SANS Internet Storm Center
- Company typePrivate
- Founded2000
- HeadquartersBethesda, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
SANS Internet Storm Center firmographics
Firmographics- Name
- SANS Internet Storm Center
- Legal name
- SANS Internet Storm Center
- Website
- https://isc.sans.edu
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
SANS Internet Storm Center industry classification
Industry- Product category
- Threat Intelligence
- NAICS
- Computer Systems Design and Related Services (54151), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Security Operations Center (SOC) as a Service (BPAEADAB)
- akta.pro secondary industries
- Network Monitoring, Assurance & Managed NOC Services (SLA Ops) (HDAIAGAJ), Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF)
Keywords
Where SANS Internet Storm Center is headquartered
LocationHeadquarters
- HQ city
- Bethesda
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
SANS Internet Storm Center business model
Business model- GTM type
- B2B
- Offering type
- Software
Revenue model
- Free Public Service: The Internet Storm Center operates as a free community service provided by the SANS Institute, a cybersecurity training organization. No direct revenue model identified - the service serves as a public good and brand extension for SANS educational products.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels9 records
SANS Internet Storm Center product offering
Product offeringCore offering
The SANS Internet Storm Center (ISC) is a free, community-driven cybersecurity threat intelligence service that monitors global internet threats through a distributed honeypot sensor network (DShield) and volunteer incident handlers. It publishes daily security diaries, a daily podcast (SANS Stormcast), threat intelligence feeds, and provides a public API for developers. The service operates as a public good under the SANS Institute and uses the proprietary Infocon color-coded threat level system to communicate changes in malicious traffic and internet infrastructure risk.
Product overview
SANS Internet Storm Center is a unified cybersecurity monitoring and threat intelligence platform offering real-time threat detection, daily security analysis through handler diaries, a daily podcast (SANS Stormcast), distributed honeypot sensors (DShield), various diagnostic tools, and a developer API. The core Internet Storm Center service provides the Infocon status system and diary-based threat analysis, supplemented by the SANS Stormcast podcast, DShield Sensor honeypot network, and various data feeds covering port activity, SSH scanning, web logs, and threat maps. The platform also offers an API for developers to integrate threat intelligence data.
Differentiator
Problem solved
Functional benefit
Brands
- SANS Stormcast: Daily cybersecurity podcast summarizing the latest information security threats
- DShield
- Infocon
Products and services
- Internet Storm Center A cybersecurity monitoring and threat intelligence service providing daily diary analysis, real-time threat alerts, and the Infocon status system to track global internet security threats for cybersecurity professionals.
- SANS Stormcast
Quantifiable outcome
- 50x increase in malicious SVG attachments detected and tracked in 2025
- +1 more outcomes
Companies that use SANS Internet Storm Center
Customer profileNamed customers1 record
Segments3 records
SANS Internet Storm Center technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
SANS Internet Storm Center partnerships and signals
Strategic signalScale indicators4 records
Recent moves6 records
Expansion highlights5 records
SANS Internet Storm Center competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Commercial threat intelligence and incident response leader publishing high-profile threat reports. Comparable in producing authoritative cyber threat research and intelligence, but as a paid commercial offering rather than a free community service.
- Cisco Talos Intelligence: Large commercial threat intelligence group producing daily reports, threat feeds and telemetry-driven research. Comparable in mission (daily threat analysis, threat feeds, podcast-style content) but vastly better-resourced and embedded in a commercial vendor.
Direct peers
- AbuseIPDB: Community-driven IP reputation and abuse-reporting platform that aggregates data on malicious IPs from a global contributor base. Comparable as a free public service that turns distributed community contributions into actionable threat signals.
- Spamhaus Project: Non-profit that maintains real-time threat intelligence on spam, malware and abusive infrastructure through global sensors and community reporting. Comparable as a long-running, volunteer/sensor-driven nonprofit threat intelligence service.
- Shadowserver Foundation: Non-profit that operates a global sensor network to collect, analyze and disseminate threat intelligence on malware, botnets and scanning activity. Directly comparable to ISC's DShield model as a community-driven, free public service for global threat monitoring.
- Team Cymru: Provides community-grade threat intelligence feeds derived from global honeypots, darknet monitoring and botnet analysis. Closely comparable to ISC's free/community feeds and global sensor-driven threat telemetry mission.
- AlienVault Open Threat Exchange (OTX): Community-based open threat intelligence sharing platform where security professionals contribute and consume Indicators of Compromise. Directly comparable to ISC as a free, crowdsourced threat-intel exchange for security practitioners.
Emerging players
- Have I Been Pwned: Free community-driven security service aggregating breach and credential data for public use. Comparable as a high-traffic, free public-good cybersecurity service built on volunteer/open-data contributions rather than a commercial model.
- Emerging Threats (Proofpoint): Originally an open-source community IDS/threat-intel project (Emerging Threats Ruleset) now part of Proofpoint. Comparable to ISC as an open, community-oriented source of threat indicators and detection content for security defenders.
- MISP Project: Open-source threat intelligence platform for sharing, storing and correlating IOCs across communities. Comparable to ISC's free threat-feed and API mission as an open, community-led threat-intel sharing infrastructure.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
SANS Internet Storm Center social profiles
Digital presenceSANS Internet Storm Center financial estimates
Financial estimateRevenue estimate
Valuation estimate
SANS Internet Storm Center leadership team
Management profileNumber of profiles
SANS Internet Storm Center funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SANS Internet Storm Center M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SANS Internet Storm Center
What does SANS Internet Storm Center do?
The SANS Internet Storm Center (ISC) is a free, community-driven cybersecurity threat intelligence service that monitors global internet threats through a distributed honeypot sensor network (DShield) and volunteer incident handlers. It publishes daily security diaries, a daily podcast (SANS Stormcast), threat intelligence feeds, and provides a public API for developers. The service operates as a public good under the SANS Institute and uses the proprietary Infocon color-coded threat level system to communicate changes in malicious traffic and internet infrastructure risk.
Is SANS Internet Storm Center a public or private company?
SANS Internet Storm Center is a private company. It is currently operating.
When was SANS Internet Storm Center founded?
SANS Internet Storm Center was founded in 2000. It employs 11 to 50 people.
Where is SANS Internet Storm Center based?
SANS Internet Storm Center is headquartered in Bethesda, United States, in the North America region.
How does SANS Internet Storm Center make money?
One revenue line is on record: free Public Service.
Who are SANS Internet Storm Center's main competitors?
Broad incumbents on record are Mandiant (Google Cloud) and Cisco Talos Intelligence. Direct peers are AbuseIPDB, Spamhaus Project, Shadowserver Foundation, Team Cymru and AlienVault Open Threat Exchange (OTX). Emerging players are Have I Been Pwned, Emerging Threats (Proofpoint) and MISP Project.
Does SANS Internet Storm Center have an API?
Yes. SANS Internet Storm Center provides a developer API for programmatic access to their threat intelligence data and services. Developer documentation is at isc.sans.edu/api.
What industry is SANS Internet Storm Center in?
SANS Internet Storm Center's product category is Threat Intelligence. Its primary akta.pro industry code is BPAEADAB, Security Operations Center (SOC) as a Service, with a secondary code of HDAIAGAJ, Network Monitoring, Assurance & Managed NOC Services (SLA Ops). Its NAICS code is 54151 and its SIC code is 7370.