Cyber Threat Intelligence Tools: 10 Platforms Ranked (2026)
· Prefer this source on Google
Quick comparison of threat intelligence tools
Ten threat intelligence tools in ranked order, with each one's score out of 10 on the five criteria below, its own published coverage figure, the entry price on record and the buyer it fits.
| Rank | Threat intelligence tool | Score | Published coverage figure | Entry price | Best fit |
|---|---|---|---|---|---|
| 1 | Recorded Future | 7/10 | 1M+ sources, 4,000 threat actors | $72,703/yr Vendr median* | Enterprise SOC |
| 2 | OpenCTI (Filigran) | 7/10 | 300+ integrations | $0 Community Edition | Teams that self-host |
| 3 | Flashpoint Ignite | 5/10 | 3.6 PB, 975M+ forum posts | $57,855/yr Vendr median* | Dark web and fraud |
| 4 | Google Threat Intelligence | 4/10 | 1,100 Mandiant investigations/yr | $20,592/yr VirusTotal median* | Google SecOps users |
| 5 | ThreatConnect (Dataminr) | 4/10 | 300+ sources, 100+ integrations | Quote only | TIP plus SOAR |
| 6 | Cyware Intel Exchange | 4/10 | 15B+ objects ingested | Quote only | ISACs, air-gapped sites |
| 7 | CrowdStrike Falcon Adversary Intelligence | 3/10 | 290+ adversaries | $55,756/yr Vendr median, all modules* | Falcon customers |
| 8 | Group-IB Threat Intelligence | 2/10 | 1,550+ investigations | Quote only | Banks outside North America |
| 9 | Anomali ThreatStream | 1/10 | Feeds from 5 ranked vendors | Quote only | MSSPs |
| 10 | Intel 471 Verity471 | 1/10 | 7 intelligence categories | $220,425/yr Vendr median* | Cybercrime teams |
Medians marked * are anonymised buyer data from closed contracts, published by Vendr. "Quote only" means neither the vendor nor Vendr publishes a figure.
Where these figures come from
Coverage counts are each vendor's own published figure, linked from its entry below and read on 4 October 2026. Scores add up five criteria worth 0 to 2 points each.
- Prices marked * are Vendr's anonymised buyer data. The Google row carries Vendr's VirusTotal median, and the CrowdStrike median covers every Falcon module bought together.
- Reviewer quotes come from G2, Gartner Peer Insights and Hacker News, and our review of how G2 moderates reviews explains what a G2 rating can and can't prove.
- ThreatConnect, Cyware, Group-IB and Anomali publish no rate card and carry no Vendr buyer data, so their rows print no price.
Recon tools sit in the open source intelligence tools ranking, geopolitical and event risk in the risk intelligence software ranking, and vendor security ratings in the third-party risk management tools ranking. Recorded Future ranks #2 for risk intelligence and #9 for OSINT, scored on different criteria from the five used here.
Threat intelligence software collects raw threat data from sandboxes, forums and partner feeds, then turns it into threat indicators, threat actor profiles and actionable intelligence that security teams can act on. Prices run from $0 for a self-hosted threat intelligence platform to a $220,425 Vendr median for human-sourced underground intelligence.
This page ranks ten threat intelligence products, from full platforms to single feeds and threat analysis tools, on five tests a buyer can rerun. Every figure links to the vendor's page or to Vendr's anonymised buyer data, checked on 4 October 2026.
It's written for security teams choosing a threat intelligence platform (TIP), threat intelligence feeds, or both. Breach counts, breach costs and ransomware figures sit in our cybersecurity statistics report.
Gartner published its first Magic Quadrant for cyber threat intelligence on 4 May 2026. Between May 2024 and October 2025, four of the ten vendors here changed owners or packaging: Recorded Future, ThreatConnect, Intel 471 and Google.
Evaluation criteria for threat intelligence solutions
Five criteria decide the shortlist, and the ranking applies them in this order. Each one scores 0, 1 or 2 points, so the maximum is 10.
A tie goes to the threat intelligence tool with the higher score on the earlier criterion. The top two both score 7, and criterion one splits them: 4,000 published threat actors against 0.
1. A published count of threat actors tracked
Two points for a count of tracked threat actors on the vendor's domain, one for another count of security analysts' output, such as investigations a year.
2. A published figure for source volume
A stated volume of the vendor's own collection, in sources indexed or data held, earns 2 points. A narrower figure earns 1: objects ingested, third-party data sources aggregated, integrations or telemetry. "Hundreds of sources" scores zero.
3. Documented STIX/TAXII support
A documented TAXII 2.1 server or endpoint earns 2 points, and STIX support mentioned on the vendor's site earns 1. Structured Threat Information Expression is what lets threat intelligence feeds land in existing security tools without a custom parser.
4. A price on record
Published prices and free editions earn 2 points, a Vendr median earns 1, and quote-only pricing scores zero. That's par for the course in this market, and nobody can check the cost before a sales call.
5. Self-hosted or air-gapped deployment
Documented on-premises or air-gapped deployment earns 2 points; a single-tenant cloud or a customer-side execution server earns 1. Defense and critical infrastructure buyers can't send indicators to a shared cloud, and government agencies also buy on the fixed procurement cycles our public sector market intelligence guide maps out.
The 10 threat intelligence platforms, ranked
Recorded Future
Best fit
Security teams in an enterprise security operations center that want scored threat indicators pushed into Splunk or Microsoft Sentinel and can carry a five-figure contract.
The Intelligence Graph indexes over 1 million sources across the open web, dark web and technical feeds, and tracks 4,000 threat actors, including 430 nation-state groups.

Mastercard agreed to pay $2.65 billion for the company in September 2024, over nine times the $290 million deal Dataminr announced for ThreatConnect in October 2025.
Key features
- STIX/TAXII collections in the public API reference
- SIEM integrations with Splunk, Microsoft Sentinel and Google Security Operations, listed on the product page
- TIP integrations with ThreatConnect, Anomali, OpenCTI and MISP
- Insikt Group threat intelligence research attached to indicator risk scores
The vendor says graph correlation cuts false positives by about 95%. That's its own figure, and the 30-day enrichment test checks it against your alerts.
Pricing
Quote only. Vendr's buyer data puts the median at $72,703 a year across 48 purchases, from $27,000 to $215,038, with 10.25% average savings.
Pros
- The largest published actor count here, 4,000
- Full marks on STIX/TAXII and source volume
- Seven named SIEM, SOAR and TIP integrations
Cons
- Runs as a cloud service, so criterion five scores 0
- Vendr lists vulnerability, brand and third-party intelligence as separate modules
- WHOIS and passive DNS depth trails specialist tools
"Limited WHOIS information compared to other intelligence platforms. Limited Passive DNS (pDNS) coverage and historical visibility."
Verified user in financial services, G2 review, 30 September 2026
Why it's ranked #1. It ties OpenCTI on 7 points and beats it on criterion one, the tiebreak, with 4,000 published threat actors against 0. OpenCTI matches it on STIX/TAXII and wins only on price and deployment.
OpenCTI (Filigran)
Best fit
Threat intelligence teams with an engineer who can run Docker or Kubernetes and want every feed in one STIX graph for $0.
OpenCTI is an open source threat intelligence platform built by Filigran. Its GitHub repository carries 10,000+ stars and shipped a release on 2 October 2026, and Filigran says it's built on STIX 2.1 natively with 300+ one-click integrations.
The Community Edition is free and self-hosted, with no strings attached on the licence. The Enterprise Edition adds artificial intelligence summaries, playbooks, SSO and SLAs, and runs self-hosted, air-gapped or as SaaS.

Key features
- STIX 2.1 knowledge graph, exported as bundles or shared through TAXII collections
- 300+ connectors, including Google Threat Intelligence and Intel 471 feeds
- Deployment on Docker, Kubernetes, AWS and Azure
- Playbooks and priority intelligence requirements in the Enterprise Edition
Pricing
The Community Edition costs $0. Enterprise and SaaS pricing is quote only, and hosting is yours to fund.
Pros
- The only free edition among the ten
- Full marks on STIX/TAXII and deployment control
- Four ranked vendors feed into it, so a new install can hit the ground running
Cons
- The threat intelligence data comes from the feeds you connect, so criterion one scores 0
- Community support runs through Slack
- The team patches its own deployment
"They are invaluable when you have to look up certain IOCs and get results from many data sources."
A tool developer writing about MISP and OpenCTI, Hacker News, March 2025
Why it's ranked #2. It ties Recorded Future on 7 points and loses the tiebreak with 0 published threat actors against 4,000. It beats Flashpoint by 2 points on price and deployment: $0 and air-gapped against a $57,855 median and SaaS.
Flashpoint Ignite
Best fit
Fraud, executive protection or threat intelligence teams that search underground forums, chat services and stolen-credential dumps directly.
Flashpoint Ignite holds 3.6+ petabytes of threat data. It tracks 435,000 vulnerabilities, 105,000 of them pre-CVE. Vulnerability tracking matters most on end-of-life software, where a disclosed flaw stays open for good once security patches stop.
Stolen credentials inside Flashpoint Ignite's 3.6 petabytes, next to 975 million illicit forum posts and 22.3 billion chat messages.
Its Technical Indicators API provides STIX/TAXII 2.1 endpoints, with integrations for ThreatConnect, OpenCTI, Microsoft Sentinel and Splunk.
Key features
- Search across illicit forums, chat services and marketplaces that stay under the radar of web search
- Vulnerability intelligence with pre-CVE entries
- Request-for-information hours with security analysts on security incidents
- Physical security, fraud and brand intelligence modules
Pricing
Quote only. Vendr shows a $57,855 median a year, from $54,200 to $79,730.
Pros
- The largest published underground dataset among these threat intelligence tools
- STIX/TAXII 2.1 endpoints documented
- G2 rates it 4.5 out of 5 from 83 reviews
Cons
- Criterion one scores 0, with volume published and actor counts left out
- Bulk API pulls draw complaints from enterprise reviewers
- Runs as SaaS, so criterion five scores 0
"The API and platform is not geared towards developers or enterprises trying to consume the data in bulk."
Verified user in retail, enterprise, G2 review, 22 August 2024
Why it's ranked #3. It scores 5 and loses to OpenCTI by 2 points on price and deployment. It beats Google Threat Intelligence by 1 point, with 3.6 petabytes of published volume and a documented TAXII 2.1 endpoint.
Google Threat Intelligence
Best fit
Security teams on Google Security Operations that want Mandiant research and VirusTotal data under one licence.
Google launched the product on 6 May 2024, joining Mandiant's 1,100 investigations a year with VirusTotal's 1 million community users. The product page lists Standard, Enterprise and Enterprise+ tiers, sold at flat annual rates with set API quotas.
Key features
- VirusTotal file, URL and domain lookups with YARA threat hunting and machine learning verdicts
- STIX-formatted API responses
- Digital Threat Monitoring for digital risk protection on the dark web
- Gemini summaries for malware analysis
Pricing
Contact sales. Vendr records a $20,592 VirusTotal median (range $10,613 to $240,000) and a $100,000 Mandiant median (range $24,300 to $167,500).
Pros
- The lowest Vendr median among paid tools here
- Mandiant incident response feeds the research
- A Leader in the 2026 Gartner Magic Quadrant
Cons
- Extra API call packs are billed on top of each tier
- Research shows up as investigations, worth 1 point on criterion one
- Runs on Google Cloud, so criterion five scores 0
A cybersecurity manager on G2 in August 2025 flagged the multi-engine weakness: "Sometimes, antivirus engines can generate false positives or have discrepancies among themselves."
Why it's ranked #4. It scores 4 and loses to Flashpoint by 1 point on source volume and TAXII depth. It ties ThreatConnect and wins the tiebreak on criterion one, 1,100 investigations a year against 0.
ThreatConnect (Dataminr)
Best fit
A SOC that wants to kill two birds with one stone: a threat intelligence platform and SOAR playbooks in one product.
Dataminr announced a $290 million deal for ThreatConnect on 21 October 2025, when it had 250 enterprise customers. Its Agentic Threat Intelligence Platform, formerly TI Ops, normalizes 300+ threat intelligence sources and lists 100+ integrations.
Key features
- A TAXII 2.1 server for threat intelligence sharing
- No-code playbooks for automated response to security threats
- An Environment Server that runs apps inside the customer's firewall
- Threat intelligence platform (TIP) modelling of ATT&CK tied to business risk
Pricing
Quote only, and Vendr carries no buyer data for it, so no figure is on record.
Pros
- Full marks on TAXII 2.1
- Automation capabilities and threat intelligence in one console
- G2 rates it 4.6 from 14 reviews
Cons
- The roadmap has answered to Dataminr since October 2025, so keep an eye on it
- Its threat intelligence comes from aggregated sources, so criterion one scores 0
- Building efficient playbooks takes time, per a June 2025 G2 review
"Some Marketplace apps and features can require additional licensing, which may be a blocker for smaller orgs."
Principal consultant, G2 review, August 2025
Why it's ranked #5. It scores 4 and loses the tiebreak to Google on criterion one, 0 points against Google's 1 for 1,100 investigations a year. It beats Cyware on criterion three, a documented TAXII 2.1 server worth 2 points against Cyware's 1.
Cyware Intel Exchange
Best fit
An ISAC, CERT or agency sharing indicators with members, including on air-gapped networks.
Cyware says this threat intelligence platform (TIP) has ingested 15 billion+ threat intelligence objects. It's compliant with STIX 2.x and 1.x and shares feeds as MISP, OpenIOC, YARA and IODEF. The pricing page confirms cloud, on-premise and air-gapped deployments.
Key features
- Format-agnostic ingestion of threat intelligence data, including free text and PDF
- Deduplication and alias consolidation agents for threat intelligence data
- A Collaboration Suite for ISACs, ISAOs and CERTs
- Malware sandboxing
Pricing
Quote only, based on seats, feeds, automation volume and sandbox capacity, so the devil's in the details.
Pros
- Air-gapped threat intelligence platform deployment documented
- STIX 1.x and 2.x support
- Built for sharing across member organisations
Cons
- Quote-only pricing, so criterion four scores 0
- Intelligence comes from connected threat intelligence feeds, so criterion one scores 0
- Scores 1 on criterion three against ThreatConnect's 2
A reviewer on Gartner Peer Insights in February 2026 titled their review "Enterprise-grade CTI platform that truly enables automated, secure threat intelligence sharing en [sic] deduplication."
Why it's ranked #6. It scores 4 and loses to ThreatConnect on criterion three, 1 point against 2. It beats CrowdStrike by 1 point, earning 2 for air-gapped deployment where CrowdStrike scores 0.
CrowdStrike Falcon Adversary Intelligence
Best fit
Security teams already running Falcon endpoint agents that want threat intelligence tied to their own threat detection.
CrowdStrike tracks 290+ adversaries and sells three tiers: Falcon Adversary Intelligence, Adversary Intelligence Premium and Counter Adversary Operations Elite, which assigns a named analyst.
Key features
- Real-time threat intelligence indicators and dark web monitoring in the base tier
- Malware analysis and hunt agents in Premium
- Pre-tested YARA and Snort rules for automated response
- Indicator delivery through a Splunk add-on
Pricing
The pricing page lists endpoint bundles at $59.99 to $184.99 per device a year, and the intelligence tiers go through sales. Vendr's CrowdStrike median is $55,756 across 630 purchases of all modules.
Pros
- 290+ adversaries, the second-largest published count here
- Threat intelligence tied to endpoint security tools
- A Leader in Gartner's inaugural Magic Quadrant
Cons
- Threat intelligence reaches other SIEMs through its API and add-ons, so criterion three scores 0
- Runs in the Falcon cloud, so criterion five scores 0
- Reviewers report a high price for the Recon module
"The cost. Crowdstrike Falcon Recon was very expensive. More than 2 times more than others."
Gary K., IT security, mid-market, G2 review, 19 March 2026
Why it's ranked #7. It scores 3, one point behind Cyware, which earns 2 for air-gapped deployment. It beats Group-IB by 1 point: 290+ adversaries earns 2 on criterion one against Group-IB's 1.
Group-IB Threat Intelligence
Best fit
A bank or payments company in Asia, the Middle East, Europe or Africa that wants cybercrime research with an analyst desk.
Group-IB runs 11 Digital Crime Resistance Centers with a 400+ team and reports 1,550+ high-tech crime investigations across 60 countries. Group-IB Threat Intelligence collects from dark web forums, C&C servers, phishing kits and honeypots. Banks shortlisting it for fraud work will find the commercial side of that job in our financial market intelligence guide.
The product page says Group-IB doesn't charge per user, integration or API call, and connects to security tools via API and STIX/TAXII.
Key features
- Underground monitoring of threat actors and compromised-credential detection
- 12 specialist AI agents under the Prevyn name
- Graph investigation of malicious infrastructure and attack patterns
- Analyst RFI service for security incidents
Pricing
Quote only, sold as a flat licence with no per-user, per-integration or per-call metering.
Pros
- Flat threat intelligence licence with unmetered API calls
- 1,550+ investigations behind the research
- G2 rates Group-IB Threat Intelligence 4.7 from 29 reviews
Cons
- Sources listed by type without volume, so criterion two scores 0
- Runs as a cloud service, so criterion five scores 0
- A higher subscription price than rivals, per reviewers
"Every good product comes with a price, GIB being one of the leading TI platform, the subscription price will be slight higher compare to the other vendors."
Lawrence T., product sales director, G2 review, 21 February 2025
Why it's ranked #8. Group-IB Threat Intelligence scores 2 and loses to CrowdStrike on price, quote only against a $55,756 Vendr median. It beats Anomali by 1 point with 1,550+ published investigations.
Anomali ThreatStream
Best fit
An MSSP or large SOC that buys several premium threat intelligence feeds and wants one place to store and distribute them.
This threat intelligence platform collects from hundreds of open, commercial and community sources and distributes finished intelligence to ISACs through Trusted Circles and STIX/TAXII. Its Marketplace sells feeds from five other vendors on this page, among them Mandiant, Flashpoint and Intel 471.
Key features
- Threat intelligence feeds marketplace
- Trusted Circles for sharing
- Managed threat intelligence services and threat intelligence solutions for MSSPs
- API access to every intelligence object
Pricing
Quote only, and Vendr carries no buyer data for ThreatStream.
Pros
- One threat intelligence platform contract can carry several premium feeds
- STIX/TAXII distribution documented
- Feeds from 5 ranked vendors in one marketplace
Cons
- Source volume published as "hundreds", which scores 0 on criterion two
- TrustRadius scores it 6.4 out of 10 from 12 reviews
- Reviewers call it expensive
An enterprise SOC engineering lead on G2 in July 2023 called it "a handy threat intelligence platform that provides curated threat intelligence through IOCs and Reports," then opened the complaints with "Anomali ThreatStream is comparatively expensive."
Why it's ranked #9. It scores 1 and loses to Group-IB by 1 point on analyst output. It ties Intel 471 on 1 point and wins on criterion three, documented STIX/TAXII distribution against 0.
Intel 471 Verity471
Best fit
A fraud or cybercrime team that pays for human intelligence operators inside criminal communities.
Intel 471 launched Verity471 on 31 July 2025, after buying Cyborg Security on 1 May 2024. Its cyber threat intelligence page lists seven categories: adversary, brand, credential, fraud, geopolitical, malware and vulnerability.
Key features
- Malware Emulation and Tracking System (METS), patented
- OCR and logo detection for data analysis of underground images
- HUNTER threat hunt packages for potential security threats in SIEM, EDR and NDR
- An OpenCTI connector
Pricing
Quote only. Vendr shows a $220,425 median a year, from $165,900 to $249,000.
Pros
- Human operators collect strategic intelligence on threat actors in criminal forums
- Threat hunting packages from the Cyborg deal
- A Vendr range on record
Cons
- The highest Vendr median here, 3 times Recorded Future's $72,703, so it can cost an arm and a leg
- Criteria one and two both score 0
- Gartner Peer Insights averages 3.7 of 5 for this strategic intelligence service
A reviewer on Gartner Peer Insights in August 2026 wrote: "The platform will sometimes auto lock the account out even after resetting the password."
Why it's ranked #10. It ties Anomali on 1 point, earned by a $220,425 Vendr median, and loses the tiebreak on criterion three, where Anomali's documented STIX/TAXII distribution earns 1. It scores 0 on criteria one, two, three and five.
What a threat intelligence platform does
A threat intelligence platform collects, normalizes and scores threat intelligence data from many feeds, then pushes it to the security tools that block or detect. Palo Alto Networks describes TIPs that gather data from multiple sources, including open source intelligence, private vendor feeds and incident logs.
- Collection: it automates intake to aggregate threat data from feeds, sandboxes and partners.
- Enrichment: it correlates threat data so IP addresses and hashes arrive with an actor and campaign.
- Scoring: machine learning and natural language processing identify patterns, and human analysts review the top hits.
- Distribution: it pushes threat indicators and actionable intelligence to the SIEM, firewall and EDR.
- Automated response: playbooks act on a match, such as isolating affected systems or updating firewalls.
A threat intelligence platform that analyzes threat data as it arrives turns a feed into real time threat intelligence: actionable threat intelligence a SOC can block on, and actionable insights for the CISO. Commercial teams run the same push model on competitor and market signals, covered in our guide to real-time market intelligence.
Machine learning models that identify patterns across feeds are what separate a threat intelligence platform (TIP) from a spreadsheet of IP addresses. Threat intelligence solutions split into data and platforms: Flashpoint, Intel 471 and Group-IB sell threat data, OpenCTI, Cyware and ThreatConnect sell threat intel platforms, and Recorded Future and Google sell both.
Two neighbouring categories borrow the vocabulary. Forensic suites, which reconstruct an incident after it happens, sit in the digital intelligence platforms ranking. Platforms that catalogue a company's own databases have their own data intelligence tools ranking.
Types of threat intelligence
Most guides split the field into four types of threat intelligence, defined here as in Palo Alto Networks' TIP guide:
- Strategic intelligence: long-term trends on threat actors and cybersecurity threats that shape executive budgets.
- Tactical intelligence: the tactics, techniques and procedures of threat actors, mapped to MITRE ATT&CK. Detection engineers use tactical intelligence to zero in on the behaviour a rule should catch.
- Operational intelligence: specific, ongoing or imminent campaigns. Operational intelligence gives incident responders context during security incidents.
- Technical intelligence: indicators of compromise, malware signatures and IP addresses, which a SIEM ingests.
Intel 471 and Group-IB sell strategic intelligence on cybercrime groups, built on human operators and 1,550+ investigations respectively. VirusTotal is a technical intelligence engine for file, URL and domain lookups. Market intelligence has its own four-way split by subject, competitive, product, customer and market, set out in our guide to the types of market intelligence.
A threat intelligence lifecycle runs all four types to track emerging threats across the threat landscape, on the same collect, analyse and review loop a team uses to gather market intelligence. The threat landscape review at the end of each cycle feeds security posture decisions and actionable insights for the board, and a 5x5 risk assessment matrix ranks identified threats on likelihood and impact.
Integrating threat intelligence with SIEM, SOAR and existing security infrastructure
BlueVoyant says integrating threat intelligence with a SIEM lets security teams categorize and prioritize alerts, and remove false positives, and that it should help identify vulnerabilities and threats before an attack. A security operations center can measure that shift to proactive security: count the alerts closed as benign before and after the feed goes live, and the difference is the security posture gain the vendor promised.
Integrating threat intelligence with existing security infrastructure and existing security operations depends on three standards and one habit:
- STIX 2.1: the JSON format for indicators, actors and relationships
- TAXII 2.1: the HTTPS protocol that serves STIX collections
- MITRE ATT&CK: technique IDs for attack patterns of threat actors
- Expiry: retiring stale threat data so old IP addresses stop alerting
Traditional security controls such as firewalls and SIEM correlation rules block only the indicators already loaded into them, so modern security operations feed them tactical intelligence on identified threats over TAXII. A firewall that pulls a TAXII 2.1 collection updates its block list as new indicators arrive, which adds automated threat detection and automated response to the response capabilities security teams already run.
Threat intelligence platform pricing
Six of the ten have a price on record, and OpenCTI's $0 Community Edition is the only price a vendor publishes for its intelligence product.
Three costs sit outside those medians:
- Vendr lists vulnerability, brand and third-party intelligence as separate modules for Recorded Future.
- Google sells extra API call packs on top of each tier.
- ThreatConnect Marketplace apps carry their own licences, and free OpenCTI still needs servers.
Get the module list and API quota for any cyber threat intelligence solution in writing, so security teams know which security tools each licence covers.
For scale, our market intelligence platform pricing report puts competitive monitoring platforms at $15,000 to $50,000+ a year. Four of the five Vendr medians in the comparison table sit above that $50,000 mark.
Free threat intel tools and their limits
MISP and OpenCTI, the two free platforms here, both shipped releases within a week of 4 October 2026: MISP v2.5.48 on 29 September and OpenCTI on 2 October. The MISP repository carries 6,500+ GitHub stars.
The VirusTotal public API allows 500 requests a day at 4 a minute and is barred from commercial products. For a SOC enriching every alert, that's a drop in the bucket.
Free threat intel feeds and threat intel platforms return the indicator itself, and actor attribution sits behind a paid licence: the #1 tool tracks 4,000 threat actors and CrowdStrike 290+ adversaries.
Consolidation among threat intelligence platform vendors
Seven ownership or packaging changes between May 2024 and October 2025 reshaped the vendor side of the threat landscape, five of them at four vendors ranked here:
- 1 May 2024: Intel 471 bought Cyborg Security for threat hunting.
- 6 May 2024: Google launched Google Threat Intelligence, joining Mandiant and VirusTotal under one licence.
- 20 December 2024: Mastercard closed its $2.65 billion deal for Recorded Future.
- 11 June 2025: ThreatQuotient announced it would join Securonix, a SIEM vendor.
- 22 July 2025: Microsoft began converging Defender Threat Intelligence into Sentinel and Defender XDR at no additional cost, citing 84 trillion daily signals.
- 31 July 2025: Intel 471 launched Verity471.
- 21 October 2025: Dataminr announced its $290 million ThreatConnect deal.
SIEM and XDR licences now bundle threat intelligence, so a standalone contract has to beat what's in the box. A risk-benefit analysis template puts the bundled feed and the standalone contract side by side on one sheet.
Threat intelligence products listed in G2's category. Picking ten from that list is a needle in a haystack job.
How to evaluate threat intelligence solutions before you sign
- Export 30 days of SIEM alerts and the IP addresses, domains and hashes in them.
- Ask each vendor to enrich the list, and count identified threats that return with an actor or campaign.
- Count false positives by analyzing data on indicators scored malicious that security teams closed as benign.
Step three tests the false-positive claims vendors print, the 95% cut claimed for the #1 tool among them, against your own alerts. A feed tuned for recall makes the SIEM cry wolf, and security professionals pay in hours spent analyzing data on potential security threats that were never there, a cost that compounds across threat intelligence teams.
Log each vendor's enrichment hit rate and false-positive count in our vendor evaluation scorecard template, next to its score on the five criteria.
Threat intelligence tools FAQ
What is the best threat intelligence platform?
On five testable criteria, the best threat intelligence tools are Recorded Future and OpenCTI at 7 of 10, then Flashpoint at 5. Recorded Future wins on published research, OpenCTI on price.
What is a cyber threat intelligence program?
The team, requirements and tools that run the threat intelligence lifecycle for one organisation. Each cyber threat intelligence tool above covers part of that loop against cyber attacks and emerging threats across the threat landscape. The analyst seat runs the same collect-and-brief cycle as a market intelligence analyst, pointed at attackers.
How much does a threat intelligence platform cost?
Vendr's buyer data puts medians between $20,592 a year for VirusTotal and $220,425 for Intel 471, with Recorded Future at $72,703. OpenCTI's Community Edition costs $0 plus the servers to run it, and ThreatConnect, Cyware, Group-IB and Anomali sell by quote with no figure on record.
Is there a free threat intelligence platform?
Yes. OpenCTI's Community Edition and MISP are both free to self-host. The VirusTotal public API is free too, capped at 500 requests a day and barred from commercial products.
What are the four types of threat intelligence?
Strategic, tactical, operational and technical. Strategic intelligence covers long-term trends for executives, tactical intelligence maps attacker techniques to MITRE ATT&CK, operational intelligence covers live campaigns, and technical intelligence is the indicators a SIEM ingests.
What is STIX/TAXII?
STIX 2.1 is the JSON format for indicators, actors and relationships, and TAXII 2.1 is the HTTPS protocol that serves STIX collections. Recorded Future, OpenCTI, Flashpoint and ThreatConnect document TAXII support and score 2 on criterion three.
Bottom line
Recorded Future is the pick for an enterprise SOC that wants the most published research and can carry a $72,703 median. OpenCTI suits teams with engineering time. As free threat intelligence software it pairs with any paid feed, so nobody has to put all their eggs in one basket.
Flashpoint fits dark web work, Google fits Google SecOps users, ThreatConnect fits TIP-plus-SOAR buyers and Cyware fits air-gapped networks. CrowdStrike suits a Falcon estate, Group-IB banks, Anomali feed resellers and Intel 471 cybercrime teams with six-figure budgets.