Menaya
Menaya (the rebranded GamaSec) runs an AI-powered external attack surface management platform that discovers and continuously scores an organization's internet-facing assets and vulnerabilities.
Visit Website ↗ + Add to CompareOverview
Menaya is the current name for GamaSec, an Israeli company founded in 2006 in Herzliya Pituach that originally built a website vulnerability scanner (GamaScan) using what it called “virtual hacker” simulated-attack technology to find SQL injection, cross-site scripting, and malware on customer web properties. Under the Menaya name, the company has repositioned around external attack surface management (EASM): continuously discovering an organization’s internet-facing assets from an attacker’s vantage point, scoring the risk each one presents, and prioritizing remediation with AI-assisted guidance, primarily for small and mid-sized enterprises that lack a dedicated attack-surface-management program.
The rebrand and repositioning track a broader industry shift from point-in-time vulnerability scanning toward continuous, attacker’s-eye-view asset discovery, which has become table stakes as organizations’ external footprints sprawl across cloud services, forgotten subdomains, and shadow IT. Menaya’s roots in nearly two decades of web vulnerability detection give it a longer operating history than many EASM entrants, even though the current product framing is comparatively recent.
Menaya is best suited to SMEs that need external exposure visibility but don’t have the budget or headcount for enterprise-grade EASM platforms like CyCognito or Randori; its long-running heritage in website-specific vulnerability detection is a genuine differentiator versus EASM vendors built from scratch on generic asset-discovery techniques.
Innovation Matrix Assessment
The GamaSec-to-Menaya repositioning from web vulnerability scanning to EASM shows the company adapting its product to market shifts, but there is little public evidence of a fast release cadence on the current EASM platform specifically.
Nearly two decades of continuous operation since 2006, plus offices spanning Israel, the US, APAC, LATAM, and MEA per company materials, indicate an established but modestly sized operation with a small reported headcount (LinkedIn lists 11-50).
No funding rounds, headcount growth, or major new customer wins were found in public sources; the rebrand itself is the most concrete recent signal of change, and momentum is difficult to independently verify beyond that.
External attack surface management is now a mature, well-populated category with established leaders (CyCognito, Censys, Randori); Menaya's approach does not appear to introduce a novel detection technique relative to category peers.
No independent benchmark or named customer case study documenting detection accuracy was found for either the legacy GamaSec scanner or the current Menaya EASM platform; efficacy claims are vendor-described.
External attack surface visibility remains a persistent, real gap for SMEs specifically, which is the segment Menaya targets, making the core use case relevant even where the vendor's independent differentiation is limited.
Why CISOs Should Care
Smaller organizations without a dedicated attack-surface-management function get a long-running vendor (formerly GamaSec, now Menaya) offering continuous external asset discovery and vulnerability scoring at a price point aimed at the SME segment.
What Makes It Different
Menaya's differentiation is tenure — nearly 20 years of web vulnerability detection heritage under the GamaSec name — combined with SME-focused pricing, rather than a technically novel EASM detection method.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A long-tenured, low-profile vendor that has repositioned from web vulnerability scanning to EASM; a reasonable budget option for SMEs, though it lacks the independent validation and market visibility of category leaders.
Editorial Note: Claims vs. Verified Findings
Vendor-sourced and unverified: all specific efficacy, detection-accuracy, and platform-capability claims — no independent third-party evaluation of either the legacy GamaSec scanner or current Menaya platform was found. The GamaSec-to-Menaya name history and 2006 founding date are corroborated across multiple independent listings (CB Insights, Startup Nation Finder, CyberDB).
Sources
Alternatives to Menaya
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…