Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Malanta Emerges From Stealth With $10 Million for Its Pre-Attack Security Platform

By TheFinanceBase Team7 min read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Tel Aviv-based cybersecurity startup Malanta announced on November 5, 2025, that it had emerged from stealth with a $10 million seed round led by Cardumen Capital, with participation from The Group Ventures. The company is pitching a platform that looks for signs of attacker preparation—such as lookalike domains and staged infrastructure—before the activity becomes a conventional compromise alert. That is a useful security problem to target, but the funding announcement and product claims do not yet demonstrate that Malanta prevents breaches or outperforms established tools.

What Malanta announced

Malanta said the $10 million seed round was led by Cardumen Capital, with The Group Ventures participating. The company also described an earlier pre-seed investment that included CyberArk founder and executive chairman Udi Mokady and other angel investors. Public materials do not establish that those earlier investors participated in the newly announced seed round, so the two stages should not be conflated. Business Wire and SecurityWeek reported the launch and funding.

Founded in 2024 and headquartered in Tel Aviv, Malanta says it is making its platform available to enterprises and design partners. It plans to use the funding to expand engineering and go-to-market efforts, add types of Indicators of Pre-Attack (IoPAs) and data sources, deepen integrations with existing security controls, and identify attack infrastructure earlier.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “pre-attack prevention” means

Malanta’s thesis is that defenders often encounter an attack only after an attacker has sent phishing messages, delivered malware, exploited an exposed asset, or left evidence that triggers a detection. Before that point, an attacker may already have registered a deceptive domain, prepared a phishing kit, customized tooling, or staged command-and-control (C2) infrastructure.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The platform is meant to find those internet-visible signals and connect them to an organization’s digital footprint. Malanta calls the signals IoPAs, contrasting them with Indicators of Compromise (IoCs), which generally indicate that malicious activity or an intrusion has occurred. The company presents this as a chance to investigate and disrupt preparation before it becomes an incident. “IoPA,” however, is Malanta’s product terminology, not a universally established indicator category comparable to IoCs or tactics, techniques, and procedures.

Concept What it is intended to signal Typical security use
Indicator of Compromise (IoC) Evidence associated with malicious activity or an intrusion Detect, investigate, contain, or respond to activity already underway
Indicator of Pre-Attack (IoPA) Signals that infrastructure or tools may be prepared for a future attack Investigate, prioritize, and potentially disrupt activity before compromise

A suspicious domain is not proof of an attack, and a prediction is not confirmed attribution. The value of an early-warning signal depends on the evidence linking it to a target, the quality of its confidence scoring, and whether a team can act before the infrastructure changes.

How the platform appears to work

Malanta’s public description suggests a workflow with several stages:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Map the organization’s footprint. A customer supplies domains and organization context so the platform can identify relevant internet-facing assets. The launch announcement says the map can be built within minutes of onboarding; that is a company claim, not an independently measured result.
  2. Collect external signals. The system monitors information about domains, servers, phishing infrastructure, adversarial tooling, and related assets.
  3. Correlate signals to the organization. It attempts to connect suspicious infrastructure to a company, brand, subsidiary, employee group, or exposed asset rather than presenting only a broad threat feed.
  4. Prioritize possible threats. Malanta describes “neural exposure mapping” and predictive adversary modeling to rank threats it considers relevant or imminent. Public materials do not disclose the model’s validation, false-positive rate, or comparative performance.
  5. Route findings into response. The company advertises dashboards, remediation guidance, feeds, APIs, and integrations. It also describes infrastructure disruption and takedown as part of the model.

Finding or reporting hostile infrastructure is not the same as taking it down. Removal may depend on a registrar, hosting provider, content platform, law-enforcement agency, or national cyber authority. Some infrastructure may not be removable quickly—or at all—so buyers should establish which actions Malanta performs directly and which it recommends or coordinates.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Where it fits in a security stack

Malanta describes integrations with SIEM, threat-intelligence platform (TIP), SOAR, EDR, and attack-surface-management (ASM) tools, as well as enterprise APIs and data lakes. It also advertises API access for threat hunting, data enrichment, and cyber research. That positioning makes it look complementary to existing detection and response systems, not a replacement for endpoint protection, SIEM, incident response, vulnerability management, or conventional threat intelligence.

The distinction from adjacent categories matters. External ASM is generally centered on discovering and monitoring an organization’s exposed assets. Digital-risk-protection and brand-monitoring services focus on impersonation and customer-facing abuse. Threat-intelligence platforms aggregate and operationalize intelligence, while managed takedown services focus on removing malicious domains, pages, or accounts. Malanta’s proposed differentiator is correlating potential attacker preparation to a specific organization early enough to support disruption. Buyers will need to test whether that correlation and workflow add value beyond tools they already own.

Before evaluation, ask which SIEM, SOAR, EDR, TIP, and ASM products have native integrations; whether data flows one way or supports actions; whether teams can trigger blocking or submit takedown requests; what evidence accompanies each IoPA; and whether data can be exported in formats such as STIX/TAXII. Also clarify how the platform models subsidiaries, brands, acquisitions, and third parties, what onboarding permissions it needs, and where customer data is processed and retained.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Founders, customers, and the evidence so far

Malanta identifies four founders: Kobi Ben Naim, co-founder and CEO; Guy Ben Arie, co-founder and head of engineering; Yossi Dantes, co-founder and chief product officer; and Tal Kandel, co-founder and chief business officer. The company says the founders previously worked together at CyberArk and collectively have more than 20 years of cybersecurity experience across defensive and offensive security, engineering, AI, and product development. These are company-reported biographies, available on its About page.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

The launch announcement says Malanta worked with the Israel National Cyber Directorate and that IoPA intelligence helped identify and dismantle adversary infrastructure targeting hundreds of Israeli companies across multiple sectors. This is a potentially meaningful deployment example, but the public account does not provide a full incident report, name all affected organizations, explain the attribution method, quantify prevented attacks, or isolate Malanta’s contribution. The quoted CERT official supports the value of information-sharing; it is not an independent audit of product efficacy.

The company says it is deployed with customers in financial services, software, technology, and government. Its website includes testimonials attributed to a global CISO, a CTI analyst at a travel-services company, and a CISO at Migdal Insurance. Most references lack detailed performance data or enough customer context to assess outcomes. Malanta’s claim that it is the “industry’s first” pre-attack prevention platform should likewise be treated as company positioning, not an independently established market conclusion.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What buyers should test—and where the risk lies

Early-warning products face a difficult balance: flagging infrastructure early enough to matter without flooding analysts with benign lookalikes. A lookalike domain may be parked or unrelated; cloud, CDN, or SaaS infrastructure may be shared by legitimate and malicious users. Incomplete asset inventories can also leave subsidiaries, regional domains, development environments, or acquired brands out of scope. If attackers rotate domains and hosting faster than an organization can respond, a dashboard alert alone may not change the outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Evaluation should distinguish a forecast from verified malicious activity and measure whether intelligence reaches operational controls. Ask for evidence and confidence behind each attribution, suppression and review workflows, alert precision after analyst review, time from infrastructure creation to alert, and the number of takedowns or other actions completed. Test the full path from detection through SIEM or SOAR to an actual mitigation, including what happens when a provider or registrar does not respond.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Malanta’s public pricing page advertises enterprise capabilities including automated IoPA discovery and clustering, exposure dashboards, remediation guidance, integrations, predictive adversary modeling, and API or data-lake access. It shows no enterprise dollar price and directs buyers to book a demo. The page also advertises a 30-day free trial, while the SaaS terms describe trial use as internal evaluation rather than production and include a provision allowing the trial to end after written termination notice. Those public statements do not establish an unconditional 30-day production trial; confirm the applicable terms in writing.

Before sharing asset inventories or brand details, review the data-processing agreement, data residency, retention and deletion policies, access controls, and breach-notification terms. Also establish whether Malanta submits takedowns itself, what customer authorization is required, and who is responsible for legal and operational decisions.

Bottom line

Malanta’s launch is a real funding and product announcement built around a plausible shift in timing: identify and act on attacker preparation rather than wait for evidence of compromise. Its external-signal correlation may be useful to organizations with broad digital footprints and mature CTI or security-operations teams. But public materials do not yet show measurable prevention rates, detection precision, independent efficacy testing, or superiority over established ASM, digital-risk, and threat-intelligence products. Treat it as a platform to evaluate against operational evidence—not as proof that a new label or funding round changes breach risk by itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.