Threat Intelligence Platforms
Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. This category covers open-source TIPs, IOC sharing communities, and STIX/TAXII tooling that feed detection and response workflows.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| AlienVault OTX | Proprietary (service); Apache-2.0 (Python SDK) | Linux, Windows | Free | Profile→ |
| IntelOwl | AGPL-3.0-only | Linux | Open Source | Profile→ |
| MISP | AGPL-3.0-or-later | Linux | Open Source | Profile→ |
| OpenCTI | Apache-2.0 (Community Edition) + OpenCTI Enterprise Edition License (proprietary) | Linux | Free / Commercial | Profile→ |
| Yeti | Apache-2.0 | Linux | Open Source | Profile→ |
Tools in Threat Intelligence Platforms
AlienVault OTX
FreeOpen threat exchange community where researchers share and investigate threat data through Pulses (IOC bundles), a searchable portal, and a free STIX/TAXII API.
IntelOwl
Open SourceOpen-source threat intelligence orchestration platform that enriches files and observables through a single REST API against multiple analyzers and external services.
MISP
Open SourceThreat intelligence platform for sharing, storing, and correlating indicators of compromise across security teams and SOCs.
OpenCTI
Free / CommercialThreat intelligence platform for organizing, storing, and visualizing STIX-based knowledge, observables, and threat actors.
Yeti
Open SourceOpen-source threat intelligence and forensics platform for storage, correlation, and export of IOCs, TTPs, and DFIR artifacts.
Frequently Asked Questions
What is Threat Intelligence Platforms?→
Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. This category covers open-source TIPs, IOC sharing communities, and STIX/TAXII tooling that feed detection and response workflows.
What topics does the Threat Intelligence Platforms category cover?→
Threat Intelligence Platforms (TIP), IOC Sharing Communities, STIX / TAXII Protocol Tooling, Observable Enrichment Automation, Adversary Threat Feeds
About Threat Intelligence Platforms
Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. The category covers threat intelligence platforms (TIPs) that store and manage IOC data, IOC sharing communities where organizations exchange threat indicators, and orchestration tools that automate enrichment of observables against multiple data sources. OpenCTI is a graph-based TIP that models threats using STIX 2.1 and provides a web interface for analysts to explore relationships between indicators, threat actors, and campaigns. MISP is a community-driven sharing platform where organizations exchange IOCs through trusted circles, with support for STIX, OpenIOC, and custom export formats. IntelOwl orchestrates enrichment by querying a single API against dozens of analyzers and external services, automating the manual work of looking up IPs, domains, and file hashes across multiple sources. AlienVault OTX provides a free community feed of threat indicators contributed by researchers worldwide, accessible via REST API and STIX/TAXII. The category feeds detection engineering and DFIR workflows, since IOCs from threat intelligence platforms populate blocklists, detection rules, and SIEM correlation queries. Tools in this category range from open source community platforms to commercial services with curated analyst reports.
Covered Topics & Disciplines
Related Security Categories
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Disk and memory forensics, malware sandboxes, and incident response collection platforms.
Reconnaissance frameworks, attack-surface discovery engines, and public-data enrichment platforms.