Noetic Cyber
Last updated: Jul 31, 2026
Noetic Cyber developed a cyber asset attack surface management (CAASM) platform that unified internal asset, identity, control, and exposure data. Rapid7 acquired the company in July 2024 and incorporated the technology into its current Surface Command attack-surface-management offering.
Visit WebsiteCompany Overview
Noetic Cyber addressed a persistent security-operations problem: organizations collect asset and control data in endpoint, vulnerability, identity, cloud, IT, and network tools, but those systems rarely agree on what an asset is, who owns it, how it is configured, or whether required controls are operating. Its CAASM platform was designed to ingest those fragmented sources, correlate records into a more useful inventory, expose control drift and blind spots, and help security teams prioritize remediation. Rapid7's current Surface Command documentation describes the resulting product direction in concrete terms: connectors ingest records, correlation creates unified assets and relationships, and workflows can act on query results.
The commercial buyer is typically an enterprise security, infrastructure, or risk organization with hybrid infrastructure and too many overlapping security tools. The practical use cases include finding unmanaged devices and identities, identifying missing endpoint or vulnerability coverage, correlating exposed services with internal ownership, supporting audit evidence, and giving remediation teams a defensible order of operations. The current Rapid7 documentation makes the operating model more concrete: scheduled connectors ingest source data, correlation creates unified assets and inherited relationships, queries and dashboards expose gaps, and workflows can take action. The product is more valuable when those feeds remain fresh and map cleanly to operational owners. Rapid7 combines inside-out internal inventory with outside-in discovery of domains, IPs, certificates, and services.
The category is strategically important but crowded. Axonius, JupiterOne, runZero, Armis, Tenable, Wiz, Palo Alto Networks, CrowdStrike, and other platform vendors address overlapping portions of asset visibility, exposure management, cloud security, vulnerability prioritization, and control validation. Noetic's strongest historical proposition was the quality of its cross-source asset and control context rather than a unique sensor or novel detection model. Rapid7's acquisition creates distribution and integration advantages across vulnerability management, detection and response, and security operations, but it also means the Noetic brand, standalone roadmap, and historical startup metrics are no longer reliable indicators of an independent business.
The acquisition is a verified commercialization signal, not proof of independent scale or durable product-market leadership. Rapid7 announced the transaction on July 1, 2024, and its SEC filing records that it completed the acquisition on July 3 for aggregate consideration of approximately $51.2 million, including developed technology valued at $11.5 million; Rapid7 also reported that Noetic revenue and net loss were not material to 2024 consolidated results. Rapid7’s later annual-report disclosures continue to identify the developed technology as the acquired intangible. Those disclosures support treating the record as an acquired technology asset with real product value, while avoiding unsupported claims about customer count, recurring revenue, retention, or post-acquisition growth.
The defense and national-security relevance is credible because military, intelligence, critical-infrastructure, and government environments face the same inventory fragmentation and control-accountability problem, often with more complicated ownership, segmentation, contractor, and legacy-system constraints. Asset and identity correlation can support cyber defense, vulnerability prioritization, zero-trust implementation, and incident scoping. The public evidence does not establish a dedicated defense deployment, classified-network operation, or government contract, so the strongest conclusion is capability adjacency rather than demonstrated defense traction. Diligence should focus on deployment boundaries, data residency, support for restricted or disconnected environments, auditability, connector behavior, and measurable remediation outcomes.
Dual-Use Assessment
The core capability is substantively dual-use: correlating assets, identities, exposures, and security-control coverage supports commercial security operations and can also improve cyber defense, vulnerability management, zero-trust implementation, and incident scoping for government or national-security environments. Public sources support the capability case, but do not prove dedicated defense deployments or classified-network operation.
Strategic Fit Assessment
Noetic's technology has credible strategic value, but the company is an acquired asset inside Rapid7 rather than an independently actionable startup. Rapid7's public filing confirms the acquisition and identifies developed technology as a material acquired intangible, while also stating that Noetic's 2024 revenue and net loss were not material to consolidated results. The appropriate diligence lens is integration quality and product impact, not a standalone financing or diligence thesis.
Strategic Value to U.S.-Israel Alliance
The asset is strategically relevant because trusted attack-surface inventory is foundational to vulnerability prioritization, security operations, zero-trust programs, and cyber resilience. Rapid7 can distribute the capability through a broader platform and combine internal inventory with external exposure discovery. Its value for defense and regulated users depends on connector coverage, isolation and data-residency options, auditability, and demonstrated remediation improvement; public evidence does not yet establish those specialized deployments.
Key Technologies
- Continuous cyber asset discovery and inventory ingestion
- API connector framework for endpoint, vulnerability, cloud, identity, and IT systems
- Cross-source entity resolution and asset correlation
- Unified asset, identity, exposure, and control-property modeling
- External attack-surface discovery for domains, IPs, certificates, and services
- Graph-style relationship queries and contextual dashboards
- Workflow automation for remediation and control-gap response
Use Cases & Applications
- Consolidating hybrid-cloud and on-premises asset inventories
- Finding unmanaged devices, identities, services, and shadow IT
- Measuring endpoint, vulnerability-scanning, patching, and other control coverage
- Prioritizing exposed assets by ownership, configuration, and vulnerability context
- Supporting audit, cyber-insurance, and zero-trust asset-accountability work
- Scoping incident response and identifying related assets or identities
- Government and defense cyber-defense inventory and vulnerability prioritization, subject to deployment constraints
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- rapid7.com Public source used for profile verification.
- docs.rapid7.com Public source used for profile verification.
- docs.rapid7.com Public source used for profile verification.
- SEC filing Public source used for profile verification.
- SEC filing Public source used for profile verification.
- rapid7.com Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Acquired asset
Why it may matter
Noetic Cyber may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify technical claims
- Verify regulatory/export-control issues
Main investor questions
- Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
- What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Noetic Cyber's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.