Randori (IBM)
Hacker-founded attack surface management and continuous automated red-teaming platform acquired by IBM in 2022 and folded into its security portfolio.
Visit Website ↗Overview
Randori was founded in 2018 by Brian Hazzard and David “Moose” Wolpoff, both with hands-on offensive security backgrounds, and built its reputation on running real, continuous attack simulations rather than passive asset scanning. IBM announced its intent to acquire Randori in June 2022, planning to embed its attack surface management and offensive capabilities with IBM Security QRadar’s extended detection and response (XDR) tooling.
Randori’s original differentiator was its “target temptation” scoring, which ranked discovered assets by how attractive they would realistically be to a real attacker, combined with an in-house red team that used the platform’s own reconnaissance to run authorized attacks against customer environments — validating exploitability rather than just flagging exposure. Since the IBM acquisition, the product has operated as part of IBM’s broader security portfolio, which has itself undergone significant restructuring in recent years.
Innovation Matrix Assessment
Independent product development slowed following integration into IBM's security portfolio; IBM's broader security business has undergone notable divestitures and restructuring since 2022.
The original combination of attacker-eye-view discovery with an in-house red team validating exploitability was a genuine operational strength at launch.
As an acquired unit inside a large, restructuring security portfolio, independent momentum signals specific to Randori are not publicly reported.
"Target temptation" attacker-prioritized scoring, built by a hacker-led founding team, was a meaningfully different framing from conventional severity-based asset scoring at the time of launch.
Founders' offensive-security pedigree and the platform's live red-team validation model lend credibility, though current independent efficacy evidence post-acquisition is limited.
Continued relevance is uncertain given IBM's broader security portfolio changes since the acquisition; current product status and roadmap commitment were not independently confirmed in this research pass.
Why CISOs Should Care
A CISO originally chose Randori for attacker-prioritized asset scoring backed by a real, hacker-led red team validating exploitability, not just flagging exposed assets.
What Makes It Different
Rather than scoring assets by generic severity, Randori ranked them by how attractive they would realistically be to an attacker, and paired that with authorized, live red-team attacks using the platform's own reconnaissance.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A technically credible, hacker-built ASM platform whose independent trajectory is now tied to IBM's broader and shifting security portfolio strategy, creating uncertainty about its current investment level and roadmap.
Editorial Note: Claims vs. Verified Findings
Founding details and the IBM acquisition are corroborated by TechCrunch and SecurityWeek; current product status, roadmap commitment, and any changes to Randori's position within IBM's security portfolio since 2022 could not be independently confirmed with available research tools and should be verified directly with IBM before publication.
Sources
- TechCrunch — https://techcrunch.com/2022/06/06/ibm-acquires-offensive-security-startup-randori-to-bolster-its-cybersecurity-toolkit/
- SecurityWeek — https://www.securityweek.com/ibm-acquire-randori-attack-surface-management-tech/
- IBM Newsroom — https://newsroom.ibm.com/2022-06-06-IBM-Tackles-Growing-Attack-Surface-Risks-with-Plans-to-Acquire-Randori
Alternatives to Randori (IBM)
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…
Assetnote (Searchlight Cyber)
Offensive-security-researcher-built EASM platform from Brisbane, profitable and self-funded until its 2025 acquisition by dark-web intelligence firm Searchlight Cyber.
Palo Alto Networks Cortex Xpanse
DARPA-derived internet scanning platform, now Palo Alto Networks' EASM module, that continuously maps and attributes internet-facing assets.