Fundraising Fox

Red Canary

Acquired

Sterling, US · Delaware corporation · 8 known investors

Atomic Red Team is an open source, community-maintained library of small security tests mapped to the MITRE ATT&CK framework, letting security teams validate their ability to detect threats across Windows, macOS, Linux, and cloud environments. It is developed by Red Canary and includes tools such as the PowerShell-based Invoke-Atomic execution framework and Atomic Test Harnesses.

Also known as Red Canary, Inc.

Founders & leadership

BBBrian Beyer
Brian BeyerCEO

Board

FM
Frank MendicinoBoard director
ATAlan Taetle
Alan Taetlein𝕏Board Member2016–2025General Partner at Noro-Moseley Partners
WD
W Daniel HallBoard director

Investors · 8

Also in the syndicate · 1

Kyrus-Techlead

Reported raises · per SEC filings

Form D private placements

$139.8M disclosed across 6 of 7 rounds · 2015–2023

$7.4MraisedDec 2023 · 2 investors · Computers
Rule 506(b)
Officers, directors & promoters on the filing
  • Alan TaetleDirector
  • John RitchieExecutive Officer
  • Andrew CollinsDirector
  • Frank Mendicino, IIIDirector
  • Katherine BullardExecutive Officer
  • Chris ZookExecutive Officer
  • Dean HagerDirector
  • W. Daniel HallDirector
  • Matthew SpohnExecutive Officer
  • Colin MisteleDirector
  • Michael ViscusoDirector
  • Brian BeyerExecutive Officer, Director
Offering amount
$7.4M
Amount sold
$7.4M
First sale
Sep 2023
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$4.9MraisedDec 2021 · 2 investors · Computers
Rule 506(b)
Officers, directors & promoters on the filing
  • Alan TaetleDirector
  • Andrew CollinsDirector
  • Colin MisteleDirector
  • Matthew SpohnExecutive Officer
  • Dean HagerDirector
  • William DedrickDirector
  • Chris ZookExecutive Officer
  • W. Daniel HallDirector
  • Brian BeyerExecutive Officer, Director
  • John TurnerExecutive Officer
  • Frank Mendicino, IIIDirector
Offering amount
$4.9M
Amount sold
$4.9M
First sale
May 2021
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$81.1MraisedFeb 2021 · 19 investors · Computers
Rule 506(b)
Officers, directors & promoters on the filing
  • Alan TaetleDirector
  • Frank Mendicino, IIIDirector
  • W. Daniel HallDirector
  • Colin MisteleDirector
  • Brian BeyerExecutive Officer, Director
  • Nelson BlitzExecutive Officer
  • William DedrickDirector
  • Andrew CollinsDirector
  • Chris ZookExecutive Officer
Offering amount
$86M
Amount sold
$81.1M
First sale
Feb 2021
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$33.8MraisedApr 2019 · 12 investors · Computers
Rule 506(b)
Officers, directors & promoters on the filing
  • Chris ZookExecutive Officer
  • W. Daniel HallDirector
  • Brian BeyerExecutive Officer, Director
  • Andrew CollinsDirector
  • William DedrickDirector
  • Nelson BlitzExecutive Officer
  • Alan TaetleDirector
  • Frank Mendicino, IIIDirector
Offering amount
$33.8M
Amount sold
$33.8M
First sale
Apr 2019
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$6.3MraisedMay 2018 · 7 investors · Computers
Rule 506(b)
Officers, directors & promoters on the filing
  • Brian BeyerExecutive Officer
  • Frank Mendicino, IIIDirector
  • Chris ZookExecutive Officer
  • Daniel W HallDirector
  • Alan TaetleDirector
Offering amount
$6.3M
Amount sold
$6.3M
Minimum investment
$80K
First sale
Apr 2018
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$6.2MraisedAug 2016 · 8 investors · Computers
Rule 506(b)
Officers, directors & promoters on the filing
  • W Daniel HallDirector
  • Frank MendicinoDirector
  • Alan TaetleDirector
  • Brian BeyerExecutive Officer
Offering amount
$6.2M
Amount sold
$6.2M
Minimum investment
$50K
First sale
Jul 2016
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗

Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.

Company profile

researched Aug 2026

Red Canary is a security operations company that delivers managed detection and response (MDR) through a combination of purpose-built software, threat intelligence and human security analysts. Its Security Operations Platform ingests high-volume telemetry from endpoints and extends to network alerts, identity and cloud workloads, applying behavioral and binary analysis, anomaly analytics and third-party threat intelligence before a team of security engineers reviews the results. The stated aim is to surface confirmed threats with low false-positive rates and to support automated remediation workflows, so customers can either outsource threat detection and response entirely or augment an in-house team.

The company originated inside the Kyrus-Tech incubator in Sterling, Virginia, and built its early service around Carbon Black endpoint sensors, bundling the sensor license with its subscription. Over time it expanded its platform, launching Red Canary Alert Center and Red Canary Cloud Workload Protection in 2020. Red Canary also develops Atomic Red Team, an open source library of small security tests mapped to the MITRE ATT&CK framework.

In May 2025 Zscaler announced a definitive agreement to acquire Red Canary, positioning its detection and response capabilities alongside Zscaler's Zero Trust Exchange platform and Avalor-derived data fabric to build an agentic, AI-driven security operations center.

Founding story

Red Canary was founded in 2014 by a team of security and data processing experts, including co-founder and CEO Brian Beyer along with Keith McCammon, Jason Garman and Chris Rothe. The team came out of the Sterling, Virginia-based Kyrus-Tech incubator in February 2014, becoming the second company incubated there after Carbon Black. While working at Kyrus with Carbon Black's endpoint sensor technology, the founders identified an opportunity to deliver real-time threat detection built on that telemetry.

Business model

Red Canary sells SaaS-based security operations and managed detection and response as a subscription service, pairing its detection technology with a remotely delivered, around-the-clock security operations team. Early in its history the service was priced on an endpoint-per-year basis, ranging from roughly $80 to $120 per endpoint per year with volume discounts, and included the software license for the Carbon Black endpoint sensor as part of an all-in-one package.

Recurring subscription revenue from managed detection and response and security operations services; historically priced per endpoint per year with discounts scaling to the number of endpoints deployed.

Traction

Revenue grew 270 percent over the two years preceding the 2021 Series C, headcount reached 249, and customers from channel partners doubled. By 2021 the company defended hundreds of organizations worldwide, and by 2025 it was described as having an extensive customer base built over more than 10 years in security operations.

Latest developments

On May 27, 2025, Zscaler announced a definitive agreement to acquire Red Canary, combining Red Canary's threat detection and response capabilities across endpoints, identity, network and cloud workloads with Zscaler's Zero Trust Exchange platform, data fabric technology acquired from Avalor, and ThreatLabz intelligence to build an agentic AI security operations center. The transaction was expected to close in August 2025, subject to regulatory approvals and customary closing conditions.

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

Red Canary is described as a pioneer and recognized leader in the managed detection and response market, named a Leader in the Forrester Wave for Managed Detection and Response for three consecutive years and featured in the Gartner Market Guide for MDR for seven consecutive years. The broader MDR market was projected to reach $1.9 billion by 2024. Other funded players in the managed security space during the same period included ReliaQuest and Arctic Wolf.

Red Canary positions its multi-dimensional analysis approach - combining behavioral and binary analysis, anomaly analytics and threat intelligence, followed by expert human review - against competing services that rely on fewer detection avenues, with the aim of eliminating false positives so that every delivered detection is actionable. Partners have cited its willingness to share intelligence and detection methodology, and its research into specific attacker techniques and threat actors, as differentiators.

Technology

The platform processes 300-400 terabytes of telemetry per day, applying behavioral and binary analysis, anomaly detection in analytics, and threat intelligence enrichment from partners such as Threat Recon and Farsight Security, with human security engineers acting as a final validation layer. Coverage spans endpoints, identity, network and cloud workloads, and the company describes the use of agentic AI, behavioral analytics and global threat intelligence together with automated remediation workflows. Red Canary reports 99.6% detection accuracy, investigations up to 10 times faster, and a 75% reduction in realized risk per endpoint. It also maintains Atomic Red Team, an open source library of security tests mapped to MITRE ATT&CK.

Go-to-market

The company sells directly and through channel partners and managed security solution providers, and reported doubling growth in customers from channel partners in the year before its Series C. Proceeds from the 2021 round were earmarked in part for expanding sales and marketing teams to accelerate customer growth and reach.

Organizations of all sizes seeking to outsource or augment threat detection and response, ranging from global Fortune 500 companies to roughly 100-employee businesses. Customers span multiple industries and geographies, including pharmaceutical and defense and intelligence contracting, and the company also serves channel partners and security solution providers.

Geography

Headquartered in Denver, Colorado, with roots in Sterling, Virginia, where its Kyrus-Tech incubator was based. The workforce has been distributed since early days, with about half in Denver and the remainder remote. Customers are located in the United States and in markets outside it.

History

After spinning out of Kyrus-Tech in February 2014, Red Canary raised $2.5 million in seed funding led by Kyrus and announced partnerships with Carbon Black, Threat Recon and Farsight Security. The company grew from a team of roughly 10-25 people, split between Denver and remote locations, to 249 employees by the time of its 2021 Series C, a 49 percent increase over the prior year. Summit Partners first partnered with the company in 2019 and led an $81 million follow-on Series C in 2021, bringing total outside funding to more than $125 million. In May 2025, Zscaler signed a definitive agreement to acquire the company, with closing expected in August 2025.

Risks & controversies

Zscaler's announcement identified execution risks associated with the transaction, including the ability to integrate Red Canary's technology into Zscaler's cloud platform and to retain key Red Canary employees after closing, and noted the acquisition remained subject to regulatory approvals and customary closing conditions.

Compiled by commissioned research from 4 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Data processed per dayJan 2021300-400 terabytes of data per day
Employee growth year over yearJan 202149%
EmployeesJan 2021249 people
Investigation speed improvementMay 2025customers investigate threats up to 10 times faster
Reduction in realized risk per endpointJan 202175%
Revenue growth over prior two yearsJan 2021270%
Threat detection accuracyMay 202599.6%
Total outside funding raised since foundingJan 2021$125M

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Founder mafia

2 people who came through Red Canary went on to found or lead other companies.

Competitors · 10

by search overlap
Palo Alto Networks1315 shared keywordsPalo Alto Networks provides cybersecurity platforms and services to protect organizations' digital infrastructure across cloud, network, and security operations. The company serves enterprise organizations, governments, financial institutions, utilities, and healthcare providers globally.
Crowdstrike1272 shared keywordsCrowdStrike provides an AI-native cybersecurity platform that unifies endpoint, identity, cloud, SaaS, and AI protection to detect and stop breaches for enterprise organizations. It combines automated response with human-led security operations including managed detection and response, threat hunting, and security services.
Sentinel One1225 shared keywordsSentinelOne provides an AI-powered cybersecurity platform for enterprises that integrates endpoint protection, threat detection, and incident response capabilities. The company serves large enterprises, including many Fortune 500 organizations, to protect against cyber threats at scale.
Netezza1161 shared keywordsIBM is a global technology company whose business spans enterprise software (including Red Hat, HashiCorp, and Confluent), IT infrastructure such as mainframes, servers, and storage, and IT consulting services. The company is also investing heavily in quantum computing and AI-based enterprise offerings, including its Lightwell open-source software security clearinghouse and the Anderon quantum wafer foundry.
Check Point Software958 shared keywordsCheck Point Software Technologies is a cybersecurity company providing security products and solutions. This page is its investor relations section, containing annual reports, SEC filings, financial results, and corporate governance information.
Trend Micro804 shared keywordsTrendAI (Trend Micro) provides enterprise cybersecurity through its TrendAI Vision One platform, which unifies endpoint, network, cloud, and identity security with XDR visibility, threat intelligence, and AI-focused threat protection. It serves enterprise customers across 185 countries, including hybrid cloud, virtualized data center, and modern SOC environments.
Splunk743 shared keywordsSplunk offers a unified platform for security and observability that ingests and analyzes large-scale data across hybrid cloud environments. Its tools support security operations centers with analytics and automated response, and help teams monitor application and infrastructure performance.
Huntress677 shared keywordsHuntress provides enterprise-grade cybersecurity solutions designed for businesses of all sizes, focusing on threat detection and response to protect organizations against hackers.
ArrowPoint669 shared keywordsCisco provides networking, data center, and security technology for enterprises, including infrastructure to run traditional and AI workloads and tools to keep organizations running against cyberattacks and outages. Its platform connects networking devices and monitors security events across corporate networks.
Cynet609 shared keywordsCynet provides enterprise-grade cybersecurity protection designed to be accessible and affordable for mid-market and smaller organizations. The platform delivers threat detection, protection, and remediation capabilities to help companies defend against cyber threats without requiring large security teams.

Companies competing with Red Canary for the same Google search keywords, organic and paid, via search-intersection analysis.

Timeline · 5

launches, deals, and filings
May 2025
Zscaler signs definitive agreement to acquire Red Canary

Zscaler, Inc. (NASDAQ: ZS) announced a definitive agreement to acquire Red Canary to extend its Zero Trust Exchange platform and Avalor data fabric into managed detection and response and threat intelligence, targeting an AI-powered security operations center. The transaction was expected to close in August 2025, subject to customary closing conditions including regulatory approvals.

source ↗

Jan 2025
Recognized as a Leader in the Forrester Wave for Managed Detection and Response

Red Canary was named a Leader in the Forrester Wave: Managed Detection and Response for the third consecutive year and was featured in the Gartner Market Guide for MDR for the seventh year in a row.

source ↗

Jan 2020
Launch of Red Canary Alert Center and Red Canary Cloud Workload Protection

Red Canary introduced Alert Center and Cloud Workload Protection to extend its Security Operations Platform across endpoints, network alerts and cloud workloads.

source ↗

Jan 2015
Partnerships with Carbon Black, Threat Recon and Farsight Security

Alongside its seed funding announcement, Red Canary announced three partnerships: Carbon Black (endpoint sensor software, whose license is bundled with Red Canary's service), Threat Recon and Farsight Security for threat intelligence enrichment.

source ↗

Feb 2014
Red Canary spun out of the Kyrus-Tech incubator

Red Canary emerged from the Sterling, Virginia-based Kyrus-Tech incubator in February 2014 as the second company incubated there, following Carbon Black.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

Legal entities · 1

corporate structure
Red CanaryDelaware

In the news

Research sources · 4

primary sources listed

4 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Red Canary do?
Managed detection and response provider combining SaaS security software with a 24/7 team of security analysts.
Who founded Red Canary?
Red Canary was founded by Brian Beyer.
Who are Red Canary's investors?
Red Canary's investors include Access Venture Partners, Gray Ventures, Noro-Moseley Partners, Savano Capital Partners, Service Provider Capital, Summit Partners, Access Ventures.
How much funding has Red Canary raised?
Red Canary has disclosed $139.8M raised across 6 of its 7 known rounds.
Where is Red Canary headquartered?
Red Canary is headquartered in Sterling, US.