Dossier · Acquired asset · 1 independent source

Minerva Labs

Cybersecurity Acquired asset Dual-Use Technology Founded 2014

Last updated: Jul 31, 2026

Minerva Labs developed a prevention-first endpoint security platform that used anti-evasion and ransomware-prevention techniques to disrupt malicious activity before payload execution. Rapid7 acquired the company in 2023 and redirected its former website to Rapid7, so this record now represents an acquired cyber capability rather than an independent startup.

Visit Website

Company Overview

Minerva Labs was an Israeli cybersecurity company founded in 2014 around a narrow but important endpoint-security problem: malware can evade conventional prevention and detection long enough to execute, establish persistence, or begin encryption. Its product used behavioral analysis, environmental deception, and execution controls to make evasive malware reveal itself or fail before the destructive payload could run. Rapid7 described the technology as multi-layer prevention that neutralized malicious activity before execution and could operate alongside existing endpoint protection, which positioned Minerva as a prevention layer rather than a full replacement for EDR, XDR, or managed detection and response.

The commercial use case was enterprise ransomware and advanced-malware resilience. Organizations could deploy the technology alongside incumbent endpoint products to address gaps involving obfuscation, anti-analysis behavior, malicious scripts, fileless activity, and other execution-stage tactics. This approach was relevant to security teams that wanted to reduce the number of incidents requiring analyst investigation, but it also created the normal point-solution burden: endpoint agents must be lightweight, compatible with existing controls, operationally reliable, and demonstrably low in false positives. Public product material and third-party profiles support the anti-ransomware and anti-evasion positioning, but the available evidence does not establish a current standalone customer base, deployment scale, or recurring-revenue trajectory.

Competition came from broad endpoint platforms such as CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender for Endpoint, Sophos Intercept X, and Palo Alto Networks Cortex XDR, all of which have incentives to absorb prevention and anti-evasion features into larger suites. Minerva's potential edge was specialization in deception and pre-execution interruption, plus interoperability with other endpoint controls. That specialization could be valuable where a customer needed an additional ransomware barrier, but it was exposed to platform consolidation, procurement preference for bundled controls, and the technical challenge of keeping pace with rapidly changing evasion methods.

Rapid7 announced that it acquired Minerva Labs on 15 March 2023 for approximately $38 million in cash and stock, stating that Minerva's technology and engineering team would extend Rapid7's managed detection and response capabilities from the endpoint to the cloud. The former Minerva domain now redirects to Rapid7's corporate site, corroborating that the independent company is no longer operating as a standalone web presence. The acquisition is a concrete commercialization and strategic-validation signal, but it should not be read as proof of current product independence, continuing Minerva-branded sales, or successful defense-sector deployment.

The dual-use relevance is credible at the capability level. Preventing ransomware and evasive malware on endpoints is useful for civilian enterprises, healthcare, financial services, public-sector networks, and other mission-critical environments; the same defensive properties can support government and defense cyber resilience. The evidence supports a transferable security capability, not a claim that Minerva had military customers, classified deployments, or government contracts. For strategic diligence, the key question is therefore how much of the anti-evasion technology and team remains identifiable inside Rapid7 and whether it continues to improve endpoint-to-cloud prevention outcomes.

Dual-Use Assessment

Military & Commercial Applications

The core capability has substantive dual-use potential because pre-execution ransomware prevention, anti-evasion analysis, and endpoint execution controls protect both commercial networks and public-sector or mission-critical systems. The available evidence supports applicability to government and defense cyber resilience, but does not verify military customers, classified use, or government contracts; the assessment is capability-based rather than customer-based.

Strategic Fit Assessment

Minerva Labs was a credible strategic cyber asset, but it is no longer an independent strategically relevant startup: Rapid7 announced its acquisition in 2023 and the former company domain now redirects to Rapid7. The acquisition price and stated integration rationale are useful historical validation of the technology and team, while current standalone revenue, headcount, product availability, and ownership of specific intellectual property are not established by the available public evidence. Accordingly, this record should retain historical diligence value without treating Minerva as a current investment priority or implying an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Minerva's strategic value is the endpoint prevention capability it contributed to Rapid7's broader managed detection and response strategy. Anti-evasion and ransomware controls can improve operational resilience by stopping destructive behavior earlier and by complementing telemetry, investigation, and response workflows. For national-security analysis, the relevant asset is a transferable defensive technique for protecting mission-critical endpoints, not a verified defense program. The acquisition also illustrates how a focused Israeli cyber startup can become a component of a larger security platform, while making post-acquisition product continuity and technical integration important diligence questions.

Key Technologies

  • Behavioral analysis of malware evasion
  • Pre-execution ransomware prevention
  • Endpoint deception and environment manipulation
  • Malicious script and fileless-activity interruption
  • Anti-analysis and obfuscation detection
  • Interoperable endpoint prevention agent

Use Cases & Applications

  • Blocking ransomware before file encryption begins
  • Adding a prevention layer beside existing EDR, EPP, or XDR tools
  • Interrupting evasive malware during execution and staging
  • Reducing analyst workload from commodity and semi-targeted endpoint attacks
  • Hardening endpoints in healthcare, finance, and other operationally sensitive enterprises
  • Improving cyber resilience for public-sector and mission-critical networks
  • Evaluating endpoint-to-cloud prevention orchestration after Rapid7 integration

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 4 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • rapid7.com Public source used for profile verification.
  • rapid7.com Public source used for profile verification.
  • g2.com Public source used for profile verification.
  • LinkedIn company page Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.