Skip to main content

Threat Intelligence Platforms

Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. This category covers open-source TIPs, IOC sharing communities, and STIX/TAXII tooling that feed detection and response workflows.

5 Tools Cataloged
ToolLicensePlatformsPricingAction
AlienVault OTXProprietary (service); Apache-2.0 (Python SDK)Linux, WindowsFreeProfile
IntelOwlAGPL-3.0-onlyLinuxOpen SourceProfile
MISPAGPL-3.0-or-laterLinuxOpen SourceProfile
OpenCTIApache-2.0 (Community Edition) + OpenCTI Enterprise Edition License (proprietary)LinuxFree / CommercialProfile
YetiApache-2.0LinuxOpen SourceProfile

Tools in Threat Intelligence Platforms

Open threat exchange community where researchers share and investigate threat data through Pulses (IOC bundles), a searchable portal, and a free STIX/TAXII API.

LicenseProprietary (service); Apache-2.0 (Python SDK)
PlatformLinux, Windows

IntelOwl

Open Source

Open-source threat intelligence orchestration platform that enriches files and observables through a single REST API against multiple analyzers and external services.

LicenseAGPL-3.0-only
PlatformLinux

MISP

Open Source

Threat intelligence platform for sharing, storing, and correlating indicators of compromise across security teams and SOCs.

LicenseAGPL-3.0-or-later
PlatformLinux

OpenCTI

Free / Commercial

Threat intelligence platform for organizing, storing, and visualizing STIX-based knowledge, observables, and threat actors.

LicenseApache-2.0 (Community Edition) + OpenCTI Enterprise Edition License (proprietary)
PlatformLinux

Yeti

Open Source

Open-source threat intelligence and forensics platform for storage, correlation, and export of IOCs, TTPs, and DFIR artifacts.

LicenseApache-2.0
PlatformLinux

Frequently Asked Questions

What is Threat Intelligence Platforms?

Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. This category covers open-source TIPs, IOC sharing communities, and STIX/TAXII tooling that feed detection and response workflows.

What topics does the Threat Intelligence Platforms category cover?

Threat Intelligence Platforms (TIP), IOC Sharing Communities, STIX / TAXII Protocol Tooling, Observable Enrichment Automation, Adversary Threat Feeds

About Threat Intelligence Platforms

Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. The category covers threat intelligence platforms (TIPs) that store and manage IOC data, IOC sharing communities where organizations exchange threat indicators, and orchestration tools that automate enrichment of observables against multiple data sources. OpenCTI is a graph-based TIP that models threats using STIX 2.1 and provides a web interface for analysts to explore relationships between indicators, threat actors, and campaigns. MISP is a community-driven sharing platform where organizations exchange IOCs through trusted circles, with support for STIX, OpenIOC, and custom export formats. IntelOwl orchestrates enrichment by querying a single API against dozens of analyzers and external services, automating the manual work of looking up IPs, domains, and file hashes across multiple sources. AlienVault OTX provides a free community feed of threat indicators contributed by researchers worldwide, accessible via REST API and STIX/TAXII. The category feeds detection engineering and DFIR workflows, since IOCs from threat intelligence platforms populate blocklists, detection rules, and SIEM correlation queries. Tools in this category range from open source community platforms to commercial services with curated analyst reports.

Covered Topics & Disciplines

Threat Intelligence Platforms (TIP)IOC Sharing CommunitiesSTIX / TAXII Protocol ToolingObservable Enrichment AutomationAdversary Threat Feeds