Mandiant
Cybersecurity company specializing in incident response, threat intelligence, cyber investigations, and security consulting.
Last updated August 21, 2026
Overview
Mandiant is a United States cybersecurity company focused on helping organizations investigate, contain, and recover from sophisticated cyberattacks. Its work combines incident response, threat intelligence, digital forensics, security validation, managed defense, and strategic consulting. The company serves major corporations, governments, and other institutions that require specialized assistance during or after security incidents. Kevin Mandia, a former United States Air Force officer, founded the business in 2004 as Red Cliff Consulting. It adopted the Mandiant name in 2006. In its early years, the company concentrated on business-to-business incident response and broader security consulting, while also developing tools and methods for incident management. Funding from Kleiner Perkins Caufield & Byers and One Equity Partners in 2011 supported staff expansion and growth in its enterprise activities. Mandiant became particularly influential in threat intelligence through its investigations of advanced persistent threats and its development of OpenIOC, an extensible format for describing technical indicators of compromise. In February 2013, the company published a widely cited report attributing a long-running cyber-espionage campaign against organizations in the United States and other English-speaking countries to a unit of the People's Liberation Army. Mandiant called the group APT1 and associated it with PLA Unit 61398. The report helped make commercial threat intelligence and public attribution central parts of the cybersecurity industry. FireEye acquired Mandiant in December 2013 for approximately $1 billion. Under FireEye, Mandiant continued its consulting and incident-response activities while becoming closely associated with investigations of high-impact intrusions. In October 2020, the business announced Mandiant Advantage, a subscription software platform intended to combine Mandiant threat intelligence with information from incident-response engagements and help security teams automate and improve their response processes. Mandiant investigated the 2020 SolarWinds supply-chain compromise and assisted with the response to the 2021 ransomware attack affecting Colonial Pipeline. In 2021, FireEye sold its product business, name, and employees to Symphony Technology Group for approximately $1.2 billion; Mandiant became an independent company again in that transaction. It subsequently expanded its capabilities through the acquisition of Intrigue, a company focused on attack-surface management. Google announced in March 2022 that it would acquire Mandiant for approximately $5.4 billion. The transaction received regulatory review, including scrutiny by the United States Department of Justice Antitrust Division, and closed on September 12, 2022. Mandiant was integrated into Google Cloud but retained its brand and continued operating as a specialized cybersecurity business. Its later work has included research into influence operations and assistance with investigations of the 2024 Snowflake-related data-theft campaign. Mandiant also operates Flare-On, an annual global reverse-engineering and malware-analysis challenge.
History
Mandiant began in 2004 when Kevin Mandia founded Red Cliff Consulting. Mandia's background as a United States Air Force officer informed the firm's emphasis on disciplined investigation, forensic analysis, and response to sophisticated intrusions. The company adopted the Mandiant name in 2006 and developed a business serving large organizations, governments, and Fortune 100 companies. Its early offering combined emergency incident response with general security consulting and incident-management products. In 2011, investment from Kleiner Perkins Caufield & Byers and One Equity Partners supported expansion of its staff and business-to-business operations. Mandiant also developed OpenIOC, an extensible XML-based format for representing indicators of compromise and sharing technical descriptions of malicious activity. The company's public profile grew sharply in February 2013, when it published a report on a cyber-espionage group it named APT1. Mandiant said the activity had affected at least 141 organizations in the United States and other English-speaking countries and connected the campaign to PLA Unit 61398 in Shanghai. The report was influential because it publicly linked technical evidence from intrusions with an alleged state-sponsored actor, helping establish commercial threat intelligence as a major cybersecurity discipline. FireEye acquired Mandiant in December 2013 for about $1 billion. Mandiant continued to operate as the incident-response and investigation center of expertise within the enlarged cybersecurity company. Its investigators subsequently worked on several prominent incidents, including the SolarWinds supply-chain compromise disclosed in 2020. In October 2020, the company introduced Mandiant Advantage, a subscription-based software platform designed to combine Mandiant's intelligence with information from incident-response work and give security teams more automated support. FireEye announced in 2021 that it would sell its product business, brand, and employees to Symphony Technology Group for approximately $1.2 billion. Mandiant was separated from that transaction and operated independently. During this period it continued responding to major incidents, including the ransomware attack affecting Colonial Pipeline, and acquired Intrigue in August 2021 to strengthen attack-surface management. Google announced its proposed acquisition of Mandiant in March 2022 for approximately $5.4 billion. The transaction underwent regulatory scrutiny, including a review by the United States Department of Justice Antitrust Division. The DOJ approved the deal, and the Australian Competition & Consumer Commission announced that it would not oppose the transaction. The acquisition closed on September 12, 2022, and Mandiant was incorporated into Google Cloud while retaining its name and identity as a cybersecurity business. After the acquisition, Mandiant continued publishing threat research and supporting investigations. Its researchers reported on a pro-China influence campaign aimed at American voters before the 2022 midterm elections. In 2023, the company announced integrations for MISP and Splunk SIEM and SOAR environments. In 2024, it assisted with investigations into a major Snowflake-related data-theft and extortion campaign. Separately, Mandiant has organized Flare-On, an annual reverse-engineering challenge held since 2014 for participants around the world.
- 2024Snowflake-related breach investigations
Mandiant assisted investigations into a major data-theft and extortion campaign involving Snowflake customers.
- 2023Security-platform integrations announced
Mandiant announced integrations with MISP and Splunk SIEM and SOAR environments.
- 2022Google announces acquisition
Google announced a proposed $5.4 billion acquisition of Mandiant.
- 2022Integrated into Google Cloud
The Google acquisition closed on September 12, 2022, and Mandiant began integration into Google Cloud.
- 2021Separation from FireEye
Mandiant became independent after FireEye sold its product business, name, and employees to Symphony Technology Group.
- 2021Intrigue acquired
Mandiant acquired Intrigue to expand attack-surface management capabilities.
- 2020Mandiant Advantage announced
The company introduced a subscription platform combining threat intelligence and incident-response information.
- 2014Flare-On begins
Mandiant began its annual Flare-On reverse-engineering and cybersecurity challenge.
- 2013APT1 report published
Mandiant published research attributing a major cyber-espionage campaign to PLA Unit 61398.
- 2013Acquired by FireEye
FireEye acquired Mandiant for approximately $1 billion.
- 2011Growth financing supports expansion
Kleiner Perkins Caufield & Byers and One Equity Partners provided funding for staffing and business expansion.
- 2006Company adopts the Mandiant name
Red Cliff Consulting was rebranded as Mandiant.
- 2004Red Cliff Consulting founded
Kevin Mandia founded the company that would become Mandiant as Red Cliff Consulting.
Products and positioning
A high-end cybersecurity partner for advanced threat investigations, incident response, threat intelligence, and resilience programs serving complex enterprises and government organizations.
Mandiant Incident ResponseIncident response and digital forensics
Mandiant's incident-response practice helps organizations investigate suspected compromises, determine the scope and mechanics of an attack, contain adversary activity, preserve evidence, and recover operations. It is designed for urgent breaches as well as preparedness and response-retainer arrangements.
Mandiant AdvantageCybersecurity software platform2020
Mandiant Advantage was introduced as a subscription-based software platform that combines Mandiant threat intelligence with information gathered through incident-response engagements. Its purpose is to help security teams prioritize threats, improve investigation workflows, and automate elements of response.
Mandiant Threat IntelligenceThreat intelligence
This offering provides intelligence on threat actors, campaigns, malware, vulnerabilities, and indicators of compromise. It draws on Mandiant's investigations and research to support detection, attribution, strategic risk assessment, and security operations.
Mandiant Security ValidationSecurity validation
Security validation services assess whether an organization's defensive controls can detect and respond to realistic attack behaviors. The offering is intended to identify gaps between documented security capabilities and operational performance.
OpenIOCOpen cybersecurity standard
OpenIOC is an extensible XML schema created by Mandiant for describing technical characteristics that can indicate compromise. It supports structured communication of forensic evidence, malicious activity, and attacker methods.
Flare-OnCybersecurity competition2014
Flare-On is an annual reverse-engineering challenge organized by Mandiant. It attracts participants internationally and focuses on malware analysis, reverse engineering, and related technical problem-solving skills.
Flagship businesses
- Mandiant Incident Response
- Mandiant Advantage
- Mandiant Threat Intelligence
- Mandiant Security Validation
- Flare-On
Marketing campaigns
- 2014Flare-On
Global
Mandiant launched an annual autumn reverse-engineering challenge for cybersecurity practitioners and researchers worldwide.
Outcome. The challenge became a recurring global technical event associated with Mandiant's research and engineering community.
Brand decisions
- 2023Integrate MISP and Splunk environmentsProduct launch
Customers increasingly required threat intelligence and response tools to interoperate with existing intelligence-sharing and security-operations platforms.
What changed. Mandiant announced integrations for MISP, Splunk SIEM, and Splunk SOAR.
Aftermath. The integrations were intended to improve interoperability between Mandiant capabilities and customers' existing security workflows.
- 2022Join Google CloudM&A
Google sought to expand its cloud cybersecurity capabilities, while Mandiant offered established incident-response expertise, threat intelligence, and investigation services.
What changed. Google announced and completed the acquisition of Mandiant, integrating the company into Google Cloud while preserving the Mandiant brand.
Aftermath. Mandiant became a Google Cloud subsidiary after regulatory review and the transaction's September 12 closing.
Acquisition value. $5.4 billion (Announced March 2022; completed September 12, 2022)
- 2021Separate from FireEyeM&A
FireEye agreed to sell its product business, name, and employees to Symphony Technology Group.
What changed. Mandiant was separated from the FireEye transaction and continued as an independent company.
Aftermath. Mandiant retained its consulting, investigation, and threat-intelligence identity while FireEye's former product operations moved to Symphony Technology Group.
Transaction value for FireEye product business, name, and employees. $1.2 billion (June 2021)
- 2020Launch Mandiant AdvantageProduct launch
Security teams increasingly sought subscription software that could connect threat intelligence with operational incident-response workflows.
What changed. Mandiant announced Mandiant Advantage as a subscription-based SaaS platform combining its intelligence and incident-response data.
Aftermath. The launch broadened Mandiant's proposition beyond consulting toward recurring software-supported security operations.
- 2013Accept FireEye acquisitionM&A
Mandiant had established a strong position in incident response and threat intelligence, while FireEye was expanding its cybersecurity platform and services portfolio.
What changed. FireEye acquired Mandiant in December 2013 for approximately $1 billion.
Aftermath. Mandiant continued its incident-response and investigation activities within FireEye.
Acquisition value. $1 billion (December 2013)
Leadership
| Name | Title | Tenure |
|---|---|---|
| Kevin Mandia | Founder and former Chief Executive Officerformer | 2004– |
Recent events
- 2024Mandiant assists investigation of Snowflake-related data theft
Mandiant assisted with investigations into a large data-theft and extortion campaign targeting customers of Snowflake, including several major businesses.
Other - 2023Mandiant announces integrations with MISP, Splunk SIEM, and SOAR
Mandiant announced integrations intended to connect its intelligence and security capabilities with MISP and Splunk security information, event management, and orchestration platforms.
Product launch - 2022Google announces acquisition of Mandiant
Google announced an agreement to acquire Mandiant for approximately $5.4 billion, with the business planned for integration into Google Cloud.
M&A - 2022U.S. antitrust review of Google-Mandiant transaction
The United States Department of Justice Antitrust Division reviewed the proposed acquisition for potential federal antitrust issues. Mandiant later disclosed that approval had been granted.
RegulationM&A - 2022Google completes Mandiant acquisition
The acquisition closed on September 12, 2022, after which Mandiant was integrated into Google Cloud while retaining its operating brand.
M&ALeadership change - 2022Mandiant researches pro-China influence campaign
Mandiant researchers identified a pro-China disinformation campaign that targeted American voters ahead of the 2022 midterm elections.
Other - 2021Mandiant assists Colonial Pipeline ransomware response
Mandiant was engaged to assist with the response to a ransomware incident affecting Colonial Pipeline, a major fuel-pipeline operator serving the United States East Coast.
Other - 2021Mandiant becomes independent after FireEye transaction
Symphony Technology Group acquired FireEye's product business, name, and employees for approximately $1.2 billion, leaving Mandiant as an independent company.
M&A - 2021Mandiant acquires Intrigue
Mandiant acquired Intrigue to expand its capabilities in attack-surface management and external exposure assessment.
M&A - 2020Mandiant Advantage subscription platform announced
Mandiant announced a subscription software platform intended to combine threat intelligence and incident-response data to support and automate security operations.
Product launch - 2020Mandiant investigates SolarWinds supply-chain compromise
Mandiant investigated the compromise of SolarWinds software and the resulting intrusion campaign affecting United States government infrastructure and other organizations.
Other - 2013Mandiant publishes APT1 cyber-espionage report
Mandiant released research attributing a broad cyber-espionage campaign against at least 141 organizations to a unit of the People's Liberation Army, which it identified as APT1 and linked to PLA Unit 61398.
Other - 2013FireEye acquires Mandiant
FireEye acquired Mandiant in a transaction valued at approximately $1 billion, bringing the incident-response firm into FireEye's cybersecurity business.
M&A
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/mandiant · Editorial policy · How profiles are compiled