ShadowDragon
An OSINT investigation platform (SocialNet, Horizon) that aggregates data from 550+ public sources for law enforcement, financial-crimes, and corporate security investigations.
Visit Website ↗ + Add to CompareOverview
ShadowDragon builds OSINT investigation tooling — primarily SocialNet and the Horizon link-analysis platform — used to pull and connect data from more than 550 public sources (social media, forums, dark web listings, breach data, and more) into a single investigative workflow. The core use case is digital investigations: law enforcement building a case file, financial-crimes units tracing a fraud network, or corporate security/threat-intel teams mapping an actor’s online footprint, all without manually pivoting between dozens of individual OSINT sources by hand.
The company was spun out in 2016 by Daniel Clemens as a licensing vehicle for tools his consultancy, Packet Ninjas, had built internally since 2009 (SocialNet itself predates ShadowDragon as a company by seven years). It has grown as a bootstrapped, self-funded business built on consulting-style revenue rather than venture capital, reporting roughly $6.6 million in ARR without an outside funding round, and now serves government, military, law enforcement, and commercial investigative teams.
ShadowDragon’s tooling has also drawn public scrutiny: a 2021 investigative report by The Intercept examined its use for law-enforcement social-media surveillance, raising the kind of civil-liberties questions that come with any investigative-OSINT platform sold to government customers. That is a real tension for the category, not a defect specific to ShadowDragon, but it is worth weighing alongside the vendor’s own claims of ethical, publicly-available-data-only collection.
Innovation Matrix Assessment
ShadowDragon has expanded its data-source coverage to 550+ sources and 1,500+ endpoints and added the Horizon link-analysis layer on top of the original SocialNet collector, a steady cadence of expansion for a bootstrapped company.
The platform runs live automated searches across hundreds of public data sources and is reported to serve hundreds of clients and thousands of end users, indicating real operational scale for an OSINT-specific tool.
Frost & Sullivan named ShadowDragon its 2024 Global Entrepreneurial Company of the Year in OSINT, and the company has grown to a reported ~$6.6M ARR entirely without outside funding, both independently reported momentum signals.
Consolidating hundreds of individually-pivoted OSINT sources into one link-analysis workflow meaningfully speeds up digital investigations, though OSINT aggregation itself is a well-established investigative discipline rather than a new category.
Adoption by government, law enforcement, and military customers over nearly a decade is a real efficacy signal, but there is no independent, named case study of an investigation ShadowDragon's tools directly solved, and no third-party technical evaluation was found.
OSINT-driven investigation is core to modern financial-crimes, threat-intelligence, and law-enforcement work, keeping a mature aggregation platform like ShadowDragon's relevant to those buyers.
Why CISOs Should Care
For a corporate threat-intel or fraud team, ShadowDragon collapses what would be dozens of manual OSINT source pivots into one link-analysis workflow, cutting investigation time when tracing a threat actor's or fraudster's online footprint.
What Makes It Different
ShadowDragon's breadth of source coverage (550+ sources, 1,500+ endpoints) combined with the Horizon link-analysis layer differentiates it from narrower single-source OSINT tools.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
A mature, bootstrapped OSINT investigation platform with real government and commercial adoption; useful and durable within its niche, though buyers should weigh the same civil-liberties questions that apply to any social-media investigative tool sold into law enforcement.
Editorial Note: Claims vs. Verified Findings
ShadowDragon's own claims of ethical, publicly-available-data-only collection and specific source/endpoint counts (550+/1,500+) are vendor-sourced and not independently audited. Its 2016 founding as a Packet Ninjas spinout, Frost & Sullivan 2024 award, and use by law enforcement documented in The Intercept's 2021 investigative report are independently corroborated.
Sources
Alternatives to ShadowDragon
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Sophos
Sophos is a UK-founded, Thoma Bravo-owned cybersecurity vendor unifying endpoint protection, network firewalls, and managed detection and response…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…