Anomali

Anomali, founded in 2013 and headquartered in Redwood City, California, is a cybersecurity company focused on threat intelligence and security operations.

Reviewed by 7wData

On this page

Profile

Provides a unified platform for threat detection, investigation, and response using AI and centralized security data.

Anomali, founded in 2013 and headquartered in Redwood City, California, is a cybersecurity company focused on threat intelligence and security operations. The company initially gained traction with its threat intelligence platform, ThreatStream, and has since expanded into a broader security operations platform. Anomali's core offering combines elements of SIEM, threat intelligence, and automation into a unified platform, targeting enterprises looking to consolidate security tools.

The company raised a $40 million Series D in 2018 led by Lumia Capital, with participation from Deutsche Telekom Capital Partners and others, though more recent funding details are not publicly disclosed. Anomali's current positioning emphasizes AI-driven threat detection and operational efficiency, claiming to reduce costs by up to 50% for some customers while improving detection rates. Their platform is used by Fortune 500 companies across financial services, healthcare, and government sectors.

Recent executive hires from competitors like IronNet and Forcepoint suggest ongoing efforts to strengthen go-to-market operations. The company launched its virtual user conference, Detect Live, in July 2025 to showcase AI-powered security capabilities and customer case studies.

Track Anomali and 240+ vendors.

335k+ subscribers read the daily AI & data note. One email, both newsletters. Unsubscribe anytime.

Products by Anomali

Who buys this

  • Large enterprises seeking SIEM consolidation
  • Financial institutions with complex compliance needs
  • Government agencies requiring threat intelligence
  • Healthcare organizations managing sensitive data
  • Technology companies with distributed infrastructure

Publicly disclosed clients

  • Bank of Hope
  • Air Canada

Strengths and what to watch

Strengths

  • Claims 50% cost reduction for some customers replacing legacy SIEMs
  • Integrated threat intelligence with detection workflows
  • AI-driven automation for security operations

Watch for

  • Heavy reliance on AI claims without public third-party validation
  • Competition from established SIEM vendors like Splunk
  • Executive turnover in sales and marketing leadership

Recent moves

Key Information

Founded
2013
Headquarters
Redwood City, California

Frequently Asked Questions

What does Anomali do in cybersecurity?

Anomali provides a unified security platform combining threat intelligence, SIEM capabilities, and AI-driven automation. Founded in 2013, it helps enterprises detect, investigate, and respond to threats while consolidating tools. Their solution targets financial, healthcare, and government sectors, claiming up to 50% cost reduction for some customers.

How does Anomali use AI for threat detection?

Anomali's platform applies AI to analyze security data and automate threat detection workflows. The company claims this improves detection rates while reducing manual effort. However, specific AI methodologies aren't publicly detailed, and third-party validation of these claims isn't readily available in their published materials.

Can Anomali really reduce security operations costs?

Anomali states some customers achieve 50% cost savings when replacing legacy SIEMs with their platform. These claims stem from tool consolidation and automation efficiencies. While referenced in case studies like Bank of Hope, independent verification of these savings across diverse environments isn't publicly documented.

What types of companies use Anomali?

Anomali primarily serves large enterprises including financial institutions, healthcare providers, government agencies, and technology companies. Notable clients include Bank of Hope and Air Canada. The platform appeals to organizations needing threat intelligence integration and SIEM consolidation for complex compliance or distributed infrastructure.

How does Anomali compare to Splunk?

Anomali positions itself as a cost-effective alternative to Splunk for SIEM consolidation, emphasizing integrated threat intelligence and AI automation. While Splunk has broader market adoption, Anomali focuses specifically on reducing security operations complexity. Direct feature comparisons require evaluating specific organizational needs and infrastructure.

What's new with Anomali in 2025?

In July 2025, Anomali launched its virtual user conference Detect Live, showcasing AI security capabilities and customer case studies. The company has also hired executives from competitors like IronNet, signaling intensified go-to-market efforts while continuing to emphasize cost reduction and detection improvements.

Sources

  1. www.anomali.com — Recent product launch and customer cost reduction claims
  2. www.anomali.com — Notable client reference
  3. techcrunch.com — Funding history
  4. www.prnewswire.com — Executive movement from competitors