Seculert
Seculert was an Israeli cloud-based cybersecurity company focused on detecting malware, network breaches, and advanced persistent threats.
Last updated August 26, 2026
History
Seculert was founded in Israel in 2010 by Aviv Raff, Dudi Matot, and Alex Milstein. The founders brought experience from fraud research, product marketing, and security-software operations. Their objective was to address malware and targeted attacks that could remain invisible to traditional defenses, especially when those defenses depended on known signatures or isolated endpoint observations. The company launched Seculert Echo in 2011 as its first offering. Its approach relied on cloud-based analysis and the examination of evidence generated by network activity. In 2012, Seculert announced $5.35 million in venture financing from YL Ventures and Norwest Venture Partners. That year also brought substantial attention to the company’s research. It publicized findings related to Ramnit’s theft of Facebook credentials, the ongoing Kelihos botnet, the Mahdi espionage campaign, Shamoon, and the Dexter point-of-sale malware. The company’s research activity helped establish its reputation as a specialist in malware discovery and threat intelligence. In October 2012, Seculert released Seculert Sense, a system for analyzing network traffic logs. The product was designed to use HTTP and HTTPS gateway records to detect suspicious communication patterns and identify indications of compromise. Seculert described its analytical engine as capable of working across very large volumes of data, looking for anomalies and malicious behavior that might not match an existing threat signature. At the RSA Conference in February 2013, the company unveiled a beta version of Seculert Swamp, an automated cloud malware-analysis sandbox. The platform was later described as an elastic environment capable of examining suspicious files across multiple platforms and simulated geographic locations. Its purpose was to produce behavioral classifications and profiles by observing what files did during execution. This capability complemented traffic analysis by allowing Seculert to connect network indicators with file behavior. Seculert announced an additional $10 million Series B financing round in July 2013, with Sequoia Capital identified as an investor. The same period brought external recognition, including selection as a 2013 Red Herring Europe finalist. In 2012, The New York Times identified Seculert among promising new security start-ups, and the company was a finalist for SC Magazine’s Rookie Security Company of the Year award. The company continued to publish threat research in 2013 and 2014. Its work on the Red October operation identified a further infection method involving malicious email links and Java exploitation. In January 2014, Seculert reported an Xtreme RAT campaign that used spear-phishing emails against Israeli organizations. It also reported on the Dyre Wolf campaign, a banking-trojan operation associated with the theft of more than $1 million from corporate accounts and the circumvention of two-factor authentication. On January 31, 2017, Radware acquired Seculert. The transaction integrated Seculert’s technology and expertise into Radware, a larger provider of application and network security products. After the acquisition, Seculert was no longer an independent operating company. Public information about a continuing standalone Seculert product brand is limited, so its post-acquisition brand status is best treated as defunct or absorbed.
- 2017Acquired by Radware
Radware acquired Seculert on January 31, ending its independent corporate operation.
- 2013Seculert Swamp beta unveiled
Seculert presented the beta version of its cloud malware-analysis sandbox at the RSA Conference.
- 2013Series B financing announced
Seculert announced an additional $10 million Series B investment from Sequoia Capital.
- 2012First reported venture financing
Seculert announced $5.35 million in funding from YL Ventures and Norwest Venture Partners.
- 2012Seculert Sense released
The company released its traffic-log analysis product in October.
- 2011Seculert Echo launched
Seculert introduced its first offering, Seculert Echo.
- 2010Seculert founded
Aviv Raff, Dudi Matot, and Alex Milstein founded the Israeli cybersecurity company.
Products and positioning
Seculert positioned itself as a cloud-based security analytics company specializing in the discovery of previously undetected malware, targeted attacks, and advanced persistent threats through network telemetry, automated malware analysis, and threat research.
Seculert EchoCloud-based breach detection2011
Seculert Echo was the company’s first commercial offering, launched in 2011. It represented Seculert’s initial cloud-based approach to identifying hidden malware and network compromise, using centralized analysis rather than relying solely on locally installed security controls.
Seculert SenseTraffic-log analysis2012
Released in October 2012, Seculert Sense analyzed HTTP and HTTPS gateway traffic logs. Its purpose was to find anomalous communication and malicious patterns that could indicate malware activity or a targeted attack, including activity not previously represented in conventional threat signatures.
Seculert SwampMalware-analysis sandbox2013
Seculert Swamp was introduced as a beta cloud-based sandbox at the February 2013 RSA Conference. It was designed to execute and analyze suspicious files automatically, helping researchers classify malware through observed behavior across different environments.
Seculert Traffic Log AnalysisNetwork security analytics
The traffic-log analysis capability used gateway records and large-scale cloud processing to identify suspicious destinations, communication patterns, anomalies, and evidence of compromise. It was intended to expose targeted attacks and unknown malware through behavioral indicators.
Seculert Elastic SandboxAutomated malware analysis
The Elastic Sandbox was described as an automated analysis environment able to examine suspicious files across multiple platforms and simulate different geographic contexts. It generated behavioral profiles using large malware datasets and information from a crowdsourced threat repository.
Flagship businesses
- Seculert Echo
- Seculert Sense
- Seculert Swamp
- Seculert Traffic Log Analysis
- Seculert Elastic Sandbox
Brand decisions
- 2017Radware acquisitionM&A
Seculert operated as a specialist provider of cloud-based breach detection and malware analytics, while Radware maintained a broader application and network security portfolio.
What changed. Radware acquired Seculert on January 31, 2017.
Aftermath. Seculert ceased to operate as an independent company, and its technology and expertise were integrated into Radware.
Leadership
| Name | Title | Tenure |
|---|---|---|
| Alex Milstein | Co-founder; former Finjan Software vice president of operationsformer | 2010– |
| Aviv Raff | Co-founder; former RSA FraudAction Research Lab managerformer | 2010– |
| Dudi Matot | Co-founder; former SanDisk product marketing managerformer | 2010– |
Recent events
- 2017Radware acquires Seculert
Radware acquired Seculert on January 31, 2017, ending Seculert’s independent corporate existence.
M&A - 2014Seculert reports Xtreme RAT campaign targeting Israeli organizations
Seculert’s research lab described a targeted spear-phishing campaign using Xtreme RAT against Israeli organizations, including systems associated with the Israeli Civil Administration.
Other - 2013Seculert identifies an additional Red October attack vector
After the disclosure of the Red October espionage operation, Seculert identified a related attack path involving a malicious email link, a specially crafted PHP page, and exploitation of a Java vulnerability.
Other - 2012Seculert reports Ramnit theft of Facebook credentials
Seculert reported that the Ramnit malware had targeted Facebook accounts and stolen more than 45,000 login credentials, with many victims in the United Kingdom and France.
Other - 2012Seculert identifies continuing Kelihos botnet activity
The company reported that the Kelihos botnet remained active and was spreading through a Facebook-themed worm.
Other - 2012Seculert and Kaspersky Lab uncover the Mahdi campaign
Seculert and Kaspersky Lab described a cyber-espionage operation known as Mahdi that targeted Iran and other Middle Eastern countries.
Other - 2012Seculert participates in disclosure of Shamoon malware
Seculert, Kaspersky Lab, and Symantec reported on Shamoon, malware associated with attacks against Qatar’s RasGas and Saudi Aramco.
Other - 2012Seculert identifies Dexter point-of-sale malware
Seculert reported Dexter, malware designed to steal payment-card information from point-of-sale systems used by retailers, hotels, and other businesses.
Other
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/seculert · Editorial policy · How profiles are compiled