IntSights

Cybersecurity Acquired asset Dual-Use Technology Founded 2015

Last updated: Jul 31, 2026

IntSights developed cloud-native external threat intelligence and digital risk protection capabilities that monitored clear, deep, and dark web sources, prioritized organization-specific threats, and supported remediation. Rapid7 acquired the company in July 2021, and the capability is now represented in Rapid7 Threat Command rather than an independent IntSights business.

Visit Website

Company Overview

IntSights built an external threat intelligence platform around a practical operational problem: defenders often receive telemetry from inside their networks while important warning signals are already visible outside the perimeter. The product monitored clear-web, deep-web, dark-web, criminal-forum, social, paste-site, and related sources for threats associated with an organization’s domains, brands, employees, executives, customers, and suppliers. Its value proposition was not simply the delivery of a large intelligence feed. It combined asset discovery, source collection, enrichment, prioritization, investigation, and remediation workflows so that a security team could move from an external signal to a concrete defensive action.

The product category sits at the intersection of cyber threat intelligence, digital risk protection, brand protection, identity exposure monitoring, and security operations. Typical use cases include discovering leaked credentials, identifying phishing or impersonation infrastructure, monitoring adversary discussions, correlating indicators of compromise, prioritizing externally visible vulnerabilities, and coordinating takedowns or blocking actions. Rapid7’s current Threat Command documentation describes tens of thousands of monitored sources, tailored intelligence based on an organization’s digital assets, IOC management, vulnerability-risk enrichment, third-party monitoring, and integrations with SIEM, SOAR, identity, and network-security tools. Those capabilities support a clear commercial buyer need: reducing the time and specialist effort required to decide which external threats are credible and what to do next.

Commercially, IntSights had a broad enterprise-oriented footprint before the transaction, with offices reported in Amsterdam, Boston, Dallas, New York, Singapore, Tel Aviv, and Tokyo. Rapid7 announced the acquisition of IntSights Cyber Intelligence Ltd. in July 2021 for approximately $335 million in cash and stock, and its SEC filing states that the acquisition closed on July 16, 2021. This is the strongest available traction signal for the record, but it should not be confused with current standalone revenue, customer count, employee count, or independent product momentum. The post-acquisition product page and documentation demonstrate continued commercialization under Rapid7; they do not establish that IntSights still exists as a separately strategically relevant company.

Competition is structurally intense. Recorded Future, Flashpoint, Cybersixgill, SOCRadar, Searchlight Cyber, Mandiant intelligence products, and broader security platforms all compete for some combination of threat-data, external-exposure, investigation, and response budgets. IntSights’ defensible contribution was the integration of contextual external collection with action-oriented workflows, analyst support, and security-stack integrations. That advantage is useful only if collection remains timely, false positives stay manageable, and the resulting alerts connect reliably to the customer’s identity, SIEM, SOAR, incident-response, and takedown processes. Acquisition by Rapid7 supplied distribution and platform adjacency, but also means roadmap, staffing, packaging, and differentiation are controlled by the parent company.

The dual-use case is credible but bounded. The same external monitoring and prioritization methods can support government, defense, critical-infrastructure, and diplomatic organizations that need early warning of phishing, credential targeting, impersonation, supply-chain exposure, or adversary preparation. The technology can contribute to force protection and cyber defense, but the public evidence reviewed here does not establish a specific defense contract, classified deployment, or government customer for IntSights. Mission adoption would therefore require separate diligence on secure-environment deployment, data provenance, language and regional coverage, analyst tradecraft, legal authority, chain of custody, and integration with government incident-response procedures. This profile is best used as a strategic technology and build-versus-buy reference, not as a live venture opportunity.

Dual-Use Assessment

Military & Commercial Applications

The core capability has substantive commercial and security-mission applicability: external collection, asset-linked threat correlation, credential and impersonation monitoring, IOC enrichment, and remediation workflow support are useful to enterprises and can also support government, defense, and critical-infrastructure cyber defense. The public evidence supports a credible dual-use technology thesis, but does not establish a specific classified deployment, defense contract, or government customer. The defense case therefore depends on future diligence around secure hosting, data provenance, analyst tradecraft, legal authorities, and mission-system integration.

Strategic Fit Assessment

IntSights is not an independent direct-diligence target: Rapid7 acquired the company in July 2021, and the technology is now commercialized through Rapid7 Threat Command and related intelligence capabilities. The record merits strategic attention as an acquisition and product-integration benchmark in external threat intelligence, especially for assessing detection-to-remediation workflows, source coverage, and platform distribution. It should not be treated as a current standalone financing opportunity, and public materials do not provide enough evidence to assess current IntSights-level revenue, margins, retention, or team continuity separately from Rapid7.

Strategic Value to U.S.-Israel Alliance

The asset has high reference value for cyber-defense strategy because it demonstrates how external threat collection can be connected to organization-specific assets, analyst investigation, IOC management, and remediation. It can inform build-versus-buy decisions for enterprise, government, and critical-infrastructure security programs and provides a useful benchmark for newer companies claiming digital risk protection or dark-web intelligence differentiation. Its strategic relevance is tempered by acquisition dependence: the available public evidence describes a Rapid7 product capability, not an independently controlled technology roadmap or a standalone partner.

Key Technologies

  • Clear-web, deep-web, dark-web, criminal-forum, paste-site, and social-source monitoring
  • Organization-specific digital asset discovery and external attack-surface mapping
  • Threat-intelligence data mining, entity correlation, and contextual prioritization
  • Credential-leak, phishing, brand-impersonation, and malicious-mobile-app detection
  • IOC enrichment, CVE relevance scoring, and MITRE ATT&CK-aligned threat context
  • SIEM, SOAR, identity, network-security, and takedown/remediation integrations
  • Analyst-assisted investigation and multilingual threat research

Use Cases & Applications

  • Detect leaked employee or customer credentials and trigger identity-protection workflows
  • Identify phishing domains, fraudulent sites, impersonating applications, and brand abuse
  • Monitor criminal forums and adversary channels for organization-specific targeting signals
  • Prioritize externally visible vulnerabilities and indicators using threat context
  • Provide SOC teams with enriched external intelligence for investigation and blocking
  • Monitor third-party and supply-chain exposure connected to critical business services
  • Support government and defense early warning for personnel, supplier, and mission-system targeting
  • Coordinate evidence collection and takedown or blocklist remediation for malicious infrastructure

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 4 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • rapid7.com Public source used for profile verification.
  • SEC filing Public source used for profile verification.
  • rapid7.com Public source used for profile verification.
  • docs.rapid7.com Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Investor Lens

What this entry is

Acquired asset

Why it may matter

IntSights may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies IntSights's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.