Skip to content

Anomali

Threat intelligence platform aggregating and correlating intel feeds with SIEM, XDR, UEBA, and SOAR capabilities to give SOC teams actionable threat context.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

Anomali provides a threat intelligence platform that ingests, aggregates, and correlates threat intelligence feeds and integrates that context into an AI-powered security and IT operations suite spanning ETL, SIEM, Next-Gen SIEM, XDR, UEBA, SOAR, and threat intelligence platform (TIP) functionality. The core value proposition is turning raw threat feeds into actionable, correlated context that SOC analysts can act on directly within their existing detection and response workflows, rather than treating threat intel as a separate research function disconnected from operations.

Founded in 2012 by Greg Martin and based in Redwood City, California, Anomali has raised roughly $96-100 million across five rounds, including a $40 million Series D in 2018 with participation from Deutsche Telekom Capital Partners and Telstra. The company’s most recent large disclosed funding round dates to 2018, suggesting comparatively slower recent momentum relative to newer, more recently-funded threat intelligence and detection vendors, in an increasingly crowded and commoditizing threat-intel market.

Innovation Matrix Assessment

Innovation Velocity 6/10

Has expanded from a pure threat intelligence platform into a broader SIEM/XDR/SOAR suite, though its most recent major funding/product milestones are several years old.

Operational Value 6/10

Correlates threat intelligence directly into SOC workflows, reducing the gap between raw threat feeds and actionable detection.

Market Momentum 8/10

No major funding round has been publicly disclosed since 2018, suggesting slower recent momentum relative to newer, more recently capitalized competitors in this space. Recognized in Cyber Defense Media Group's 2026 Global InfoSec Awards (1 award), independently juried industry validation of market traction.

Category Disruption 4/10

Threat intelligence platforms are a mature, increasingly commoditized category with several established competitors already well-represented in this market.

Real-World Efficacy 6/10

A long operating history and established enterprise customer base support a credible, if unspectacular, efficacy record.

Enduring Relevance 6/10

Threat intelligence remains a relevant input to detection and response, though its value is increasingly bundled into broader platforms rather than sold standalone.

Why CISOs Should Care

Correlates threat intelligence feeds directly into SIEM/XDR/SOAR workflows, giving analysts actionable context without manually cross-referencing separate threat feeds.

What Makes It Different

Combines threat intelligence platform (TIP) functionality with a broader detection and response suite (SIEM, XDR, UEBA, SOAR) rather than remaining a standalone intel aggregator.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A mature, established threat intelligence vendor; Incremental Innovator given slower recent funding/product momentum relative to the broader market.

Editorial Note: Claims vs. Verified Findings

Funding figures vary slightly between sources (Crunchbase vs. CyberScoop); the most recent large disclosed round is from 2018.

Sources