RST Cloud
RST Cloud is an Australia-based AI-enabled cyber threat intelligence vendor offering IoC feeds, multilingual report processing, honeypot-derived telemetry, and multi-agentic CTI AI APIs to enterprise, government, and financial-sector SOCs globally, with a particular GCC growth focus.
- Company typePrivate
- Founded2022
- HeadquartersSydney, Australia
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What RST Cloud does
RST Cloud is a privately held cyber threat intelligence (CTI) vendor headquartered in Sydney, Australia, founded in 2022 when the Australian entity RST Cloud Pty Ltd acquired all intellectual property from SIA RST Cloud. The company operates an AI-enabled threat intelligence engine that ingests multilingual threat data from over 260 sources, processes more than 250,000 unique indicators daily, and outputs normalized machine-readable intelligence in STIX 2.1, MISP, JSON, CSV, and related formats. Proprietary first-party collection includes a global honeypot network deployed across 20+ countries and a C2 Tracker developed in collaboration with Netlas.io. The product portfolio comprises RST Threat Feed (core IoC subscription), RST Report Hub (multilingual report-to-STIX library), RST Threat Library (MISP/OpenCTI Galaxy clusters), RST IoC Lookup, RST Whois API, RST Noise Control, RST C2 Tracker, RST Honeypot Network, and RST CTI Assistant (a multi-agentic AI API layer on Google's A2A and MCP protocols).
RST Cloud distributes its products through a multi-channel model combining direct enterprise field sales, PLG via free trials and self-service API access, technology partnerships with Splunk, Microsoft, IBM, Palo Alto, Fortinet, Cisco, Trend Micro, ThreatQuotient, Filigran/OpenCTI, and Priam AI, and a regional channel partner (VM Group W.L.L) covering the GCC. The platform integrates with major SIEM, SOAR, TIP, NGFW, EDR, and XDR solutions, and is used by named customers including inDrive (mobility), AlpenShield (cybersecurity), Sahara Net (KSA telecom), and UWV (Dutch government). Revenue is generated via subscription-based API and feed pricing that is quote-based and not publicly disclosed; the company reports 1-10 employees, remains founder-controlled under CEO Yury Sergeev, and has not raised institutional capital.
RST Cloud firmographics
Firmographics- Name
- RST Cloud
- Legal name
- RST Cloud Pty Ltd
- Website
- https://rstcloud.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- RST Cloud is an Australia-based AI-enabled cyber threat intelligence vendor offering IoC feeds, multilingual report processing, honeypot-derived telemetry, and multi-agentic CTI AI APIs to enterprise, government, and financial-sector SOCs globally, with a particular GCC growth focus.
- Ownership category
- akta.pro rank
RST Cloud industry classification
Industry- Product category
- Cybersecurity Threat Intelligence
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
Keywords
Where RST Cloud is headquartered
LocationHeadquarters
- HQ city
- Sydney
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
RST Cloud business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- RST Threat Feed Subscription: Subscription-based service delivering indicators of compromise collected, aggregated, filtered, and scored from hundreds of threat intelligence sources. Provides comprehensive context to accelerate incident prevention and response with actionable data for automation solutions.
- RST Report Hub Subscription: Subscription access to the electronic library housing threat reports transformed from human-readable formats into machine-readable formats including STIX 2.1.
- RST IoC Lookup API: API subscription service for checking individual indicators against the full aggregated database of historical threat intelligence.
- RST Whois API: Subscription-based WHOIS lookup API providing unlimited domain registration information queries with no rate limiting.
- RST Noise Control: Subscription service for verifying whether indicators are 'known-good' and filtering false positives from security pipelines.
- Free Trial: Free trial accounts offered for customers to evaluate products before committing to subscription.
Go-to-market motion5 records
Distribution channels5 records
Marketing channels9 records
RST Cloud product offering
Product offeringCore offering
RST Cloud sells a subscription-based cyber threat intelligence (CTI) platform built on an AI/ML-enabled engine that aggregates, normalizes, scores, and enriches threat data from 260+ global sources in multiple languages. Its core products are the RST Threat Feed (IoCs delivered in STIX 2.1, MISP, CSV, JSON), RST Report Hub (multilingual threat reports converted to machine-readable formats), and complementary API services (RST IoC Lookup, RST Noise Control, RST Whois API, RST Threat Library, and the RST CTI Assistant multi-agentic AI layer) targeting SOC teams and enterprises.
Product overview
RST Cloud is a cyber threat intelligence (CTI) platform built around a proprietary AI-enabled threat intelligence engine. The core portfolio consists of the RST Threat Feed (main IoC feed delivering ~250k+ indicators daily in STIX 2.1/MISP/CSV/JSON formats) and RST Report Hub (library transforming multilingual threat reports into machine-readable formats). These are complemented by enrichment and utility modules: RST IoC Lookup (individual indicator reputation queries), RST Whois API (domain registration enrichment), RST Noise Control (false positive filtering), RST Threat Library (structured threat actor/malware/TTP definitions as Galaxy clusters), and RST CTI Assistant (multi-agentic AI API layer on A2A/MCP protocols). Proprietary data-collection technologies include the RST Honeypot Network (global sensor deployment) and RST C2 Tracker (real-time C2 server detection via Netlas.io and Shodan/Censys integration). All products are accessible via REST APIs, support industry-standard integrations with SIEM (Splunk, Microsoft Sentinel, QRadar, Elastic, ArcSight), NGFW (FortiGate, Palo Alto, Cisco Firepower), SOAR (Cortex XSOAR), and TIP platforms (OpenCTI, MISP, ThreatQuotient), and deliver data as machine-readable IoCs, STIX objects, and enriched threat context.
Differentiator
Problem solved
Functional benefit
Products and services
- RST Threat Feed Subscription-based threat intelligence feed delivering indicators of compromise (IP addresses, domains, URLs, file hashes) collected, aggregated, filtered, and scored from hundreds of sources worldwide. Provides approximately 250,000+ unique indicators per day, enriched with threat category, malware family, CVE attribution, threat actor attribution, and risk scores. Supports machine-readable formats including STIX 2.1, MISP, CSV, JSON, XML, ndJSON. Designed for SOC teams and enterprises integrating CTI into SIEM, SOAR, TIP, NGFW, EDR, XDR, and WAF systems.
- RST Report Hub Electronic library of threat reports transformed from human-readable formats (blogs, PDFs, technical articles in multiple languages) into machine-readable STIX 2.1 and MISP formats. Automatically translates multilingual sources, extracts summaries, key facts, IoCs, TTPs, malware names, YARA and Sigma rules, and maps to MITRE ATT&CK. Provides Galaxy mapping with four clusters: Threat Actors, Malware, Campaigns, and Tools. Designed for SOC analysts and CTI teams.
- RST Threat Library
Quantifiable outcome
- New indicators of compromise available within an hour of detection
- +4 more outcomes
Companies that use RST Cloud
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
RST Cloud technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability10 records
Feature10 records
RST Cloud partnerships and signals
Strategic signalPartnerships
20 partnerships are on record, tiered strategic and core.
- Cyberani by Aramco DigitalstrategicAgreement signed at Black Hat Middle East and Africa 2025 to strengthen Cyberani's OSINT-driven cyber investigation capabilities and enhance 24/7 security operations for enterprise and industrial customers.
- Filigran (OpenCTI)strategicPartnership to bring structured global threat research and universal threat profiles to OpenCTI. RST Cloud's threat intelligence integrated natively into the leading open-source threat intelligence platform.
- Sahara NetstrategicCTI partnership to strengthen cloud and network protection across the Kingdom of Saudi Arabia. Sahara Net is both a customer and strategic partner, focusing on SAMA compliance requirements.
- Priam AIstrategicWorld's first CTI AI agents powered by A2A and MCP protocols. Integration of RST Cloud's threat intelligence data into Priam AI's AVA platform for enhanced SOC capabilities. Addresses shortage of skilled cybersecurity personnel.
- ThreatQuotientstrategicStrategic partnership bringing RST Cloud's advanced CTI services together with ThreatQuotient's ThreatQ Platform to bolster threat detection and response capabilities for joint customers.
- VirtuThinkostrategicPartnership announced at LEAP expo in Riyadh for cutting-edge cybersecurity solutions in Bahrain, Saudi Arabia, and the broader Middle East. VirtuThinko combines RST Cloud's threat intelligence with VM Group's strategic expertise.
- Netlas.iocoreStrategic partnership for RST C2 Tracker development. Netlas.io's advanced Internet Scan technology combined with RST Cloud's threat intelligence to detect and monitor active C2 servers worldwide in real time. This collaboration enables comprehensive C2 infrastructure visibility.
- VM GroupcoreRST Cloud representative in the GCC region. VM Group W.L.L handles sales, support, and partner relationships in Bahrain, UAE, Saudi Arabia and broader Middle East market. Located in Manama, Bahrain.
- Trend MicrostrategicIntegration of RST Cloud's CTI into Trend Micro's Trend Vision One platform, enhancing automated threat hunting capabilities for joint customers.
- SAF SystemscoreTechnology alliance integrating RST Threat Feed and RST Report Hub into the SAF monitoring platform. Empowers cybersecurity features with real-time CTI data access.
- Peakhour.iocoreJoint solution to expose and block malicious residential proxy traffic. Integration helps detect sophisticated automation and proxy-driven abuse, reducing fraud and security events.
- FortinetcoreRST Threat Feed directly integrated with FortiGate firewalls via API, enabling blocking or alerting on malicious websites and IP addresses with seamless integration.
- Palo Alto NetworkscoreIntegrations with Palo Alto NGFW and Cortex XSOAR. NGFW integration via API for blocking malicious resources; XSOAR integration for querying RST Cloud API directly from playbooks.
- SplunkcoreRST Threat Feed app available on Splunk marketplace for automated downloading and maintenance of feeds into Splunk Enterprise. Includes detection rules and daily sync support.
- MicrosoftcoreRST Threat Feed integrated with Microsoft Sentinel via STIX v2.1 and TAXII protocol, populating threat intelligence tables automatically.
- IBMcoreRST Threat Feed integrated with IBM QRadar SIEM via RST Downloader agent for automated data download and push to SIEM via API.
- ElasticcoreRST Threat Feed integrated with Elastic SIEM via custom elastic filebeat/agent configuration.
- MISPcoreRST Threat Feed integrated with MISP via Python script, enabling filtering of indicators through scores, types, malware, and tags.
- ArcSightcoreRST Threat Feed integrated with ArcSight ESM/Logger via RST Downloader agent.
- CiscocoreCisco Firepower directly integrated with RST Threat Feed via API for blocking or alerting on malicious resources.
Scale indicators4 records
Recent moves7 records
Expansion highlights5 records
RST Cloud competitors and assessment
Company assessmentBroad incumbents
- Mandiant: Mandiant (now part of Google Cloud) provides finished threat intelligence, IoC feeds, and adversary tracking via its Advantage Threat Intelligence product. Comparable as a higher-end intelligence offering with broader incident response and consulting services that complement the CTI feed play.
- CrowdStrike: CrowdStrike Falcon Intelligence delivers threat intelligence feeds and adversary profiling as part of its broader XDR/EDR platform. A formidable incumbent with vastly larger distribution and bundling power that competes with RST Cloud for SOC CTI budgets.
Direct peers
- ThreatConnect: ThreatConnect offers a combined TIP and SOAR platform with threat intelligence feeds, enrichment APIs, and orchestration — directly overlapping with RST Cloud's feed + Report Hub + CTI Assistant value proposition for SOC automation.
- Group-IB: Group-IB offers threat intelligence, fraud prevention, and incident response with feeds, adversary tracking, and integrations — overlapping with RST Cloud's CTI offering, particularly for financial sector and APAC/EMEA enterprise customers.
- Recorded Future: Recorded Future (owned by Mastercard) is the largest pure-play threat intelligence platform, offering IoC feeds, finished intelligence, and integrations with the same SIEM/SOAR/NGFW ecosystem as RST Cloud. It is the most directly comparable CTI vendor in terms of offering breadth (threat feeds, reports, APIs) and customer base.
- Cybersixgill: Cybersixgill specializes in deep and dark web threat intelligence with automated IoC collection and enrichment APIs — closely aligned with RST Cloud's multilingual, automated threat feed and Report Hub capabilities serving enterprise SOCs.
- Anomali: Anomali provides a threat intelligence platform (TIP) with threat feeds, IoC enrichment, and integrations into SIEM/EDR/SOAR — closely matching RST Cloud's Threat Feed, IoC Lookup, and STIX/TAXII delivery model. Both target enterprise SOCs seeking to operationalize CTI at machine speed.
- SOCRadar: SOCRadar provides threat intelligence, digital risk protection, and attack surface management — overlapping directly with RST Cloud's external threat monitoring, IoC feeds, and enterprise SOC use cases. Comparable size and go-to-market as a challenger CTI vendor.
- Flashpoint: Flashpoint delivers finished threat intelligence and breach data with IoC feeds and APIs — directly comparable to RST Cloud's threat feed, report hub, and IoC enrichment model for SOC and fraud teams.
- LookingGlass Cyber: LookingGlass provides threat intelligence feeds, IoC scoring, and attack surface monitoring — directly comparable to RST Cloud's scored IoC feed, multi-source aggregation, and enterprise SOC integrations.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
RST Cloud social profiles
Digital presenceRST Cloud financial estimates
Financial estimateRevenue estimate
Valuation estimate
RST Cloud leadership team
Management profileNumber of profiles
Profiles1 record
RST Cloud funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RST Cloud M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RST Cloud
What does RST Cloud do?
RST Cloud sells a subscription-based cyber threat intelligence (CTI) platform built on an AI/ML-enabled engine that aggregates, normalizes, scores, and enriches threat data from 260+ global sources in multiple languages. Its core products are the RST Threat Feed (IoCs delivered in STIX 2.1, MISP, CSV, JSON), RST Report Hub (multilingual threat reports converted to machine-readable formats), and complementary API services (RST IoC Lookup, RST Noise Control, RST Whois API, RST Threat Library, and the RST CTI Assistant multi-agentic AI layer) targeting SOC teams and enterprises.
Is RST Cloud a public or private company?
RST Cloud is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was RST Cloud founded?
RST Cloud was founded in 2022. It employs 1 to 10 people.
Where is RST Cloud based?
RST Cloud is headquartered in Sydney, Australia, in the Oceania region.
How does RST Cloud make money?
Six revenue lines are on record. RST Threat Feed Subscription is the primary driver. The others are RST Report Hub Subscription, RST IoC Lookup API, RST Whois API, RST Noise Control and free Trial.
Who are RST Cloud's main competitors?
Broad incumbents on record are Mandiant and CrowdStrike. Direct peers are ThreatConnect, Group-IB, Recorded Future, Cybersixgill, Anomali, SOCRadar, Flashpoint and LookingGlass Cyber.
Does RST Cloud have an API?
Yes. RST Cloud offers multiple API products: RST Threat Feed API (delivers indicators of compromise in machine-readable formats including CSV, TSV, JSON, ndJSON, XML, MISP, STIX 2.1); RST Report Hub API (converts human-readable threat reports into machine-readable STIX 2.1 and MISP formats); RST IoC Lookup API (query individual IP addresses, domains, URLs, and file hashes for reputation scores and threat context); RST Noise Control API (verify whether indicators are classified as 'known-good'); RST Whois API (domain registration data in JSON format with unlimited speed); RST CTI Assistant API (multi-agentic AI layer over threat feeds and enrichment APIs for SOAR, TIP, and custom workflows with source-referenced answers). The STIX/TAXII integration supports STIX v2.1 and TAXII protocol for Microsoft Sentinel. RST Threat Feed supports standard formats: STIX/TAXII, MISP, CSV, JSON, ndJSON, XML. API is accessible via api.rstcloud.net. Authentication uses API keys. Developer documentation is at www.rstcloud.com/resources.
What industry is RST Cloud in?
RST Cloud's product category is Cybersecurity Threat Intelligence. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services. Its NAICS code is 5182 and its SIC code is 7372.