Access |
| Subscription | Annual | Scout Ultimate - Advanced API Access |
| Subscription | Annual | Total Insights Feed - Tiered Configurations |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels11 records
Team Cymru product offering
Product offeringCore offering
Team Cymru sells real-time cyber threat intelligence via its Pure Signal platform, built on direct first-party observation of global internet traffic through 800+ ISP partnerships. Core products include Pure Signal Scout (real-time threat infrastructure analysis), Pure Signal Recon (proactive threat hunting intelligence), Pure Signal Orbit (attack surface management), and Total Insights Feed (unified machine-readable threat feed with weighted risk scoring). The platform processes over 1.3 billion daily events covering 90% of global internet traffic and serves enterprise SOC teams, government agencies, and critical infrastructure operators through subscriptions, API access, and data feeds.
Product overview
Team Cymru offers the Pure Signal platform, a unified threat intelligence ecosystem consisting of core products Pure Signal Scout (real-time threat intelligence platform for global infrastructure analysis), Pure Signal Recon (internet signal intelligence for threat hunting), and Total Insights Feed (unified feed replacing legacy indicator lists). The platform includes add-on modules: Pure Signal Orbit (attack surface management), IP Reputation Feed (lightweight near-real-time feed with reputation scoring), Controller Feed (C2 identification), BARS (botnet analysis and reporting covering 40+ malware families), RADAR (passive asset discovery), NetFlow Advantage (network traffic visibility), Pure Signal MCP Server (AI agent integration for automated threat operations), and Community Services (free tools including Nimbus, UTRS, Bogon Reference, and CSIRT Assistance Program). The platform processes over 1.3 billion daily events from 800+ ISP partnerships, 90% of internet traffic observed, and 100% first-party original data.
Differentiator
Problem solved
Functional benefit
Brands
- Pure Signal™: The company's core threat intelligence platform and data ocean that provides real-time visibility into global internet activity and threat actor behavior.
- Pure Signal™ Recon
- Pure Signal™ Scout
- Pure Signal™ Orbit
- Total Insights Feed
- BARS - Botnet Analysis & Reporting Service
- RADAR
- Red Dragon Alliance Program
Products and services
- Pure Signal Scout Real-time threat intelligence platform providing the fastest tool on the market for global threat infrastructure analysis. Enables security teams to query the world's largest collection of real-time telemetry and threat intelligence to identify threats, make informed decisions, and drive rapid automated response through enrichment. Designed for SOC teams, threat hunters, and security analysts.
- Pure Signal Recon Next-generation internet signal intelligence solution enabling proactive threat hunting and threat reconnaissance. Provides the most comprehensive source of cyber threat intelligence data available with real-time access to over 50 datasets. Designed for defenders seeking to proactively identify threats outside their perimeter.
- Pure Signal Orbit Attack surface management solution that transforms how organizations manage digital business risk. Discovers more digital assets than any other method or service with industry-leading vulnerability scanning frequency and uniquely integrated asset-specific threat intelligence. Designed for security teams managing organizational external attack surface.
- Total Insights Feed Unified threat intelligence platform that evaluates over 57 million IPs and 400 million domains daily with weighted risk scoring. Provides machine-actionable, scored intelligence with over 2,000 contextual attributes including malware families, MITRE ATT&CK mapping, and actor attribution. Replaces legacy static indicator lists enabling automated security operations without manual triage. Delivered as single JSON stream compatible with major security platforms.
- Botnet Analysis & Reporting Service (BARS) In-depth analysis, tracking, and history of 40+ malware families that utilize unique control protocols and possibly encryption mechanisms. Provides holistic view of adversarial campaigns with correlation across C2s, victim IPs, malware targets, and DDoS attack instructions. Includes geolocation, victimology, and complete campaign history. Updated every 60 minutes.
- IP Reputation Feed Lightweight near-real-time feed of all controllers and victims providing IP-centric threat intelligence with the widest range of victims. Enables users to vet visitors to a service, optimize firewalls, and automatically deprioritize low-criticality alerts. Updated hourly with individual reputation scores derived from behavioral patterns observed over 30 days.
- Controller Feed DNS-centric feed covering all observed controllers with full URL, malware hash, and DNS resource record. Provides real-time identification of botnet command and control IP addresses including IRC, HTTP, and P2P botnets. Enables blocking compromised nodes, malicious attachments, and application-level firewalling.
- RADAR (Pure Signal Radar) Passive asset discovery tool providing instant infrastructure visibility to cyber defenders. Enables discovery of digital assets through passive observation without active scanning, supporting attack surface awareness and infrastructure reconnaissance.
- Pure Signal MCP Server MCP server connecting AI agents from Microsoft, Anthropic, and Google to the world's largest threat intelligence database using the Model Context Protocol standard. First purpose-built, production-grade, LLM-native integration for high-volume threat intelligence enabling automated security operations at machine speed including alert investigations and threat hunting.
- Scout API API access to threat intelligence data for developers and technology partners through the Red Dragon Alliance Program. Scout Insight API provides IP/domain insights, rapid malicious IP identification, 1800+ tags, open ports, X.509 certificate details, and cryptographic hashes. Scout Ultimate API provides access to over 300 billion internet communication records daily, IP activity overview, open ports analysis, PDNS insights, fingerprint and hash database, and X.509 certificate details.
- Community Services Free community services including Nimbus Threat Monitor (near-real-time threat monitoring), UTRS Unwanted Traffic Removal Service (DDoS mitigation), Bogon Reference (filtering invalid/unallocated IP addresses), MHR Malware Hash Registry API, and CSIRT Assistance Program (supporting over 124 CSIRTs worldwide protecting 52% of IPv4 and 72% of IPv6). Available to security researchers, CSIRTs, and the broader internet community at no cost.
Quantifiable outcome
- 57+ million IPs and 400+ million domains analyzed daily with 2000+ contextual attributes
- +3 more outcomes
Companies that use Team Cymru
Customer profileNamed customers10 records
Segments6 records
Ideal customer profiles4 records
Team Cymru technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability5 records
Feature11 records
Team Cymru partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core, strategic and minor.
- OpenCTI (Filigran)coreStrategic partnership integrating Team Cymru's Pure Signal intelligence and Scout capabilities into OpenCTI platform. Enables instant enrichment, automated threat-hunting workflows, and global visibility for security analysts.
- The Vertex ProjectstrategicPartnership to enable real-time threat visibility with Synapse platform, integrating Team Cymru's intelligence capabilities.
- INTERPOLcorePrivate-sector partner in INTERPOL operations including Operation Ramz (MENA region, Oct 2025-Feb 2026, 201 arrests) and Operation Red Card 2.0. Provided threat intelligence enabling law enforcement to locate and dismantle malicious infrastructure.
- Microsoft Security CopilotcoreIntegration bringing Team Cymru's threat intelligence directly into Microsoft Security Copilot for AI-generated context in security teams.
- AmplicycoreAcquired by Team Cymru in November 2021 to enhance cyber risk analysis capabilities. Amplicy was a threat surface management firm, and the combination aimed to provide comprehensive view of organizational attack surfaces and vulnerabilities.
- EdgeUnocorePartnership to implement first international PoP in Sao Paulo, Brazil for Team Cymru's global network backbone. Enables more efficient visibility into malicious internet activity within or traversing through Latin America.
- Google SecOpscoreJointly developed integration integrating Team Cymru's Scout with Google SecOps SIEM and SOAR. Provides IP, domain, and NetFlow intelligence enrichment. Includes free playbooks and blocks for automated security operations.
- Arctic SecuritystrategicPartnership delivering joint cyber threat research. Collaboration revealed compromised organizations data during COVID-19 pandemic.
- NisosstrategicPartnership to give cybersecurity teams advantage of applying network forensics at internet scale.
- Network Time FoundationminorTeam Cymru joined as member of NTP Consortium, Time Source Consortium, and General Timestamp API Consortium to support accurate timekeeping for cybersecurity applications.
- MANRS (Internet Society)strategicFirst cybersecurity partner to join MANRS initiative for improving routing security. Supports filtering, anti-spoofing, coordination, and global validation.
- SplunkcoreFeatured technology partner in Red Dragon Alliance Program. Integration into Splunk security platform for threat intelligence enrichment.
- Palo Alto NetworkscoreFeatured technology partner in Red Dragon Alliance Program. Integration with Palo Alto XSOAR for security orchestration.
- ThreatQuotientstrategicTechnology partner in Red Dragon Alliance Program. Integration for threat intelligence platform coordination.
- CywarestrategicTechnology partner in Red Dragon Alliance Program. Integration for threat intelligence sharing and orchestration.
- VertexstrategicTechnology partner in Red Dragon Alliance Program. Integration for threat intelligence operations.
Scale indicators13 records
Recent moves7 records
Expansion highlights7 records
Team Cymru competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Mandiant, now part of Google Cloud, provides threat intelligence as part of a broader incident response and consulting portfolio. It competes with Team Cymru for enterprise threat intelligence budget but operates at a larger scale and across a wider service offering including IR retainers and adversary simulation.
- CrowdStrike: CrowdStrike is both a customer of Team Cymru (using its intelligence for Falcon enrichment) and a competitor via Falcon Intelligence, which embeds threat intelligence into its broader endpoint and cloud security platform. Represents the platform-bundling threat to pure-play threat intelligence.
- Palo Alto Networks Unit 42: Unit 42 is Palo Alto Networks' threat intelligence and incident response arm, embedded in their broader security platform including XSOAR and Cortex. Comparable to Team Cymru in intelligence category, but bundled within a larger network security platform.
- Microsoft Defender Threat Intelligence: Microsoft offers Defender Threat Intelligence as part of its broader security platform, integrating intelligence across Defender, Sentinel, and Security Copilot. As a hyperscaler, Microsoft represents the most significant bundling threat to Team Cymru's enterprise market.
Direct peers
- Anomali: Anomali provides a threat intelligence platform (TIP) and security analytics that competes with Team Cymru's Pure Signal Scout and Total Insights Feed. Both serve enterprise security operations and are integrated with similar SIEM/SOAR platforms (Splunk, Palo Alto, Microsoft), making them direct alternatives for security teams.
- Intel 471: Intel 471 is a direct competitor providing adversary intelligence and cybercrime intelligence, with a focus on malware, fraud, and underground market activity. Like Team Cymru, it sells subscription intelligence to enterprise and government customers and emphasizes first-party intelligence collection.
- Recorded Future: Recorded Future is a direct competitor offering a threat intelligence platform that ingests data from across the open, dark, and deep web. Both companies sell subscription threat intelligence to enterprise SOCs and security teams, and both emphasize the breadth and uniqueness of their underlying data sources as key differentiators.
- Cyware: Cyware provides a threat intelligence platform and SOAR solutions focused on operationalizing threat intelligence and automating security workflows. Like Team Cymru, it integrates with major security stacks (Splunk, Palo Alto, Microsoft) and is part of the Red Dragon Alliance Program as an integration partner.
- ThreatQuotient: ThreatQuotient is a direct competitor in the threat intelligence platform space, offering a TIP that ingests, operationalizes, and shares threat data. Team Cymru and ThreatQuotient are listed together in the Red Dragon Alliance Program as integration partners, indicating close category overlap.
- LookingGlass Cyber Solutions: LookingGlass Cyber Solutions offers external threat intelligence, attack surface management, and threat response solutions that directly overlap with Team Cymru's Pure Signal Scout, Recon, and Orbit products. Both serve enterprise security teams with real-time internet intelligence.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Team Cymru social profiles
Digital presenceTeam Cymru compliance and trust
Trust signalCompliance4 records
Team Cymru financial estimates
Financial estimateRevenue estimate
Valuation estimate
Team Cymru leadership team
Management profileNumber of profiles
Profiles6 records
Team Cymru funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Team Cymru M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Team Cymru
What does Team Cymru do?
Team Cymru sells real-time cyber threat intelligence via its Pure Signal platform, built on direct first-party observation of global internet traffic through 800+ ISP partnerships. Core products include Pure Signal Scout (real-time threat infrastructure analysis), Pure Signal Recon (proactive threat hunting intelligence), Pure Signal Orbit (attack surface management), and Total Insights Feed (unified machine-readable threat feed with weighted risk scoring). The platform processes over 1.3 billion daily events covering 90% of global internet traffic and serves enterprise SOC teams, government agencies, and critical infrastructure operators through subscriptions, API access, and data feeds.
Is Team Cymru a public or private company?
Team Cymru is a private company. It is classified as private equity controlled and is currently operating.
When was Team Cymru founded?
Team Cymru was founded in 2005. It employs 51 to 100 people.
Where is Team Cymru based?
Team Cymru is headquartered in Lake Mary, United States, in the North America region.
How does Team Cymru make money?
Four revenue lines are on record. Threat Intelligence Platform Subscriptions are the primary driver. The others are data Feeds, API Access and professional Services.
Who are Team Cymru's main competitors?
Broad incumbents on record are Mandiant (Google Cloud), CrowdStrike, Palo Alto Networks Unit 42 and Microsoft Defender Threat Intelligence. Direct peers are Anomali, Intel 471, Recorded Future, Cyware, ThreatQuotient and LookingGlass Cyber Solutions.
Does Team Cymru have an API?
Yes. Team Cymru offers the Scout API through its Red Dragon Technology Alliance Program. The Scout Insight API provides detailed IP and domain insights, rapid malicious IP identification, extensive tagging system (over 1,800 tags), advanced data access including open ports, X.509 certificate details, and cryptographic hashes. The Scout Ultimate API provides access to over 300 billion internet communication records daily, with IP activity overview, open ports analysis, PDNS insights, fingerprint and hash database, and X.509 certificate details. Access requires a Scout Insight license (30-day free trial available) or Red Dragon program membership for Scout Ultimate API, Orbit API, and Recon API. Developer documentation is at scout.cymru.com/docs/scout/insight.
What industry is Team Cymru in?
Team Cymru's product category is Cybersecurity Threat Intelligence. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services. Its NAICS code is 5415 and its SIC code is 7371.