Dossier · Acquired asset · 6 independent sources
Aorato
Last updated: Jul 31, 2026
Aorato was an Israeli cybersecurity startup that used machine learning and an Organizational Security Graph to detect anomalous behavior around Windows Server Active Directory. Microsoft acquired the company in 2014, and its technology became part of Microsoft's identity-threat-detection product lineage rather than an independent business.
Company Overview
Aorato developed identity-centric threat detection for enterprise Windows environments. Its best-documented product concept, the Directory Services Application Firewall, monitored activity around Active Directory and built a continuously updated Organizational Security Graph of users, machines, and access relationships. Microsoft described the approach as learning normal behavior and identifying suspicious activity, giving security teams visibility into attacks that use valid credentials or move inside the network after bypassing perimeter controls. This was a meaningful technical choice: Active Directory is a control plane for enterprise access, so behavioral signals around it can expose compromised accounts, privilege abuse, reconnaissance, and lateral movement that signature-oriented controls may miss.
The target market was enterprise security teams operating on-premises or hybrid Windows estates. Aorato's value proposition was strongest where directory infrastructure was large, interconnected, and difficult to model manually. It addressed a concrete operational gap between identity and security operations by correlating identity, device, network, and event context rather than treating authentication as an isolated log event. Public evidence supports a released product and venture backing, but does not establish a durable independent customer base, recurring revenue scale, retention, or post-launch market share. Those unknowns matter because anomaly detection products depend heavily on telemetry access, deployment quality, analyst workflow, and the ability to demonstrate fewer missed attacks without overwhelming teams with false positives.
Microsoft announced the acquisition on November 13, 2014 and said Aorato's technology and team would strengthen identity and access protection across on-premises and cloud environments. Microsoft subsequently used the acquired methodology in Advanced Threat Analytics, later part of the broader Microsoft identity-security portfolio. The acquisition is credible commercialization and strategic-validation evidence, but it also ends the case for evaluating Aorato as a live standalone venture. Current diligence should therefore distinguish the historical Aorato asset from Microsoft's later product engineering, distribution, telemetry, and roadmap decisions. The former aorato.com domain no longer resolves, and no current independent company operation is evidenced.
The national-security relevance is substantive but technology-based rather than contract-based. Government, defense, and critical-infrastructure networks commonly depend on directory services and privileged identities, making detection of credential theft and internal movement strategically important. The same capability can support cyber defense in those environments without requiring a defense-specific product thesis. However, this record contains no verified evidence of classified deployments, government contracts, or military customers. Aorato is therefore best treated as a historical Israeli cyber acquisition and a reference point for identity-threat-detection architecture, not as evidence of current defense traction or an investable company.
Dual-Use Assessment
Aorato's core technology has substantive commercial and defense/security applicability because it detects abnormal behavior in identity infrastructure, including compromised credentials, privilege abuse, and lateral movement. Those problems affect enterprises as well as government, defense-contractor, and critical-infrastructure networks. The dual-use assessment is limited to the technical capability: public sources do not verify military customers, classified deployments, government procurement, or a defense-specific operating unit.
Strategic Fit Assessment
Aorato is not a live investment priority because Microsoft acquired it in 2014 and the independent company no longer operates as a standalone venture. The acquisition provides meaningful strategic-validation evidence for identity analytics and demonstrates that a focused Israeli cybersecurity team addressed a platform-level problem attractive to a major security vendor. It does not provide current information about ownership, product economics, employees, valuation, or standalone financing. The appropriate diligence use is historical category mapping and comparison with current identity-threat-detection companies, not a recommendation or an active deal thesis.
Strategic Value to U.S.-Israel Alliance
Aorato has high historical strategic value as an example of identity security becoming a core cyber-defense layer. Its Organizational Security Graph connected people, machines, and directory access patterns, illustrating why protecting authentication and privilege pathways can reveal attacks that perimeter controls miss. Microsoft's acquisition and subsequent use of the technology in Advanced Threat Analytics show platform relevance, while the later Microsoft product lineage demonstrates how a narrow detection primitive can be absorbed into a broader identity-security stack. For Claw & Talon, the record is useful for studying Israeli cyber technology, acquisition pathways, and the transfer of commercial identity analytics into security products used across sensitive networks.
Key Technologies
- Machine-learning behavioral anomaly detection
- Organizational Security Graph modeling
- Active Directory telemetry and identity analytics
- Directory Services Application Firewall concepts
- Deep packet inspection of directory-related traffic
- User and entity behavior analytics
- Security event and access-pattern correlation
Use Cases & Applications
- Detecting compromised Active Directory accounts
- Identifying pass-the-hash and pass-the-ticket behavior
- Finding privilege escalation and suspicious administrator activity
- Exposing lateral movement across users, devices, and servers
- Investigating insider misuse of legitimate access
- Monitoring hybrid enterprise identity infrastructure
- Supporting cyber defense for government and critical-infrastructure networks
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Microsoft: Microsoft acquires Aorato Official acquisition announcement describing machine-learning detection, the Organizational Security Graph, Windows Server Active Directory, and the hybrid-cloud identity rationale.
- Microsoft Investor Relations acquisition history Microsoft's acquisition-history listing records Aorato under November 13, 2014.
- Microsoft Entra: Microsoft Acquires Aorato Microsoft identity documentation states that Aorato's Active Directory anomaly-detection work joined the Identity and Security Services Division.
- Startup Nation Finder: Aorato Public Israeli startup-ecosystem profile used cautiously for 2012 founding, Israel location, 1-10 employee range, released product status, and historical funding-round metadata.
- Globes: Cyber security co Aorato raises $1m Contemporaneous reporting on the 2012 founding team, Israeli location, product direction, and early financing.
- Microsoft Ignite: Advanced Threat Analytics Microsoft presentation describing Advanced Threat Analytics as based on the recent Aorato acquisition and focused on compromised credentials and anomalous behavior.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.