Best Threat Intelligence Tools

    Compare and discover the best Threat Intelligence software and tools for your team. Find the right solution for your needs.

    133 vendors
    0din by Mozilla logo

    0din by Mozilla

    AI Security Posture (AI-SPM)
    4 products

    the pioneering GenAI bug bounty platform designed to safeguard the future of artificial intelligence

    Automated vulnerability detectionCustom security boundary testingReal-time threat monitoring+3
    360 Privacy logo

    360 Privacy

    Privacy & Consent Management
    4 products

    360 Privacy was founded to reduce the critical gap between cybersecurity and real-world protection, securing personal data that puts high-profile people, families, and companies at risk.

    Centralized consent registerConsent record mapping and normalizationConsent provenance and audit trail+9
    7AI logo

    7AI

    Agentic SOC & Investigations
    6 products

    7AI is the foundational AI security company. Founded in 2024 by Cybereason co-founders Lior Div and Yonatan Striem-Amit, 7AI came out of stealth in February 2025 to take on the non-human work of the SOC, with AI agents that detect, investigate, respond, and hunt, and humans on the loop.

    AI-powered Alert Triage & EnrichmentAutonomous InvestigationsAutomated Remediation+1
    AbuseIPDB logo

    AbuseIPDB

    Threat Intelligence
    5 products

    AbuseIPDB provides high-fidelity IP reputation data and a massive crowd-sourced database of reported malicious infrastructure. It offers a high-performance API and on-premises feeds used for real-time traffic analysis, automated enrichment in SOC workflows, and blocking of known bad actors. This platform complements SIEM and SOAR systems by providing the contextual intelligence needed to identify botnets, scanners, and brute-force actors before they breach the network.

    Report abusive IP addressesCheck IP reputation historyMaintain a crowdsourced blacklist+8
    Abusix logo

    Abusix

    Email Security
    4 products

    Abusix is the essential solution in today's network security landscape, enabling fast and reliable mitigation of network abuse and cyber threats.

    Commercial DNSBL for email threat blockingReal-time IP and domain threat intelligenceAutomated spam and phishing detection+7
    Alpha Level logo

    Alpha Level

    Threat Intelligence
    3 products

    Alpha Level is a next-generation cybersecurity company transforming how Security Operations Centers (SOCs) detect and respond to threats. Alpha Level combines statistical modeling, anomaly detection, and agentic AI to filter out non-actionable alerts, surface rare and high-risk behaviors, and provide contextualized evidence for investigation. The result is a data-driven, behavior-based detection system that improves signal quality while reducing cost.

    Automated alert triage and classificationDeterministic alert classification without hallucinationSelf-learning feedback mechanism+5
    A

    alphaMountain.ai

    Threat Intelligence
    3 products

    alphaMountain.ai provides AI-driven domain and IP threat intelligence focuses on web reputation and content classification. Utilizing proprietary machine learning, it offers real-time detection of malicious sites, phishing domains, and risky infrastructure through high-speed APIs and feeds. It is typically integrated into web gateways, SIEMs, and firewalls to provide a dynamic layer of categorization and risk assessment for internet-bound traffic.

    Domain and IP reputation scoringURL classification by content categoryContextual enrichment for hosts+7
    Anomali logo

    Anomali

    Threat Intelligence
    4 products

    Anomali ThreatStream is a threat intelligence platform that aggregates IOCs and IOAs from hundreds of global sources including Anomali Labs curated feeds, OSINT, premium feeds, and ISACs. It enriches telemetry via automated correlation, campaign analysis, and ML-based scoring for confidence and severity. The Next-Gen version integrates agentic AI for natural language queries via Anomali Copilot, MITRE ATT&CK mapping, and pushes high-confidence intelligence into SIEM, SOAR, EDR, and firewall workflows. Trusted by enterprises and governments for over a decade, it accelerates investigations 300x faster, ideal for CTI and SOC teams operationalizing intelligence at scale.

    Aggregate and curate global threat intelligenceEnrich security data with threat contextCorrelate IOCs with internal telemetry+9
    ANY.RUN logo

    ANY.RUN

    Threat Intelligence
    1 product

    ANY.RUN helps security teams detect malware and phishing earlier and respond with confidence. It combines real-time interactive analysis with threat intelligence from live attacks, delivering immediate visibility into behavior, indicators, and active campaigns. This helps SOCs and MSSPs assess risk faster, reduce uncertainty, and act without delays. ANY.RUN fits into SOC workflows across monitoring, triage, incident response, and threat hunting.

    Threat intelligence lookup serviceIOC and TTP searchThreat intelligence feeds+8
    Arctic Security logo

    Arctic Security

    Vulnerability Management
    5 products

    Arctic EWS provides a comprehensive and international early warning service for distributed organizations, expanding on the scope of services available from the government. Our service lets you split your organization into areas of responsibility, and automatically routes the security warnings to the right people. Our monitoring can also cover your suppliers.

    Continuous vulnerability monitoringActive vulnerability scanning with NessusAutomatic discovery of connected devices+7
    ArmorPoint logo

    ArmorPoint

    Managed Detection & Response (MDR)
    7 products

    ArmorPoint is a cloud-native managed security operations platform built for midsize enterprises and the partners who serve them. The platform brings detection, response, risk, and compliance together within a shared operations environment where customers, partners, and ArmorPoint's 24/7 U.S.-based SOC work side by side.

    24x7x365 professional SOC team performing continuous monitoring, alert investigation, validation, and escalation to incident with SANS-based incident response protocolsCloud-based SIEM correlating EDR telemetry, network sensor data, syslog, API integrations, and identity/cloud activity to visualize full attack stories from root cause across endpoints, devices, users, applications, and cloud deploymentsHuman-led response efforts including remote quarantining, isolating, and eradicating threats on in-scope endpoints and servers via ArmorPoint-managed EDR agents+5
    AttackIQ logo

    AttackIQ

    Penetration Testing & Red Team
    7 products

    The leading platform for Adversarial Exposure Validation (AEV) We help security teams make better decisions by continuously measuring how adversaries can exploit gaps across people, processes, and technology.

    Automate adversary emulation testsMITRE ATT&CK-aligned attack scenariosRed team augmentation workflows+9
    Axur logo

    Axur

    Digital Risk & Executive Protection
    9 products

    Axur focuses on External Threat Protection (ETP) and brand protection by monitoring the digital landscape for brand abuse, data leaks, and fraudulent activities. The platform automates the detection and takedown of phishing sites, unauthorized apps, and leaked credentials across the deep, dark, and open web. It complements internal security controls by mitigating risks that originate outside the traditional network perimeter.

    AI-driven threat intelligence mappingExternal threat monitoring and analysisThreat alert filtering and enrichment+9
    Beazley Security logo

    Beazley Security

    Security Operations
    5 products

    Beazley Security is a cyber risk management vendor whose Security Operations offering centers on managed detection and response plus exposure management. Its MXDR service provides always-on monitoring, threat identification, and containment across endpoints, networks, cloud services, identity, and email, while exposure management continuously inventories external assets and prioritizes known-exploited vulnerabilities. The company is positioned for organizations that want operational security support from a team that combines incident response, forensics, and risk intelligence with insurance heritage. It is best suited for buyers seeking a managed SOC-style service rather than a standalone software tool.

    Managed extended detection and responseIncident response and containmentForensics and restoration services+8
    Binary Defense logo

    Binary Defense

    Managed Detection & Response (MDR)
    5 products

    Binary Defense delivers a human-led, 24x7x365 Managed Detection & Response (MDR) service that detects and isolates threats early in the attack lifecycle using behavioral-based detections and an attacker’s mindset. Their Security Operations Center analysts triage, disposition, and prioritize events, conduct full kill chain analysis, and provide tactical and strategic mitigation recommendations. Best suited for organizations needing an extension of their security team, whether they have an existing team or none, Binary Defense MDR operates as a cloud-based, tool-agnostic service integrated via their BD Platform. The vendor also offers adjacent capabilities like MDR Plus with managed deception and malware disruption, but core MDR focuses on analyst-driven monitoring and response.

    24x7x365 SOC monitoring of endpoints, servers, and cloud resources using behavioral-based detections to identify anomalies, lateral movement, privilege escalation, and PowerShell injectionAnalyst-driven triage, disposition, and prioritization of security events with full kill chain analysis to determine threat scope and impactContinuous analytic threat hunting that actively searches for hidden threats and vulnerabilities using collective intelligence and real-time threat pattern adaptation+5
    Bitglass logo

    Bitglass

    CASB (Cloud Access Security Broker)
    6 products

    Bitglass provides a multi-mode CASB that secures SaaS applications, IaaS instances, data lakes, and private apps via forward proxy, reverse proxy, and API integrations. It delivers real-time data protection and threat prevention using machine-learning to adapt to new cloud apps, malware, and user behaviors. The agentless architecture offers end-to-end visibility, prevents data leakage, and limits external sharing. As part of its integrated SASE platform with SmartEdge SWG and ZTNA, Bitglass suits enterprises adopting cloud and BYOD while addressing compliance gaps in dynamic environments.

    Multi-mode cloud access controlAgentless cloud securityReal-time data protection+8
    BitSight logo

    BitSight

    Compliance & GRC
    12 products

    Risk now moves across enterprises, supply chains, cloud environments, and digital identities, and AI is accelerating how quickly vulnerabilities can be exploited. Bitsight continuously maps assets and vulnerabilities, prioritizing them with real-time threat intelligence so teams can see where risk is building, focus on what matters, and act before exposure becomes disruption.

    Third-party risk monitoring and onboardingGovernance analytics and control insightsCompliance reporting and audit readiness+8
    BlackBerry CylancePROTECT logo

    BlackBerry CylancePROTECT

    Endpoint Detection & Response (EDR)
    1 product

    BlackBerry® equips governments, critical industries and leading automakers with secure, reliable software that drives productivity, resilience, and mission-critical performance.

    Machine-learning malware preventionEndpoint breach preventionBehavioral threat detection+8
    BlinkOps logo

    BlinkOps

    Agentic SOC & Investigations
    9 products

    BlinkOps is an agentic security automation platform that utilizes AI-driven agents to handle end-to-end security operations tasks including alert triage, investigation, and incident containment. It replaces traditional, manual SOAR playbooks with LLM-powered agents that can interpret natural language instructions to execute complex workflows across disparate security tools. The platform provides a low-code/no-code interface for building scalable security automations that reduce Mean Time to Respond (MTTR).

    AI agents investigate incoming alertsNatural-language investigations and responseHuman-built workflows with guardrails+6
    Cellebrite logo

    Cellebrite

    Threat Intelligence
    6 products

    Cellebrite is the global leader in partnering with public and private organizations to transform how data is managed in investigations to protect and save lives, accelerate justice and ensure data privacy.

    Digital evidence extractionCross-device intelligence correlationThreat network mapping+8
    Censys logo

    Censys

    Attack Surface Management
    5 products

    Censys provides Attack Surface Management focused on external internet visibility: it continuously scans the public Internet, attributes discovered assets to an organization, and tracks changes in hosts, ports, certificates, services, and exposures. In this category it is known for its Internet-scale dataset, near-real-time exposure monitoring, and evidence-based prioritization of externally reachable risks. It is best suited for security teams that need to discover unknown internet-facing assets, confirm what attackers can actually reach, and route remediation into existing workflows. Censys also sells adjacent products, but this profile is limited to ASM capabilities.

    Continuous internet exposure discoveryFirst-party internet scanningAsset attribution and ownership mapping+9
    C

    Center for Internet Security (CIS)

    Compliance & GRC
    6 products

    The Center for Internet Security (CIS) provides Hardened Images and configuration benchmarks that serve as the industry standard for securing cloud operating systems and infrastructure. Their virtual machine images are pre-configured to meet CIS Benchmark standards, providing a secure baseline for AWS, Azure, and GCP environments out of the box. They complement CSPM tools by providing the gold-standard configurations used for compliance auditing and system hardening.

    CIS Hardened Images for cloud workloadsCSPM posture monitoring and assessmentCIS Benchmarks-based configuration guidance+3
    CertiK logo

    CertiK

    Blockchain Security
    9 products

    Founded in 2017 by professors from Columbia and Yale, CertiK is a New York-based leader in Web3 security.

    Smart contract audits for blockchain securityFormal verification of smart contractsOn-chain monitoring with Skynet+9
    Chainalysis logo

    Chainalysis

    Blockchain Security
    9 products

    Chainalysis is the blockchain data platform. We provide data, AI-powered software, services, and research to government agencies, exchanges, financial institutions, and cybersecurity companies in over 70 countries.

    Real-time transaction monitoring and threat detectionWallet address labeling for scam and mixer identificationCross-chain visibility for exploit detection+7
    Check Point logo

    Check Point

    Cloud Security / CSPM
    7 products

    Check Point Software Technologies is a global leader in cyber security solutions, dedicated to protecting corporate enterprises and governments worldwide.

    Multi-cloud posture managementCompliance policy assessmentContinuous compliance monitoring+9
    Cisco logoC

    Cisco

    Zero Trust / SASE / SSE
    14 products

    Cisco Umbrella is a cloud-delivered Security Service Edge (SSE) solution that enforces zero trust by continuously verifying identity, device posture, and context before granting access to applications. It converges multiple security functions, secure web gateway, firewall-as-a-service, cloud access security broker, and zero trust network access, into a unified cloud platform. Cisco Umbrella serves enterprises requiring distributed security across remote workers, branch offices, and on-premises infrastructure without complete network architecture overhauls.

    CASBCisco SD-WAN integrationCloud access security broker protection+15
    Cloudmark logo

    Cloudmark

    Email Security
    7 products

    Cloudmark, now part of Proofpoint, delivers carrier-grade email security primarily for service providers and large-scale messaging environments, protecting over 1.6 billion mailboxes globally. Its Cloudmark Platform for Email automatically detects and mitigates spam, phishing, malware, and other email-borne threats using patented content fingerprinting, URL/CTA analysis, and machine learning. The solution functions as a high-performance mail transfer agent (MTA) integrated at the network edge, offering flexible policy controls and an integrated reputation system. While Cloudmark also supports mobile and rich communications, its core Email Security role targets telecom operators and hosted email providers requiring near-zero false positives and real-time threat blocking.

    Patented message and content fingerprinting technology analyzes email payloads to identify and block known spam and malware variants with high accuracy across SMTP traffic.Call-To-Action (CTA) and URL analysis inspects embedded links in real time to detect malicious destinations and phishing attempts before delivery to end users.Machine learning and predictive AI models automate threat detection by correlating global threat intelligence from over a billion subscribers with local behavioral patterns.+5
    C

    CloudSEK Research Pte. Ltd.

    Threat Intelligence
    6 products

    CloudSEK is a digital risk protection platform (DRPP) that utilizes AI to monitor the deep, dark, and open web for external threats. It provides automated detection of leaked credentials, brand impersonation, and exposed infrastructure to quantify digital risk. The platform complements internal SOC operations by providing an external-facing view of an organization's attack surface and supply chain vulnerabilities.

    Real-time threat intelligence monitoringThreat signal aggregation and analysisContextual AI threat prediction+6
    Cofense logo

    Cofense

    Security Awareness & Phishing Simulation
    5 products

    Smarter Phishing Defense. Stronger Human Security.

    Post-delivery phishing threat detectionThreat remediation and containmentHigh-confidence alert triage+9
    Cognyte logo

    Cognyte

    Threat Intelligence
    5 products

    We are a market leader in investigative analytics software that empowers a variety of government and other organizations with Actionable Intelligence for a Safer World™.

    External threat intelligence collectionActionable threat insights generationThreat data correlation and pattern analysis+8
    Cotool logo

    Cotool

    Agentic SOC & Investigations
    4 products

    Cotool is our vision of how security work should be: faster, simpler, and less exhausting.

    AI co-pilot for investigationsNo-code security agent builderAutomated security documentation+4
    CounterCraft logo

    CounterCraft

    Deception Technology
    1 product

    CounterCraft provides the Cyber Deception Platform, a scalable distributed system that deploys digital twin replicas of organizational IT and OT environments to lure attackers into controlled decoys. It captures adversary tactics, techniques, and procedures via kernel-level implants and ActiveBehavior automation, which simulates user logins and activities to maintain authenticity. The platform delivers zero-false-positive alerts and real-time threat intelligence through stealthy ActiveLink exfiltration. Trusted by governments, nation-states, and Fortune 500 enterprises in finance and critical infrastructure, it detects targeted attacks within weeks of deployment, ideal for organizations needing proactive defense against sophisticated threats.

    Replicate the network as a digital twinDeploy high-interaction decoysDetect attackers during early activity+8
    Criminal IP logo

    Criminal IP

    Threat Intelligence
    3 products

    Criminal IP delivers Decision-Ready Intelligence powered by AI and OSINT, enabling precise threat analysis and deep investigations into IPs, domains, and URLs with reputation data, threat scoring, along with real-time detection of malicious indicators such as C2, IOCs, and other critical threats. Its API is designed to integrate seamlessly with workflows SIEM, SOAR, and XDR for enhanced visibility and automation.

    IP address threat analysisReal-time global IP and domain intelligenceMalicious domain and phishing detection+6
    CrowdStrike logo

    CrowdStrike

    Endpoint Detection & Response (EDR)
    12 products

    CrowdStrike secures the most critical areas of risk – endpoints and cloud workloads, identity, and data – to keep customers ahead of today's adversaries and stop breaches.

    Adversary intelligence profilesAI application discovery and governanceBehavioral detection with IOAs+12
    Cybereason logo

    Cybereason

    Endpoint Detection & Response (EDR)
    10 products

    Cybereason provides Endpoint Detection and Response (EDR) that correlates endpoint telemetry across machines into MalOp™ narratives, revealing full attack chains from initial compromise to lateral movement. It uses behavioral analysis, machine learning on threat feeds ranked by historical accuracy, and cross-machine correlation for real-time detection of sophisticated threats. The platform supports instant remediation like process termination, file quarantine, persistence removal, and machine isolation. Best for enterprises needing high analyst efficiency (1:200,000 endpoint ratio) and advanced threat hunting without alert fatigue, as validated by top Forrester Wave and MITRE ATT&CK scores.

    Behavioral detection of malicious activityAutomated endpoint threat huntingOne-click endpoint remediation+8
    Cybersixgill logo

    Cybersixgill

    Threat Intelligence
    1 product

    Cybersixgill is a deep and dark web threat intelligence provider acquired by Bitsight, delivering automated collection and analysis across cybercriminal underground forums, markets, and messaging platforms. The platform serves Fortune 500 companies, financial institutions, governments, and law enforcement with real-time IOC feeds, threat actor profiling, and vulnerability exploit scoring. Cybersixgill indexes historical data from the 1990s and monitors 95+ million threat actor profiles to enable proactive threat detection and remediation.

    Automated deep and dark web collectionReal-time risk and threat alertsThreat actor and peer network profiling+8
    Cyble logo

    Cyble

    Threat Intelligence
    1 product

    Cyble is an AI-native threat intelligence provider that delivers deep visibility into dark web activities, brand exposure, and digital risks. The platform automates the collection and analysis of leak sites, underground forums, and cybercrime chatter to provide actionable intelligence. It complements existing SOC workflows by providing external context that helps prioritize internal alerts and block emerging threats proactively.

    AI-Powered Threat Intelligence with Blaze AIDeep, Dark, and Surface Web MonitoringReal-Time Data Leak and Breach Detection+6
    CybrHawk logo

    CybrHawk

    Agentic SOC & Investigations
    6 products
    Verified

    CybrHawk is a leading provider of cybersecurity solutions. Our offerings help organizations to get their cyber-defences attuned to stall, manage, mitigate and prevent breaches. Our solutions help detect real time suspicious activities and respond quickly to prevent breaches besides predicting possible threats. Our solutions are designed to get better off the problems.

    Natural-language SOC investigationAI-assisted alert triageThreat investigation and response automation+6
    CyCognito logo

    CyCognito

    Attack Surface Management
    4 products

    CyCognito empowers companies to take full control over their attack surface by taking the attacker's view to uncover and fix critical security risks.

    Seedless external asset discoveryBusiness context asset mappingContinuous exploitability validation+6
    CYJAX logo

    CYJAX

    Threat Intelligence
    5 products

    Real-time threat intelligence, curated analysis, and actionable insights. All in one unified platform.

    Filters and summarizes global threat dataAnalyst-enriched threat intelligence feedsReal-time web and Darknet monitoring+7
    CyLock logo

    CyLock

    Vulnerability Management
    5 products

    I could not verify a CyLock vulnerability management product from the provided search results or from the information available to me here. The sources returned in the query do not include an official CyLock product page, technical documentation, pricing, or integration list. For a CISO evaluating vulnerability management, that means I cannot factually describe CyLock’s scanner coverage, prioritization logic, remediation workflow, or deployment model without inventing details. If CyLock is a private vendor, its public footprint appears too limited in the supplied material to support a reliable profile.

    Website vulnerability assessmentIT system vulnerability testingSimulated attack execution+1
    Cyware logo

    Cyware

    Threat Intelligence
    6 products

    Cyware enables security teams at leading global organizations to operationalize threat intelligence data and execute real-time actions by integrating intelligence management, automating workflows, and promoting secure collaboration for a stronger, unified defense.

    Automated threat feed ingestion and enrichmentAgentic AI-driven threat lifecycle automationBi-directional threat intelligence sharing across communities+6
    Dataminr logo

    Dataminr

    Threat Intelligence
    5 products

    DarkInvader is a modern cyber security company specialising in External Attack Surface Management (EASM). For over three years, we've been developing a cutting-edge SaaS solution that empowers organisations to discover and monitor their assets, identify infrastructure and Web application vulnerabilities, and monitor surface Web and Dark Web OSINT.

    Multi-Modal Threat DetectionCollection at Massive ScaleProprietary Knowledge Graph+6
    DeepWatch logo

    DeepWatch

    Managed Detection & Response (MDR)
    7 products

    Deepwatch® is the leader in Precision MDR powered by AI and humans. We amplify human expertise with AI insights to reduce the risks that matter most to your business.

    AI-powered Threat Detection and ResponseIntegrated Security Operations24/7/365 Expert Monitoring and Response+1
    Detectify logo

    Detectify

    Attack Surface Management
    6 products

    Detectify is the application security platform that gives modern security teams ultimate control over their actual attack surface, delivering proprietary vulnerability data designed for both humans and agents.

    Continuously monitor external attack surfaceDiscover subdomains and web assetsMap domains, DNS records, IPs, ports, certificates+8
    Digital Shadows SearchLight logo

    Digital Shadows SearchLight

    Threat Intelligence
    1 product

    Digital Shadows SearchLight is a digital risk protection service that monitors over 100 million data sources across the open, deep, and dark web in 27 languages for cyber threats, data exposure, brand abuse, infrastructure vulnerabilities, physical threats, VIP exposure, and third-party risks. It combines scalable data analytics with human intelligence analysts to triage alerts, prioritize risks, and provide remediation options including managed takedowns. Tailored for enterprises, it integrates with Microsoft Sentinel for alert synchronization and triage, Splunk for data ingestion, and ThreatConnect for threat actor correlation, offering comprehensive external attack surface visibility.

    Monitor open, deep, and dark web sourcesTailored threat intelligence alertsThreat actor and intelligence repository access+9
    DNIF logo

    DNIF

    SIEM
    2 products

    Securing your digital world with trusted expertise and ease.

    Real-time security event monitoringLog normalization and mappingThreat correlation and noise reduction+5
    Dragos logo

    Dragos

    OT & ICS Security
    7 products

    We make the industry's most intelligent and intuitive cybersecurity platform for Operational Technology (OT). Customers gain visibility, monitoring, and threat management for the OT, IT, and IoT assets within industrial environments, powered by continuous insights from Dragos's threat intelligence and services team.

    OT and IoT asset visibilityNetwork security monitoring for OT environmentsIntelligence-driven threat detection+7
    EclecticIQ Platform logo

    EclecticIQ Platform

    Threat Intelligence
    4 products

    EclecticIQ is a global provider of threat intelligence technology and services. Guided by our values, being curious, bold, accountable, and collaborative, we help security teams make smarter, faster decisions with dynamic solutions that reduce complexity and streamline threat detection and response.

    Define and capture intelligence requirementsIngest feeds and custom threat dataNormalize intelligence to STIX 2.1 and EIQ-JSON+7
    ESET logo

    ESET

    Email Security
    14 products

    ESET Mail Security provides multilayered protection for Microsoft Exchange servers, scanning mailboxes, public folders, and hybrid Microsoft 365 environments. It uses proprietary anti-spam engines with SPF/DKIM validation, backscatter protection, and SMTP safeguards, alongside anti-malware scanning for attachments including corrupted or password-protected archives. A 64-bit architecture supports clustering for high-performance mail processing. Optional modules include Advanced Threat Defense and LiveGuard for suspicious emails. Best suited for organizations prioritizing on-premises Exchange security with remote management via ESET PROTECT console and comprehensive rule-based filtering.

    Spam filtering for inbound mailPhishing link detectionMalicious attachment detection+8
    Filigran logo

    Filigran

    Threat Intelligence
    1 product

    Filigran is a cybertech company specializing in open-source-centric threat intelligence and cybersecurity simulation platforms. Its core offerings, including OpenCTI and OpenBAS, allow organizations to manage complex cyber threat intelligence (CTI) and validate their security posture through automated breach and attack simulations. The platform helps SOC teams structure raw threat data into actionable insights and operationalize threat hunting within existing security stacks.

    Collect and correlate threat dataStore and organize threat intelligenceVisualize threat environment data+8
    Flare logo

    Flare

    Threat Intelligence
    7 products

    the Flare identity-first cyber threat intelligence SaaS platform combines proprietary world-class collection from across the dark and clear web with radical ease-of-use, empowering organizations to proactively detect, prioritize, and respond to external threats, ultimately reducing risk exposure and enhancing overall cyber resilience.

    Identity-first threat intelligence detectionDark web and stealer log monitoringIntelligence Browser for threat actor research+6
    Flashpoint logo

    Flashpoint

    Threat Intelligence
    5 products

    Harness the power of data, human expertise, and automated analysis with Flashpoint's threat intelligence platform. Identify and remediate risk and take rapid, decisive action against cyber threats, fraud, vulnerability, physical, and national security threats.

    Deep and dark web searchThreat actor monitoring and profilingFinished intelligence reporting+8
    Fortinet logo

    Fortinet

    Firewall / NGFW
    9 products

    Fortinet’s FortiGate line is the company’s Firewall/NGFW offering, covering stateful firewalling, application control, IPS, web filtering, SSL/TLS inspection, and threat-intelligence-backed blocking. It is widely deployed from branch and edge sites to enterprise perimeter and segmentation use cases, with hardware, virtual, and cloud form factors managed through the same Fortinet policy stack. Buyers typically choose it when they need firewall enforcement plus inline inspection and VPN capability in one appliance, especially in environments that already use FortiGuard threat feeds or the Fortinet Security Fabric. Adjacent products include SD-WAN and ZTNA, but those are not the core scope here.

    Next-generation firewall inspectionIntrusion prevention systemApplication control policies+8
    F-Secure (now WithSecure Elements) logo

    F-Secure (now WithSecure Elements)

    Deception Technology
    2 products

    WithSecure (formerly F-Secure) Elements is a cloud-native endpoint protection platform (EPP) focused on defending endpoints across Windows, macOS, Linux, Citrix, iOS, and Android against ransomware, exploits, fileless attacks, and zero-day threats. It integrates vulnerability management, automated patch management, DeepGuard behavioral analysis, and security cloud threat intelligence within a unified Elements console. Best suited for mid-sized enterprises seeking modular XDR capabilities with single-agent deployment for comprehensive endpoint visibility and response, without deception technology features.

    Endpoint protection against ransomware and exploitsSingle endpoint agent deploymentThreat visibility and event search+9
    GreyNoise logo

    GreyNoise

    Threat Intelligence
    1 product

    Our mission is to collect the most diverse primary scanning and exploitation data, and transform it into the most actionable intelligence for defenders, so that no attack works twice.

    Internet background noise filteringReal-time scan activity monitoringBenign versus malicious IP classification+8
    Group-IB logo

    Group-IB

    Threat Intelligence
    1 product

    Group-IB is a leading creator of predictive cybersecurity technologies to investigate, prevent and fight digital crime globally

    Enrich SIEM alerts with threat intelligencePublish IOCs and IOAs to security toolsMonitor supplier leaks and exposed assets+8
    H

    HackNotice

    Threat Intelligence
    1 product

    HackNotice is a service that notices trends and patterns in publically available data so as to identify possible data breaches, leaks, hacks, and other data incidents on behalf of our clients.

    Real-time attacker activity monitoringDark web and breach database monitoringRansomware attack tracking+8
    IBM QRadar logo

    IBM QRadar

    SIEM
    1 product

    IBM Security QRadar SIEM is a security information and event management platform that collects, normalizes, and correlates log and network flow data from thousands of on-premises, hybrid, and cloud sources. It uses the Sense Analytics Engine for real-time threat detection via correlation rules, behavioral anomaly identification, and integration with over 700 pre-built device connectors. Complementary modules include Risk Manager, Vulnerability Manager, and Incident Forensics. Available as cloud-native SaaS with Sigma community rules and machine learning-based risk scoring. Best suited for large enterprises requiring scalable SOC operations and compliance reporting.

    Centralized security log collectionEvent normalization and correlationNetwork flow and log source consolidation+6
    Infrawatch logo

    Infrawatch

    Threat Intelligence
    1 product

    Infrawatch is the intelligence layer for internet infrastructure. We combine real-time, multi-source data with behavioural analysis to give security teams deep visibility into malicious infrastructure before it’s operationalised. Replace fragmented tools with a single platform to investigate threats faster, reduce noise, and act with confidence. From fraud to intrusion detection, Infrawatch helps teams stay ahead of modern threats.

    Real-time internet infrastructure visibilityTrack proxies VPNs and hostile networksProcess internet-scale telemetry events+7
    Intel 471 logo

    Intel 471

    Threat Intelligence
    1 product

    Intel 471 delivers cyber threat intelligence via human-led HUMINT and proprietary technology, sourcing data from underground marketplaces and closed adversary forums. Their Verity471 platform structures intelligence for threat hunting, exposure management, and retroactive threat detection across existing security stacks. HUNTER deploys TTP-based hunt content for behavioral analysis. Positioned as a high-fidelity provider for enterprises and government, they target ransomware, intrusions, fraud, and sophisticated actors, enabling rapid compromise confirmation and attack surface remediation.

    Adversary intelligence collectionMalware intelligence analysisVulnerability intelligence tracking+9
    IPinfo logo

    IPinfo

    Threat Intelligence
    1 product

    IPinfo is primarily an IP data provider, but in threat intelligence it surfaces IP reputation and proxy-related context that security teams use for enrichment, fraud screening, and incident triage. Its security-relevant data includes VPN/proxy detection, named anonymizers, residential proxy signals, abuse-contact lookups, and change tracking tied to IP behavior. It is best suited for SOC teams, fraud operations, and platform engineers that need lightweight IP-centric intelligence rather than a full multi-source threat feed. The vendor also offers adjacent IP data products and delivery methods, but the threat-intelligence use case centers on API, database, and warehouse access to IP context.

    IP threat intelligence dataPrivacy service identificationHigh-resolution IP intelligence+9
    Joe Security logo

    Joe Security

    Threat Intelligence
    1 product

    Joe Security delivers deep malware and phishing analysis as a threat intelligence provider, leveraging reasoning-capable generative AI for automated reverse engineering and dynamic/static file inspection. The platform excels in identifying attack types, extracting IOCs, and analyzing offline phishing URLs for domain anomalies. It serves CERT, CIRT, SOC, and IR teams requiring automated, analyst-driven insights into malicious files, emails, and URLs across Windows, macOS, and Linux. While Joe Security also offers sandbox cloud services, its core threat intelligence value lies in AI-driven behavior signatures and comprehensive reporting. The vendor holds a strong market position for technical intelligence focused on malware and phishing detection.

    Automated agentic reverse engineering that selects disassembly, decompilation, unpacking, and web-intelligence steps to produce human-readable threat intelligence and Q&A context for malware and phishing filesReasoning-capable AI analysis of files, emails, senders, links, attachments, and phishing pages to summarize threats, identify attack types, and extract indicators of compromise (IOCs)Dynamic and static analysis of malicious file types including SVGs, assessing senders, links, and attachments to detect phishing and malware across Windows, macOS, and Linux operating systems+4
    Juniper Networks logo

    Juniper Networks

    Firewall / NGFW
    1 product

    Juniper Networks provides SRX Series firewalls and Juniper Secure Edge for firewall/NGFW use cases, with policy enforcement across physical, virtual, containerized, and as-a-service deployments. In this category, it is positioned for enterprise campus, data center, branch, and regional headquarters networks that need application-aware traffic control, intrusion prevention, URL filtering, SSL inspection, and malware detection in a single firewall stack. Its value is strongest for organizations already using Juniper networking gear or looking for centralized policy management through Security Director Cloud and JUNOS OS.

    Application-aware traffic inspectionUser identity-based policiesIntrusion prevention for exploits+7
    Lunar, powered by Webz.io logo

    Lunar, powered by Webz.io

    Threat Intelligence
    1 product

    Lunar is a specialized threat intelligence platform that focuses on monitoring the deep and dark web to detect stolen credentials and hijacked session tokens. By providing real-time data on leaked authentication data, it allows security teams to proactively invalidate compromised sessions before they are used for account takeover (ATO). It complements traditional identity providers by adding an external layer of credential risk visibility.

    Monitor compromised credentialsMonitor compromised assetsMonitor sensitive data exposure+8
    Magnet Forensics logo

    Magnet Forensics

    Threat Intelligence
    1 product

    Magnet Forensics is primarily a digital investigations vendor, but in the Threat Intelligence context it supports incident responders by turning endpoint, cloud, and device artifacts into actionable TTP-level intelligence. Its Axiom Cyber and related workflow tools help teams map activity to MITRE ATT&CK, correlate evidence, and accelerate early case assessment during cyber incidents. It is best suited for enterprise and public-sector DFIR teams that need forensic-grade analysis rather than a standalone CTI feed. The company also sells adjacent evidence collection and case-management products.

    MITRE ATT&CK mappingYARA rule scanningMemory analysis+9
    Mallory logo

    Mallory

    Threat Intelligence
    1 product

    Mallory unifies live adversary activity with your attack surface to prioritize the exposures real threat actors are targeting right now.

    Threat source monitoringEntity and observable libraryNatural-language intelligence querying+8
    Mandiant (Google Cloud) logo

    Mandiant (Google Cloud)

    Threat Intelligence
    3 products

    Mandiant Threat Intelligence, now part of Google Cloud Security, is a SaaS threat intelligence platform combining Google's detection telemetry, Mandiant's frontline incident response intelligence, and VirusTotal's malware database. It delivers unified threat scoring, vulnerability tracking, and threat actor attribution to mid-market and enterprise security teams. Best for organizations requiring operationalized threat intelligence with low false-positive rates and integration into existing SOC workflows.

    Automated threat triage and indicator scoringThreat correlation and investigation pivotingCurated threat detection and hunting hypotheses+9
    Mars Security logo

    Mars Security

    Threat Intelligence
    2 products

    MARS Security is a threat hunting and detection engineering platform that transforms threat intelligence into active detections. It continuously analyzes global threat intelligence, extracts attacker TTPs, maps them to MITRE ATT&CK, and automatically generates validated detection rules for deployment into existing SIEM environments. Through federated search, automated attack simulations, continuous threat hunting, and detection gap analysis, MARS helps organizations operationalize intelligence, expand detection coverage, reduce attacker dwell time, and proactively identify threats without requiring additional infrastructure or security personnel.

    Operationalizes threat intelligence into validated detectionsEnables continuous campaign-driven threat huntsIdentifies detectable real-world attacks today+7
    Menlo Security logo

    Menlo Security

    Browser & Web Isolation
    10 products

    As a pioneer of browser security, Menlo Security delivers a solution with a comprehensive approach to enterprise browser security, protecting users where they work and securing applications from internet-borne attacks.

    Cloud-based remote browser isolationZero Trust web content handlingBrowser-agnostic isolation support+9
    Microsoft logo

    Microsoft

    Cloud Security / CSPM
    15 products

    Microsoft Defender for Cloud is a multicloud CSPM platform that provides continuous security posture assessment across Azure, AWS, and GCP. It delivers agentless vulnerability scanning, misconfiguration detection, and compliance monitoring against industry benchmarks (CIS, NIST, ISO, PCI-DSS). The platform generates hardening recommendations ranked by risk and includes attack path analysis to identify exploitable chains. Defender for Cloud serves enterprises managing hybrid and multicloud infrastructure seeking unified posture visibility and compliance reporting.

    Agentless vulnerability scanningAPI-connected app governanceAPI security+19
    Microsoft Sentinel logo

    Microsoft Sentinel

    SIEM
    4 products

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform deployed on Azure that centralizes threat detection, investigation, and response across multicloud and hybrid environments. It combines machine learning analytics, threat intelligence integration, and automated playbook orchestration to reduce alert noise and accelerate incident handling. Best suited for organizations with existing Microsoft security investments (Microsoft 365 Defender, Azure Defender for Cloud) seeking unified cloud-based security operations without on-premises infrastructure.

    Ingests security data from many sourcesGroups alerts into incidentsMaps detection coverage to MITRE ATT&CK+8
    MIND logo

    MIND

    Insider Risk Management
    2 products

    MIND is a data security platform that integrates Data Loss Prevention (DLP) with Insider Risk Management (IRM) using an AI-native approach. It automates the detection and protection of sensitive data at rest and in motion across SaaS, GenAI tools, and endpoints. The vendor aims to replace legacy, high-maintenance DLP solutions with an 'autopilot' system that reduces false positives and manual policy tuning.

    Autonomous DLP and IRM automationData discovery and AI classificationPolicy management and automated remediation+9
    Mobb logo

    Mobb

    Application Security Posture Management (ASPM)
    3 products

    Mobb is a code remediation product positioned around static application security testing workflows rather than a standalone scanner. It takes vulnerabilities detected by SAST tools such as OpenText Fortify and generates secure code fixes that can be pushed back into the codebase, helping teams reduce manual triage and remediation time. The product is best suited for development and AppSec teams already using SAST in CI/CD who want automated fix suggestions and pull-request-based workflows. Its documented role is complementary to SAST rather than replacing DAST or other testing layers.

    Transforms vulnerabilities detected by Fortify into concrete secure code fixes, reducing manual rewrite work after static analysis findings.Pushes suggested remediation changes back into the codebase with a one-click workflow, fitting pull-request and developer-review processes.Supports SAST remediation workflows by acting on findings produced by static analysis tools rather than by scanning runtime applications itself.+5
    Morado logo

    Morado

    Threat Intelligence
    2 products

    Morado delivers an integrated Threat Management Platform that unifies finished intelligence, dark web monitoring, and brand protection into a centralized workspace. Built on the STIX standard, the platform correlates attack surface intelligence with third-party risk data to provide a holistic view of the threat landscape. It replaces disparate point solutions for digital risk protection (DRPS) and brand monitoring with a single operational intelligence hub.

    Centralizes cyber threat intelligenceStreamlines threat intelligence workflowsEnhances threat intelligence operations+3
    N-able Mail Assure logo

    N-able Mail Assure

    Email Security
    9 products

    N-able Mail Assure is a cloud-based email security gateway for MSPs and Microsoft 365 environments. In scope for email security, it filters inbound and outbound mail, blocks spam and email-borne threats, supports policy-based controls, and provides quarantine, archiving, and continuity functions through a web console. N-able positions it for service providers and IT teams that need centralized protection for multiple domains and tenants, plus message-level visibility and administrative reporting. Adjacent capabilities include a private portal for handling sensitive messages and Microsoft 365 add-ons, but the core product is email gateway protection.

    Inbound and outbound email securityPattern recognition for phishing and malware24/7 email continuity service+5
    Nextron Systems logo

    Nextron Systems

    Managed Detection & Response (MDR)
    5 products

    Nextron Systems provides specialized forensic analysis and compromise assessment tools designed to detect APTs and active breaches. Their technology utilizes advanced YARA scanners and forensic artifacts to identify indicators of compromise (IoC) that traditional EDR/AV solutions often miss. It replaces manual forensic collection and complements existing SOC workflows by providing deep-system visibility into unauthorized persistence and lateral movement.

    Compromise assessment to determine intrusion scopeEndpoint and server trace huntingDetection gap discovery across systems+6
    NordLayer logo

    NordLayer

    Zero Trust / SASE / SSE
    5 products

    NordLayer is a cloud-native SASE platform consolidating SD-WAN, firewall-as-a-service (FWaaS), secure web gateway (SWG), cloud access security broker (CASB), and zero trust network access (ZTNA) into a unified service. The vendor targets enterprises transitioning from point-solution security architectures to integrated cloud-delivered frameworks. NordLayer serves organizations requiring secure remote access, hybrid IT environments, and zero trust implementation without hardware-dependent infrastructure.

    Zero Trust Network Access with context-based authorizationSecure Web Gateway for inline traffic filteringCloud Access Security Broker with IAM integration+9
    Nozomi Networks logo

    Nozomi Networks

    OT & ICS Security
    8 products

    Nozomi Networks delivers an IoT Security solution focused on passive OT and IoT network monitoring to automate device discovery, asset visibility, and threat detection. Their Guardian sensor passively ingests SPAN traffic to decode protocols, identify newly connected assets, and detect anomalies using AI-driven behavioral analysis. The platform prioritizes risks inherent to industrial environments, offering guided remediations to reduce MTTR. Best suited for utilities, manufacturing, and critical infrastructure operators managing complex OT/IoT ecosystems. While they also offer broader OT security capabilities, their IoT solution specifically targets visibility and anomaly detection in heterogeneous device networks.

    Automated IoT device discoveryContinuous IoT device monitoringThreat and anomaly detection+7
    NSFOCUS logo

    NSFOCUS

    Extended Detection & Response (XDR)
    1 product

    NSFOCUS offers a broad portfolio of security products including DDoS protection, Web Application and API Protection (WAAP), and an Integrated Security Operations Platform. The company serves large enterprises and telcos with high-capacity mitigation hardware and cloud-based threat intelligence. It provides massive-scale DDoS scrubbing and continuous threat exposure management (CTEM) capabilities.

    AI-driven XDR automation for threat detection and responseExtended Detection and Response across endpoint, network, and cloudFull traffic analysis with 30-day event retrospection+8
    Nucleus Security logo

    Nucleus Security

    Vulnerability Management
    5 products

    Nucleus Security is the leader in Unified Exposure Management turning exposure into measurable exposure reduction at enterprise scale. The Nucleus platform orchestrates enterprise programs to drive outcomes, continuously unifying security data from 200+ sources, prioritizing risk with AI-powered vulnerability and exploit intelligence, and effectively mobilizing remediation. A FedRAMP authorized vendor

    Aggregate vulnerability data from many toolsBuild unified asset inventoryRisk-based vulnerability prioritization+7
    O

    OneSpan Inc

    Multi-Factor Authentication (MFA)
    7 products

    OneSpan specializes in digital identity verification and hardware/software-based multi-factor authentication for high-security environments like banking and enterprise access. The platform supports a wide range of authentication methods including FIDO2, OTP, and mobile push, alongside mobile application shielding to protect against reverse engineering and overlay attacks. It complements IAM stacks by providing the enforcement layer for secure login and transaction signing.

    Mobile two-factor authentication with biometrics and OTPSMS one-time password delivery for authenticationFIDO passkeys for device-based biometric authentication+5
    OpenCTI logo

    OpenCTI

    Threat Intelligence
    3 products

    Filigran provides open-source cybersecurity solutions covering threat intelligence management, breach and attack simulation, and cyber risk management.

    Real-time threat intelligence analysis across systemsCyber threat intelligence knowledge base managementKnowledge graph generation from threat feeds and alerts+6
    OPSWAT logo

    OPSWAT

    Vulnerability Management
    9 products

    OPSWAT prevents known, unknown, and AI-generated threats from reaching the systems the world depends on. The MetaDefender Platform, OPSWAT's AI-powered cybersecurity solution, secures every file, device, and data transfer across IT, OT, and cross-domain environments.

    Detect and report installed software vulnerabilitiesAutomated patch management for third-party applicationsRemediate Known Exploited Vulnerabilities cataloged by CISA+7
    Orryx AI logo

    Orryx AI

    Agentic SOC & Investigations
    2 products

    Where Human Expertise Meets Autonomous Intelligence.

    Autonomous alert triageInvestigation question generationCross-tool threat correlation+3
    Outpost24 logo

    Outpost24

    Vulnerability Management
    1 product

    Leading Global Provider of Exposure, Identity and Access Management, made in Europe

    Continuous vulnerability scanningRisk-based vulnerability prioritizationDetailed vulnerability risk profiles+9
    Palo Alto Networks logoP

    Palo Alto Networks

    Firewall / NGFW
    21 products

    Palo Alto Networks is a major vendor in the Firewall / NGFW market, best known for PAN-OS-based next-generation firewalls and Cloud NGFW. Its firewalls combine application-aware policy, user-based controls, and threat prevention to inspect traffic, including encrypted sessions, and block known and unknown threats. It fits enterprises that need granular segmentation, internet edge protection, and consistent policy across physical and cloud deployments. Adjacent offerings exist, but the core firewall line remains centered on network traffic control, inspection, and prevention.

    Active-passive firewall high availabilityAI gateway and LLM API traffic routingAI runtime security for autonomous agents+20
    Patch My PC logo

    Patch My PC

    Vulnerability Management
    8 products

    Patch My PC provides automated patch management for third-party applications, integrating directly with Microsoft Configuration Manager (ConfigMgr/SCCM), WSUS, and Intune. It handles packaging, testing, and deployment of thousands of updates, delivering CVE-linked vulnerability details for prioritization. The SaaS-based Publisher portal consolidates reporting on patch compliance, installed updates, and endpoint risks. Trusted by over 10,100 customers, it targets IT/security teams in Microsoft-centric environments seeking to reduce manual patching efforts and enhance endpoint security against known vulnerabilities.

    CVE vulnerability details and prioritizationAutomated third-party patch packaging and deploymentReal-time vulnerability alerting and awareness+7
    Penlink logo

    Penlink

    Threat Intelligence
    2 products

    A Next generation Intelligence Platform for Better Decision-Making

    Open-source intelligence aggregationReal-time threat alertingAI-powered data analytics+8
    Pradeo logo

    Pradeo

    Mobile Security
    8 products

    Pradeo is a mobile security vendor focused on mobile threat defense for smartphones, tablets, and mobile applications. Its core product, Pradeo Security, is positioned around detecting device, network, and application-level threats, enforcing mobile policy compliance, and integrating with enterprise mobility controls such as MDM and Microsoft Intune. It is best suited for organizations that need risk-based access decisions and remediation for managed mobile fleets, especially where phishing, malicious apps, and network attacks are concerns. The company is described in external sources as a leader or emerging leader in mobile security.

    Mobile threat detection and responseConditional Access risk enforcementMobile app security scanning+8
    Proofpoint logo

    Proofpoint

    Email Security
    9 products

    Proofpoint is a human-centric cybersecurity platform focused on protecting organizations from email-based and identity-driven attacks such as phishing, business email compromise (BEC), and social engineering. It secures inbound and outbound communications using advanced threat detection, AI-driven impersonation analysis, URL and attachment sandboxing, and behavioral risk signals. Beyond email protection, it extends into data loss prevention (DLP), insider threat detection, and security awareness training to reduce human risk across the organization. The platform integrates across email, cloud applications, and collaboration tools to protect sensitive data and stop attacks targeting users.

    Detect AI-augmented email threatsBlock phishing and business email compromiseAnalyze sender behavior and message content+9
    Prophet Security logo

    Prophet Security

    Agentic SOC & Investigations
    5 products

    Prophet Security is building an AI SOC platform that empowers teams to move faster and make better decisions.

    Autonomous AI agent alert triage and investigationDynamic investigation plan generationMulti-source data correlation for investigation+2
    Rapid7 logo

    Rapid7

    Vulnerability Management
    11 products

    Rapid7 is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations' cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers.

    Asset discovery and vulnerability scanningRisk-based vulnerability prioritizationAttack surface monitoring with Project Sonar+9
    Recorded Future logo

    Recorded Future

    Threat Intelligence
    5 products

    Recorded Future secures the world by empowering businesses, governments, and other organizations to stay one step ahead of today's relentless threat actors.

    Real-time threat intelligenceThreat data collection and aggregationAI-driven Intelligence Graph analysis+9
    ReliaQuest logo

    ReliaQuest

    Agentic SOC & Investigations
    10 products

    ReliaQuest delivers an Agentic AI Security Operations platform, GreyMatter, that unifies detection, investigation, and response across SIEM, EDR, and Cloud environments. It utilizes AI agents to automate data collection and the standard diagnostic workflows typically handled by Tier 1 and Tier 2 analysts. The platform provides a centralized console to orchestrate response actions without the need for constant data migration to a single lake.

    Autonomous alert investigation and triageNatural-language threat huntingAutomated threat containment actions+8
    ReversingLabs logo

    ReversingLabs

    Supply Chain Security
    6 products

    ReversingLabs provides software supply chain security through Spectra Assure, leveraging a 40 billion file threat repository for binary analysis of OSS packages and commercial binaries. It detects novel malware via proprietary RL engines, supply chain attacks through differential analysis, secrets exposure with liveness verification, and vulnerabilities from NVD, OSV, GitHub, and KEV sources plus proprietary exploitation intelligence. Trusted by Fortune 500 for vetting compiled software against tampering and compromise. Best for enterprises and developers securing build pipelines, third-party software, and cryptocurrency infrastructure against sophisticated attacks.

    Binary artifact security analysisSoftware supply chain attack detectionPolicy-based release gating+7
    Riot Security logo

    Riot Security

    Security Awareness & Phishing Simulation
    8 products

    Riot Security is a security awareness and employee security posture management platform focused on reducing human-risk exposures through training, phishing simulations, and employee-facing security nudges. Based on the available product information, it is positioned for companies that want to run ongoing awareness programs for distributed teams rather than one-off training courses. The product appears best suited for small to mid-sized organizations that need Slack- or Teams-based delivery, breach notifications, and phishing exercises as part of a structured awareness program. Adjacent employee posture features are mentioned by the vendor, but the core fit is security awareness.

    Chat-based awareness training in Slack and TeamsPhishing testing and drillsAutomated awareness program delivery+6
    RSA NetWitness logo

    RSA NetWitness

    SIEM
    5 products

    RSA provides an AI-powered Unified Identity Platform to protect the world's most secure organizations. RSA provides automated identity intelligence, authentication, access, governance, and lifecycle capabilities to reduce risks, secure authentication, maintain compliance, and automate processes.

    Centralized log managementDynamic parsing and normalizationReal-time threat detection+7
    SecurityScorecard logo

    SecurityScorecard

    Attack Surface Management
    5 products

    A swarm of agents. An army of risk engineers. One threat-informed TPRM platform to stop risk before it spreads across your supply chain.

    Continuously rates external-facing vendor security posture using an A-F score derived from ten risk-factor groups, helping GRC teams maintain an always-current control view for third-party due diligence.Monitors external attack surface signals such as DNS health, IP reputation, web application security, network security, endpoint security, and patching cadence to support vendor risk evidence collection.Provides factor-level security findings that can be mapped into enterprise risk taxonomies, allowing teams to correlate technical exposures with operational, financial, compliance, and reputational risk categories.+5
    Securonix logo

    Securonix

    SIEM
    7 products

    Securonix is a cloud-native SIEM vendor offering unified detection and response across SIEM, UEBA, SOAR, and threat intelligence capabilities in a single platform. The company positions itself as analytics-driven with integrated machine learning for threat detection and automated incident response. Securonix targets mid-to-large enterprises seeking to consolidate security tools and reduce alert fatigue through behavioral analytics and threat chain modeling rather than signature-based detection alone.

    Cloud-native SIEM data collectionLog normalization and enrichmentMachine learning threat detection+6
    Sendmarc logo

    Sendmarc

    Email Security
    5 products

    At the heart of everything we do, is our purpose of making the Internet a safer place for all.

    DMARC implementation and managementSPF and DKIM alignment monitoringDMARC aggregate report analysis+9
    Sherpa.ai logo

    Sherpa.ai

    Threat Intelligence
    2 products

    Sherpa.ai provides a federated learning platform that lets organizations collaboratively train AI powered threat detection and threat intelligence models without sharing raw security data such as logs, network telemetry or endpoint activity. The platform uses privacy enhancing techniques including secure multiparty computation and differential privacy so participating companies, financial institutions, hardware manufacturers and critical infrastructure operators can pool insight on ransomware, malware and intrusion patterns while data stays local. It is delivered as a cloud based SaaS with a decentralized architecture that supports edge devices and cross organization model training, aimed at security teams that need collective threat visibility while meeting data sovereignty and regulatory compliance requirements.

    Federated learning for threat detectionRansomware detection without log sharingSecure multiparty computation+3
    Silent Push logo

    Silent Push

    Threat Intelligence
    1 product

    Silent Push was founded to transform the way organizations across the world track, monitor and counteract global threat activity.

    Indicators of Future Attack discoveryAdversary infrastructure trackingGlobal IPv4 scanning and enrichment+9
    Silobreaker logo

    Silobreaker

    Threat Intelligence
    2 products

    To equip organizations with intelligence grounded in clarity, judgment, and human insight, so decisions are made without noise, panic, or posturing.

    Collects intelligence from open web, dark web, and premium sources and normalizes it into a single analytical workspace for cyber, geopolitical, and physical threat monitoring.Supports IOC enrichment and pivoting on indicators such as IP addresses, domains, malware, and vulnerabilities to connect raw artifacts to related threat context.Provides reputation scoring for indicators of compromise using blended open and commercial intelligence sources, including reputation data for IP addresses and domains.+5
    SmishAlert logo

    SmishAlert

    Security Awareness & Phishing Simulation
    5 products

    SmishAlert is a mobile-first security awareness platform that specializes in defending against SMS-based phishing (smishing), QR code scams (quishing), and mobile social engineering. It provides real-time analysis of incoming messages and reinforces secure user behavior within native mobile workflows. The platform complements traditional email-centric security awareness programs by addressing the growing threat of mobile-based corporate credential theft.

    Learn from real messaging attacksDetect messaging-based phishing threatsSurface workforce-reported threats+4
    SOC Prime logo

    SOC Prime

    Threat Intelligence
    5 products

    SOC Prime operates the world's largest and most advanced platform for detection engineering, transforming how security teams discover, build, and respond to threats through real-time intelligence, AI-driven context, and advanced detection engineering workflows.

    Provides continuously updated threat detection content enriched with actionable cyber threat intelligence and metadata, so teams can operationalize new threats without building every rule from scratch.Maps detection content to the MITRE ATT&CK framework, helping analysts link indicators and techniques to adversary tactics, techniques, and procedures.Serves as a centralized repository for threat detection content, allowing threat-intel-driven content to be managed and deployed from one platform.+5
    SOCRadar logo

    SOCRadar

    Threat Intelligence
    1 product

    SOCRadar’s Threat Intelligence offering is an external threat intelligence platform focused on collecting, enriching, and prioritizing indicators and adversary activity from open web, dark web, and technical sources. It is positioned for security teams that need contextualized alerts about phishing, leaked credentials, ransomware activity, and third-party exposure without stitching together separate feeds and monitoring tools. SOCRadar is best suited for SOC, CTI, and digital risk teams that want one place to track actors, infrastructure, and brand abuse; the broader platform also includes adjacent attack surface and digital risk capabilities.

    Cyber threat intelligence collectionExternal attack surface monitoringDark web threat monitoring+6
    Splunk logo

    Splunk

    SIEM
    8 products

    Our purpose is simple and unwavering: to build a safer and more resilient digital world. Every day, we help SecOps, ITOps, and engineering teams secure their systems, resolve issues quickly, and keep their organizations running without interruption.

    Collect and normalize security dataCorrelate events in real timeSearch and investigate historical events+9
    Spur Intelligence logo

    Spur Intelligence

    Threat Intelligence
    1 product

    Spur Intelligence is an IP intelligence vendor focused on revealing anonymized network infrastructure behind internet traffic, including VPNs, residential proxies, mobile gateways, botnets, and other obscured services. In the threat intelligence category, it is best known for high-fidelity IP enrichment that helps security teams identify risky sources, investigate incidents, and attribute hidden traffic in real time. Its core buyers are threat hunting, fraud, and security operations teams that need infrastructure-aware context rather than generic IP reputation data. The company is privately held and operates as a specialist point solution rather than a broad threat intelligence platform.

    IP intelligence enrichmentAnonymized traffic detectionVPN and proxy attribution+9
    SpyCloud logo

    SpyCloud

    Threat Intelligence
    9 products

    SpyCloud pioneered the category of identity threat protection: transforming stolen identity data like breached credentials, malware-exfiltrated data, and phishing intelligence into automated action that prevents account takeover, fraud, ransomware, and session hijacking.

    Recaptured darknet identity intelligenceActionable evidence of compromiseAutomated remediation workflows+7
    Stairwell logo

    Stairwell

    Threat Intelligence
    1 product

    Stairwell detects threats your stack misses, maps exactly where they spread, and gives you the evidence to close the case, not just the alert.

    Continuous file analysisThreat intelligence searchIOC presence and absence checks+9
    Stellar Cyber logo

    Stellar Cyber

    Network Detection & Response (NDR)
    12 products

    Build the platform that makes it easy for everyone to see what's coming – and act fast with confidence.

    Deep packet inspection collects L2–L7 metadata and files for over 4,000 network applications from raw packets to enable behavioral anomaly detection and threat identification.Encrypted traffic analysis inspects network flows without interception, allowing detection of malicious patterns in encrypted communications using metadata and flow-based indicators.Multi-stage, multi-method detection runs rules, signatures, and machine learning at edge sensors and centrally on aggregated data to identify sophisticated attacks and lateral movement.+5
    Team Cymru logo

    Team Cymru

    Threat Intelligence
    7 products

    Intelligence that moves first.

    Real-time threat intelligence feedsMalicious infrastructure identificationIncident response optimization+6
    ThreatBreaker logo

    ThreatBreaker

    Threat Intelligence
    1 product

    ThreatBreaker does not appear to be a standalone threat intelligence platform; public materials describe it primarily as an AI-native endpoint detection and response product with automated forensics, MITRE ATT&CK mapping, and incident summaries. Within a threat intelligence lens, its value is in turning endpoint telemetry into contextualized detections and investigator-ready incident intelligence for MSSPs and SMB-focused security teams. It is best suited to organizations that want endpoint-derived intelligence and triage support rather than a broader threat feed aggregation or strategic intelligence platform.

    Endpoint telemetry collectionLocal AI threat scoringBehavioral threat analysis+8
    ThreatConnect logo

    ThreatConnect

    Threat Intelligence
    4 products

    ThreatConnect, headquartered in Arlington, Virginia, provides a Threat Intelligence Platform (TIP) called TI Ops that aggregates threat data from internal and external sources, enriches it with business context, and integrates it into security operations. It supports incident response via automated playbooks, threat hunting with business-specific models, and third-party risk assessments tied to adversary behaviors. The platform orchestrates actions across detection, response, and reporting tools, enabling collaboration between threat intelligence, SOC, and executive teams. Favored by Global 2000 organizations for operationalizing intelligence into workflows.

    Threat data aggregation and correlationThreat intelligence analysisThreat enrichment and prioritization+8
    ThreatLens logo

    ThreatLens

    Agentic SOC & Investigations
    5 products

    ThreatLens builds AI-augmented security products that help organizations investigate threats, secure AI adoption, and make evidence-backed decisions across modern security operations.

    AI-agent-driven autonomous investigationAutonomous Tier-1/2/3 alert triageNatural-language threat hunting+8
    threatnet logo

    threatnet

    Threat Intelligence
    3 products
    Verified

    I could not verify a specific vendor named “threatnet” from the provided sources, so this profile cannot be grounded in vendor-specific evidence. The threat intelligence category itself covers platforms that collect, normalize, enrich, analyze, and disseminate indicators, actor context, and TTPs so security teams can prioritize risk and support SOC, incident response, and strategic planning. If “threatnet” is an actual product name, it likely belongs in the TIP market, but its exact positioning, buyer fit, pricing, and integrations are not confirmable from the evidence provided.

    Real-time emerging threat data collectionAutomated threat analysis and prioritizationActionable insights and IoC generation+2
    Threat Point logo

    Threat Point

    Threat Intelligence
    1 product

    Every organization has to change its cryptography. The danger was never the fix, it's the fallout: everything the change touches downstream. Threat Point shows you the blast radius before you ship, so you can move with confidence today, and into the post-quantum world.

    Threat intelligence platformReal-time threat intelligenceThreatCloud telemetry aggregation+3
    ThreatQuotient logo

    ThreatQuotient

    Threat Intelligence
    1 product

    Partnering with ThreatQuotient empowers threat intelligence and security operations teams to detect, investigate and respond to cyber threats with greater efficiency, efficacy and precision. Our award-winning ThreatQ Platform enables organizations to aggregate, analyze, and act on threat intelligence, reducing complexity and improving decision-making.

    Aggregate threat data into a threat libraryEnrich data with threat contextCustomer-defined scoring and prioritization+9
    Tidal Cyber logo

    Tidal Cyber

    Vulnerability Management
    4 products

    Tidal Cyber is primarily a threat-informed defense platform, not a traditional vulnerability management scanner. In a vulnerability-management evaluation, it is best understood as a tool for mapping exposure and defensive coverage to adversary techniques in MITRE ATT&CK, helping security teams identify where their controls may leave gaps against relevant threats. It fits organizations that already run vulnerability scanners and want to prioritize remediation using threat context, especially detection engineering, SOC, CTI, and threat hunting teams. Adjacent capabilities include ATT&CK-aligned intelligence processing and defensive coverage analysis.

    BAS control validation and tuningThreat-informed defense assessmentBAS test result diagnostics+5
    Tines logo

    Tines

    SOAR
    6 products
    Verified

    We believe that by combining AI, automation, and integration with human ingenuity organizations are more efficient, secure, and will have more engaged, happier teams.

    No-code security workflow automationSecurity orchestration across toolsAlert deduplication and triage+8
    Trellix Helix logo

    Trellix Helix

    SIEM
    5 products

    Trellix Helix is a SaaS security operations platform that unifies SIEM, SOAR, and threat intelligence, integrating over 600 Trellix and third-party tools for multi-vector threat detection and response. It augments existing SIEMs with analytics, behavioral analysis, and workflow automation, enabling correlated investigations across endpoints, networks, and cloud environments. Best suited for enterprises seeking XDR capabilities without replacing legacy SIEMs, it leverages Trellix's global threat intelligence for contextual IOCs and TTP-based rules, streamlining alert triage and containment.

    Next-generation SIEM with advanced searchMulti-vector correlation and detectionUser and entity behavior analytics+9
    Upstream Security logo

    Upstream Security

    AI Runtime & Agent Security
    4 products

    Upstream Security is primarily an automotive and physical-AI security vendor, but its AI runtime offering extends into agent and API enforcement through its Runtime AI and API Security platform. In this scope, it monitors traffic across AI and API ecosystems, discovers agents and endpoints, and applies stateful inspection and custom detections for OWASP MCP and LLM risks, prompt-injection-style abuse, and business-logic misuse. It is best suited for organizations that need runtime controls around agentic workflows and API-backed AI services, especially in connected-vehicle and industrial environments.

    Runtime AI and API securityAgent and API discoveryPrompt and context inspection+9
    Validin logo

    Validin

    Threat Intelligence
    1 product

    Validin is an internet and DNS intelligence vendor focused on threat intelligence for security teams that need to investigate infrastructure, enrich indicators, and track adversary activity over time. Its core value is historical and context-rich visibility into domains, IPs, certificates, registration data, and web fingerprints, rather than sampled traffic or opaque scoring. It is best suited for threat hunters, CTI teams, and analysts doing infrastructure-led investigations and lookalike domain discovery. Validin also exposes an API and workflow automation features for integrating curated intelligence into security tooling.

    DNS intelligence for threat huntingHistorical infrastructure investigationHidden connection discovery+9
    Vertex Synapse logo

    Vertex Synapse

    Threat Intelligence
    2 products

    Vertex Synapse is a hypergraph-based central intelligence system designed specifically for threat intelligence, enabling analysts to fuse commercial threat data with internal sources and map relationships across disparate datasets. Unlike static indicator-matching tools, it uses a flexible data model that mirrors human analytical thinking in relationships, surfacing non-obvious connections for real investigations. The platform is best suited for security operations teams and intelligence analysts requiring deep contextual analysis of malware families, threat clusters, vulnerabilities, and attack patterns. While Synapse serves as a comprehensive intelligence lifecycle platform, its threat intelligence capabilities focus on tagging, taxonomies, and risk modeling for actionable insights.

    Central intelligence system for analyst teamsThreat intelligence entity modelingThreat activity correlation and tracking+7
    Vetric logo

    Vetric

    Threat Intelligence
    1 product

    Vetric helps the organizations on the front lines of trust, safety, and security see what they need, exactly when they need it, so they can stay ahead of bad actors.

    Open-web threat monitoringBrand abuse and impersonation detectionCounterfeit and anti-fraud monitoring+9
    VMRay Inc logo

    VMRay Inc

    Threat Intelligence
    1 product

    VMRay Inc sells threat intelligence centered on malware- and phishing-derived indicators, behavioral context, and analyst-ready enrichment. In this scope, its UniqueSignal and TotalInsight offerings turn sandbox detonation and behavioral analysis into high-confidence IOCs, MITRE ATT&CK mappings, and feed outputs for SOC and CTI teams. VMRay positions itself around evasion-resistant analysis and lower-noise intelligence versus generic feeds, making it most suitable for organizations that need intelligence tied to real payload behavior rather than broad third-party aggregation.

    Noise-free IOC extractionBehavioral threat mappingTailored threat intelligence building+8
    VulnCheck logo

    VulnCheck

    Threat Intelligence
    5 products

    VulnCheck helps organizations outpace adversaries with vulnerability intelligence that predicts avenues of attack with speed and accuracy.

    Exploit and vulnerability intelligenceReal-time attacker infrastructure trackingInternet-connected device intelligence correlation+7
    Vulners logo

    Vulners

    Vulnerability Management
    6 products

    We provide the essential building blocks for cybersecurity solutions with comprehensive, structured, and constantly updated vulnerability and exploits data

    Search vulnerabilities by CVE, CPE, and referencesTrack vulnerability and exploit intelligenceAnalyze software dependency vulnerabilities+5
    watchTowr logo

    watchTowr

    Threat Intelligence
    1 product

    watchTowr is redefining External Attack Surface Management with its Continuous Automated Red Teaming technology, built by offensive security experts and backed by real-world vulnerability research. Critical infrastructure companies globally trust watchTowr to continuously validate and strengthen their security postures. If there’s a way to compromise an organization, the watchTowr Platform will find it.

    Proactive threat intelligence researchHighly likely exploit identificationReal-world attacker behavior telemetry+8
    Wraithwatch logo

    Wraithwatch

    Security Operations
    5 products

    Wraithwatch is a next-generation cyber defense data fabric and control plane that unifies security telemetry across tools and environments. It ingests, normalizes, and correlates data from diverse sources to give security teams a single operational layer for detection, investigation, and response. The platform enables real-time visibility, automated workflows, and scalable security operations across enterprise environments, helping organizations reduce complexity and improve decision speed across their security stack.

    Agentic Threat HuntingContext-Aware Attack Surface AnalysisAutomated Control Plan Generation+7
    ZeroFox logo

    ZeroFox

    Digital Risk & Executive Protection
    9 products

    ZeroFox is an external cyber threat intelligence vendor that focuses on collecting, correlating, and validating threat data from the surface web, deep web, dark web, social media, and criminal channels. Its CTI offering is centered on actor tracking, leak detection, campaign monitoring, and vulnerability intelligence, with analyst validation and an Intelligence Evidence Graph used to turn raw signals into finished intelligence. It is best suited for CTI and InfoSec teams that need operationally actionable intelligence rather than uncorrelated feeds. ZeroFox also sells adjacent digital risk and disruption capabilities, but its threat intelligence product is the core here.

    Threat intelligence search portalCurated threat intelligence feedsActor tracking and campaign monitoring+9
    Zscaler logo

    Zscaler

    Zero Trust / SASE / SSE
    11 products

    Zscaler provides a cloud-native Zero Trust Exchange platform with over 150 global POPs, processing 200 billion+ daily transactions for secure user-to-application connectivity. It delivers Zscaler Internet Access (ZIA) as a security service edge (SSE) with secure web gateway (SWG), full SSL inspection, and Zscaler Private Access (ZPA) for zero trust network access (ZTNA) replacing VPNs. Backed by machine learning from massive scale, it offers 200,000+ daily security updates. Best for distributed enterprises needing low-latency protection for remote users, SaaS, and private apps without legacy hardware.

    Agentic SecOpsAI SecurityAPI gateway for private access+17

    What is Threat Intelligence software?

    Compare and discover the best Threat Intelligence software and tools for your team. Find the right solution for your needs. With 219 threat intelligence tools listed on Picari, you can compare features, pricing models, and real user experiences side-by-side, without speaking to a single sales rep until you're ready.

    Who needs threat intelligence tools?

    Threat Intelligence software is typically adopted by teams that have outgrown manual processes and need repeatable, scalable workflows. You'll get the most value if:

    • Your team spends more than 5 hours/week on tasks that could be automated
    • You're scaling past 10 team members and need consistent processes
    • You need better visibility into performance metrics and ROI
    • Your current tools don't integrate well with the rest of your stack

    Buying criteria checklist for threat intelligence

    Before committing to a threat intelligence platform, run through this evaluation checklist:

    Does it integrate with your CRM and existing stack?
    What's the total cost of ownership (setup + seats + add-ons)?
    How steep is the learning curve for your team?
    Does it scale with your expected growth over 12–24 months?
    What does onboarding and customer support look like?
    Can you trial it with real data before committing?

    Common mistakes when evaluating threat intelligence tools

    • 1.Buying based on demos alone. A polished demo doesn't reveal how the tool handles your actual data and workflows. Always run a proof-of-concept.
    • 2.Ignoring total cost of ownership. The sticker price is rarely the full cost, factor in implementation, training, integrations, and potential add-on fees.
    • 3.Not involving end users in the evaluation. The people who'll use the tool daily should have a say. Top-down purchases often lead to low adoption.
    • 4.Comparing too many tools at once. Shortlist 2–3 finalists max. Evaluating 5+ tools in parallel leads to decision fatigue and delayed timelines.

    How to evaluate threat intelligence tools on Picari

    Picari is built to help security teams evaluate cybersecurity tools on their terms, no cold calls, no spam, no pressure. Here's how to get started:

    1. Browse and compare, Review features, pricing, and team fit for each tool above.
    2. Start a Briefing, Describe your problem and get a personalised shortlist of vendors in minutes.
    3. Run a Stack Audit, See how a new tool fits alongside what you already use, and identify gaps or overlaps.
    4. Open an Evaluation Room, Collaborate with your team, organize requirements, and message vendors directly, all in one place.

    Not sure which threat intelligence tool fits?

    Start a Briefing to tell us what you're trying to solve, get a shortlist and a stack audit in minutes.

    Top Threat Intelligence tools on Picari (2026)

    Here are some of the most popular threat intelligence tools currently listed on the platform:

    • 0din by Mozilla Intel · A subscription threat intelligence service that delivers verified vulnerability…
    • 360 Privacy Monitor, $$$$ pricing · Enables detection of breached data, stolen credentials, and doxing threats acros…
    • 7AI Threat Hunt, $$$$ pricing · Hunt at the speed of the threat through proactive threat detection using plain l…
    • AbuseIPDB · AbuseIPDB provides high-fidelity IP reputation data and a massive crowd-sourced…
    • AbuseIPDB Bulk IP Checker, $ pricing · Check multiple IP addresses against the abuse database in batch operations…
    • AbuseIPDB Bulk IP Reporter, $ pricing · Report multiple abusive IP addresses to the community database for crowd-sourced…
    • AbuseIPDB CIDR Block Checker, $ pricing · Evaluate entire IP address ranges rather than individual addresses for malicious…
    • AbuseIPDB IP Reputation Database & Lookup API, $ pricing · Query a central database of abusive IP addresses for malicious activity to ident…