G2 is a peer review website for software and services. Find the right software and services based on 3,506,300+ real reviews. Featured sponsored content does not receive preferential treatment in the Threat Intelligence Software category, or any of G2’s ratings. All review data is from real users.
Cloudflare Application Security and Performance
Product Description
Cloudflare Application Security and Performance solutions provide performance, reliability, and security for all of your web applications and APIs, wherever they are hosted and wherever your users are.
Pros
Cons
CrowdStrike Falcon Endpoint Protection Platform
Product Description
CrowdStrike Falcon endpoint protection unifies the technologies required to successfully stop breaches: next-generation antivirus, endpoint detection and response, IT hygiene, 24/7 threat hunting and threat intelligence. They combine to provide continuous breach prevention in a single agent.
Pros
Cons
Recorded Future
Product Description
Recorded Future Intelligence Cloud elevates your existing security defenses by enhancing the depth and breadth of protection by giving you insights into threats and attacks before they impact, so you can stay ahead of attackers, at the speed and scale of today’s threat environment.
Pros
Cons
Intezer
Product Description
Automate your malware analysis. Get answers quickly about any suspicious file, URL, endpoint or memory dump.
Pros
Cons
Check Point Exposure Management
Product Description
Cyberint is now a Check Point Company. Its impactful intelligence solution combines cyber threat intelligence, external attack surface management, brand protection, and digital supply chain intelligence into a single, powerful solution. By leveraging autonomous discovery of all of an organization’s external-facing assets, coupled with open, deep & dark web intelligence, the solution enables cybersecurity teams to accelerate the detection and disruption of their most pressing cyber risks. Global customers, including Fortune 500 leaders across all major market verticals, rely on us to prevent, detect, investigate, and remediate phishing, malware, fraud, brand abuse, data leaks, external vulnerabilities, and more, ensuring continuous external protection from cyber threats.
Pros
Cons
Pentera
Product Description
Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. For more info visit: pentera.io.
Pros
Cons
Cyble
Product Description
Cyble Vision, our SaaS-based enterprise platform collects real-time intelligence data from both open and closed sources to map, monitor, and mitigate digital risk.
Pros
Cons
CloudSEK
Product Description
Cloudsek is an Infosec Risk assessment company which provides intelligence needed to tackle online threats.
Pros
Cons
ZeroFox
Product Description
With a global data collection engine, artificial intelligence-based analysis, and automated remediation, the ZeroFOX Platform protects you from cyber, brand and physical threats on social media & digital platforms.
Pros
Cons
GreyNoise
Product Description
GreyNoise is a cybersecurity platform that collects, analyzes, and classifies internet-wide scan and attack traffic to help security teams distinguish between benign and malicious activities. By leveraging a global network of passive sensors, GreyNoise identifies IP addresses involved in mass scanning and categorizes them based on intent, enabling organizations to reduce false positives and focus on genuine threats. This approach enhances the efficiency of Security Operations Centers (SOCs by filtering out irrelevant alerts and providing actionable intelligence on emerging threats.
Key Features and Functionality:
- Real-Time Threat Intelligence: Provides up-to-date information on internet scanning activities, allowing security teams to respond swiftly to potential threats.
- IP Classification: Categorizes IP addresses as benign, suspicious, or malicious based on their behavior, aiding in accurate threat assessment.
- Vulnerability Prioritization: Offers insights into active in-the-wild exploitation of vulnerabilities, assisting teams in prioritizing patching and remediation efforts.
- Integrations: Seamlessly integrates with existing security tools and platforms, enhancing the overall security infrastructure.
- Advanced Analytics: Utilizes data science techniques and AI to process vast amounts of data, providing meaningful insights and reducing alert fatigue.
Primary Value and Problem Solved:
GreyNoise addresses the challenge of alert fatigue faced by security teams due to the overwhelming volume of false positives generated by security tools. By filtering out internet background noise and focusing on relevant threats, GreyNoise enables organizations to:
- Enhance Efficiency: Reduce the time spent investigating non-threatening alerts, allowing teams to concentrate on critical issues.
- Improve Threat Detection: Identify and respond to emerging threats more effectively with real-time, actionable intelligence.
- Optimize Resource Allocation: Prioritize vulnerability remediation efforts based on active exploitation data, ensuring resources are directed where they are needed most.
By providing a clear distinction between benign and malicious internet activities, GreyNoise empowers security teams to act with speed and confidence, ultimately strengthening an organization's cybersecurity posture.
Pros
Cons
Cloudflare Application Security and Performance
Product Description
Cloudflare Application Security and Performance solutions provide performance, reliability, and security for all of your web applications and APIs, wherever they are hosted and wherever your users are.
Integrates with:
GitHub
Datadog
Microsoft PowerPoint
WordPress.com
IBM Terraform (formerly HashiCorp Terraform)
AWS Elastic Load Balancing
CrowdStrike Falcon Endpoint Protection Platform
Product Description
CrowdStrike Falcon endpoint protection unifies the technologies required to successfully stop breaches: next-generation antivirus, endpoint detection and response, IT hygiene, 24/7 threat hunting and threat intelligence. They combine to provide continuous breach prevention in a single agent.
Integrates with:
Okta
Palo Alto Networks Next-Generation Firewalls
Splunk Enterprise
OneLogin
Slack
Microsoft Entra ID
Recorded Future
Product Description
Recorded Future Intelligence Cloud elevates your existing security defenses by enhancing the depth and breadth of protection by giving you insights into threats and attacks before they impact, so you can stay ahead of attackers, at the speed and scale of today’s threat environment.
Integrates with:
Okta
Jira
Brinqa
Splunk Enterprise
Slack
Microsoft Entra ID
Intezer
Product Description
Automate your malware analysis. Get answers quickly about any suspicious file, URL, endpoint or memory dump.
Check Point Exposure Management
Product Description
Cyberint is now a Check Point Company. Its impactful intelligence solution combines cyber threat intelligence, external attack surface management, brand protection, and digital supply chain intelligence into a single, powerful solution. By leveraging autonomous discovery of all of an organization’s external-facing assets, coupled with open, deep & dark web intelligence, the solution enables cybersecurity teams to accelerate the detection and disruption of their most pressing cyber risks. Global customers, including Fortune 500 leaders across all major market verticals, rely on us to prevent, detect, investigate, and remediate phishing, malware, fraud, brand abuse, data leaks, external vulnerabilities, and more, ensuring continuous external protection from cyber threats.
Integrates with:
Jira
Check Point Next Generation Firewalls (NGFWs)
Palo Alto Networks Next-Generation Firewalls
SonicWall Next Generation Firewall
Check Point Mobile Access
Splunk Enterprise
Pentera
Product Description
Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. For more info visit: pentera.io.
Integrates with:
IBM QRadar SIEM
Cyble
Product Description
Cyble Vision, our SaaS-based enterprise platform collects real-time intelligence data from both open and closed sources to map, monitor, and mitigate digital risk.
Integrates with:
Jira
Microsoft Outlook
Microsoft 365
Splunk Enterprise
Splunk Enterprise Security
Microsoft Teams
CloudSEK
Product Description
Cloudsek is an Infosec Risk assessment company which provides intelligence needed to tackle online threats.
Integrates with:
Jira
Microsoft Outlook
Splunk Enterprise
RSA SecureID
Jira Service Management
LogRhythm SIEM
ZeroFox
Product Description
With a global data collection engine, artificial intelligence-based analysis, and automated remediation, the ZeroFOX Platform protects you from cyber, brand and physical threats on social media & digital platforms.
Integrates with:
Microsoft SharePoint
Jira
Splunk Enterprise
Slack
Datadog
Jira Service Management
GreyNoise
Product Description
GreyNoise is a cybersecurity platform that collects, analyzes, and classifies internet-wide scan and attack traffic to help security teams distinguish between benign and malicious activities. By leveraging a global network of passive sensors, GreyNoise identifies IP addresses involved in mass scanning and categorizes them based on intent, enabling organizations to reduce false positives and focus on genuine threats. This approach enhances the efficiency of Security Operations Centers (SOCs by filtering out irrelevant alerts and providing actionable intelligence on emerging threats.
Key Features and Functionality:
- Real-Time Threat Intelligence: Provides up-to-date information on internet scanning activities, allowing security teams to respond swiftly to potential threats.
- IP Classification: Categorizes IP addresses as benign, suspicious, or malicious based on their behavior, aiding in accurate threat assessment.
- Vulnerability Prioritization: Offers insights into active in-the-wild exploitation of vulnerabilities, assisting teams in prioritizing patching and remediation efforts.
- Integrations: Seamlessly integrates with existing security tools and platforms, enhancing the overall security infrastructure.
- Advanced Analytics: Utilizes data science techniques and AI to process vast amounts of data, providing meaningful insights and reducing alert fatigue.
Primary Value and Problem Solved:
GreyNoise addresses the challenge of alert fatigue faced by security teams due to the overwhelming volume of false positives generated by security tools. By filtering out internet background noise and focusing on relevant threats, GreyNoise enables organizations to:
- Enhance Efficiency: Reduce the time spent investigating non-threatening alerts, allowing teams to concentrate on critical issues.
- Improve Threat Detection: Identify and respond to emerging threats more effectively with real-time, actionable intelligence.
- Optimize Resource Allocation: Prioritize vulnerability remediation efforts based on active exploitation data, ensuring resources are directed where they are needed most.
By providing a clear distinction between benign and malicious internet activities, GreyNoise empowers security teams to act with speed and confidence, ultimately strengthening an organization's cybersecurity posture.
Integrates with:
Jira
Splunk Enterprise
Slack
Sumo Logic
Coralogix
Apollo.io
Cloudflare Application Security and Performance
Product Description
Cloudflare Application Security and Performance solutions provide performance, reliability, and security for all of your web applications and APIs, wherever they are hosted and wherever your users are.
CrowdStrike Falcon Endpoint Protection Platform
Product Description
CrowdStrike Falcon endpoint protection unifies the technologies required to successfully stop breaches: next-generation antivirus, endpoint detection and response, IT hygiene, 24/7 threat hunting and threat intelligence. They combine to provide continuous breach prevention in a single agent.
Features:
Recorded Future
Product Description
Recorded Future Intelligence Cloud elevates your existing security defenses by enhancing the depth and breadth of protection by giving you insights into threats and attacks before they impact, so you can stay ahead of attackers, at the speed and scale of today’s threat environment.
Features:
Intezer
Product Description
Automate your malware analysis. Get answers quickly about any suspicious file, URL, endpoint or memory dump.
Features:
Check Point Exposure Management
Product Description
Cyberint is now a Check Point Company. Its impactful intelligence solution combines cyber threat intelligence, external attack surface management, brand protection, and digital supply chain intelligence into a single, powerful solution. By leveraging autonomous discovery of all of an organization’s external-facing assets, coupled with open, deep & dark web intelligence, the solution enables cybersecurity teams to accelerate the detection and disruption of their most pressing cyber risks. Global customers, including Fortune 500 leaders across all major market verticals, rely on us to prevent, detect, investigate, and remediate phishing, malware, fraud, brand abuse, data leaks, external vulnerabilities, and more, ensuring continuous external protection from cyber threats.
Features:
Pentera
Product Description
Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. For more info visit: pentera.io.
Features:
Cyble
Product Description
Cyble Vision, our SaaS-based enterprise platform collects real-time intelligence data from both open and closed sources to map, monitor, and mitigate digital risk.
Features:
CloudSEK
Product Description
Cloudsek is an Infosec Risk assessment company which provides intelligence needed to tackle online threats.
Features:
ZeroFox
Product Description
With a global data collection engine, artificial intelligence-based analysis, and automated remediation, the ZeroFOX Platform protects you from cyber, brand and physical threats on social media & digital platforms.
Features:
GreyNoise
Product Description
GreyNoise is a cybersecurity platform that collects, analyzes, and classifies internet-wide scan and attack traffic to help security teams distinguish between benign and malicious activities. By leveraging a global network of passive sensors, GreyNoise identifies IP addresses involved in mass scanning and categorizes them based on intent, enabling organizations to reduce false positives and focus on genuine threats. This approach enhances the efficiency of Security Operations Centers (SOCs by filtering out irrelevant alerts and providing actionable intelligence on emerging threats.
Key Features and Functionality:
- Real-Time Threat Intelligence: Provides up-to-date information on internet scanning activities, allowing security teams to respond swiftly to potential threats.
- IP Classification: Categorizes IP addresses as benign, suspicious, or malicious based on their behavior, aiding in accurate threat assessment.
- Vulnerability Prioritization: Offers insights into active in-the-wild exploitation of vulnerabilities, assisting teams in prioritizing patching and remediation efforts.
- Integrations: Seamlessly integrates with existing security tools and platforms, enhancing the overall security infrastructure.
- Advanced Analytics: Utilizes data science techniques and AI to process vast amounts of data, providing meaningful insights and reducing alert fatigue.
Primary Value and Problem Solved:
GreyNoise addresses the challenge of alert fatigue faced by security teams due to the overwhelming volume of false positives generated by security tools. By filtering out internet background noise and focusing on relevant threats, GreyNoise enables organizations to:
- Enhance Efficiency: Reduce the time spent investigating non-threatening alerts, allowing teams to concentrate on critical issues.
- Improve Threat Detection: Identify and respond to emerging threats more effectively with real-time, actionable intelligence.
- Optimize Resource Allocation: Prioritize vulnerability remediation efforts based on active exploitation data, ensuring resources are directed where they are needed most.
By providing a clear distinction between benign and malicious internet activities, GreyNoise empowers security teams to act with speed and confidence, ultimately strengthening an organization's cybersecurity posture.
Features:
What is Threat Intelligence Software?
Threat intelligence software provides organizations with information related to the newest forms of cyber threats like zero-day attacks, new forms of malware, and exploits. Companies use these tools to keep their security standards up to date and fit to address new threats as they emerge. These tools can improve security performance by providing information on threats to their specific networks, infrastructure, and endpoint devices. Threat intelligence software provides information about hazards and how they function, their capabilities, and remediation techniques. IT administrators and security professionals use the delivered data to better protect their systems from emerging threats and plan for possible vulnerabilities. The tools alert users as new threats emerge and provide information detailing best practices for resolution.
Many products, like security information and event management (SIEM) software and vulnerability management software, can integrate with or provide similar information as threat intelligence products. Additionally, these products continue to integrate with artificial intelligence (AI) to better tailor this complex suite of data for specific organizations’ needs. These newer capabilities can include being able to generate threat reports based on newly aggregated threat intelligence data. This data directly pertains to the organization where the software is deployed. The newer capabilities also help in creating threat detection rules based on observed patterns in malicious actors’ behaviors.
To qualify for inclusion in the Threat Intelligence category, a product must:
Provide information on emerging threats and vulnerabilities
Detail remediation practices for common and emerging threats
Analyze global threats on different types of networks and devices