Emerging Threats
Emerging Threats, founded in 2003 and now part of Proofpoint, provides behavior-based threat intelligence feeds on IPs and domains with 40+ threat categories, hourly updates, and historical context, integrating with Splunk, QRadar, ArcSight, Anomali, and Bro IDS for enterprise and government security teams.
- Company typePrivate
- Founded2003
- HeadquartersLafayette, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Emerging Threats does
Emerging Threats is a cybersecurity research organization founded in 2003 and headquartered in Lafayette, Indiana, that now operates as the ET Intelligence product line within Proofpoint's threat intelligence portfolio. Its core offering delivers behavior-based threat intelligence feeds on IP addresses and domains, derived from direct observation by Proofpoint ET Labs rather than third-party sources. The platform classifies indicators into more than 40 threat categories with confidence scores, updates its lists on an hourly basis, and pairs real-time reputation data with historical context covering threat origin, actor attribution, timing, attack methods, and target profiles.
The product surface comprises three components: ET Intelligence (the flagship reputation feed and portal), ET Pro Ruleset (a supplementary detection ruleset), and the Proofpoint Splunk TA (a free Splunk add-on). ET Intelligence supports multiple output formats — TXT, CSV, JSON, compressed, and Bro IDS — and integrates directly with major SIEM platforms (Splunk, IBM QRadar, Micro Focus ArcSight), threat intelligence platforms (Anomali), and network IDS systems. The underlying value proposition centers on providing fully verified, primary-source threat data with investigative depth that extends beyond real-time blocklists.
Emerging Threats monetizes through subscription-based access to its threat intelligence feeds and portal, supplemented by an OEM licensing model for embedding its data into third-party security products. Distribution is multi-channel: enterprise field sales with demo requests, channel partners and distributors, MSP partners, technology alliance partners, and OEM embedders, with a global footprint spanning the Americas, EMEA, and Asia Pacific. The firm is privately held under Proofpoint and serves security teams across federal, state and local government, higher education, healthcare, financial services, ISP, mobile operator, and SMB segments.
Emerging Threats firmographics
Firmographics- Name
- Emerging Threats
- Legal name
- Emerging Threats
- Website
- https://emergingthreats.net
- Company type
- Private
- Founded year
- 2003
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Emerging Threats, founded in 2003 and now part of Proofpoint, provides behavior-based threat intelligence feeds on IPs and domains with 40+ threat categories, hourly updates, and historical context, integrating with Splunk, QRadar, ArcSight, Anomali, and Bro IDS for enterprise and government security teams.
- Ownership category
- akta.pro rank
Emerging Threats industry classification
Industry- Product category
- Threat Intelligence
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Intrusion Detection & Prevention Systems (IDS/IPS) (HDAFAFAD), Deception Technology & Threat Hunting (HDADAGAI)
Keywords
Where Emerging Threats is headquartered
LocationHeadquarters
- HQ city
- Lafayette
- HQ country
- United States
- HQ region
- North America
Markets served
Emerging Threats business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Operations, Marketing or Sales, Infrastructure
Revenue model
- Threat Intelligence Subscription: Subscription-based access to threat intelligence feeds and the ET Intelligence portal with varying tiers based on feed depth, update frequency, and integration capabilities.
- OEM Licensing: OEM licensing model for embedding threat intelligence into third-party security products and platforms.
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
Emerging Threats product offering
Product offeringCore offering
Emerging Threats provides behavior-based threat intelligence feeds, primarily delivered through the Proofpoint ET Intelligence platform. The product offers actionable IP and domain reputation data classified into 40+ threat categories with confidence scores, hourly list updates, dynamic aging, and historical context covering attribution, methods, and targets. Feeds are delivered in multiple formats (TXT, CSV, JSON, compressed, Bro IDS) and integrate directly with SIEMs (Splunk, QRadar, ArcSight), threat intelligence platforms (Anomali), and other security infrastructure (firewalls, IDS/IPS, authentication systems).
Product overview
Proofpoint ET Intelligence is a single threat intelligence platform offering, not a modular platform-plus-products architecture. The core product provides actionable IP and domain reputation feeds based on behavior observed by Proofpoint ET Labs. Key features include over 40 threat categories, confidence scoring, historical context, trends and timestamps, exploit kit names, and related malware samples. The product integrates with SIEM tools (Splunk, QRadar, ArcSight) via feeds or dedicated add-ons, connects to threat intelligence platforms like Anomali, and supports multiple export formats including TXT, CSV, JSON, compressed, and Bro IDS format with hourly updates. The ET Pro Ruleset provides supplementary detection rules.
Differentiator
Problem solved
Functional benefit
Products and services
- Emerging Threat (ET) Intelligence Threat intelligence platform providing fully verified, real-time and historical metadata on IPs, domains, and related threat indicators. Delivers actionable threat intel feeds with over 40 category classifications, confidence scoring, and condemnation evidence to help prevent attacks and reduce risk, integrating with enterprise security infrastructure such as SIEMs, firewalls, and IDS/IPS.
- ET Pro Ruleset A ruleset component of the Emerging Threats Intelligence offering providing detection rules for threat identification, designed to complement the ET Intelligence feeds for customers using network security and IDS/IPS infrastructure.
Quantifiable outcome
- IP and domains classified into over 40 different threat categories
- +2 more outcomes
Companies that use Emerging Threats
Customer profileSegments8 records
Ideal customer profiles8 records
Emerging Threats technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
Feature11 records
Emerging Threats partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core.
- SplunkcoreProofpoint provides a free Splunk technology add-on (Proofpoint Splunk TA) that integrates Emerging Threat Intelligence reputation into Splunk to quickly surface log entries that appear on reputation lists. Compatible with existing Splunk reporting.
- QRadarcoreET Intelligence is directly integrable with IBM QRadar SIEM platform for security operations center deployments.
- ArcSightcoreET Intelligence feeds directly compatible with Micro Focus ArcSight SIEM platform for enterprise security monitoring.
- Anomali (formerly ThreatStream)coreThreat intelligence directly available through Anomali threat intelligence platform for TIP integration.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Emerging Threats competitors and assessment
Company assessmentDirect peers
- ReliaQuest (Digital Shadows): ReliaQuest acquired Digital Shadows, an external threat intelligence vendor that offers monitored adversary intelligence with attribution detail. Overlaps with ET Intelligence on subscription IP/domain/credential intelligence and shares federal and enterprise customer bases.
- Mandiant Intelligence (Google Cloud): Mandiant (now part of Google Cloud) provides strategic and operational threat intelligence with deep attribution and incident context, mirroring ET Intelligence's emphasis on attacker profiling and historical methodology. Both compete for SOC and federal-grade threat intel subscriptions.
- CrowdStrike Falcon Intelligence: CrowdStrike's threat intelligence module within Falcon delivers IP/domain reputation and adversary profiling drawn from the company's massive endpoint telemetry. Competes directly with ET Intelligence for enterprise SIEM/firewall enrichment feeds, differing primarily in data source rather than delivery format.
- ThreatConnect: ThreatConnect is a TIP that ingests commercial and OSINT feeds, similar to how Splunk TIP and Anomali consume ET Intelligence. Direct competitor in the TIP-or-feed subscription category that enterprise SOCs evaluate alongside Emerging Threats feeds.
- Cisco Talos Intelligence: Cisco Talos is one of the largest commercial threat intelligence operations, providing reputation feeds and rulesets (Snort/Sig). Competes with ET Intelligence on IP reputation feeds and on the ET Pro Ruleset-equivalent detection rule ecosystem for Snort/Suricata deployments.
- Recorded Future: Acquired by Mastercard, Recorded Future is one of the largest commercial threat intelligence platforms. Directly comparable to ET Intelligence: subscription IP/domain reputation feeds, confidence scoring, and integrations with Splunk, QRadar, and TIP ecosystems — competing head-to-head for enterprise security team budgets.
- Anomali: Anomali (formerly ThreatStream) is both a partner and adjacent competitor: a threat intelligence platform that aggregates feeds from providers like ET Intelligence. As both a channel partner and competing TIP with its own curated intel, Anomali represents the closest peer in TIP delivery model.
Broad incumbents
- Palo Alto Networks Unit 42: Unit 42 provides threat intelligence tightly bundled into Palo Alto's firewalls, XSIAM, and Cortex platforms. Competes as a feed embedded inside an integrated platform stack versus ET Intelligence's standalone feed approach, representing the broader-incumbent variant in the threat intelligence market.
- Microsoft Defender Threat Intelligence: Microsoft bundles threat intelligence into its Defender and Sentinel ecosystem at scale, leveraging enterprise endpoint telemetry. Competes with ET Intelligence for enterprise SOC budgets, especially where Splunk/QRadar customers consolidate onto Microsoft's security stack.
- Kaspersky Threat Intelligence: Kaspersky offers subscription threat intelligence portals with IP/domain reputation, APT reporting, and IOC context. Competes in the same commercial threat intel subscription market as ET Intelligence, with comparable historical-context features and multi-format feed exports.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Emerging Threats social profiles
Digital presenceEmerging Threats financial estimates
Financial estimateRevenue estimate
Valuation estimate
Emerging Threats leadership team
Management profileNumber of profiles
Profiles3 records
Emerging Threats funding detail
Funding detailFunding overview
Funding rounds3 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Emerging Threats M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Emerging Threats
What does Emerging Threats do?
Emerging Threats provides behavior-based threat intelligence feeds, primarily delivered through the Proofpoint ET Intelligence platform. The product offers actionable IP and domain reputation data classified into 40+ threat categories with confidence scores, hourly list updates, dynamic aging, and historical context covering attribution, methods, and targets. Feeds are delivered in multiple formats (TXT, CSV, JSON, compressed, Bro IDS) and integrate directly with SIEMs (Splunk, QRadar, ArcSight), threat intelligence platforms (Anomali), and other security infrastructure (firewalls, IDS/IPS, authentication systems).
Is Emerging Threats a public or private company?
Emerging Threats is a private company. It is classified as corporate owned and is currently operating.
When was Emerging Threats founded?
Emerging Threats was founded in 2003. It employs 11 to 50 people.
Where is Emerging Threats based?
Emerging Threats is headquartered in Lafayette, United States, in the North America region.
How does Emerging Threats make money?
Two revenue lines are on record. Threat Intelligence Subscription is the primary driver. The others are OEM Licensing.
Who are Emerging Threats's main competitors?
Direct peers on record are ReliaQuest (Digital Shadows), Mandiant Intelligence (Google Cloud), CrowdStrike Falcon Intelligence, ThreatConnect, Cisco Talos Intelligence, Recorded Future and Anomali. Broad incumbents are Palo Alto Networks Unit 42, Microsoft Defender Threat Intelligence and Kaspersky Threat Intelligence.
Does Emerging Threats have an API?
No public API is recorded for Emerging Threats.
What industry is Emerging Threats in?
Emerging Threats's product category is Threat Intelligence. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDAFAFAD, Intrusion Detection & Prevention Systems (IDS/IPS). Its NAICS code is 5415 and its SIC code is 7373.