All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Profero sells incident response as a subscription rather than a dormant retainer: its Rapid-IR platform scores a client's environment every day, and Profero says the platform's builders are the ones who respond to incidents. Profero commits a qualified responder to triaging within 20 minutes of a client declaring an incident. BleepingComputer detailed how Profero broke DarkBit ransomware encryption and recovered a client's files without payment. Rapid7 credits Profero's investigation with identifying a zero-day in SysAid's on-premise product. Seven named customer executives vouch for the firm on its own pages. No trial, documentation portal, or outside review of Rapid-IR appears in the reviewed pages, so a buyer assesses the platform in a conversation with Profero.
| Description | Incident response company whose Rapid-IR platform scores a client's environment every day across readiness, response, discovery, and intelligence. Profero says the practitioners who built the platform are the ones who respond to client incidents. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | Israel | [f2] |
| Product | What it does |
|---|---|
| Rapid-IR | Incident response platform spanning readiness scoring, response coordination, exposure discovery, and threat intelligence, driven by the Deep Breach Focus scoring model. |
| Pre-Emptive IR | Subscription offering that pairs daily environment scoring with the Profero incident response team and a contractual 20-minute response commitment. |
| GenAI Readiness Assessment | Two-day hands-on evaluation of a client's AI code assistants, agents, and chat interfaces, and of its ability to investigate an AI incident. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Rapid-IR assesses a client's endpoints, applications, and domains for exposures and watches for leaked credentials. Profero's responders bring containment and forensic collection to compromised endpoints and applications, and BleepingComputer documented them restoring a client's encrypted files. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Profero names its buyer, the CISO who already funds incident response, and the pain of a dormant retainer whose responder assembles context while the clock runs. CTech carries an account of the capacity shortage behind that pitch from Profero CEO Omri Segev Moyal, including his figure of 23 companies turned away during the December Pay2Key peak. The quantified version of the pain, 4.5 hours to close against a 300-hour figure the company calls the industry standard, comes from Profero's own casework with no published method, so a buyer cannot check either number against an outside source. [s5, s14, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Rapid-IR's pages document mechanisms rather than taglines, naming the Readiness, Response, Discovery, and Intelligence quadrants, the connectors that feed the Deep Breach Focus scoring model, and components such as Investigator, War Room, and WARP. Two outcomes carry third-party technical corroboration: SysAid's own bulletin and Rapid7's advisory record that Profero's investigation identified CVE-2023-47246, and BleepingComputer walked through the DarkBit key-recovery method. Profero also publishes an open-source HelloKitty unpacker that the Malpedia reference library indexes. [s2, s3, s16, s17, s11, s21, s22] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | CTech quoted Profero co-founder Omri Segev Moyal in February 2021 describing a worldwide shortage of incident responders that left companies waiting hours or days for someone to arrive. That scarcity is what makes a guaranteed response worth paying for in advance. Buyer-side demand for continuous readiness stays indirect in the public record, resting on Profero's own framing and testimonials rather than analyst category notes, budget-line evidence, or a mandate. [s14, s12, s5] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | CTech verifies that Moyal co-founded Profero with Barnhart-Magen in 2019, co-founded Minerva Labs, and served as CTO of ClearSky Cyber Security, a prior in-domain build plus a senior in-domain role. The research record runs across years, from an open-source unpacker for HelloKitty ransomware and the joint APT27 report with Security Joes to Ivanti EPMM forensics and the AI-induced-destruction writeup, and SANS lists Barnhart-Magen with a profile naming his Profero role. Profero's own page adds a Forbes 30 Under 30 listing for Moyal. [s13, s15, s20, s21, s24, s25, s4] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Executives at Aroundtown, Outbrain, Aidoc, Riskified, HoneyBook, BioCatch, and Guesty appear by name and title in testimonials on Profero's pages, most of them security or IT leaders, and one of them describes a two-year relationship. One engagement is corroborated outside the company: SysAid published that it engaged Profero to assist its investigation, and Rapid7 recorded that Profero's investigation identified the zero-day. No customer count, revenue figure, or analyst placement appears anywhere in the public record, which is what a 5 would need. [s1, s16, s17, s18, s6] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | CTech reported in February 2021 that Profero was bootstrapped and declining investor interest, and the cited sources disclose no round since. Profero has built the Rapid-IR platform and staffed a responder team with no outside capital disclosed anywhere in the cited record. None of those sources reports revenue, margin, or growth rate, so output per dollar cannot be computed from the public record. [s12, s2, s15] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Independent outlets categorize Profero on their own, with SecurityWeek and SANS each calling it an incident response company. Profero's own pages then spend their length teaching buyers the difference between a break-glass retainer and a subscription with continuous scoring, and the company labels the result the CISO Breach Platform rather than a category buyers already name. [s11, s18, s20, s5, s6] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Absorbing Profero's offer means running an on-call responder team, which is a staffing and process commitment rather than a release, and each client's accumulated environment context adds friction. Profero says live casework feeds the scoring model every client sees, and the cited record puts no measure on that loop. No regulation or contract in the cited record would hold a buyer who accepts losing that accumulated context. This analysis treats a staffed detection provider adding readiness scoring as the likeliest route to absorption rather than a move the record documents. [s5, s3, s6] |
Profero positions itself against the dormant incident response retainer. Its own pages argue that most retainers sit idle until a breach, so the responder arrives with no knowledge of the environment and spends an opening hour requesting credentials and mapping infrastructure. The buyer is the CISO who already funds incident response and wants the response to begin from a known state.
CTech quoted Profero co-founder Omri Segev Moyal in February 2021 saying Profero turned away 23 companies during the December Pay2Key ransomware peak while it handled 14 cases at once, and describing a worldwide scarcity of incident responders that left companies waiting hours or days for someone to arrive. Scarcity is what turns guaranteed availability into something a buyer will pay a retainer for.
Profero's homepage sets a 4.5-hour average time to close against a 300-hour figure it calls the industry standard. Both numbers are drawn from Profero's own casework rather than from an outside study. Neither carries a stated measurement method, so a buyer cannot check the comparison. The platform pages point instead at deadlines a slow start eats into, naming the GDPR 72-hour notification window and a four-day securities disclosure clock. [s5, s14, s1, s2]
Rapid-IR organizes the platform into four quadrants and names the parts of each. Readiness runs automated assessments across cloud, email, domains, and endpoints and sorts findings into Must-Do and Recommended. Response carries War Room for executive status, Investigator for endpoint forensics and isolation, an audited credential vault, and WARP for encrypted artifact exchange. Discovery watches external attack surface, look-alike domains, mail authentication, and leaked credentials, and Intelligence publishes threat-actor monitoring and advisories drawn from live casework.
Deep Breach Focus is the scoring model Profero puts at the center. The company describes it as its own model built from real incident casework, with no third-party models and client data staying inside the platform, fed by organizational context, connectors, and live engagements. Its published examples are specific enough to argue with, such as flagging an nginx configuration that drops the forwarded-for header because that blocks source attribution during forensics.
Third-party corroboration lands on the responders rather than on the platform. BleepingComputer described how Profero reduced DarkBit's key space, brute-forced VMDK headers, and recovered a client's data without a ransom payment. SysAid's own bulletin says it engaged Profero to assist an investigation that determined there was a zero-day in its on-premise product, and Rapid7's advisory records that Profero's investigation identified the vulnerability. Profero also ships an open-source HelloKitty unpacker that the Malpedia reference library indexes. No documentation portal, trial, or third-party evaluation of Rapid-IR itself appears in the public record, so a buyer assessing the platform has only Profero's description of it. [s2, s3, s11, s16, s17, s21, s22]
Profero positions against the retainer rather than against named vendors. Its partner page sets break-glass retainer against pre-emptive service line by line, contrasting a dormant contract and a two-to-24-hour response with daily scoring and a 20-minute commitment. The Rapid-IR page names security analytics, endpoint tooling, and ticketing as the wrong comparison for the product.
Profero's own pages describe that rival retainer as a dormant contract with a two-to-24-hour response, and the cited record carries no independent survey of what other providers offer. Whether managed detection vendors or cloud investigation platforms with their own responders will fold continuous readiness into the same subscription is a risk this analysis flags rather than one the cited record documents.
The visible edge is the single team. Profero states that the practitioners who built Rapid-IR are the ones who respond to client incidents, and the company treats that continuity as the reason its response commitment is credible. [s6, s1, s5, s2]
Profero's site shows a contact-led sales motion rather than a self-serve one. It offers a discovery call and an emergency line, with no trial and no published price, and its partner program runs five routes: cyber-insurance panels, law firms, resellers, referrals, and advisory seats. The insurance and legal routes fit an incident response firm, because panel placement and counsel direction are how breach work reaches a responder.
Named references are the strongest traction evidence, and they sit on Profero's own pages. Executives at Aroundtown, Outbrain, Aidoc, Riskified, HoneyBook, BioCatch, and Guesty appear by name and title, most of them security or IT leaders, and one of them describes a relationship spanning two years. One engagement carries documentation from outside the company, and it is the sturdiest reference in the set: SysAid published that it engaged Profero to assist an investigation that determined there was a zero-day in its on-premise product, Rapid7 recorded that Profero's investigation identified the vulnerability, and SecurityWeek reported the engagement.
No customer count, revenue figure, headcount, or analyst placement appears in the public record, and the 2021 CTech interview remains the single outside account of the company's growth. One reference overlaps with Profero's advisory board: Profero lists Guesty's president and chief operating officer as an advisor, and the Guesty testimonial comes from a different executive at the same company. That tie makes the Guesty endorsement weaker as independent evidence than the other six. [s6, s1, s16, s17, s18, s12, s4]
Both founders carry verifiable in-domain records. CTech reports that Omri Segev Moyal co-founded Profero with Guy Barnhart-Magen in 2019, that Moyal co-founded Minerva Labs, and that he served as CTO of ClearSky Cyber Security. Profero's own page adds a Forbes 30 Under 30 listing for Moyal and 25 years of security experience for Barnhart-Magen, and SANS lists Barnhart-Magen with a profile naming his Profero role.
The research record runs across years rather than resting on one event. Profero released a static unpacker for the HelloKitty ransomware packer as open source, published a joint APT27 investigation with Security Joes, documented forensic collection for the Ivanti EPMM zero-days, and named AI-induced destruction as a pattern after responding to cases where an AI coding assistant deleted a production codebase. The Malpedia reference library indexes the HelloKitty work.
Reporting on the APT27 investigation carried a threat-intelligence analyst who called the attribution realistically possible rather than settled and noted that pinpointing one group is often hard, and CTech notes that Moyal declines to disclose how much the company has grown. The public record names no executive hires beyond the two founders and two advisors, so the leadership a buyer can name is the two people who founded the firm. [s13, s15, s4, s20, s22, s24, s25, s21, s19, s12]
Profero publishes certifications and backs them with a live portal. SOC 2 Type II and ISO 27001 badges sit in the homepage footer and link to trust.profero.io, the portal the company launched alongside a May 2024 announcement of its SOC 2 Type II attestation and ISO 27001 certification. A probe of that subdomain in July 2026 returned a working portal.
The portal shows the control apparatus and requires a request for the reports. Its public view lists policy and control categories covering data protection, vendor risk, disaster recovery, encryption, access, and secure development, with the compliance section holding two documents behind a request-access step. Profero's partner page describes 17 independently audited control categories and offers panel-ready documentation on request.
Profero calls the 20-minute response contractual and defines it concretely, with the clock starting when a client declares an incident and a qualified practitioner actively triaging inside the window. What its pages do not state is a remedy for a miss, any exclusion, or a limit on how many clients can declare an incident at once, so those terms are settled in the negotiated contract rather than published. Neither the 4.5-hour close figure nor the claim that client data never leaves the platform appears in a third-party source in the reviewed record, so a buyer takes both on Profero's word. [s8, s23, s6, s10, s1, s3]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Mitiga | competes with | Sells cloud incident response as a platform with its own responders behind it, the closest match to Profero's argument that one team both builds the platform and responds, and the same claim that readiness work before the incident shortens the response. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Arctic Wolf | competes with | Operates security monitoring and response as a staffed service with its own platform, reaching the buyer who would otherwise fund an incident response retainer. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| CrowdStrike | competes with | Sells incident response and readiness services alongside its endpoint platform, so a buyer already licensing the platform can source breach response from the same vendor. | |
| Sygnia | competes with | Israeli incident response and consulting firm selling retainers and breach response to the same buyer, competing on responder reputation rather than on a subscription platform. |
Add analyzed competitors to compare them side by side with Profero.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Profero sells the judgment of its own responders, and Rapid-IR is how that judgment reaches a client. A rival would have to recruit and retain responders willing to answer at any hour. The connectors and the readiness scoring are engineering work a funded team can reproduce. Deep Breach Focus, Profero's proprietary scoring model, is built from its own engagements, and the cited record puts no customer count or volume behind it. A buyer cannot tell whether that casework is broader than a rival's. The fit is a buyer who wants a named responder on the phone within minutes. A larger provider could write the same 20-minute commitment into a contract, and staffing it with practitioners who also build the platform is what takes longer.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 3/3 | Profero sells the outcome of an operated incident response team and accepts a stated response obligation, with Rapid-IR as the delivery mechanism the practitioners built for their own engagements. The offering bundles the team, the platform, and the intelligence as one subscription rather than licensing software. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Incident history, cloud and on-premise connectors, credential vaults, and a readiness score tuned to a client's stated priorities accumulate inside Rapid-IR, so a departing client must rebuild that accumulated readiness work in-house or with another provider, not merely accept a coverage gap. The cited record evidences no network effect and no data-residency requirement that would make migration expensive. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | A SOC 2 Type II attestation and ISO 27001 certification are credentials any funded competitor can earn, and the cited record names no regulation or insurer requirement that a buyer can satisfy only through Profero. Panel-ready documentation eases procurement rather than blocking a replacement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Recovering data from the DarkBit attack, which Israel's National Cyber Command linked to an Iran-nexus group, required reducing the key space, brute-forcing VMDK headers in a high-performance computing environment, and walking sparse disk images, and finding a zero-day inside a live compromise is the same class of work. Continuous scoring across heterogeneous cloud and on-premise estates adds real-time engineering on top. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The named references are commercial companies, each represented by a named executive, and Profero addresses the CISO and the board rather than an owner-operator. The cited record shows no government customer and no regulated-sector requirement that a buyer's legal and purchasing teams would have to clear before switching. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Rapid-IR spans a client's cloud, endpoint, and identity data and carries the incident workflow across four quadrants, which is more than a single-use application. The reviewed record provides no evidence of partner-built extensions, or of applications depending on Rapid-IR as infrastructure. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Profero describes Deep Breach Focus as built entirely from its own incident response casework, which is an asset it accumulates rather than buys. The cited record attaches no customer count, engagement volume, or telemetry figure to that casework, so public sources establish no size for it. Profero also publishes its research openly, including an open-source HelloKitty unpacker, so a rival can read the published work and train a competing model on engagements that rival handles itself. |
Profero aims at the CISO who already funds incident response and reports readiness upward. Its Pre-Emptive IR page frames the buyer's problem as the gap between having a plan and being ready, naming the board that expects readiness and the regulator that demands proof. The pitch treats the incident response line item as already won and argues about what the money should buy.
The named references identify companies and the executives who speak for them, and little else. Executives at Aroundtown, Outbrain, Aidoc, Riskified, HoneyBook, BioCatch, and Guesty speak in Profero's testimonials, most of them security or IT leaders, and the cited pages give their roles rather than their sectors or size.
The partner routes describe a second segmentation Profero sells through rather than to. Cyber insurers, law firms, and resellers each reach the same CISO from a different direction, and the insurance route in particular names underwriting and compliance teams as the audience for its certification and SLA documentation.
Rapid-IR's capability claims are specific enough to test. Readiness runs automated assessments across cloud, email, domains, and endpoints and sorts every finding into Must-Do or Recommended, Response carries War Room for executive status and Investigator for endpoint forensics and isolation, Discovery watches external attack surface and leaked credentials, and WARP moves forensic artifacts and malware samples under encryption. The published scoring examples name concrete misconfigurations and the forensic cost of each, such as an nginx setup that hides the true source address during an investigation.
Deep Breach Focus is where the AI claim sits, and Profero draws its boundary tightly. The company states the model is its own, built from real incident casework, with no third-party models and client data staying inside the platform, fed by organizational priorities, connectors, and live engagements. That framing rests the model's distinctiveness on the casework it is built from. The cited record attaches no public measure to that casework, so a buyer cannot tell whether Profero's is broader than a rival responder's.
The AI work extends into what Profero responds to as well as what it responds with. Its GenAI Readiness Assessment is a two-day hands-on evaluation of a client's AI code assistants, agents, and chat interfaces, and the firm named AI-induced destruction as an incident pattern after handling cases where an AI coding assistant deleted a production codebase. That is incident response applied to AI systems, sold either as a standalone engagement or, on the recommended path, as findings that feed the platform's Readiness quadrant.
Profero's published routes to a buyer are a conversation and a referral. The site offers a discovery call and an emergency line, with no trial and no self-service path, and the partner program lays out five further routes: cyber-insurance panels, law firms, resellers, referrals, and advisory seats. The insurance and legal channels are how breach work actually reaches a responder, so the choice matches the business.
Profero's partner page sets break-glass retainer against pre-emptive service row by row, contrasting a dormant contract, a responder starting from zero, and a two-to-24-hour response with daily scoring and a 20-minute commitment. It also supplies the sentence a CISO can carry to a board, replacing "we have a retainer" with a statement about continuous readiness.
Profero shows its traction as named references with no scale behind them. Seven executives vouch for Profero by name and title on its pages, and one engagement is documented from outside by SysAid, Rapid7, and SecurityWeek. No customer count, revenue figure, or analyst placement appears in the public record, and CTech's 2021 interview is the single outside account of growth, in which Profero co-founder Omri Segev Moyal declined to quantify it.
No price and no packaging tier appears on the reviewed pages. Every route through the site ends at a conversation, whether that is a discovery call, an assessment request, or the emergency line, and the partner workflow describes a tailored proposal delivered in week one after a discovery call. Buyers therefore cannot size the commitment before engaging.
Profero sells a subscription in which readiness scoring runs continuously and the 20-minute response is included, positions that against the retainer that charges for availability alone, and offers the GenAI Readiness Assessment as either a standalone engagement or an input that feeds the platform's Readiness quadrant. The integrated path is the one the page recommends, which points the assessment toward the subscription, and no price appears for either option.
What a subscription buyer purchases is a commitment about people. Profero's pages define the trigger and the response condition, with the clock starting at a client's incident declaration and a qualified practitioner actively triaging inside 20 minutes. They state no remedy for a miss, no exclusions, and no cap on simultaneous incidents, so the enforceable half of the promise moves into the negotiated contract.
Delivery runs through one team that both builds and responds. Profero states that the practitioners who built Rapid-IR are the ones who respond to client incidents, and the operating claim is that a responder inherits a scored environment instead of assembling context under pressure. The 20-minute page describes the sequence, with a qualified practitioner triaging within 20 minutes of declaration and the environment context already loaded.
Rapid-IR deploys through connectors and one endpoint sensor. It ingests from cloud APIs and on-premise connectors across named systems, offers that single sensor across Windows, macOS, and Linux, and adds a WARP desktop client for large forensic transfers with resumption and integrity checks. A sampling feature tracks how much of the endpoint fleet the sensor actually covers.
The published operational apparatus is aimed at incident conditions. Emergency Details collects playbooks, contacts, and credentials on a print-ready page, a Slack integration provides coordination when other channels are down, an audit trail records every action for export, and a sleep mode narrows scanning windows to manage cost while waking on incident declaration. None of these operating claims has been examined by a third party, so a buyer has only Profero's account of how delivery works.
Profero holds the two credentials enterprise procurement asks for and publishes a portal behind them. It announced its SOC 2 Type II attestation and ISO 27001 certification in May 2024 and launched trust.profero.io at the same time, and the homepage footer carries badge images named for both that link to that portal. A probe of the subdomain in July 2026 returned a working portal.
The portal shows the control inventory and requires a request for the audit evidence. Its public view lists policy and control categories across data protection, vendor risk, disaster recovery, encryption, access management, and secure development, with the compliance section holding two documents behind a request-access step. The partner page counts 17 independently audited control categories and offers panel-ready documentation on request, which is the form an insurer or law firm would want.
The Rapid-IR page lists complete customer isolation, required multi-factor authentication with auto-lockout, and access restriction by address or country, and the Deep Breach Focus page states that client data never leaves the platform. Those are the right claims for a firm holding other companies' breach data, and no third party in the public record has examined any of them.
Profero's platform claim points inward rather than outward. Rapid-IR connects to the systems a client already runs, naming cloud providers, collaboration suites, code hosting, and endpoint tooling as data sources, and it imports findings from a client's other tools through curated modules. The reviewed record shows no API, no marketplace listing, and no partner-built extension surface, so it gives no evidence of other vendors building on Rapid-IR.
The ecosystem Profero does cultivate is a referral network of intermediaries. Cyber insurers, law firms, resellers, and referral partners sit between the firm and the buyer, and the legal route in particular describes operating under counsel direction with chain-of-custody discipline and real-time incident visibility for lawyers. That is the distribution structure incident response work actually flows through.
The competitive pressure on Rapid-IR comes from vendors whose products a client already runs. Profero's own pages set Rapid-IR apart from security analytics, endpoint tooling, and ticketing, and the cited record carries no survey of what those vendors bundle. This analysis flags the overlap as a risk rather than a documented fact: a buyer already paying for posture scoring inside a detection subscription has less reason to fund Profero's readiness quadrant separately. Profero's answer to that pressure is its responder team rather than its software.
Two founders carry the company, and both records check out. CTech reports that Omri Segev Moyal co-founded Profero with Guy Barnhart-Magen in 2019, that Moyal co-founded Minerva Labs, and that he served as CTO of ClearSky Cyber Security. SANS lists Barnhart-Magen with a profile naming his Profero role and his focus on making incident response fast and scalable, and Profero's own page adds a Forbes 30 Under 30 listing for Moyal.
Published research is the team's most visible credential. Profero released an open-source static unpacker for the HelloKitty ransomware packer that the Malpedia reference library indexes, published a joint APT27 investigation with Security Joes, documented forensic collection for the Ivanti EPMM zero-days, and named AI-induced destruction as a pattern from its own casework. SysAid records engaging Profero in the investigation, while Rapid7 explicitly credits Profero's investigation with identifying the zero-day in SysAid's on-premise product.
Coverage of the APT27 investigation carried a threat-intelligence analyst calling the attribution realistically possible rather than settled. The public record names no executive team beyond the two founders and two advisors. CTech's account of responders hired across many countries is the single public description of the team behind the 20-minute commitment.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Profero: Rapid-IR platform page | official | 2026-07-27 |
| f2 | CTech on demand for Profero's services | press | 2026-07-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Profero: homepage “Continuous readiness scoring, 20-minute guaranteed response, and proprietary AI built from real incident casework.” | official | 2026-07-27 |
| s2 | Profero: Rapid-IR platform page “Rapid-IR covers the full breach lifecycle across four quadrants: Readiness, Response, Discovery, and Intelligence.” | official | 2026-07-27 |
| s3 | Profero: Deep Breach Focus page “Profero's proprietary AI model, built entirely from real incident response casework.” | official | 2026-07-27 |
| s4 | Profero: company page “Forbes 30 under 30 honoree and seasoned malware researcher.” | official | 2026-07-27 |
| s5 | Profero: Pre-Emptive IR page “Continuous IR readiness, not emergency response. Your engagement starts before the incident.” | official | 2026-07-27 |
| s6 | Profero: partner program page “17 control categories. Independently audited. Live compliance dashboard at trust.profero.io.” | official | 2026-07-27 |
| s7 | Profero: GenAI Readiness Assessment page “Two days of hands-on-keyboard evaluation by IRT practitioners.” | official | 2026-07-27 |
| s8 | Profero certification announcement “We are pleased to announce that we have successfully been certified for the SOC-2 Type 2 and hthe ISO 27001.” | official | 2026-07-27 |
| s9 | Profero privacy policy “Segev-Magen Technologies Ltd. and Segev-Magen Technologies Inc.” | official | 2026-07-27 |
| s10 | Profero: 20-minute guarantee page “A qualified IR practitioner is actively triaging your incident within 20 minutes of declaration.” | official | 2026-07-27 |
| s11 | BleepingComputer on Profero cracking DarkBit ransomware “Cybersecurity firm Profero cracked the encryption of the DarkBit ransomware gang's encryptors, allowing them to recover a victim's files for free without paying a ransom.” | press | 2026-07-27 |
| s12 | CTech on demand for Profero's services “Profero is bootstrapped and isn't seeking any external investment despite plenty of interest.” | press | 2026-07-27 |
| s13 | CTech on Profero's founding year “Moyal founded Profero with CTO Guy Barnhart-Magen in 2019 and the company has grown significantly since” | press | 2026-07-27 |
| s14 | CTech on Profero turning clients away “In December, when the Pay2Key ransomware operation peaked, we turned down requests from 23 companies who wanted to hire our services” | press | 2026-07-27 |
| s15 | CTech on the founders' prior roles “Moyal, who is also the co-founder of Minerva Labs and the former CTO of ClearSky Cyber Security, was willing to say that Profero employs experts from across the world” | press | 2026-07-27 |
| s16 | SysAid security bulletin on CVE-2023-47246 “We engaged Profero, a cyber security incident response company, to assist us in our investigation.” | official | 2026-07-27 |
| s17 | Rapid7 advisory on the SysAid zero-day “Updated to note that Profero conducted the investigation that identified the zero-day vulnerability” | research | 2026-07-27 |
| s18 | SecurityWeek on the SysAid zero-day “Incident response company Profero, which assisted SysAid in its investigation” | press | 2026-07-27 |
| s19 | SC Media on the APT27 report, with an analyst questioning the attribution “realistically possible that APT27 or Winnti could have been responsible for the ransomware actions outlined by the Profero/Security Joes report” | press | 2026-07-27 |
| s20 | SANS Institute profile for Guy Barnhart-Magen “As the Co-Founder and CTO of the Incident Response company Profero, his focus is making incident response fast and scalable” | other | 2026-07-27 |
| s21 | Malpedia reference library entry for HelloKitty “Static unpacker and decoder for Hello Kitty Packer” | research | 2026-07-27 |
| s22 | Profero HelloKittyUnpacker repository “A tool to assist in analysis of packed HelloKitty ransomware binaries” | official | 2026-07-27 |
| s23 | Probe of trust.profero.io and a random nonsense subdomain, 2026-07-27: the portal answered and the control subdomain did not resolve, headless render | official | 2026-07-27 |
| s24 | Profero research on AI-induced destruction “an AI coding assistant that had just deleted an entire production codebase” | official | 2026-07-27 |
| s25 | Profero forensic guidance for the Ivanti EPMM zero-days “In May 2025, Profero responded to multiple security incidents stemming from the active exploitation of two zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM)” | official | 2026-07-27 |
| s26 | Profero: Rapid-IR platform security controls “Multi-Tenant Every customer completely isolated. Zero-trust by design. Your data stays yours. Auth & Login Multi-factor authentication required. Failed login attempts trigger auto-lockout. Conditional Access Restrict access by IP address or country.” | official | 2026-07-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Profero: homepage “Continuous readiness scoring, 20-minute guaranteed response, and proprietary AI built from real incident casework.” | official | 2026-07-27 |
| s2 | Profero: Rapid-IR platform page “Rapid-IR covers the full breach lifecycle across four quadrants: Readiness, Response, Discovery, and Intelligence.” | official | 2026-07-27 |
| s3 | Profero: Deep Breach Focus page “Profero's proprietary AI model, built entirely from real incident response casework.” | official | 2026-07-27 |
| s4 | Profero: company page “Forbes 30 under 30 honoree and seasoned malware researcher.” | official | 2026-07-27 |
| s5 | Profero: Pre-Emptive IR page “Continuous IR readiness, not emergency response. Your engagement starts before the incident.” | official | 2026-07-27 |
| s6 | Profero: partner program page “17 control categories. Independently audited. Live compliance dashboard at trust.profero.io.” | official | 2026-07-27 |
| s7 | Profero: GenAI Readiness Assessment page “Two days of hands-on-keyboard evaluation by IRT practitioners.” | official | 2026-07-27 |
| s8 | Profero certification announcement “We are pleased to announce that we have successfully been certified for the SOC-2 Type 2 and hthe ISO 27001.” | official | 2026-07-27 |
| s9 | Profero privacy policy “Segev-Magen Technologies Ltd. and Segev-Magen Technologies Inc.” | official | 2026-07-27 |
| s10 | Profero: 20-minute guarantee page “A qualified IR practitioner is actively triaging your incident within 20 minutes of declaration.” | official | 2026-07-27 |
| s11 | BleepingComputer on Profero cracking DarkBit ransomware “Cybersecurity firm Profero cracked the encryption of the DarkBit ransomware gang's encryptors, allowing them to recover a victim's files for free without paying a ransom.” | press | 2026-07-27 |
| s12 | CTech on demand for Profero's services “Profero is bootstrapped and isn't seeking any external investment despite plenty of interest.” | press | 2026-07-27 |
| s13 | CTech on Profero's founding year “Moyal founded Profero with CTO Guy Barnhart-Magen in 2019 and the company has grown significantly since” | press | 2026-07-27 |
| s14 | CTech on Profero turning clients away “In December, when the Pay2Key ransomware operation peaked, we turned down requests from 23 companies who wanted to hire our services” | press | 2026-07-27 |
| s15 | CTech on the founders' prior roles “Moyal, who is also the co-founder of Minerva Labs and the former CTO of ClearSky Cyber Security, was willing to say that Profero employs experts from across the world” | press | 2026-07-27 |
| s16 | SysAid security bulletin on CVE-2023-47246 “We engaged Profero, a cyber security incident response company, to assist us in our investigation.” | official | 2026-07-27 |
| s17 | Rapid7 advisory on the SysAid zero-day “Updated to note that Profero conducted the investigation that identified the zero-day vulnerability” | research | 2026-07-27 |
| s18 | SecurityWeek on the SysAid zero-day “Incident response company Profero, which assisted SysAid in its investigation” | press | 2026-07-27 |
| s19 | SC Media on the APT27 report, with an analyst questioning the attribution “realistically possible that APT27 or Winnti could have been responsible for the ransomware actions outlined by the Profero/Security Joes report” | press | 2026-07-27 |
| s20 | SANS Institute profile for Guy Barnhart-Magen “As the Co-Founder and CTO of the Incident Response company Profero, his focus is making incident response fast and scalable” | other | 2026-07-27 |
| s21 | Malpedia reference library entry for HelloKitty “Static unpacker and decoder for Hello Kitty Packer” | research | 2026-07-27 |
| s22 | Profero HelloKittyUnpacker repository “A tool to assist in analysis of packed HelloKitty ransomware binaries” | official | 2026-07-27 |
| s23 | Probe of trust.profero.io and a random nonsense subdomain, 2026-07-27: the portal answered and the control subdomain did not resolve, headless render | official | 2026-07-27 |
| s24 | Profero research on AI-induced destruction “an AI coding assistant that had just deleted an entire production codebase” | official | 2026-07-27 |
| s25 | Profero forensic guidance for the Ivanti EPMM zero-days “In May 2025, Profero responded to multiple security incidents stemming from the active exploitation of two zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM)” | official | 2026-07-27 |
| s26 | Profero: Rapid-IR platform security controls “Multi-Tenant Every customer completely isolated. Zero-trust by design. Your data stays yours. Auth & Login Multi-factor authentication required. Failed login attempts trigger auto-lockout. Conditional Access Restrict access by IP address or country.” | official | 2026-07-27 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.