Top Free Threat Intelligence Software - Page 4

How Many Threat Intelligence Software Products Does G2 Track?

Total Products under this Category: 219

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Darktrace / EMAIL (+3.53%) - Among all products in this category, Darktrace / EMAIL recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Threat Intelligence Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 219+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Threat Intelligence Software

G2 Grid® for Threat Intelligence Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Ivanti Autonomous Endpoint Management, Recorded Future, Cyble, CloudSEK, ZeroFox, SOCRadar Extended Threat Intelligence, and CTM360.

Underlying data: [Grid® JSON](https://www.g2.com/categories/threat-intelligence/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=ivanti-autonomous-endpoint-management&focus%5B%5D=recorded-future&focus%5B%5D=cyble&focus%5B%5D=cloudsek&focus%5B%5D=zerofox&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360)

VMRay

Sandboxing reinvented against the threats of today - and tomorrow. At VMRay, our purpose is to liberate the world from undetectable digital threats. Led by reputable cyber security pioneers, we develop best-of-breed technologies to detect and analyze unknown, evasive, and sophisticated threats that others miss. We empower organizations to accelerate analysis and response, automate security tasks, and build their own threat intelligence by providing the world’s best detection and analysis platform for malware and phishing threats. ___ The target audience for VMRay encompasses a wide range of organizations, including enterprises such as top technology firms, banks and financial organizations, leading manufacturing companies, accounting and consulting firms, managed security service providers (MSSPs), and government entities. These users face the daunting challenge of safeguarding sensitive data against increasingly sophisticated cyber threats. VMRay's unique technologies, based on the world’s most advanced sandbox which employs a hypervisor-based approach, enables users to observe malicious samples in a completely invisible environment. This capability not only enhances the accuracy and depth of threat detection but also ensures that security teams can analyze threats without interference from evasive tactics employed by cyber threat actors. By meticulously sorting, filtering, and prioritizing results, VMRay delivers clear and actionable reports that eliminate the noise often associated with advanced threat analysis. This clarity is crucial for security teams, as it allows them to focus on the highest-priority insights without being overwhelmed by irrelevant data. Furthermore, VMRay's integration capabilities enable seamless integrations with existing security tools, such as Endpoint Detection and Response (EDR) systems, Security Orchestration, Automation, and Response (SOAR) platforms, and Threat Intelligence platforms enhancing overall operational efficiency of SOC and CTRI teams, incident responders and threat hunters. In addition to its technological prowess, VMRay places a strong emphasis on privacy and data control. Unlike many competitors, VMRay does not share customer analysis reports, indicators of compromise (IOCs), and any kind of data with third parties, ensuring that sensitive information remains confidential. Customers have the flexibility to choose their data hosting locations (in Germany and the USA) and durations, which is particularly beneficial for organizations that must comply with stringent privacy regulations. This commitment to privacy, combined with VMRay's innovative solutions, positions the company as a trusted partner for organizations seeking to bolster their cyber resilience and enhance SOC maturity. Ultimately, VMRay's dedication to continuous innovation, coupled with its focus on delivering reliable and clear threat analysis, makes it a formidable player in the malware analysis landscape. By addressing the complexities of modern cyber threats with precision and clarity, VMRay empowers organizations to navigate the challenges of cybersecurity with confidence, ensuring they are well-equipped to defend against both current and future threats.

Average Rating: 4.6/5.0

Total Reviews: 7

How Do G2 Users Rate VMRay?

  • Ease of Use: 9.0/10 (Category avg: 9.1/10)

Who Is the Company Behind VMRay?

  • Seller: VMRay
  • Year Founded: 2013
  • HQ Location: Bochum, DE
  • Twitter: @vmray
    4,092 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    126 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 86% Large, 14% Small

What Do G2 Reviewers Say About VMRay?

AI-generated summary from verified user reviews

Pros
  • Users value the automation integrations of VMRay, enhancing their threat analysis and incident response efficiency.
  • Users commend the stellar customer support of VMRay, highlighting the team's responsiveness and expertise.
  • Users highlight the deployment ease of VMRay, appreciating its robust architecture and effective threat detection capabilities.
  • Users value the detailed analysis features of VMRay, benefiting from enhanced interaction and automation integration.
  • Users value the ease of use of VMRay, appreciating its intuitive interface and seamless integration capabilities.
Cons
  • Users find the difficult learning curve of VMRay challenging due to its less intuitive interface.
  • Users find the difficult setup of VMRay frustrating, especially with unclear processing failures for samples.
  • Users find VMRay expensive, but many believe it is worth the cost for its value and effectiveness.
  • Users report experiencing poor detection performance, occasionally missing important findings during scans with VMRay.
  • Users feel the need for a more intuitive interface to enhance the learning curve for VMRay.

What Are Recent G2 Reviews of VMRay?

VulnCheck Exploit and Vulnerability Intelligence

A next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence directly into the tools, processes, programs, and systems that need it to outpace adversaries.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate VulnCheck Exploit and Vulnerability Intelligence?

  • Security Validation: 10.0/10 (Category avg: 9.1/10)
  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Endpoint Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind VulnCheck Exploit and Vulnerability Intelligence?

  • Seller: VulnCheck
  • Year Founded: 2021
  • HQ Location: Lexington, US
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About VulnCheck Exploit and Vulnerability Intelligence?

AI-generated summary from verified user reviews

Pros
  • Users commend the accuracy of VulnCheck's information, finding it robust and valuable for enhancing security assessments.
  • Users commend the constructive customer support of VulnCheck, enhancing their integration experience and overall value provided.
  • Users highlight the ease of integration of VulnCheck, benefiting from a well-documented process and helpful support.
  • Users value the easy integration capabilities of VulnCheck, enhancing their security platform experience with accurate intelligence.
  • Users value the reliable and accurate intelligence provided by VulnCheck, enhancing their overall security capabilities.

What Are Recent G2 Reviews of VulnCheck Exploit and Vulnerability Intelligence?

AI-OS by OwlSense

AI-OS by OwlSense is an advanced open-source intelligence (OSINT) platform designed to help organizations detect, analyze, and respond to emerging digital threats. It empowers security teams, agencies, and enterprises to uncover hidden risks, monitor disinformation, and build resilience against malicious campaigns. Key Capabilities: Early Threat Detection: Identify fault lines and recognize early indicators of coordinated disinformation or destabilizing activities. Campaign Exposure: Trace individuals and networks behind harmful narratives to improve accountability and enable faster response. Counter Radicalization: Detect and analyze indoctrination methods, profiling key influencers and their reach. Comprehensive Media Analysis: Process text, audio, video, and images to deliver a complete intelligence picture. Behavioral Insights: Apply psychometric and behavioral profiling to anticipate risks and support proactive decision-making. AI-OS by OwlSense provides a holistic intelligence framework, helping organizations stay ahead of evolving online threats.

Who Is the Company Behind AI-OS by OwlSense?

DynaRisk

DynaRisk's Breach Defence software empowers small to medium sized businesses to be safer online. Cyber attacks are constant and are always evolving. 60% of SMEs can go out of business within 6 months of suffering a cyber attack. SMEs need simple yet comprehensive cyber risk management solutions to manage complex cyber risks. This is why DynaRisk has developed Breach Defence to give SMEs the tools they need to defend against cyber attacks.

Who Is the Company Behind DynaRisk?

  • Seller: DynaRisk
  • Year Founded: 2015
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Falconfeedsio

Falcon Feeds.io is a cutting-edge, cloud-native SaaS platform that specializes in cyber threat intelligence. It vigilantly monitors and delivers the latest security incidents and insights on threat actors from around the globe, around the clock. Our expansive coverage includes the surface web, Tor networks, and Telegram channels. With Falcon Feeds.io, you can: Continuous Monitoring: Keep a watchful eye on threat actors, ransomware attacks, DDoS attacks, and other security incidents around the clock. Comprehensive Analysis: Stay informed about the most affected geographies, industries, organizations, and domains in real-time. Unrestricted Access: Gain unlimited access to our extensive threat feed database to empower your security measures. Customizable Alerts: Configure alerts tailored to new threats related to specific threat actors, incident categories, countries, industries, organizations, and domains. Seamless Integration: Utilize our robust API and Webhook integration for a smooth and streamlined security workflow. Real-Time Notifications: Get instant notifications through Slack, Microsoft Teams, and email, ensuring you never miss a critical update.

Who Is the Company Behind Falconfeedsio?

  • Seller: Technisanct
  • Year Founded: 2023
  • HQ Location: London, GB
  • Twitter: @FalconFeedsio
    68,906 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3 employees on LinkedIn®

Parano.ai

Parano.ai is a competitive intelligence platform that automatically tracks changes across your competitors’ websites, pricing pages, product updates, job listings, ads, and reviews. Get real-time alerts, historical change logs, and structured insights without manual research. Built for founders, product, sales, and marketing teams who want to spot moves early, react faster, and turn competitor activity into strategic advantage.

Who Is the Company Behind Parano.ai?

RST Threat Feed

RST Cloud empowers SecOps teams with actionable, high-fidelity threat intelligence - from the RST Threat Feed with contextualized, relevant IoCs to detailed adversary insights through the RST Threat Library and near real-time global threat report delivery via RST Report Hub. Combined with powerful enrichment APIs such as RST Noise Control, RST IoC Lookup, and the RST WHOIS API, RST Cloud enables organizations to detect threats faster, respond with confidence, and make informed, threat-driven decisions. Additionally, the RST CTI Assistant offers intuitive, conversational access to all this intelligence - making threat data effortless to query, understand, and put into action.

Who Is the Company Behind RST Threat Feed?

SAGA

SAGA® is an innovative platform designed to automate the monitoring of the surface, deep, and dark web, enhancing cybersecurity. It is tailored to protect businesses, organizations, and individuals from potential cybercrime and fraud. Key Features of SAGA®: Unmatched Data Coverage: SAGA® features a proprietary scraping system combined with extensive external data integrations, offering unparalleled breadth and depth in cyber threat intelligence from the surface, deep, and dark web. SAGA® AI: Our advanced generative AI technology transforms raw intelligence into actionable insights. This includes human-readable risk alerts, contextual reports, and comprehensive intelligence, making cyber threat information accessible and actionable for all. Modular and Cost-Effective: SAGA®'s modular architecture allows customers to tailor their cybersecurity solutions. You only pay for the services you need, ensuring a cost-effective approach to comprehensive digital risk protection. Global Reach, Local Expertise: Based in Copenhagen and leveraging a global network of partners, SAGA® combines worldwide expertise with local insights, delivering solutions in 30 markets and 6 languages. SAGA® Products: SAGA® Platform: A cloud-based solution that automates monitoring across various web layers, offering robust protection against cyber threats. SAGA® AI: This tool leverages generative AI to provide intuitive and detailed risk assessments from vast amounts of web data. SAGA® API: Integrate SAGA®'s intelligence directly into your existing systems with our RESTful API, seamlessly enhancing your MSSP offerings. Air Gap Option: For highly sensitive projects, including government or state clients, SAGA® offers an on-premises solution with a data diode, ensuring one-way data flow and enhanced security.

Who Is the Company Behind SAGA?

  • Seller: Munit.io
  • Year Founded: 2015
  • HQ Location: Copenhagen, DK
  • LinkedIn® Page: www.linkedin.com
    13 employees on LinkedIn®

The Security Bulldog

The Security Bulldog lowers costs and speeds remediation of vulnerabilities for enterprise cybersecurity teams using a proprietary AI-based intelligence platform, originally developed for the intelligence community. Cyber teams are so overwhelmed that they don’t have time to save time as they struggle with the same problem: they wake up in the morning and spend two to three hours finding out what broke, does it affect them, and, if it does, how to fix it. Our proprietary natural language processing engine collects, analyses, and contextualizes the data they need in a human-friendly way to reduce cognitive burden, improve decision making, and quicken remediation.

Who Is the Company Behind The Security Bulldog?

VenariX Threat Intelligence Platform

VenariX is an analyst-reviewed cyber intelligence platform that tracks 33,500+ cyber incidents across 17 incident types and maintains 310+ threat actor profiles with TTPs, targets, and campaign history. It monitors 350+ open, deep, and dark web sources, with 80+ new incidents added daily. Each record includes financial, legal, regulatory, operational, and supply chain context, with verified findings clearly separated from unconfirmed claims. Security leaders use VenariX for executive reporting, vendor risk, and budget decisions, while security and threat analysts use it to investigate incidents, monitor threat actors, and track sectors, technologies, and regions. VenariX is available as a SaaS platform with a free tier and as commercially licensed data delivered through APIs, webhooks, or database mirroring. Alerts are available through Microsoft Teams, Slack, and email.

Who Is the Company Behind VenariX Threat Intelligence Platform?

  • Seller: VenariX
  • Year Founded: 2023
  • HQ Location: San Antonio, US
  • LinkedIn® Page: www.linkedin.com
    3 employees on LinkedIn®

Verimatrix XTD

Verimatrix XTD stands at the forefront of application security, offering unmatched protection for mobile, web desktop and embedded applications in critical industries while streamlining implementation to empower innovation. Verimatrix delivers an amazing cybersecurity experience with XTD; allowing customers to prevent, detect, respond and predict threats to their mobile applications and the devices that connect to their critical infrastructure. We have expanded our detection capabilities to the network, beyond application and device level detections. We can access risk per application to protect the connection to the company critical infra. Verimatrix XTD’s Application Protection Suite includes: - XTD Enterprise Suite - XTD Protect for Mobile (iOS and Android) - XTD Protect for Desktop and Embedded Applications (Windows, MacOS and Linux) - XTD Protect for Native Applications (C/C++) - XTD Key Shield (whitebox cryptography) - XTD Protect for Web Applications - XTD Managed Services

Who Is the Company Behind Verimatrix XTD?

  • Seller: Verimatrix
  • Year Founded: 1995
  • HQ Location: Meyreuil, FR
  • Twitter: @VerimatrixInc
    4,743 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    205 employees on LinkedIn®

Viettel Threat Intelligence

Viettel Threat Intelligence is an AI-powered Threat Intelligence Platform developed by Viettel Cyber Security, designed to empower SOC teams, threat analysts, and CISOs across the Asia-Pacific region with contextualized, real-time threat visibility. As an integrated solution combining Dark Web Monitoring, Cyber Threat Intelligence, and Digital Risk Protection, Viettel Threat Intelligence provides end-to-end coverage of external cyber risks—including APTs, phishing campaigns, credential leaks, domain impersonation, and malware infrastructure. Organizations benefit from actionable intelligence feeds (STIX/TAXII), automated alerting, and in-depth analysis of adversary TTPs and IOCs. What sets Viettel Threat Intelligenceapart is its deep integration of proprietary threat data, intelligence from dark web forums, open sources, government feeds, and the unique insight of Viettel’s elite Hunting Team. The platform scans over 200 million security events daily, delivering high-fidelity alerts with minimal false positives—within 24 hours. Trusted by governments and enterprises across APAC, Viettel Threat Intelligence delivers localized threat insight, expert-driven analysis, and value-added services such as phishing takedown, brand protection, and incident diagnostics. With a proven record of detecting over 500,000 phishing domains and 100M+ leaked credentials in a single year, Viettel Threat Intelligence helps organizations stay ahead of evolving threats with speed, precision, and clarity.

Who Is the Company Behind Viettel Threat Intelligence?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 22, 2025