All use cases
    Use case

    Threat intel & deception

    Know your adversary, and lay traps that reveal them.

    Why this fits, Threat intelligence feeds, deception platforms and incident response retainers.

    141 vendors for this

    Binary Defense logo
    Binary Defense
    Managed Detection & Response (MDR)
    5 products

    Binary Defense delivers a human-led, 24x7x365 Managed Detection & Response (MDR) service that detects and isolates threats early in the attack lifecycle using behavioral-based detections and an attacker’s mindset. Their Security Operations Center analysts triage, disposition, and prioritize events, conduct full kill chain analysis, and provide tactical and strategic mitigation recommendations. Best suited for organizations needing an extension of their security team, whether they have an existing team or none, Binary Defense MDR operates as a cloud-based, tool-agnostic service integrated via their BD Platform. The vendor also offers adjacent capabilities like MDR Plus with managed deception and malware disruption, but core MDR focuses on analyst-driven monitoring and response.

    24x7x365 SOC monitoring of endpoints, servers, and cloud resources using behavioral-based detections to identify anomalies, lateral movement, privilege escalation, and PowerShell injection
    Cloudmark logo
    Cloudmark
    Email Security
    7 products

    Cloudmark, now part of Proofpoint, delivers carrier-grade email security primarily for service providers and large-scale messaging environments, protecting over 1.6 billion mailboxes globally. Its Cloudmark Platform for Email automatically detects and mitigates spam, phishing, malware, and other email-borne threats using patented content fingerprinting, URL/CTA analysis, and machine learning. The solution functions as a high-performance mail transfer agent (MTA) integrated at the network edge, offering flexible policy controls and an integrated reputation system. While Cloudmark also supports mobile and rich communications, its core Email Security role targets telecom operators and hosted email providers requiring near-zero false positives and real-time threat blocking.

    Patented message and content fingerprinting technology analyzes email payloads to identify and block known spam and malware variants with high accuracy across SMTP traffic.Call-To-Action (CTA) and URL analysis inspects embedded links in real time to detect malicious destinations and phishing attempts before delivery to end users.
    CounterCraft logo
    CounterCraft
    Deception Technology
    1 product

    CounterCraft provides the Cyber Deception Platform, a scalable distributed system that deploys digital twin replicas of organizational IT and OT environments to lure attackers into controlled decoys. It captures adversary tactics, techniques, and procedures via kernel-level implants and ActiveBehavior automation, which simulates user logins and activities to maintain authenticity. The platform delivers zero-false-positive alerts and real-time threat intelligence through stealthy ActiveLink exfiltration. Trusted by governments, nation-states, and Fortune 500 enterprises in finance and critical infrastructure, it detects targeted attacks within weeks of deployment, ideal for organizations needing proactive defense against sophisticated threats.

    Replicate the network as a digital twin+10
    Cybereason logo
    Cybereason
    Endpoint Detection & Response (EDR)
    10 products

    Cybereason provides Endpoint Detection and Response (EDR) that correlates endpoint telemetry across machines into MalOp™ narratives, revealing full attack chains from initial compromise to lateral movement. It uses behavioral analysis, machine learning on threat feeds ranked by historical accuracy, and cross-machine correlation for real-time detection of sophisticated threats. The platform supports instant remediation like process termination, file quarantine, persistence removal, and machine isolation. Best for enterprises needing high analyst efficiency (1:200,000 endpoint ratio) and advanced threat hunting without alert fatigue, as validated by top Forrester Wave and MITRE ATT&CK scores.

    Behavioral detection of malicious activity+10
    Joe Security logo
    Joe Security
    Threat Intelligence
    1 product

    Joe Security delivers deep malware and phishing analysis as a threat intelligence provider, leveraging reasoning-capable generative AI for automated reverse engineering and dynamic/static file inspection. The platform excels in identifying attack types, extracting IOCs, and analyzing offline phishing URLs for domain anomalies. It serves CERT, CIRT, SOC, and IR teams requiring automated, analyst-driven insights into malicious files, emails, and URLs across Windows, macOS, and Linux. While Joe Security also offers sandbox cloud services, its core threat intelligence value lies in AI-driven behavior signatures and comprehensive reporting. The vendor holds a strong market position for technical intelligence focused on malware and phishing detection.

    Automated agentic reverse engineering that selects disassembly, decompilation, unpacking, and web-intelligence steps to produce human-readable threat intelligence and Q&A context for malware and phishing filesReasoning-capable AI analysis of files, emails, senders, links, attachments, and phishing pages to summarize threats, identify attack types, and extract indicators of compromise (IOCs)
    Mars Security logo
    Mars Security
    Threat Intelligence
    2 products

    MARS Security is a threat hunting and detection engineering platform that transforms threat intelligence into active detections. It continuously analyzes global threat intelligence, extracts attacker TTPs, maps them to MITRE ATT&CK, and automatically generates validated detection rules for deployment into existing SIEM environments. Through federated search, automated attack simulations, continuous threat hunting, and detection gap analysis, MARS helps organizations operationalize intelligence, expand detection coverage, reduce attacker dwell time, and proactively identify threats without requiring additional infrastructure or security personnel.

    Operationalizes threat intelligence into validated detectionsEnables continuous campaign-driven threat hunts
    Sherpa.ai logo
    Sherpa.ai
    Threat Intelligence
    2 products

    Sherpa.ai provides a federated learning platform that lets organizations collaboratively train AI powered threat detection and threat intelligence models without sharing raw security data such as logs, network telemetry or endpoint activity. The platform uses privacy enhancing techniques including secure multiparty computation and differential privacy so participating companies, financial institutions, hardware manufacturers and critical infrastructure operators can pool insight on ransomware, malware and intrusion patterns while data stays local. It is delivered as a cloud based SaaS with a decentralized architecture that supports edge devices and cross organization model training, aimed at security teams that need collective threat visibility while meeting data sovereignty and regulatory compliance requirements.

    Federated learning for threat detection+5
    Vertex Synapse logo
    Vertex Synapse
    Threat Intelligence
    2 products

    Vertex Synapse is a hypergraph-based central intelligence system designed specifically for threat intelligence, enabling analysts to fuse commercial threat data with internal sources and map relationships across disparate datasets. Unlike static indicator-matching tools, it uses a flexible data model that mirrors human analytical thinking in relationships, surfacing non-obvious connections for real investigations. The platform is best suited for security operations teams and intelligence analysts requiring deep contextual analysis of malware families, threat clusters, vulnerabilities, and attack patterns. While Synapse serves as a comprehensive intelligence lifecycle platform, its threat intelligence capabilities focus on tagging, taxonomies, and risk modeling for actionable insights.

    Central intelligence system for analyst teams+9