Sourcefire
Cybersecurity company best known for commercializing Snort and developing the FirePOWER network security platform before its acquisition by Cisco.
Last updated August 22, 2026
Overview
Sourcefire, Inc. was a United States cybersecurity company built around Snort, the open-source network intrusion detection and prevention system created by Martin Roesch. The company’s central commercial proposition was to combine the openness, extensibility, and broad deployment of Snort with proprietary security appliances, software, threat intelligence, vulnerability research, and enterprise support. Its products were aimed at organizations seeking visibility into network traffic, protection against intrusions and malware, policy enforcement, and faster response to emerging vulnerabilities. Founded in 2001, Sourcefire developed a commercial version of the Snort technology and expanded it into the Sourcefire 3D System. The 3D platform combined detection, analysis, management, and response capabilities and subsequently evolved into the FirePOWER family of network security products. FirePOWER appliances were positioned as layered defenses that could provide next-generation intrusion prevention, next-generation firewall functionality, application and access control, URL filtering, malware protection, and network visibility across hosts, users, services, protocols, applications, and content. The company broadened its portfolio through acquisitions and internal development. In 2007 it acquired Clam AntiVirus, an open-source antivirus project, adding endpoint and gateway malware capabilities to its security ecosystem. In 2011 it announced the acquisition of Immunet, a cloud-oriented antivirus company. Immunet used cloud-delivered malware intelligence and ClamAV definitions, and was offered in free and paid versions before the paid Immunet Plus product was discontinued in 2014 under Cisco ownership. Sourcefire also operated a Vulnerability Research Team that investigated exploit trends, produced Snort rules, and supplied protection for newly emerging threats and software vulnerabilities. After Cisco acquired Sourcefire, this research capability was combined with Cisco security research groups to form Cisco Talos. Sourcefire’s growth was financed initially by venture capital and later by public-market funding. The company raised $56.5 million through four financing rounds and completed an initial public offering in March 2007. It became a notable independent security vendor during a period when intrusion prevention, application-aware firewalls, and malware defense were converging into integrated platforms. Its technology received industry recognition, including awards for Snort and the Sourcefire 3D System. The company attracted acquisition interest during its independent years. Check Point Software Technologies proposed a $225 million acquisition in 2005 but withdrew after regulatory concerns emerged. Sourcefire rejected Barracuda Networks’ $187 million proposal in 2008. Cisco Systems ultimately announced a definitive agreement to acquire Sourcefire for $2.7 billion on July 23, 2013, and completed the transaction later that year. Following the acquisition, Sourcefire’s products and research were integrated into Cisco’s security portfolio. The Sourcefire corporate entity ceased operating as an independent public company, while Snort, FirePOWER-related technology, and the research organization continued through Cisco-branded offerings and successor technologies.
History
Sourcefire originated in the development of Snort, an open-source intrusion detection system created by Martin Roesch. Snort used a rule-based approach to inspect network traffic and identify suspicious signatures, protocol violations, and anomalous behavior. Its open-source distribution made it widely accessible to security practitioners and encouraged a community-driven ecosystem of rules and extensions. Sourcefire was founded in 2001 to commercialize the technology while preserving its role as the foundation of a broader security platform. The company’s early business model combined proprietary software, network appliances, subscriptions, professional services, and support. Its commercial platform developed into the Sourcefire 3D System, which linked network sensors, management functions, event analysis, and policy controls. Over time, this technology evolved into FirePOWER, a product family intended to provide next-generation intrusion prevention and firewall capabilities. FirePOWER appliances could identify users, applications, operating systems, services, protocols, content, and network behavior, allowing customers to enforce controls beyond traditional port- and signature-based filtering. Sourcefire expanded through venture financing and acquisitions. Four financing rounds reportedly raised $56.5 million from investors including Sierra Ventures, New Enterprise Associates, Sequoia Capital, Core Capital Partners, Inflection Point Ventures, Meritech Capital Partners, and Cross Creek Capital. In 2005, Check Point Software Technologies attempted to acquire the company for $225 million, but withdrew after regulatory opposition appeared likely. Sourcefire later completed an initial public offering in March 2007, raising $86.3 million. In August 2007, it acquired Clam AntiVirus, bringing an established open-source antivirus engine into its technology portfolio. In 2008, Sourcefire rejected Barracuda Networks’ offer, which valued the company at approximately $187 million. The company continued to move from network intrusion prevention toward integrated threat defense. Its Advanced Malware Protection products used cloud intelligence, large-scale analysis, continuous inspection, and retrospective alerting to identify advanced malware and targeted attacks. FireAMP extended this approach to endpoints and virtual or mobile environments. Immunet, acquired in 2011, added a cloud-assisted antivirus service based on cloud definitions and ClamAV technology. Sourcefire also maintained a Vulnerability Research Team that analyzed hacking trends, emerging exploits, and software weaknesses. The team developed official Snort rules, produced protections for newly disclosed vulnerabilities, and contributed same-day or early defenses for major malware outbreaks. Sourcefire’s financial performance supported its strategic importance as an independent security vendor. For the fourth quarter of 2012, reported revenue was $67.4 million, compared with $53.2 million in the same quarter of 2011. Full-year 2012 revenue was reported at $223.1 million, compared with $165.6 million in 2011, while international revenue reached $74.4 million. These figures reflected increasing demand for network visibility, intrusion prevention, malware analysis, and security subscriptions. Cisco Systems announced on July 23, 2013, that it would acquire Sourcefire for $2.7 billion. The transaction ended Sourcefire’s existence as an independent public company and gave Cisco a stronger security portfolio centered on Snort, FirePOWER, advanced malware protection, and Sourcefire’s research capabilities. After the acquisition, the Sourcefire Vulnerability Research Team was combined with Cisco’s TRAC and SecApps organizations. The resulting group became Cisco Talos, which carried forward the company’s threat research, vulnerability analysis, and security-rule functions. Sourcefire therefore survives primarily as a technology and product heritage within Cisco Security rather than as a standalone operating brand.
- 2014Cisco Talos is formed
Sourcefire’s research team was combined with Cisco security research groups to form Cisco Talos.
- 2013Cisco announces Sourcefire acquisition
Cisco announced a definitive agreement to acquire Sourcefire for $2.7 billion.
- 2011Immunet acquisition announced
Sourcefire announced the acquisition of cloud-based antivirus company Immunet.
- 2008Barracuda acquisition offer rejected
Sourcefire rejected Barracuda Networks’ offer valued at approximately $187 million.
- 2007Initial public offering
Sourcefire completed an IPO in March and raised $86.3 million.
- 2007Clam AntiVirus acquisition
Sourcefire acquired Clam AntiVirus, broadening its open-source security and malware-scanning capabilities.
- 2005Check Point acquisition proposal is withdrawn
Check Point Software Technologies pursued a $225 million acquisition but later withdrew after regulatory concerns emerged.
- 2001Sourcefire is founded
Martin Roesch founded Sourcefire to commercialize Snort and develop enterprise network security products around the open-source intrusion detection technology.
Products and positioning
Enterprise and government cybersecurity vendor combining open-source detection technology with commercial network security appliances, malware protection, research, and support.
SnortOpen-source intrusion detection and prevention
Snort is an open-source network intrusion detection and prevention system developed by Martin Roesch and maintained through a broader security community. It uses rules and multiple inspection techniques to identify suspicious traffic, protocol misuse, known attack patterns, and anomalous behavior. Sourcefire built its commercial business around Snort, while the project remained important to researchers, administrators, and security vendors. Snort rules also supplied a foundation for protections distributed to Sourcefire customers.
Sourcefire 3D SystemNetwork security platform
The Sourcefire 3D System was the company’s commercial platform for deploying and managing Snort-based network protection. It combined network sensors, centralized management, event analysis, and security policy functions. The platform represented Sourcefire’s transition from an open-source detection engine to an enterprise product suite and later provided the technological basis for the FirePOWER product line.
FirePOWERNext-generation network security appliances
FirePOWER was Sourcefire’s principal network security appliance family. It supported next-generation intrusion prevention and, in relevant configurations, next-generation firewall functions. Capabilities included application and access control, malware prevention, URL filtering, network visibility, and inspection of users, hosts, operating systems, services, protocols, content, and behavior. The line was designed as a layered defense rather than as a single-purpose signature-based intrusion sensor.
Sourcefire Advanced Malware ProtectionAdvanced malware protection
Advanced Malware Protection used cloud security intelligence and large-scale analytics to analyze suspicious files and activity across networks and endpoints. Its approach included malware detection, blocking, continuous analysis, and retrospective alerting, allowing a customer to be notified when later intelligence changed the assessment of previously observed content. The technology was offered through FirePOWER appliances and endpoint-oriented products.
FireAMPEndpoint malware protection
FireAMP was the endpoint-oriented deployment of Sourcefire’s advanced malware protection approach. It extended cloud-assisted analysis and retrospective threat detection beyond network appliances to endpoints and other supported environments. Following the Cisco acquisition, the product’s capabilities were incorporated into Cisco’s broader endpoint and advanced malware protection offerings.
ImmunetCloud-assisted antivirus
Immunet was a cloud-oriented antivirus product acquired by Sourcefire in 2011. It used cloud-delivered virus intelligence together with ClamAV definitions and was offered in free and paid versions. Immunet Plus was later discontinued under Cisco ownership, while Immunet Free continued with Cisco support for a period.
ClamAVOpen-source antivirus engine
ClamAV is an open-source antivirus toolkit used for malware scanning, including email-gateway and Unix-oriented deployments. Sourcefire acquired the project in 2007 and used its technology and community as part of a wider malware protection strategy. ClamAV included an antivirus engine, scanning utilities, a daemon, command-line tools, and mechanisms for updating detection databases.
Flagship businesses
- Snort
- Sourcefire 3D System
- FirePOWER
- Sourcefire Advanced Malware Protection
- FireAMP
- Immunet
- ClamAV
Brand decisions
- 2014Combine Sourcefire research with Cisco security researchStrategy
Cisco sought to consolidate threat intelligence, vulnerability research, and security application teams after acquiring Sourcefire.
What changed. Sourcefire’s Vulnerability Research Team was combined with Cisco’s TRAC and SecApps groups.
Aftermath. The combined organization became Cisco Talos and continued vulnerability analysis, threat research, and security-rule development.
- 2013Sell Sourcefire to CiscoM&A
Cisco sought to expand its security portfolio with Sourcefire’s Snort technology, FirePOWER products, malware capabilities, and threat research.
What changed. Sourcefire entered into a definitive agreement to be acquired by Cisco Systems.
Aftermath. Cisco acquired the company for $2.7 billion and integrated its products and research capabilities into Cisco Security. Sourcefire ceased to operate as an independent public company.
Acquisition value. $2.7 billion (Agreement announced July 23, 2013)
- 2011Acquire ImmunetM&A
Cloud-assisted malware intelligence was becoming an important complement to appliance-based network security.
What changed. Sourcefire announced the acquisition of Immunet, a cloud-based antivirus company.
Aftermath. Immunet broadened the company’s endpoint and cloud antivirus capabilities. Immunet Plus was subsequently discontinued under Cisco ownership.
- 2007Acquire Clam AntiVirusM&A
Sourcefire was expanding beyond network intrusion prevention and needed broader malware and antivirus capabilities.
What changed. The company acquired the Clam AntiVirus project and incorporated its technology into the Sourcefire security ecosystem.
Aftermath. The acquisition strengthened Sourcefire’s open-source antivirus and malware-scanning capabilities and supported later products such as Immunet and Advanced Malware Protection.
Leadership
| Name | Title | Tenure |
|---|---|---|
| Martin Roesch | Founder and creator of Snortformer | 2001– |
Recent events
- 2014Cisco integrates Sourcefire research into Cisco Talos
Sourcefire’s Vulnerability Research Team was combined with Cisco security research groups to create Cisco Talos, a broader threat intelligence and research organization.
M&A - 2014Immunet Plus discontinued under Cisco
Immunet Plus was discontinued and the Immunet offering continued as a free product supported by Cisco.
Product generation - 2013Cisco agrees to acquire Sourcefire
Cisco announced a definitive agreement to acquire Sourcefire for $2.7 billion, bringing Snort, FirePOWER, and related security research into Cisco’s portfolio.
M&A - 2011Sourcefire announces Immunet acquisition
Sourcefire announced the acquisition of cloud-based antivirus company Immunet to strengthen cloud-assisted malware protection and endpoint security.
M&A - 2008Sourcefire rejects Barracuda Networks acquisition proposal
Sourcefire rejected Barracuda Networks’ proposal valued at approximately $187 million.
M&A - 2007Sourcefire completes initial public offering
Sourcefire went public in March 2007, raising $86.3 million and providing capital for the expansion of its commercial network security business.
Other - 2007Sourcefire acquires Clam AntiVirus
The company acquired the Clam AntiVirus project, extending its portfolio into open-source antivirus technology and malware scanning.
M&A
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/sourcefire · Editorial policy · How profiles are compiled