An IP address is a rather unsociable thing. It offers no explanation for its presence, no confession, no helpful forwarding address. Put it on a list of suspicious infrastructure and you have a clue. Find it in your company’s logs and you have a question. Discover which machine contacted it, what that machine does, and whether the connection belongs to an active attack campaign, and the question begins to acquire an answer.
This distance between the clue and the answer is where Anomali has built its business. The company started as ThreatStream in 2013, helping organizations work with threat intelligence. It now sells a wider arrangement: a security data lake, intelligence that supplies context, and AI that helps investigate and respond. Its most interesting ambition is to shorten the handoff between people who know about threats and people who must do something about them.
- ThreatStream connects external cyber intelligence to the organization’s own evidence.
- The data lake puts security records from different systems into a common investigative view.
- AI assists decisions; autonomy comes with configurable boundaries and oversight.
- The useful buying test is a real workflow, with real data and a measured result.
The bank wanted a working memory
In its FinTech Accelerator work, the Bank of England tested ThreatStream for two months. Its problem was specific. Threat information arrived from different sources; the bank wanted a searchable repository that could connect, enrich, and distribute it. Collecting tactical indicators separately limited what those indicators could tell a security team about priorities.
The bank’s published account found the platform intuitive and compatible with existing information sources. It described automated ingestion and sharing, associations between actors and campaigns, and a workflow that matched established processes. It agreed to extend the relationship. The revealing detail is that fit with existing work: a clever tool still has to survive contact with the people using it.
This is a more useful origin for the product’s appeal than a parade of alarming breach statistics. A team can possess plenty of information and still spend its day translating between systems. Each translation creates another opportunity to lose the thread. The bank’s experiment suggested that a shared memory could help analysts preserve it.
“Before Anomali, we had tons of information without context.”Devin Ertel, identified as Blackhawk Network Holdings CISO in Anomali’s published customer account
Three pieces of a case
Consider a simplified investigation. A security tool flags an outbound connection. An analyst needs to know whether the destination is associated with malicious infrastructure, whether other devices contacted it, and whether the affected user or asset is particularly important. This is an illustrative workflow, but it explains why a feed alone cannot finish the job.
ThreatStream Next-Gen supplies the outside view. It curates and scores intelligence, connects indicators with actors and campaigns, and brings that context into operational tools. Anomali’s current managed-intelligence offering combines external knowledge with assets, users, event logs, and incident history. The same indicator can deserve different attention in different environments. Context is the part that makes the distinction useful.
The Unified Security Data Lake supplies the inside view. It collects records from cloud, endpoint, network, identity, and application systems; normalizes them into the Open Cybersecurity Schema Framework; and correlates them with intelligence. Historical hunting matters here. Learning that a destination is dangerous today creates a reason to ask whether anyone contacted it last month.

The third piece is the analyst’s route through the evidence. Anomali introduced its generative AI Copilot in January 2024 alongside a broader security operations platform. Its documentation describes an Asset Analyzer and custom-data analysis: users can upload a CSV or use a lookup table, then ask questions in natural language. The attraction is practical. A question should not require a small expedition through unfamiliar query syntax.
The feed grew ambitions
The company’s founders were Greg Martin and Colby DeRodeff. Its present leadership page also identifies Hugh Njemanze as President & Founder; his background includes co-founding ArcSight and leading its technology work. Ahmed Rubaie, whose biography dates his arrival as CEO to 2021, now leads the business. That pedigree puts Anomali close to the long-running enterprise problem of searching and interpreting security data.
The expansion did not begin with the latest AI fashion. In February 2016, ThreatStream became Anomali as it broadened its products. That April, it announced a $30 million Series C led by IVP, with General Catalyst, GV, and Paladin participating. In January 2018, a $40 million Lumia-led Series D brought the announced total raised to $96 million across four rounds. These were funds for building and expanding the company, rather than the price of buying its software.
By May 2026, ThreatStream Next-Gen’s launch brief read like an attempt to carry intelligence through the whole investigation. Recurring intelligence requirements, a prioritized command center, connected search, case management, and reporting each address a handoff. An analyst’s findings should reach the next person with their meaning intact. Anomali said the release was available both independently and embedded in its data lake.
- 2013ThreatStream begins
- 2016Anomali rebrand
- 2024Copilot + wider SecOps platform
- 2026ThreatStream Next-Gen launches
The agent needs a permission slip
Anomali’s current Agentic SOC pitch takes the argument further. AI agents can help prioritize, investigate, and carry out response workflows. The company describes an orchestration agent called AURA, or Anomali Unified Response Agent, with approval thresholds and an audit trail. Consequential actions await human approval by default.
That distinction matters because an investigation and a response carry different consequences. Suggesting that a device looks suspicious is one thing. Disconnecting it can interrupt work. Anomali describes a progression from recommending an action, to seeking approval, to acting within boundaries the organization sets. A useful agent needs both evidence and authority; confidence about the first cannot confer the second.

The May launch announcement also separated shipping triage and investigation capabilities from higher autonomy on its roadmap. That is a helpful distinction for buyers: a planned capability belongs in a conversation about delivery, not in a demonstration of what is already working. The current product direction emphasizes human-guided automation, evidence-grounded recommendations, and responses across the security stack.
Who pays for fewer handoffs?
Anomali reports more than 400 enterprise customers across financial services, critical infrastructure, government, and national defense. Its buying audience includes security operations centers, threat intelligence teams, and managed security service providers. These are organizations with enough telemetry and investigative work for fragmentation to become an expensive habit.
The business is sales-led enterprise software. Public documentation makes active Copilot and Security Analytics subscriptions prerequisites for certain features. The marketplace lets teams find and purchase outside intelligence feeds and enrichment tools. The economic question extends beyond a subscription: configuration, feed licenses, storage choices, training, and migration effort belong in the buyer’s calculation.
Distribution has widened too. In October 2025, Anomali announced availability on AWS infrastructure in the UAE, addressing local data residency needs. The next month it introduced an MSSP program with multi-tenancy and federated search, allowing providers to investigate across customers while preserving separation. In August 2025 it announced FedRAMP Moderate “In Process” status with CMS sponsorship - a step in an authorization process.
Its competitive position is consequently awkward in an interesting way. ThreatConnect and Recorded Future are alternatives in threat intelligence; broader analytics brings it into territory occupied by SIEM platforms such as Splunk. Yet Recorded Future also lists ThreatStream integrations. Enterprise security has room for both rivalry and plumbing. Anomali’s distinction is its effort to join an intelligence heritage to telemetry and investigations, rather than leave those purchases in separate rooms.
Copy the experiment before the architecture
The lesson a reader can borrow is smaller than a platform purchase. Pick one recurring investigation. Record how long it takes, which tools people consult, and where they lose context. Connect the relevant intelligence to the relevant internal records. Test whether the analyst reaches a better-supported decision with fewer handoffs. Extend automation only after that result survives review.
This is editorial advice drawn from the product’s design and the bank’s trial, not a promise of a particular return. Anomali advertises substantial time and cost improvements, but a buyer’s own baseline is the useful comparison. Count the labor of maintaining the workflow as well as the time saved inside it.
The approach depends on accessible telemetry, intelligible asset records, relevant intelligence, and a team able to define acceptable responses. Missing logs leave gaps no assistant can fill. Weak ownership makes approvals difficult. A small organization with little investigative volume may have a simpler route through its existing tools.
There is an amusing footnote in Anomali’s careers page: the company says it does not use AI to review candidates or make hiring decisions. Humans examine the applications. Even a business selling automation chooses where judgment should stay. In security operations, that choice may be the most useful part of the sale.
Follow the investigation
Explore the products, people, and ongoing conversation.