Cybersecurity · Atlanta, United States · Founded 2006
Damballa was a cybersecurity firm established in 2006 by data scientists from the Georgia Institute of Technology, including individuals like Stephen Fleury, who spun the intellectual property out of the university. The company was founded on the premise that signature and reputation-based security tools would eventually be insufficient against sophisticated attackers. Damballa specialized in advanced threat protection, focusing on detecting hidden, active threats within a network that had already bypassed traditional prevention security layers.
The company's business model centered on providing network monitoring solutions that leveraged big data and machine learning to identify malicious communications from compromised devices. At its peak, Damballa monitored nearly 15% of the world's internet traffic, protecting hundreds of millions of devices globally. Its primary clientele included large enterprises and major Internet Service Providers (ISPs) and mobile operators. For enterprises, Damballa offered a way to discover infected assets with certainty, while for service providers, it identified compromised customer devices for notification and remediation.
Damballa's flagship product was the 'Failsafe' automated breach defense system, a network sensor designed to detect command-and-control communications between infected devices and cybercriminal operators. The system would automatically analyze all evidence, rank threats by severity, and provide definitive proof of infection, allowing security teams to respond rapidly without wasting time on false positives. The technology was recognized for being an early adopter of machine learning for threat detection. Another service offering was a 'Network Security Checkup,' a 30-day engagement to analyze a company's internal security posture and provide detailed recommendations.
After raising approximately $60 million in venture capital over several years, Damballa faced challenges in meeting revenue expectations. In July 2016, the company was acquired by Core Security, a firm specializing in vulnerability and access risk management. The acquisition was intended to integrate Damballa's network detection and response capabilities into Core Security's 'Actionable Insight Platform'. This event was described by some industry observers as a 'fire sale', as the company was sold for a fraction of the capital invested.
Keywords: Damballa, network security, advanced threat protection, threat detection, breach defense, network monitoring, Failsafe, cybersecurity, botnet detection, machine learning security, command and control detection, Core Security, threat intelligence, ISP security, mobile operator security, data exfiltration, network sensor, incident response, Georgia Tech, cybercriminal detection
Dealroom maps Damballa's team person by person — pinpointing the standout operators and scoring them across the six dimensions investors underwrite. The counts and shape below are a public preview; the named individuals and exact scores live in the platform.
31team members profilednamed & role-tagged by Dealroom
Source: Dealroom Talent Intelligence. Public profiles show counts and the team's shape only — request a demo for the named individuals, per-person seniority and tenure, and team benchmarks vs peers.
Market sentiment
What the market is saying about Damballa
An AI-synthesized read of the highest-engagement posts about Damballa on X over the past 7 days. We rank by likes & retweets, ignore corporate channels, and surface the themes that broke out from real people.
Reading the room on X — pulling top posts and synthesizing themes…
Source: X recent search ranked by engagement (likes + retweets) · Synthesis by Claude · Cached for 1 hour
See Damballa on the full Dealroom platform
Live deal flow, founder pedigree, hiring signals, revenue trajectory, and the full cap table.