ExtraHop makes network detection and response software that uses machine learning to analyze network traffic and flag security threats, with its RevealX platform offering automated detection agents rather than a general-purpose AI agent product.
ExtraHop is a network detection and response (NDR) vendor that analyzes network traffic at the packet level to detect intrusions, lateral movement, and other threats that endpoint tools can miss. Its core platform, RevealX, applies machine learning and behavioral analytics to decrypted and metadata-level traffic to surface anomalies for security operations teams, and it integrates with SIEM, SOAR, and XDR tools used in enterprise security operations centers.
The company is privately held. ExtraHop was taken private in 2021 through an acquisition by private equity firms Bain Capital Private Equity and Crosspoint Capital Partners, and it has operated independently of any parent security vendor since. ExtraHop serves enterprise and public sector customers across industries including financial services, healthcare, and government, and it competes in the NDR and network security monitoring space against vendors such as Darktrace, Corelight, and Vectra AI.
Documented from public materials · these are the products the AMS scores
ExtraHop RevealX
Shipping since 2007
RevealX is ExtraHop's flagship network detection and response platform. It ingests network traffic, decrypts and analyzes it using machine learning models trained on network behavior, and surfaces threats such as ransomware activity, command-and-control traffic, and lateral movement. RevealX is available as a cloud-delivered SaaS product (RevealX 360) and as a self-managed on-premises deployment.
RevealX 360
Shipping since 2021
RevealX 360 is ExtraHop's cloud-native NDR offering that centralizes network visibility and detection across hybrid and multi-cloud environments from a single SaaS console. It extends RevealX detections with cloud workload visibility for AWS and other cloud platforms and is positioned as the primary delivery model for new deployments.
2024 - 2026 ·gold = a monetization move· grey = product or capital
ExtraHop was acquired by Bain Capital Private Equity and Crosspoint Capital Partners in a deal that took the company private, ending its run as a venture-backed independent vendor. Source: ExtraHop press release
ExtraHop continued expanding RevealX 360 cloud detection capabilities, including expanded workload and cloud-native visibility for hybrid environments, as part of its shift toward SaaS-first delivery. Source: ExtraHop RevealX 360 product page
ExtraHop does not publish list pricing for RevealX or RevealX 360 on its website. Historically, and per third-party procurement and reseller listings, ExtraHop has priced its network detection and response products based on network traffic volume, typically measured in sustained Mbps or Gbps of monitored traffic, along with the number of sensors or deployment scale required to cover an organization's network segments.
Contracts are typically structured as annual or multi-year subscriptions, consistent with standard enterprise security software procurement, and sold through direct sales and channel partners. Public sector and government pricing is available through partners on cooperative purchasing vehicles, though specific unit pricing is not disclosed publicly.
Pricing not public. There is no evidence of a separate, distinctly metered charge for AI or machine learning detection capability; ML-based threat detection appears bundled into the core RevealX and RevealX 360 platform tiers rather than sold as a separate agent-based add-on.
Analyst layer · placement follows the documented capability above
Independence. RevealX operates with moderate human involvement. Its machine learning models autonomously flag anomalies and generate detections, but security analysts review, triage, and act on those detections within a SOC workflow. This places the product in the M band, roughly 20 to 50 percent independent operation, since a human remains firmly in the loop for investigation and response decisions.
Job width. RevealX addresses a single, well-defined task within the security operations function: network traffic analysis and threat detection. It does not orchestrate cross-functional workflows spanning incident response, remediation, and reporting end to end, which places job width at the S level, a single task rather than a full workflow or cross-functional scope.
Output versus cost. By automating traffic analysis that would otherwise require significant manual packet inspection and correlation work, RevealX plausibly delivers output gains in the Inflecting range, an order of magnitude or more improvement in detection throughput per analyst hour compared to manual network monitoring, though ExtraHop does not publish specific productivity multipliers.
Monetization pattern. ExtraHop's documented pattern is traditional platform subscription pricing tied to network traffic volume and deployment scale, not usage-based or outcome-based pricing tied to the AI detection capability itself. There is no public evidence of a separate agent-based or consumption meter for ML-driven detection; it is sold as an included capability within the core platform license.
| Edition | AMS score | Change | |
|---|---|---|---|
| Aug 2026 | M · S · Infl | Baseline, first edition |
Future editions add a row whenever the score or the metric moves, with the evidence that moved it.
About this data
Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.