Threat Intelligence Tools
Threat intelligence platforms and software collect, correlate, and distribute indicators of compromise and adversary tradecraft data. This category covers open-source TIPs, IOC sharing communities, and STIX/TAXII tooling that feed detection and response workflows.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Abuse.ch Threat Feeds | Proprietary | Web | Freemium | Profile→ |
| AlienVault OTX | Proprietary (service); Apache-2.0 (Python SDK) | Linux, Windows | Free | Profile→ |
| Hunt.io | Proprietary | Web | Commercial | Profile→ |
| IntelOwl | AGPL-3.0-only | Linux | Open Source | Profile→ |
| MISP | AGPL-3.0-or-later | Linux | Open Source | Profile→ |
| OpenCTI | Apache-2.0 (Community Edition) + OpenCTI Enterprise Edition License (proprietary) | Linux | Free / Commercial | Profile→ |
| Recorded Future | Proprietary | Web | Commercial | Profile→ |
| Vertex Synapse | Apache-2.0 | Linux, Web | Free / Commercial | Profile→ |
| Yeti | Apache-2.0 | Linux | Open Source | Profile→ |
Software in Threat Intelligence Tools
Abuse.ch Threat Feeds
FreemiumCommunity threat intel family: URLhaus, MalwareBazaar, ThreatFox, and YARAify, in partnership with Spamhaus.
AlienVault OTX
FreeOpen threat exchange community where researchers share and investigate threat data through Pulses (IOC bundles), a searchable portal, and a free STIX/TAXII API.
Hunt.io
CommercialPlatform for hunting adversary infrastructure, from exposed C2 panels to phishing and stealer endpoints.
IntelOwl
Open SourceOpen-source threat intelligence orchestration platform that enriches files and observables through a single REST API against multiple analyzers and external services.
MISP
Open SourceThreat intelligence platform for sharing, storing, and correlating indicators of compromise across security teams and SOCs.
OpenCTI
Free / CommercialThreat intelligence platform for organizing, storing, and visualizing STIX-based knowledge, observables, and threat actors.
Recorded Future
CommercialAI-driven threat intelligence platform with sandboxing, now a Mastercard subsidiary.
Vertex Synapse
Free / CommercialAnalytic platform for object-driven threat analysis with an open source core and enterprise edition.
Yeti
Open SourceOpen-source threat intelligence and forensics platform for storage, correlation, and export of IOCs, TTPs, and DFIR artifacts.
Frequently Asked Questions
What is Threat Intelligence Tools?→
Threat intelligence platforms and software collect, correlate, and distribute indicators of compromise and adversary tradecraft data. This category covers open-source TIPs, IOC sharing communities, and STIX/TAXII tooling that feed detection and response workflows.
What topics does the Threat Intelligence Tools category cover?→
Threat Intelligence Platforms (TIP), IOC Sharing Communities, STIX / TAXII Protocol Tooling, Observable Enrichment Automation, Adversary Threat Feeds
About Threat Intelligence Tools
Threat intelligence platforms collect, correlate, and distribute indicators of compromise and adversary tradecraft data. The category covers threat intelligence platforms (TIPs) that store and manage IOC data, IOC sharing communities where organizations exchange threat indicators, and orchestration tools that automate enrichment of observables against multiple data sources. OpenCTI is a graph-based TIP that models threats using STIX 2.1 and provides a web interface for analysts to explore relationships between indicators, threat actors, and campaigns. MISP is a community-driven sharing platform where organizations exchange IOCs through trusted circles, with support for STIX, OpenIOC, and custom export formats. IntelOwl orchestrates enrichment by querying a single API against dozens of analyzers and external services, automating the manual work of looking up IPs, domains, and file hashes across multiple sources. AlienVault OTX provides a free community feed of threat indicators contributed by researchers worldwide, accessible via REST API and STIX/TAXII. The category feeds detection engineering and DFIR workflows, since IOCs from threat intelligence platforms populate blocklists, detection rules, and SIEM correlation queries. Tools in this category range from open source community platforms to commercial services with curated analyst reports.
Covered Topics & Disciplines
Related Security Categories
Disk and memory forensics, malware sandboxes, and incident response collection platforms.
Reconnaissance frameworks, attack-surface discovery engines, and public-data enrichment platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.