Best Threat Intelligence Software - Page 10

How Many Threat Intelligence Software Products Does G2 Track?

Total Products under this Category: 211

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: UpGuard Breach Risk (+0.92%) - Among all products in this category, UpGuard Breach Risk recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Threat Intelligence Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 211+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Threat Intelligence Software

G2 Grid® for Threat Intelligence Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Recorded Future, Ivanti Neurons for Unified Endpoint Management, Cyble, CloudSEK, ZeroFox, SOCRadar Extended Threat Intelligence, and CTM360.

Underlying data: [Grid® JSON](https://www.g2.com/categories/threat-intelligence/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=recorded-future&focus%5B%5D=ivanti-neurons-for-unified-endpoint-management&focus%5B%5D=cyble&focus%5B%5D=cloudsek&focus%5B%5D=zerofox&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360)

Cyber Threat Intelligence Feed

Cyber Threat Intelligence Feed delivers continuous up-to-the-minute information and context about cyberattacks that threaten an organization's safety. It enables comprehensive monitoring, detection, and response to online threats, providing a multi-source database that supports cyberdefence mechanisms. The CTI Feed covers all major attack vectors like malicious URLs, phishing URLs, spam, bot IPs, social media, and websites.

Who Is the Company Behind Cyber Threat Intelligence Feed?

  • Seller: PREBYTES
  • Year Founded: 2009
  • HQ Location: Leżajsk, PL
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Cyzo

Who Is the Company Behind Cyzo?

Darkweb Tracker

Darkweb Tracker is an advanced deep and dark web intelligence platform developed by StealthMole. Leveraging cutting-edge AI technology and open-source intelligence (OSINT) techniques, it systematically collects, categorizes, and analyzes data from both open and concealed online sources. This empowers users to efficiently access, interpret, and derive critical insights from vast amounts of information.

Who Is the Company Behind Darkweb Tracker?

  • Seller: StealthMole
  • HQ Location: Singapore, SG
  • Twitter: @stealthmole_int
    124,833 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    17 employees on LinkedIn®

Dataminr Pulse for Cyber Risk

Dataminr Pulse for Cyber Risk is an AI-driven solution designed to enhance organizational resilience by providing real-time detection of external cyber events, risks, and threats. By analyzing over one million public data sources, it delivers actionable intelligence across four critical areas: digital risk, third-party risk, vulnerability intelligence, and cyber-physical risk. This comprehensive approach enables security teams to proactively identify and mitigate potential threats, ensuring the protection of digital assets and the continuity of business operations.

Who Is the Company Behind Dataminr Pulse for Cyber Risk?

  • Seller: Dataminr
  • Year Founded: 2009
  • HQ Location: New York, NY
  • Twitter: @Dataminr
    16,454 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    838 employees on LinkedIn®

DynaRisk

DynaRisk's Breach Defence software empowers small to medium sized businesses to be safer online. Cyber attacks are constant and are always evolving. 60% of SMEs can go out of business within 6 months of suffering a cyber attack. SMEs need simple yet comprehensive cyber risk management solutions to manage complex cyber risks. This is why DynaRisk has developed Breach Defence to give SMEs the tools they need to defend against cyber attacks.

Who Is the Company Behind DynaRisk?

  • Seller: DynaRisk
  • Year Founded: 2015
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

EclecticIQ Platform

EclecticIQ Platform re-imagines intelligence, hunting and response, by delivering intelligence-led solutions to Threat Intelligence, Endpoint Security and Security Operations challenges.

Who Is the Company Behind EclecticIQ Platform?

  • Seller: EclecticIQ
  • Year Founded: 2014
  • HQ Location: Amsterdam, NL
  • Twitter: @EclecticIQ
    3,048 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    80 employees on LinkedIn®

Exodus Intelligence Vault

Who Is the Company Behind Exodus Intelligence Vault?

  • Seller: EXOD.ai
  • Year Founded: 2012
  • HQ Location: Austin, TX
  • Twitter: @ExodusIntel
    1,396 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    48 employees on LinkedIn®

Expose

AI-powered engine that cross-references billions of public data points across the internet and delivers a complete, structured overview in moments.

Who Is the Company Behind Expose?

  • Seller: Expose
  • Year Founded: 2025
  • HQ Location: Tel Aviv, IL
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Falconfeedsio

Falcon Feeds.io is a cutting-edge, cloud-native SaaS platform that specializes in cyber threat intelligence. It vigilantly monitors and delivers the latest security incidents and insights on threat actors from around the globe, around the clock. Our expansive coverage includes the surface web, Tor networks, and Telegram channels. With Falcon Feeds.io, you can: Continuous Monitoring: Keep a watchful eye on threat actors, ransomware attacks, DDoS attacks, and other security incidents around the clock. Comprehensive Analysis: Stay informed about the most affected geographies, industries, organizations, and domains in real-time. Unrestricted Access: Gain unlimited access to our extensive threat feed database to empower your security measures. Customizable Alerts: Configure alerts tailored to new threats related to specific threat actors, incident categories, countries, industries, organizations, and domains. Seamless Integration: Utilize our robust API and Webhook integration for a smooth and streamlined security workflow. Real-Time Notifications: Get instant notifications through Slack, Microsoft Teams, and email, ensuring you never miss a critical update.

Who Is the Company Behind Falconfeedsio?

  • Seller: Technisanct
  • Year Founded: 2023
  • HQ Location: London, GB
  • Twitter: @FalconFeedsio
    68,906 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3 employees on LinkedIn®

Horizon®

Horizon® is an open source intelligence and data analysis platform that enables organizations to collect, analyze, and operationalize publicly available online information to support investigations, security operations, and risk management. The platform is designed to help users identify relevant digital signals, monitor online activity, and derive actionable insights from large volumes of open source data. Horizon® supports a wide range of investigative and intelligence workflows by providing tools to search across surface web sources, analyze online entities, and identify connections between people, organizations, and digital infrastructure. It is used by security teams, investigators, analysts, and risk professionals who require timely access to structured and unstructured online information. Common use cases include threat intelligence, investigations, fraud detection, insider risk analysis, and situational awareness. The platform enables users to conduct targeted searches, track changes over time, and organize findings within a centralized environment. Horizon® is built to support both proactive monitoring and reactive investigations, allowing teams to respond to emerging risks and incidents more efficiently. It integrates data collection with analysis and reporting workflows, helping users move from raw information to informed decision making. Horizon® is used across multiple industries, including enterprise security, government, financial services, and compliance driven organizations. It supports collaboration among teams by enabling shared access to findings and consistent investigative processes. The platform is designed to scale with organizational needs and accommodate both routine monitoring and complex investigative requirements. Key capabilities of Horizon® include: - Open source data collection and search across online environments - Entity analysis to identify relationships and digital footprints - Monitoring and alerting to track changes and emerging activity - Investigation workflows for organizing, analyzing, and reporting findings - Support for security, intelligence, and risk management use cases By combining data collection, analysis, and operational workflows in a single platform, Horizon® helps organizations better understand online activity and manage digital risk using publicly available information.

Who Is the Company Behind Horizon®?

iDNA

Who Is the Company Behind iDNA?

Infrawatch

Infrawatch scans the global public IPv4 and IPv6 ranges for malicious infrastructure. Identify malicious hosts before they are operationalised by an adversary. Discover, block, and explore residential proxy networks, VPNs, command-and-control (C2) servers, and more - all in real-time and attributed to a service.

Who Is the Company Behind Infrawatch?

InSights

Harness InQuest’s unique perspective and insight to find threats months before the competition. Our Threat Intelligence team gathers and analyzes unique data sources from open source industry feeds, as well as InQuest proprietary data sets, to provide you with leading edge and highly-trusted indicators of compromise so you can stay ahead of emerging threats and reduce dwell times.

Who Is the Company Behind InSights?

  • Seller: InQuest
  • Year Founded: 2013
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    21 employees on LinkedIn®

isMalicious

isMalicious is a real-time threat intelligence platform that helps security teams and developers detect malicious IPs, domains, and URLs. It aggregates data from 600+ curated intelligence sources into a database of 500M+ threat records, delivering sub-100ms API responses for production-grade security decisions. Unlike file-focused scanners, isMalicious is purpose-built for IP and domain reputation checking at scale. The unified REST API covers IPs, domains, URLs, email addresses, and file hashes through a single endpoint. Features include a Streaming API for real-time threat feeds (<5s latency), webhooks for event-driven alerting, built-in monitoring with watchlists, and bulk processing for batch operations. isMalicious offers official SDKs for Python, Node.js, Go, and Rust, plus an interactive API playground for testing. It integrates with any SIEM (Splunk, QRadar, Sentinel), SOAR platform, or custom application — no vendor lock-in. Enterprise plans with STIX/TAXII and dedicated infrastructure are available.

Who Is the Company Behind isMalicious?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 22, 2025