Logo officiel de ThreatX by A10 Networks

ThreatX by A10 Networks

by A10 Networks, Inc.

4.2
WAFPlanet Rating

Managed WAAP that combines a next-gen WAF, API protection, bot defense, and Layer 7 DDoS mitigation with behavioral risk scoring and a 24/7 SOC included in the subscription.

Company: A10 Networks, Inc.
Pricing: Subscription tiered by monthly HTTP/HTTPS request volume, managed SOC included
Founded: 2014

Overview

ThreatX by A10 Networks is a web application and API protection (WAAP) platform built around attacker behavior rather than signatures. Traffic reaches an NGINX-based reverse proxy sensor, and a cloud analytics engine A10 calls the Hacker Mind scores every entity behind that traffic. The score rises as an attacker probes, correlates across vectors, and persists over time, so blocking decisions follow the attacker instead of a single request.

The subscription bundles what most vendors sell separately: next-gen WAF, API discovery and protection, bot management, Layer 7 DDoS defense, and access to the ThreatX SOC. That SOC is the part buyers talk about most. It handles onboarding, tuning, virtual patching, threat hunting, and incident response, and it validates alerts by hand before they reach you. For a team without a dedicated appsec function, that is the difference between owning a WAF and having one run for you.

ThreatX shipped as a standalone product from 2014 until A10 Networks acquired the business in February 2025. Sensors stay decoupled from the analytics backend, so you can let the SOC host them in the ThreatX cloud (a DNS CNAME switch), run machine images in your own AWS, Azure, or GCP account, run Docker containers in a data center, or mix all three. Sensors are agentless, so nothing gets installed on application servers.

Ratings Breakdown

Ease of Use 4.4/5
Value for Money 3.9/5
Customer Support 4.6/5
Features 4.1/5

Key Features

Hacker Mind Risk Engine

Adaptive risk scoring that tracks entities across sessions and attack vectors, correlating probing behavior over time instead of judging requests one at a time.

Managed SOC

24/7 analysts included in the subscription who tune policies, hunt threats, apply virtual patches, and hand-validate alerts before they reach your team.

API Protection

Automatic API cataloging with behavioral analysis and fingerprinting to catch abuse, enumeration, and business logic attacks against north-south API traffic.

Bot Management

Blocks credential stuffing, scraping, and scalping by profiling the attacker rather than matching a static bot signature list.

Layer 7 DDoS Defense

Entity and transaction based tracking that absorbs multi-vector application-layer floods without blanket rate limits on real users.

Sensitive Data Redaction

Automatic redaction of credentials, tokens, card numbers, and SSN patterns in captured traffic, with a 90-day retention policy.

Pros & Cons

Pros

  • SOC included, not an upsell

    24/7 analyst coverage, tuning, and virtual patching ship with the base subscription, which is where most WAF programs stall.

  • Behavioral detection cuts false positives

    Risk scoring follows attackers across requests and vectors, so legitimate traffic that trips one signature does not get blocked.

  • Fast to deploy

    SOC-hosted sensors go live with a DNS CNAME change, and Docker sensors start in minutes. A10 quotes deployment in hours.

  • Flexible sensor placement

    Sensors are decoupled from the analytics backend, so cloud, on-premises, and hybrid topologies all work without a different product.

  • Agentless

    Nothing installs on application servers and no privileged access is needed, which shortens security review and change approval.

Cons

  • No public pricing

    Every deal is a quote based on request volume, so budgeting requires a sales conversation before you can compare against listed alternatives.

  • No free tier or self-service signup

    Evaluation runs through a trial request and demo rather than a credit card, which rules it out for small sites and quick tests.

  • Managed model means less direct control

    Teams that want to write and own every rule themselves may find the SOC-managed workflow adds a step rather than removing one.

  • No CDN or caching

    This is a security proxy, not a content delivery network, so you still need a separate CDN for performance.

  • Post-acquisition uncertainty

    The product moved under A10 Networks in February 2025, and documentation and support paths are still consolidating into A10 systems.

Pricing

Pricing model: Subscription tiered by monthly HTTP/HTTPS request volume, managed SOC included

ThreatX Protect

Custom quote

Base subscription priced on monthly request volume

  • Next-gen WAF and OWASP Top 10 coverage
  • API discovery, cataloging, and protection
  • Bot management and credential stuffing defense
  • Layer 7 DDoS mitigation
  • ThreatX SOC included, 24/7

Enterprise

Contact Sales

Multi-environment and higher-volume deployments

  • Self-managed sensors on-premises or in your cloud accounts
  • Hybrid sensor topologies across regions
  • Virtual patching and dedicated threat hunting
  • Custom compliance reporting
  • Named SOC engagement and onboarding

Our Verdict

ThreatX sells an outcome rather than a toolbox. The base subscription covers WAF, API protection, bot defense, and L7 DDoS, and the SOC that comes with it does the tuning most teams never get around to. If your WAF is currently in log-only mode because nobody has time to fix the false positives, that bundling is the whole pitch.

The behavioral approach is the technical differentiator. Instead of scoring requests, ThreatX scores entities and watches them across sessions and attack vectors, which is closer to how Wallarm and Traceable handle API abuse than to a rule-based edge like Cloudflare. See ThreatX vs Wallarm for how the two split on API-first design versus managed operations.

The cost is transparency. There is no published price, no free tier, and no way to try it without talking to sales. Against Imperva or a self-serve edge WAF, you are buying a service relationship, and that only pays off if you actually want someone else running the thing.

Our verdict: The strongest managed WAAP option for teams that would rather buy security operations than staff them. Skip it if you want published pricing or full rule-level control.

CVE Coverage

ThreatX by A10 Networks can detect and block attacks matching 105K+ known CVEs based on its supported rule sets.

13K+
Critical
25K+
High
44K+
Medium
1.7K+
Low

Coverage by Attack Type

19K+ CVEs
12K+ CVEs
9.1K+ CVEs
6.5K+ CVEs
5.9K+ CVEs
4.1K+ CVEs
3.6K+ CVEs
Open Redirect Medium
1.5K+ CVEs
1.2K+ CVEs

Latest Blockable CVEs

CVE Severity
CVE-2026-49294 UNKNOWN
CVE-2026-20262 MEDIUM
CVE-2026-9863 UNKNOWN
CVE-2026-9862 UNKNOWN
CVE-2025-15659 UNKNOWN
CVE-2025-15658 UNKNOWN
CVE-2026-52704 UNKNOWN
CVE-2019-25746 HIGH
CVE-2018-25436 CRITICAL
CVE-2016-20084 HIGH

Frequently Asked Questions

Is ThreatX still a separate product after the A10 acquisition?

Yes. A10 Networks acquired the ThreatX Protect assets and team in February 2025 and continues to sell it as ThreatX by A10 Networks. The platform, sensors, and SOC service carry on; what changed is that documentation, support, and sales now run through A10 rather than the standalone threatx.com organization.

What does the ThreatX SOC actually do?

The SOC handles onboarding and sensor deployment, tunes policies as your applications change, hunts threats, applies virtual patches for newly disclosed vulnerabilities, and reviews alerts before they reach you. The platform filters and validates automatically first, then analysts check the result by hand, so what lands in your inbox is meant to be actionable rather than raw. It is included in the subscription, not a separate managed-service line item.

How is ThreatX deployed?

Four ways. The simplest is ThreatX Cloud, where the SOC hosts sensors and you point a DNS CNAME at them. You can also run machine images in your own AWS, Azure, or GCP account, run Docker containers in your data center, or combine these in a hybrid topology. Sensors are NGINX-based reverse proxies and are agentless, so nothing is installed on your application servers.

How much does ThreatX cost?

A10 does not publish pricing. Subscriptions are tiered by monthly HTTP/HTTPS request volume, with the managed SOC bundled into the price rather than sold on top. There is no free tier and no self-service signup, so you need a sales conversation and a trial to get a number. If published pricing matters to you, look at Cloudflare or AWS WAF instead.

Does ThreatX replace my CDN?

No. ThreatX is a security reverse proxy with no content delivery or caching layer, so you keep your CDN and run ThreatX for protection. That differs from Cloudflare or Fastly, where WAF and CDN come from the same edge. It does mean one less vendor lock-in on the delivery side if you already have a CDN you like.

Ready to try ThreatX by A10 Networks?

Visit the website to learn more or request a demo.