Hatching
Hatching International B.V. is a Netherlands-based cybersecurity vendor specializing in automated malware sandboxing. Its flagship Triage platform provides dynamic analysis at up to 500,000 analyses per day for enterprise security teams, MSSPs, and security researchers, and operates as a subsidiary of Recorded Future.
- Company typePrivate
- Founded2018
- HeadquartersZaandam, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Hatching does
Hatching International B.V. is a Netherlands-based cybersecurity vendor specializing in automated malware sandboxing. The company was founded by former developers of Cuckoo Sandbox, including its current leader Jurriaan Bremer, and today operates as a wholly-owned subsidiary of Recorded Future following its August 2022 acquisition. Hatching's flagship product, Hatching Triage, provides dynamic analysis of files and URLs by detonating samples inside isolated virtual machines running Windows 7/10, Linux, Android, and macOS environments, and surfacing behavioral signals, malware family classifications, and extracted configurations to the operator.
The Triage platform is built on a purpose-built distributed architecture designed from scratch — without legacy constraints inherited from Cuckoo — and is engineered to scale up to 500,000 analyses per day. It exposes a comprehensive REST API with Python SDK support, integrates with Splunk, Cortex XSOAR, TheHive, Suricata, and URLScan, and supports over 100 file types and archives. Differentiated components include the onemon Windows kernel driver (developed with CERT.PL) for real-time process memory inspection via Yara, and live VM interaction that lets analysts take control during detonation. The product is ISO 27001 and SOC 2 Type 2 certified and supports horizontal customer segments.
Hatching monetizes through volume-based enterprise licensing priced per analyses-per-day (tiers starting at 500/day and scaling to 50,000+/day, with bespoke pricing for very high-volume automated workflows), typically structured as multi-year contracts. Enterprise buyers include MSSPs, SOAR vendors, SOC/CERT teams, and in-house security organizations requiring high-volume automated triage. A free public cloud at tria.ge serves individual researchers and the security community, functioning as a freemium funnel and a source of community-led sample diversity. Distribution combines a direct enterprise field-sales motion with private-cloud deployments and a self-serve PLG route via the public cloud.
Hatching firmographics
Firmographics- Name
- Hatching
- Legal name
- Hatching International B.V.
- Website
- https://hatching.io
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Hatching International B.V. is a Netherlands-based cybersecurity vendor specializing in automated malware sandboxing. Its flagship Triage platform provides dynamic analysis at up to 500,000 analyses per day for enterprise security teams, MSSPs, and security researchers, and operates as a subsidiary of Recorded Future.
- Ownership category
- akta.pro rank
Hatching industry classification
Industry- Product category
- Malware Sandboxing Software
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Threat Intelligence Platforms (TIP) (HDADAGAD)
Keywords
Where Hatching is headquartered
LocationHeadquarters
- HQ city
- Zaandam
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Hatching business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Volume-based Enterprise Licensing: Enterprise customers purchase volume-based licenses for automated malware analysis. Packages start at 500 analyses per day and scale up to 50,000 analyses per day. Bespoke pricing is available for fully automated enterprise workflows handling hundreds of thousands of file and URL analyses per day.
- Public Cloud (Freemium): Individual users and researchers can access Triage public cloud for free, serving the security community and enabling community-led adoption.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Usage-based | Multi-year contract | Entry-level package starting at 500 analyses per day |
| Usage-based | Multi-year contract | Mid-tier package scaling up to 50,000 analyses per day |
| Usage-based | Multi-year contract | Enterprise bespoke pricing for high-volume automated workflows |
| Freemium | Monthly | Free public cloud access for researchers |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels4 records
Hatching product offering
Product offeringCore offering
Hatching provides Hatching Triage, a modern malware sandboxing platform that performs automated dynamic analysis of files and URLs. It supports Windows, Linux, Android, and macOS environments and scales up to 500,000 analyses per day. The platform is delivered via enterprise volume-based licensing (private cloud) and a free public cloud (tria.ge), and exposes its capabilities through a comprehensive REST API for security workflow automation.
Product overview
Hatching offers a single unified product: Hatching Triage, a modern malware sandboxing solution. The company was founded by former Cuckoo Sandbox developers and builds on years of sandboxing experience. Triage is the company's flagship product - a revolutionary malware analysis sandbox that succeeded the open-source Cuckoo Sandbox project. The solution provides automated file and URL analysis with a comprehensive REST API, supporting enterprise security teams and security service providers. Pricing is volume-based, starting at 500 analyses per day and scaling to 50,000+ analyses per day for enterprise customers.
Differentiator
Problem solved
Functional benefit
Brands
- Triage: Hatching's flagship malware sandboxing solution with support for Windows, Linux, Android, and macOS analysis, scaling up to 500,000 analyses per day.
Products and services
- Hatching Triage Modern high-volume malware sandboxing platform that performs automated dynamic analysis of files and URLs across Windows, Linux, Android, and macOS environments, supporting 100+ file types and archives and exposing a comprehensive REST API. Used by enterprise security teams and security service providers (MSSPs/SOAR) for malware triage and incident response; also available via the tria.ge free public cloud.
Quantifiable outcome
- Scales to 500,000 analyses per day
- +1 more outcomes
Companies that use Hatching
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles2 records
Hatching technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability2 records
Feature8 records
Hatching partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered minor and core.
- CERT.PLminorCollaboration with CERT.PL on development of the onemon Windows kernel driver, co-financed by the Connecting Europe Facility of the European Union (action no: 2016-PL-IA-0127).
- PolySwarmcoreHatching became PolySwarm's first Arbiter for their threat intelligence marketplace. As an Arbiter, Hatching analyzes file samples to judge malicious intent, contributing to the Ground Truth verdicts that settle bounties. This partnership provides continuous R&D advantages through analyzing diverse malware samples.
- Recorded FuturecoreHatching is a subsidiary of Recorded Future, operating as part of the Recorded Future family of companies. The company is based near Amsterdam and governed by stringent national and European standards on privacy and security.
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
Hatching competitors and assessment
Company assessmentDirect peers
- VirusTotal: Google-owned multi-engine file and URL analysis platform that detonates samples across dozens of engines. Most directly comparable to Triage as a publicly accessible malware analysis sandbox, though it is free and broader in scope.
- Joe Sandbox: Commercial malware analysis sandbox with deep behavioral reporting and Windows/Linux/macOS/Android coverage. Competes head-to-head with Hatching Triage for enterprise SOC, CERT, and MSSP malware triage workloads.
- Hybrid Analysis: Free public malware analysis service operated by CrowdStrike (formerly Payload Security). Directly comparable to Hatching's freemium public cloud at tria.ge, serving security researchers and individual analysts.
- ANY.RUN: Interactive online malware sandbox offering real-time VM interaction for analysts and researchers. Overlaps with Triage's live VM interaction capability and its freemium public-cloud model.
- VMRay: Enterprise-focused malware analysis and threat intelligence platform using hypervisor-based sandboxing with strong evasion resistance. Directly competes with Hatching in the high-end enterprise and MSSP segment.
Others
- PolySwarm: Threat intelligence marketplace where Hatching serves as an Arbiter judging malicious intent. Functions as a partner and ecosystem participant rather than a direct competitor, but operates in adjacent threat intelligence territory.
- Cuckoo Sandbox: Open-source malware analysis system originally developed by Hatching's founding team. Functions as the technical ancestor of Triage and an ecosystem peer that still competes in the open-source segment of the sandbox market.
Broad incumbents
- CrowdStrike Falcon Sandbox: Malware sandboxing capability bundled inside the CrowdStrike Falcon platform. Not a standalone product, but a broader incumbent that competes for the same enterprise security budget through integrated EDR/XDR.
- Palo Alto Networks WildFire: Cloud-based malware analysis and threat intelligence engine embedded in Palo Alto's Next-Generation Firewall and Cortex XDR products. A broad incumbent that competes with Hatching for enterprise malware analysis workloads.
Emerging players
- Intezer: AI-driven malware analysis platform using genetic code reuse analysis for triage and classification. Adjacent emerging player whose AI-first approach could shift the competitive landscape for sandbox-centric vendors like Hatching.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Hatching social profiles
Digital presenceHatching compliance and trust
Trust signalCompliance2 records
Hatching financial estimates
Financial estimateRevenue estimate
Valuation estimate
Hatching leadership team
Management profileNumber of profiles
Profiles2 records
Hatching funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Hatching M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Hatching
What does Hatching do?
Hatching provides Hatching Triage, a modern malware sandboxing platform that performs automated dynamic analysis of files and URLs. It supports Windows, Linux, Android, and macOS environments and scales up to 500,000 analyses per day. The platform is delivered via enterprise volume-based licensing (private cloud) and a free public cloud (tria.ge), and exposes its capabilities through a comprehensive REST API for security workflow automation.
Is Hatching a public or private company?
Hatching is a private company. It is classified as corporate owned and is currently operating.
When was Hatching founded?
Hatching was founded in 2018. It employs 11 to 50 people.
Where is Hatching based?
Hatching is headquartered in Zaandam, Netherlands, in the Europe region.
How does Hatching make money?
Two revenue lines are on record. Volume-based Enterprise Licensing is the primary driver. The others are public Cloud (Freemium).
Who are Hatching's main competitors?
Direct peers on record are VirusTotal, Joe Sandbox, Hybrid Analysis, ANY.RUN and VMRay. Others are PolySwarm and Cuckoo Sandbox. Broad incumbents are CrowdStrike Falcon Sandbox and Palo Alto Networks WildFire. Intezer is listed as an emerging player.
Does Hatching have an API?
Yes. Triage offers a comprehensive REST API for automating workflows. The API supports bearer token authentication. Individual users and researchers can use the Triage public cloud for free, while enterprise customers have access to fully automated workflows. Developer documentation is at docs.tria.ge.
What industry is Hatching in?
Hatching's product category is Malware Sandboxing Software. Its primary akta.pro industry code is HDADAGAD, Threat Intelligence Platforms (TIP). Its NAICS code is 561621 and its SIC code is 7372.