LiveAction
Network detection and response platform (ThreatEye) analyzing encrypted traffic for threats without decryption, built on technology from its 2021 acquisition of CounterFlow AI.
Visit Website ↗ + Add to CompareOverview
LiveAction builds ThreatEye, a network detection and response (NDR) platform that analyzes encrypted network traffic for anomalies and attacker behavior without needing to decrypt it, using machine-learning-driven traffic analysis and behavioral baselining. The platform grew out of LiveAction’s original network performance monitoring and diagnostics (NPMD) business, which it extended into security by acquiring CounterFlow AI in May 2021. CounterFlow brought a streaming machine-learning engine for deep packet dynamics and encrypted-traffic analysis that became the technical foundation for ThreatEye, and the CounterFlow brand has since been fully absorbed into LiveAction’s product line rather than operating separately.
LiveAction is headquartered in Palo Alto, California, and has raised roughly $41 million in funding from investors including Cisco Investments, Insight Partners, and Sway Ventures. It has also entered a strategic investment and technology development agreement with In-Q-Tel, the not-for-profit investment arm that helps deliver technology to U.S. government and intelligence agencies, signaling interest in ThreatEye’s applicability to government network environments.
By combining network performance monitoring and security detection in one platform, LiveAction targets the practical overlap between NetOps and SecOps teams, who often work from different tools and disagree on what a given traffic anomaly means. Its differentiation rests on unifying that data and workflow rather than on a single breakthrough detection technique; independent third-party detection-efficacy benchmarking (e.g., MITRE ATT&CK evaluations) was not found in public sources.
Innovation Matrix Assessment
Continued to evolve ThreatEye with long-term behavioral analytics and new NDR capabilities since the 2021 CounterFlow acquisition, a steady but not exceptionally fast pace for an established vendor integrating acquired technology.
Combines network performance monitoring with encrypted-traffic security analysis in one platform, a genuinely useful integration for teams that otherwise run separate NetOps and SecOps tools, built on real acquired ML technology from CounterFlow AI.
A strategic agreement with In-Q-Tel signals credible interest from the government/intelligence sector, but LiveAction has not announced new funding since its CounterFlow acquisition and total raised ($41M) is modest for the NDR category.
NDR analyzing encrypted traffic without decryption is now a well-established approach used by multiple competitors; LiveAction's differentiation is combining it with NPMD rather than introducing a new detection paradigm.
No independent third-party detection benchmarking (such as a MITRE ATT&CK evaluation) was found in public sources; efficacy evidence is limited to vendor case studies and trade press coverage of product launches.
Encrypted-traffic threat detection and NetOps/SecOps convergence remain relevant problems as encryption adoption grows, though NDR is now a crowded category with several well-funded competitors.
Why CISOs Should Care
Useful for organizations wanting to detect threats in encrypted traffic without decryption overhead, while also unifying network performance and security visibility in one platform rather than separate NetOps/SecOps tools.
What Makes It Different
Distinguished by originating from a network performance monitoring business rather than a pure-play security startup, giving ThreatEye deep network-visibility roots that it layers security detection on top of.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
A capable, established NDR platform with a credible technical foundation from the CounterFlow acquisition and government-sector interest via In-Q-Tel, but competing in an increasingly crowded category without independent efficacy validation on the public record.
Editorial Note: Claims vs. Verified Findings
The CounterFlow AI acquisition (May 2021), funding total, and In-Q-Tel agreement are independently reported by trade press (MSSP Alert, BusinessWire) and LiveAction's own announcements. Specific detection-accuracy and performance claims for ThreatEye come from company and partner marketing and are not independently benchmarked here.
Sources
Alternatives to LiveAction
Forward
CISO ReviewedBuilds a mathematically accurate 'digital twin' of enterprise networks, letting teams verify network and security changes before they…
Claroty
Cyber-physical systems protection platform securing industrial, healthcare and enterprise IoT devices for critical infrastructure operators.
Zscaler
A cloud-native security-service-edge pioneer that routes all user traffic through a global proxy cloud instead of backhauling it…
Tailscale
A zero-configuration mesh VPN built on WireGuard that applies Google's BeyondCorp zero-trust model to make secure networking accessible…
TXOne Networks Inc.
OT and industrial control system cybersecurity built for zero operational disruption, protecting legacy manufacturing and critical infrastructure devices…
Illumio
A microsegmentation pioneer built on the assumption that breaches are inevitable, focused on containing lateral movement rather than…