ThreatConnect

ThreatConnect is a cybersecurity software provider focused on helping organizations operationalize threat intelligence and connect it to security operations and cyber risk management. Its portfolio combines threat intelligence analysis and management, federated search, automation, orchestration, knowledge capture, and cyber risk quantification so security teams can move from raw data to prioritized action.

ThreatConnect now frames its platform strategy around the Intel Hub, which links threat intelligence, risk quantification, and operational response. Across its offerings, ThreatConnect emphasizes AI-assisted intelligence curation, contextual intelligence delivered inside analyst workflows, and financially grounded risk analysis that helps teams align technical investigations with business impact.

Offerings, Capabilities, and Integrations

ThreatConnect delivers capabilities for collecting, enriching, analyzing, prioritizing, and operationalizing threat and risk intelligence. Its offerings support threat modeling with MITRE ATT&CK, intelligence reporting, collaborative investigation workflows, alert triage, incident response, threat hunting, vulnerability prioritization, and cyber risk communication for executive stakeholders.

A major part of the value proposition is integration. ThreatConnect connects with existing security and IT environments across SIEM, SOAR, EDR/XDR, vulnerability management, ticketing, identity, cloud, and collaboration tools. It also supports no-code and low-code automation, API-driven extensibility, and context overlays that bring intelligence into the tools analysts already use instead of forcing more console switching.

Products and Services

  • Threat Intelligence Platform: ThreatConnect’s core threat intelligence platform for aggregating, enriching, modeling, and operationalizing threat data across detection, investigation, response, and reporting workflows.
  • Polarity by ThreatConnect: A federated search and context overlay platform that surfaces intelligence, enrichment, and team knowledge directly inside analyst workflows, with AI summaries and one-click actions.
  • Risk Quantifier: A cyber risk quantification offering that translates technical exposure and control performance into financial terms to support prioritization, remediation planning, and board reporting.
  • Intel Hub: ThreatConnect’s umbrella platform for Threat and Risk-Informed Defense, connecting threat intelligence, risk quantification, and security operations to focus teams on the highest-priority exposures.
  • ThreatConnect CAL™: An AI- and ML-powered intelligence capability that curates open-source intelligence, generates summaries, applies ATT&CK context, and provides enrichment to help analysts work faster.
  • ThreatConnect Intelligence Anywhere: A browser extension that scans web content and tool interfaces for indicators and groups, exposing ThreatConnect and CAL context and allowing analysts to memorialize findings without leaving their workflow.
  • Playbooks: ThreatConnect’s automation and orchestration capability for building drag-and-drop workflows that enrich data, trigger actions, and automate cyber defense tasks and internal processes.

Target Customers

ThreatConnect targets enterprise security organizations that need to connect cyber threat intelligence with day-to-day operational workflows. Typical users include threat intelligence teams, SOC teams, incident responders, threat hunters, detection engineers, vulnerability management teams, and cyber risk management leaders.

The platform is well suited to large, complex, and highly regulated organizations that operate diverse security stacks and need stronger collaboration across threat, risk, and operations. Its customer fit spans industries such as financial services, healthcare, retail, technology, manufacturing, automotive, utilities, consumer goods, and professional services.

Cloud Integrations and Marketplace

  • Azure Marketplace: ThreatConnect has a verified Microsoft marketplace presence, including the ThreatConnect Platform listing and a ThreatConnect Solution for Microsoft Sentinel listing.
  • AWS: ThreatConnect provides verified AWS integrations through its marketplace and App Catalog, including support for Amazon GuardDuty, Amazon EC2, Amazon S3, and AWS DynamoDB across TI Ops and Polarity workflows.
  • Google: ThreatConnect provides verified Google integrations through its marketplace and App Catalog, including Google Gmail, Google Calendar, Google Drive, and Google Drive with Polarity.

Key People

  • Chris Lehman: President of Global Field Operations
  • Daniel Moser: Chief Financial Officer
  • Andrew Pendergast: EVP of Product
  • Jason Spies: EVP of Engineering and Chief Architect
  • Charles Gold: Chief Marketing Officer
  • David Hopland: VP of Global Sales
  • Joseph Rivela: SVP, Customer Success and Co-Founder of Polarity.io
  • Gerald Caponera: General Manager, Cyber Risk Quantification Products
  • Lara Meadows: VP of Sales Engineering

Key Facts

  • Headquarters: Arlington, Virginia, United States
  • Employees: Approximately 170
  • Annual Revenue: $26M-$40M
  • Parent Company: Dataminr
  • Subsidiaries: None
  • Publicly Listed: No; part of privately held Dataminr

Analyst Recognitions

  • Forrester: Leader in The Forrester Wave™: Cyber Risk Quantification (CRQ), Q3 2023.
ThreatConnect

Enter a search