ThreatConnect
A veteran threat intelligence and SOAR platform reportedly used by a third of the Fortune 50, acquired by Dataminr for $290 million in late 2025 to pair real-time public signals with intelligence management.
Visit Website ↗ + Add to CompareOverview
ThreatConnect provides a threat intelligence platform (TIP) combined with security orchestration, automation, and response (SOAR) capability, letting security operations teams aggregate and score threat intelligence feeds and drive automated response playbooks from within a single environment. According to Dataminr’s acquisition announcement, ThreatConnect is used by roughly a third of the Fortune 50, giving it a large-enterprise footprint that is unusual for a company of its size.
The company was founded in Arlington, Virginia in 2011 as Cyber Squared Inc. by Adam Vincent, Andrew Pendergast, and Leigh Reichel, later renaming to ThreatConnect after a $4 million Series A. It went on to raise a $16 million Series B in 2015 led by SAP National Security Services, plus a further round led by PSG in 2019. In November 2025, Dataminr closed its acquisition of ThreatConnect for $290 million, combining Dataminr’s real-time public data signal detection with ThreatConnect’s intelligence management environment under a joint offering marketed as Dataminr Pulse for Cyber Risk.
Fourteen years of focused TIP/SOAR development and genuine large-enterprise adoption give ThreatConnect real operational credibility, and the Dataminr acquisition adds a real-time public-signal capability that few pure-play TIPs have. It is a mature, incumbent platform rather than a disruptive newcomer at this point, and its most notable recent claims — customer scale and post-acquisition roadmap — currently come from the acquirer’s own announcements rather than independent audits.
Innovation Matrix Assessment
Fourteen years of steady TIP/SOAR feature development, now being integrated with Dataminr's real-time signal platform, reflects a mature but not especially fast-moving development pace.
A long operating history serving large enterprise SOC teams, reportedly including roughly a third of the Fortune 50, demonstrates real operational capability at scale.
A $290 million acquisition by Dataminr in November 2025 is a strong, recent, independently reported momentum signal after years as an independent vendor.
A long-established TIP/SOAR incumbent rather than a novel disruptive approach; the new Dataminr combination adds real-time public signal correlation but builds on an existing category rather than creating one.
Reported adoption by roughly a third of the Fortune 50 implies real operational reliability at scale, though this figure comes from the acquirer's own announcement rather than an independent audit.
Threat intelligence management and SOC automation remain core security operations needs, and the Dataminr combination is aimed at making that intelligence more real-time and AI-driven.
Why CISOs Should Care
Gives large-enterprise SOC teams a mature platform for aggregating, prioritizing, and acting on threat intelligence with SOAR-style automation, now backed by Dataminr's real-time public data signal network post-acquisition.
What Makes It Different
Fourteen years of TIP/SOAR-specific focus and reported adoption by roughly a third of the Fortune 50 differentiate it from newer, less-proven threat intelligence platforms; the Dataminr combination adds real-time public signal correlation most TIPs lack.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A mature, credibly adopted threat intelligence and SOAR platform whose recent $290 million acquisition by Dataminr signals continued relevance; solid rather than disruptive, with genuine large-enterprise traction.
Editorial Note: Claims vs. Verified Findings
The $290 million Dataminr acquisition (closed November 2025) is independently reported by multiple outlets, including BankInfoSecurity and GovCon Wire. The 'roughly a third of the Fortune 50' customer claim comes from Dataminr's own acquisition announcement and was not independently verified in this research.
Sources
Alternatives to ThreatConnect
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
ReliaQuest
ReliaQuest operates GreyMatter, a security operations platform that unifies detection, investigation, and response across a customer's existing security…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…