Skip to content

Elemendar

Elemendar builds AI models that convert unstructured cyber threat intelligence reports into structured, machine-readable STIX and MITRE ATT&CK data.

Visit Website ↗ + Add to Compare
50/100Incremental Innovator

Overview

Elemendar builds natural-language-processing models that read unstructured cyber threat intelligence (CTI) reports, blog posts, and PDFs, then convert the prose into structured, machine-readable STIX 2.x objects mapped to MITRE ATT&CK techniques. The core problem it targets is real and well-documented in the CTI field: most threat intelligence still arrives as human-written narrative, and analysts spend a large share of their time manually re-keying that narrative into the structured formats that SIEM, SOAR, and threat-intel platforms actually consume. Elemendar automates that translation step rather than generating the intelligence itself.

The company was founded in 2017 by Giorgos Georgopoulos and Syra Marshall out of the UK National Cyber Security Centre-backed Cyber Accelerator (Wayra UK), and is based in London. Its flagship product, READ, ingests CTI documents and outputs STIX bundles with ATT&CK tagging, intended to plug into existing threat-intel platforms (MISP, ThreatConnect, and similar) rather than replace them.

Elemendar is a small, early-stage company that has raised a modest amount of outside capital relative to the broader AI-security market, and it operates in a narrow niche (CTI structuring) rather than a broad security category. That focus is also its main limitation: the value of READ is capped by how much of an organization’s workflow still depends on unstructured intelligence versus feeds that already arrive structured.

Innovation Matrix Assessment

Innovation Velocity 5/10

Has iterated its READ engine to add ATT&CK-technique tagging on top of base STIX 2.0 output, a meaningful but incremental improvement rather than a fast release cadence typical of well-funded AI startups.

Operational Value 5/10

As a narrow point tool that ingests documents and outputs STIX bundles for integration into existing MISP/ThreatConnect-style platforms, deployment friction is low, but the product only automates one step of the CTI workflow.

Market Momentum 4/10

Total disclosed funding is under $2M as of the most recent reporting, small even by seed-stage cybersecurity standards, and public news flow has been limited since its early accelerator-era coverage.

Category Disruption 5/10

Automating CTI-to-STIX conversion addresses a genuine analyst time sink, but it is a workflow-efficiency tool rather than a new detection or prevention capability, limiting how disruptive it can be to the broader threat-intel category.

Real-World Efficacy 5/10

No independent, named-customer case studies or third-party accuracy benchmarks for READ's STIX/ATT&CK extraction were found; efficacy assessment rests mainly on the plausibility of the NLP approach rather than verified outcomes.

Enduring Relevance 6/10

CTI teams still spend significant manual effort structuring intelligence, so the underlying problem remains relevant, particularly for smaller CTI/SOC teams without dedicated intel analysts.

Why CISOs Should Care

For CISOs whose threat-intel function is thin, automating the conversion of narrative reporting into structured, ATT&CK-tagged intelligence can meaningfully cut analyst time spent on manual re-keying.

What Makes It Different

Focuses narrowly on the CTI structuring step itself (unstructured text to STIX/ATT&CK) rather than trying to be a full threat-intelligence platform, positioning it as a feeder tool for existing TIPs.

The Matrix Verdict

50/100 — INCREMENTAL INNOVATOR

A credible, narrowly-scoped NLP tool for a real CTI pain point, but its small scale, limited funding, and lack of independently verified accuracy data keep it a niche play rather than a category leader.

Editorial Note: Claims vs. Verified Findings

Founding story, accelerator backing (NCSC/Wayra UK), and funding figures come from independently reported sources (Crunchbase, Newable Ventures, UK Companies House); no independently verified accuracy or customer-outcome data for the READ product itself was found, so efficacy claims should be treated as unverified.

Sources