Today we’re announcing Scanner’s $22M Series A, led by Sequoia Capital.
Scanner turns object storage into a high-performance security database.
No security data should be off-limits to detection and investigation.
🤘 We’re AMP’D to announce that Scanner is an official @torq_io AMP partner! Together, we’re transforming how security teams operate — empowering our customers to detect and defend against threats, faster.
Security teams are underwater. 🌊 Alert volume is up, but headcount isn't.
Our new guide shows how to build autonomous SOC agents using MCP to automate triage across CrowdStrike, Wiz, and Scanner. scanner.dev/blog/building-yo…
ALT Building Your First AI SOC Agents: Foundations and Your First Agent
Security teams aren’t missing attacks.
They’re deleting the evidence.
Not intentionally.
Keeping everything is too expensive.
Threat actors don’t evade detection.
They live in the 80% of logs you never kept.
Cliff from @scanner_dev
🎙 Full episode on Cloud Security Podcast
Legacy SIEMs: all noise, no signal.
Scanner: built for teams who actually want to fix things.
- 1,000s of useless alerts? Nope.
- Context first. Triage in seconds.
That’s why @tryramp, @getpostman & @Lemonade_Inc ditched the bloat.
🔗 blog.scanner.dev/why-fast-mo…
FloQast was stuck with short log retention, rising SIEM costs, and way too much friction - so they made a switch.
Now they analyze 100TB in seconds, keep 12 months of EDR data, and query straight from S3, no handoff and no headaches.
Read about it scanner.dev/customers/floqas…
Resetting MFA at 3AM? Logging in from two continents in an hour?
If it's in your Okta logs, it's worth investigating.
New guide: How to build a real detection pipeline from Okta → Grove → Substation → Scanner.
Here is the full guide:
blog.scanner.dev/monitoring-…
Big news: Scanner.dev is hitting the stage at @BlueTeamCon 2025
Cliff’s heading to Chicago this Sept to talk AI SecOps — specifically, how modern security teams can boost productivity without burning out.
Let’s connect IRL:
🔗 blueteamcon.com/directory/ai…
Changelog: You can now transform your logs as they flow into your Scanner indexes.
- Add normalized Elastic Common Schema (ECS) fields to popular log source types.
- Auto-parse JSON strings and "key=value" pairs.
- And more...
Transformers - more than meets the eye.
anyone using data lakes for their logs? doing an info session next week about good methods we're seeing these days, particularly what detection & response teams are doing. come share how you do things! scanner.dev/events/data-lake…
Join our hands-on webinar Jan 30 to learn how to streamline and deploy security detections with Scanner's schemaless log search index in your S3 bucket. UI & code-first approaches, GitHub integration—no complex schemas or heavy engineering. bit.ly/4h3h6IH
Announcing a major expansion of Scanner's detection capabilities with ready-to-use rules across 12 critical log sources bringing our total to 214 detection rules, covering 11 MITRE ATT&CK tactics and 45 techniques. bit.ly/4jjriyb
Explore the key benefits of Security Data Lakes, including advanced use cases for threat hunting, streamlined detection and response workflows, and their role in GenAI-powered analysis. bit.ly/40coiuO
Struggling with Datadog log costs? Security teams face challenges balancing Standard Logs, Flex Logs & Cloud SIEM. Learn how @scanner_dev helps optimize performance and detections, cuts costs, and enhances @datadoghq's power & efficiency. bit.ly/4fwSqHD
The @scanner_dev Playground is live! Dive into an interactive demo with AWS CloudTrail logs to experience a full threat investigation scenario. Sign up now and start exploring at scanner.dev/demo. bit.ly/4fKBlde
Congrats to the Scanner team for launching Detection Rules As Code! Our users can now manage detection rules directly in their own GitHub repos, improving collaboration, change management, continuous delivery, and streamlining threat detection development bit.ly/3XgZbqE