Preempt Security

Cybersecurity Acquired asset Dual-Use Technology Founded 2014

Last updated: Jul 31, 2026

Preempt Security was an identity-security company founded in 2014 that combined identity, behavior, and risk analytics with Zero Trust and conditional-access controls. CrowdStrike acquired the company in 2020, so this record describes an acquired asset and its continuing strategic relevance rather than an independent startup opportunity.

Visit Website

Company Overview

Preempt built software for detecting and preventing identity-based attacks across enterprise environments. Its platform connected identity and directory data with authentication and network activity, then used behavioral and risk analytics to identify compromised accounts, unusual privilege use, suspicious service-account activity, and lateral-movement patterns. Its deployment model could range from sensorless analysis of Active Directory and other enterprise sources to passive or active sensors. The active model could enforce adaptive authentication, block risky access, or apply other conditional-access policies in real time. This made the product more than an alerting layer: it was intended to turn identity context into an access-control decision.

The commercial problem was especially acute in hybrid enterprises that still relied on Active Directory while adding cloud applications, remote access, and distributed workforces. Identity stores contain the privileges attackers need after initial compromise, but traditional endpoint, network, and identity systems often expose different pieces of the attack chain. Preempt positioned itself around that gap, selling to organizations that needed identity threat detection, insider-threat controls, privileged-account visibility, and a path toward Zero Trust without replacing every existing directory or endpoint system. Public company materials described enterprise deployments, but the available evidence does not justify treating reported customer or workforce counts as independently audited traction.

Preempt raised an $8 million Series A in 2016 and a $17.5 million Series B in 2018, according to contemporaneous financing announcements. CrowdStrike announced an approximately $96 million acquisition in September 2020 and later disclosed that it acquired 100% of Preempt Security on September 30, 2020. The transaction validated the strategic value of identity-aware access controls to a large endpoint-security platform, but it also ended Preempt's independent commercialization and makes current standalone revenue, employee count, product roadmap, and customer retention difficult to assess. CrowdStrike subsequently described Preempt's capabilities as part of its identity-protection and Zero Trust portfolio.

The defense and national-security case is credible but should be stated narrowly. Military, government, and critical-infrastructure networks face credential theft, privilege abuse, and lateral movement, and the underlying control problem is materially similar to that of large commercial networks. Preempt's identity analytics and conditional access could therefore support defensive cyber operations, especially in environments with legacy directory infrastructure. There is no reliable evidence in the reviewed sources of a specific military deployment, government contract, or classified use, so the record treats defense relevance as technology adjacency rather than proven defense traction. The principal diligence question is not whether the problem matters, but how much of the original capability remains differentiated inside CrowdStrike's broader platform and how well it operates across modern cloud identity, machine identity, and non-human access patterns.

Dual-Use Assessment

Military & Commercial Applications

Preempt's core capabilities have substantive commercial and defensive-security applicability: identity telemetry, Active Directory analysis, behavioral anomaly detection, adaptive authentication, and policy enforcement can protect enterprise, government, and critical-infrastructure networks from credential misuse and lateral movement. The defense case is technically credible because the same identity-control problems occur in mission and commercial environments, but no reviewed source establishes a named defense customer, government contract, or operational military deployment. Dual-use strength is therefore based on transferable defensive capability, not claimed defense traction.

Strategic Fit Assessment

Preempt is not an independent strategically relevant startup: CrowdStrike announced an approximately $96 million acquisition in September 2020 and disclosed completion on September 30, 2020. Historical financing announcements provide evidence of venture validation, including an $8 million 2016 Series A and a $17.5 million 2018 Series B, but those facts do not establish a current standalone security business. The acquisition is strategically informative because it shows a major endpoint vendor valuing identity context, conditional access, and Zero Trust enforcement. Any present-day diligence would need to focus on the capability's integration, differentiation, and contribution within CrowdStrike rather than on direct ownership of Preempt.

Strategic Value to U.S.-Israel Alliance

Preempt addressed a persistent security-control gap between endpoint detection and identity enforcement. Its technology could connect directory state, user and service-account behavior, authentication context, and access policy so that a suspicious identity event could trigger a prevention action instead of only an alert. That architecture is relevant to cyber defense because credential compromise and privilege abuse can enable quiet lateral movement through sensitive networks. The strategic value is strongest as an identity-security building block for a larger platform; it is weaker as an independent asset because the company has been acquired, its product branding and roadmap are controlled by CrowdStrike, and the market has continued to consolidate around Microsoft, Okta, CrowdStrike, and specialist identity-security vendors.

Key Technologies

  • Identity, behavior, and risk analytics
  • Active Directory and privileged-account security
  • Sensorless, passive-sensor, and active-sensor deployment
  • Risk-based conditional access and adaptive MFA
  • Real-time lateral-movement and attack-tool detection
  • Service-account and credential-compromise monitoring
  • Identity-aware policy enforcement and access blocking

Use Cases & Applications

  • Detecting compromised workforce identities across hybrid enterprise networks
  • Mapping privileged and exposed Active Directory accounts
  • Applying adaptive MFA or blocking access when identity risk changes
  • Detecting suspicious service-account logins and privilege use
  • Reducing lateral movement after endpoint or credential compromise
  • Supporting insider-threat investigations with behavioral context
  • Hardening government and critical-infrastructure identity stores
  • Providing identity telemetry to a broader endpoint or XDR platform

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Acquired asset

Why it may matter

Preempt Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Preempt Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.