Best Threat Intelligence Software - Page 12

How Many Threat Intelligence Software Products Does G2 Track?

Total Products under this Category: 211

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: UpGuard Breach Risk (+0.92%) - Among all products in this category, UpGuard Breach Risk recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Threat Intelligence Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 211+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Threat Intelligence Software

G2 Grid® for Threat Intelligence Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Recorded Future, Ivanti Neurons for Unified Endpoint Management, Cyble, CloudSEK, ZeroFox, SOCRadar Extended Threat Intelligence, and CTM360.

Underlying data: [Grid® JSON](https://www.g2.com/categories/threat-intelligence/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=recorded-future&focus%5B%5D=ivanti-neurons-for-unified-endpoint-management&focus%5B%5D=cyble&focus%5B%5D=cloudsek&focus%5B%5D=zerofox&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360)

OpenText Core Adversary Signals

OpenText™ Core Adversary Signals is a SaaS-based global signal analytics tool designed to enhance cybersecurity defenses by providing comprehensive visibility into malicious internet traffic. It identifies and analyzes adversarial behaviors, early warning signs, and sophisticated attack paths, enabling organizations to proactively monitor and respond to threats beyond their traditional security perimeters. Key Features and Functionality: - Adversary Signal Analytics: Utilizes advanced analytics to detect and filter malicious internet signals, effectively reducing noise and highlighting targeted attacks. - Threat-Actor Attribution: Tracks threat actors across multiple proxies, uncovering their true origins and motives, thereby providing deeper insights into potential threats. - Cross-Agency Models: Facilitates the validation of threat activities across various divisions within an organization, promoting a unified security approach. - SaaS-Based Deployment: Offers a plug-and-play solution that requires no additional hardware, ensuring quick implementation and seamless integration with existing systems. - Enriched Context: Provides actionable intelligence by leveraging adversary data to offer additional context about threat actors and their activities. - Open Integration: Easily integrates with any Security Information and Event Management (SIEM) or Extended Detection and Response (XDR) systems, enhancing visibility and enabling early threat detection. Primary Value and Problem Solved: OpenText Core Adversary Signals addresses the challenge of limited visibility into external threats by extending monitoring capabilities beyond organizational boundaries. By analyzing global internet traffic, it identifies malicious activities targeting the organization, allowing for early detection and proactive defense measures. This comprehensive approach minimizes disruptions, reduces potential damage, and enhances the overall security posture by providing actionable insights into adversarial behaviors and attack vectors.

Who Is the Company Behind OpenText Core Adversary Signals?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,048 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Outseer Global Data Network

The Outseer Global Data Network™ is a collaborative consortium that aggregates and shares high-quality fraud and transaction data from hundreds of financial institutions across over 150 countries. This extensive network enables near real-time sharing of confirmed fraud events and emerging threat patterns, significantly enhancing fraud detection capabilities. By leveraging this collective intelligence, financial institutions can proactively identify and prevent fraudulent activities, safeguarding their customers and assets. Key Features and Functionality: - Comprehensive Data Aggregation: Collects and analyzes data from a vast network of global contributors, encompassing billions of transactions to identify fraud patterns effectively. - Real-Time Fraud Intelligence Sharing: Facilitates near real-time dissemination of fraud-related data among consortium members, ensuring timely updates on emerging threats and tactics. - Advanced Risk Assessment: Utilizes sophisticated analytics and predictive AI models to assess risk, enabling precise identification of fraudulent activities with a low false-positive rate. - Diverse Data Signals: Incorporates various data elements such as device identifiers, IP addresses, geolocation, and behavioral patterns to enhance fraud detection accuracy. Primary Value and Problem Solved: The Outseer Global Data Network addresses the escalating challenge of sophisticated and rapidly evolving fraud schemes by providing a unified platform for data sharing and analysis. By harnessing collective intelligence from a global consortium, it empowers financial institutions to detect and prevent fraud more effectively, reducing losses and enhancing customer trust. This collaborative approach ensures that organizations stay ahead of emerging threats, offering a robust defense against cybercriminal activities.

Who Is the Company Behind Outseer Global Data Network?

  • Seller: Outseer
  • HQ Location: Bedford, US
  • Twitter: @OutseerCo
    123 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    244 employees on LinkedIn®

Parano.ai

Parano.ai is a competitive intelligence platform that automatically tracks changes across your competitors’ websites, pricing pages, product updates, job listings, ads, and reviews. Get real-time alerts, historical change logs, and structured insights without manual research. Built for founders, product, sales, and marketing teams who want to spot moves early, react faster, and turn competitor activity into strategic advantage.

Who Is the Company Behind Parano.ai?

Pillar Security

The Security Stack for AI Teams. Pillar security provides comprehensive AI management and security platform for the entire AI lifecycle, including: 1. MONITORING & VISIBILITY Efficiently manage and audit your AI systems, logging usage, interactions and sessions with full transparency. 2. AI DETECTION & RESPONSE Protect your applications with fast, robust security measures to prevent attacks and maintain user and data integrity. 3. AI EXPOSURE MANAGEMENT Continuously test and improve your AI apps' security to mitigate risks and stay ahead of new threats.

Who Is the Company Behind Pillar Security?

Pure Signal™ Recon

Pure Signal™Recon is a web based Threat Intelligence query platform. It allows Security Analysts access to Team Cymru’s proprietary data called Pure Signal™, enabling them to create searches and filters to discover insights from over 40 datasets. These datasets include NetFlow, PDNS and x509 Certificates among others. Pure Signal™ Recon is designed for highly advanced users, and mostly used for the purpose of Cyber Reconnaissance, Cyber Threat Hunting, Cyber Incident Response, Victimology and Third Party Digital Risks. Pure Signal™ Recon is licensed per user as an annual subscription, with a range of options to suit the budget and requirements of customer needs.

Who Is the Company Behind Pure Signal™ Recon?

  • Seller: Team Cymru
  • Year Founded: 1998
  • HQ Location: Lake Mary, FL
  • Twitter: @teamcymru
    41,148 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    128 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 20% Large

What Do G2 Reviewers Say About Pure Signal™ Recon?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time monitoring capabilities of Pure Signal™ Recon, enhancing their situational awareness and communication analysis.
  • Users highlight the real-time monitoring capability of Pure Signal™ Recon, enhancing situational awareness in communications.
  • Users value the real-time monitoring of wireless signals, enhancing their situational awareness and communication analysis.
Cons
  • Users are concerned about the inadequate security of Pure Signal™ Recon, fearing potential data leaks and hacking risks.
  • Users face information overload from Pure Signal™ Recon, making it challenging to identify critical data efficiently.

Q-Feeds

QFeeds is a real-time threat intelligence platform that empowers organizations to proactively detect and block cyber threats before they impact operations. Designed for seamless integration with SIEMs, and NGFW such as Cisco, Fortinet and Sophos. Q-Feeds delivers curated, actionable data updated every 20 minutes. By reducing malicious traffic and minimizing network strain, Q-Feeds enhances security, boosts performance, and keeps you ahead of evolving threats. • Actionable Intelligence: Gain insights from over 2,500 trusted sources, including phishing, botnets, and dark web data. • Real-Time Updates: Threat data is refreshed every 20 minutes to ensure your defenses stay current. • Fast & Easy Integration: Be up and running in just 5 minutes with our pre-built configurations for major platforms.

Who Is the Company Behind Q-Feeds?

  • Seller: Q-Feeds
  • Year Founded: 2024
  • HQ Location: Hilversum, NL
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

RedCarbon

RedCarbon is a Swiss company specialised in AI-powered cybersecurity. Founded in 2020 by experienced cybersecurity professionals with over two decades of industry expertise, the company focuses on designing and deploying virtual AI Agents to support human teams in managing the increasing volume and complexity of cyber threats. RedCarbon addresses the inefficiencies and limitations of traditional cybersecurity operations by automating the most repetitive and time-intensive activities. Its AI Agents are engineered to act as virtual colleagues, providing round-the-clock support to human analysts, without replacing their strategic value. What It Does RedCarbon offers a modular suite of AI-driven cybersecurity agents capable of autonomously operating across all SOC tiers. These agents are designed to: Autonomous Threat Detection & Analysis Incident Response and Proactive Threat Hunting Seamless Integration with SIEM, EDR, XDR platforms Automated triage, prioritisation and risk scoring Retrospective attack investigation and forensic analysis Threat intelligence monitoring across deep, dark and open web sources All AI Agents operate through a unified dashboard, with full observability and auditability, allowing real-time insights and control. Why It Matters Unlike conventional tools that depend heavily on rule-based systems and manual oversight, RedCarbon’s AI Agents are capable of learning, adapting and responding autonomously, drastically improving the speed and consistency of security operations. With RedCarbon, cybersecurity teams benefit from: Scalability without proportional hiring Significant reduction in response times—from hours to seconds Reduction in alert fatigue and false positives Minimised analyst turnover and operational stress Improved cost efficiency and workload distribution This results in better service quality for Managed SOC providers and greater protection for enterprise environments. For Whom RedCarbon is ideally suited for: Security Operations Centres (SOC/MSOC) Telecommunication providers and MSSPs System integrators seeking AI augmentation for their cybersecurity stack Medium and large enterprises aiming to automate without expanding teams Organizations facing analyst fatigue, burnout, or hiring constraints For further information or to request a demo, please visit: https://www.redcarbon.ai/get-a-demo

Who Is the Company Behind RedCarbon?

Red Sky Alliance CTAC

Wapack Labs is a cyber intelligence operation designed to monitor and report on threats to IT, key personnel and investments in dozens of venues, and make that data available in both human and machine readable formats.

Who Is the Company Behind Red Sky Alliance CTAC?

Resecurity Context Cyber Threat Intelligence Platform

Resecurity Context™ is a Cyber Threat Intelligence (CTI) Platform enabling enterprises and government agencies to collect actionable intelligence from multiple sources by different criteria and to accelerate analysis, prevention and investigation workflow required for strategic and timely decision-making. The production of finished intelligence including but not limited to IOCs, TTPs, threat artifacts is organized through TAXII server located at taxii.resecurity.com. Resecurity developers, engineers and technical support team will provide documentation and assistance in configuration of secure data exchange based on Client specifications. Resecurity Context™ has a robust monitoring module allowing to configure multiple long-term monitoring tasks based on different criteria in order to optimize time-consuming and manual operations. Monitoring module provides real-time and near real-time cyber threat intelligence reporting capabilities depending on the technical specifications, structure and type of the source and Operational Security (OPSEC) level. The platform enables operator to configure frequency of data updates which may affect the timeframe to identify new data. Resecurity is constantly monitoring the status of data updates and is managing resources required for effective and high-quality cyber threat intelligence acquisition process 24/7/365. Using monitoring module operator can organize and facilitate: Confidential monitoring of all web environments (deep web, dark web, public web) for the presence or absence of a provided set of indicators, which could include IP address, file hashes, URLs, phone numbers, email addresses, physical addresses, names of similar. Identification of threat actors, attack tools or campaigns targeting State, Local, Tribal, and Territorial government agencies. Identification of threat actors, attack tools or campaigns targeting law enforcement (in the United States and/or internationally). - Identification of threat actors, attack tools or campaigns targeting the Client. - Identification of threat actors, attack tools or campaigns targeting employees of the Client. - Identification of Client information or identifies being sold on the “black market”. - Identification of the precursors to or signs of identity theft targeting Client high profile employees. - Actor-Centric Intelligence - Botnet Intelligence - Dark Web Intelligence - Data Breach Intelligence - Human Intelligence - Open-Source Intelligence - Malware Intelligence - ISP Traffic Intelligence - Signal Intelligence Platform ability to collect and analyze input from all these sources, Resecurity Context™ can provide comprehensive finished intelligence about subjects of interest (SOI) or multiple Essential Elements of Information (EEI), including but not limited to: - Adversaries, Suspects, and Victims - Device Identifiers - Indicators of Attack (IOAs) - Indicators of Compromise (IOCs) - Malware Artifacts - Network Indicators (IP, Domain) - Particular Signatures or Events Resecurity Context™ has additional modules included in “Context Library” used for independent search, correlation and pivoting between different data sets and criteria, and monitoring operations. Modules represent aggregated intelligence by the following categories: - Intelligence (Dark Web, Deep Web, Surface Web) – by default; - Data Breaches (Compromised Credentials, Data Leaks, Botnets, Third-party Data Leaks); - Compromised Payment Data (Compromsied Credit Cards, Identity Information); - Indicators of Compromise (IOCs Repository); - IP Reputation (indicators of malicious network activity with additional background information); - Passive DNS (DNS records with associated additional meta-data and WHOIS repository); - Security Incidents (Updating feed of recent security incident, APT campaigns, data breaches); - Threat Actors (library of threat actor profiles). Resecurity Context™ allow operator to see what information is available to and being discussed by potential cyber-attackers. In order to increase relevancy of the search results the operator may define exact category which will allow to prioritize the selection of sources, threat actors and other artifacts by thematic cluster (“niche”): - Cybercrime (underground communities) - Carding (underground communities, groups and resources related to financial crimes) - Marketplace (underground shops, illegal communities providing products or services) - Hacktivism (hacktivists, protest and other activity identified in dark, deep and surface web) - Research (security research resources for cross-reference, including external threat intelligence) - State-sponsored (confirmed and potential activity by nation-state actors) - Geopolitics (malicious and other activity related to recent geopolitical events and trends) - Malware (malicious activity caused by malware, spyware, ransomware, and/or other tradecraft) - Terrorism (extremist and illegal content identified through various digital channels and means) - Piracy (various counterfeit, piracy-related online-resources). Resecurity Context™ guarantees confidentiality of monitoring process and non-attributable search operations due to purpose-built architecture and isolated infrastructure for data aggregation and translation. The platform allows to work with the collected data preventing possible leaks of client-side details from the operator, as well as blocks active content execution from “mined” data sources.

Who Is the Company Behind Resecurity Context Cyber Threat Intelligence Platform?

Revbits Cyber Intelligence Platform

The effort to manage multiple security tools is time-intensive. The lack of intelligence sharing across solutions results in the lost opportunity for proactive defense from threats. Realizing the power of four superior security solutions, RevBits Cyber Intelligence Platform takes XDR to full speed security. The integrated platform offers superior protection by sharing threat intelligence from ten security modules.

Who Is the Company Behind Revbits Cyber Intelligence Platform?

Reveelium

Reveelium.ai is an AI-enabled collaborative cybersecurity platform that unifies SIEM/XDR, EASM, SOAR, and Cyber Threat Intelligence (CTI) into a single, modular solution. It helps organizations anticipate, detect, investigate, and respond to cyber threats in real time while automating security operations Reveelium.ai is a scalable, AI-powered cybersecurity platform designed to provide complete visibility and control over an organization's cyber risk. Combining SIEM/XDR, External Attack Surface Management (EASM), Security Orchestration, Automation and Response (SOAR), and Cyber Threat Intelligence (CTI), it centralizes security operations within a single collaborative platform. Built with advanced AI technologies, including Machine Learning, Deep Learning, LLMs, and UEBA, Reveelium.ai enhances threat detection, reduces false positives, prioritizes alerts, and accelerates incident response. Its multi-tenant architecture, customizable detection scenarios, API-driven integrations, and flexible deployment options (on-premises or dedicated SaaS hosted in France) make it an ideal solution for organizations seeking a modern, proactive, and scalable Security Operations Platform.

Who Is the Company Behind Reveelium?

  • Seller: Reveelium
  • Year Founded: 2007
  • HQ Location: Labège, FR
  • Twitter: @Reveelium_AI
    478 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    119 employees on LinkedIn®

RST Threat Feed

RST Cloud empowers SecOps teams with actionable, high-fidelity threat intelligence - from the RST Threat Feed with contextualized, relevant IoCs to detailed adversary insights through the RST Threat Library and near real-time global threat report delivery via RST Report Hub. Combined with powerful enrichment APIs such as RST Noise Control, RST IoC Lookup, and the RST WHOIS API, RST Cloud enables organizations to detect threats faster, respond with confidence, and make informed, threat-driven decisions. Additionally, the RST CTI Assistant offers intuitive, conversational access to all this intelligence - making threat data effortless to query, understand, and put into action.

Who Is the Company Behind RST Threat Feed?

SAGA

SAGA® is an innovative platform designed to automate the monitoring of the surface, deep, and dark web, enhancing cybersecurity. It is tailored to protect businesses, organizations, and individuals from potential cybercrime and fraud. Key Features of SAGA®: Unmatched Data Coverage: SAGA® features a proprietary scraping system combined with extensive external data integrations, offering unparalleled breadth and depth in cyber threat intelligence from the surface, deep, and dark web. SAGA® AI: Our advanced generative AI technology transforms raw intelligence into actionable insights. This includes human-readable risk alerts, contextual reports, and comprehensive intelligence, making cyber threat information accessible and actionable for all. Modular and Cost-Effective: SAGA®'s modular architecture allows customers to tailor their cybersecurity solutions. You only pay for the services you need, ensuring a cost-effective approach to comprehensive digital risk protection. Global Reach, Local Expertise: Based in Copenhagen and leveraging a global network of partners, SAGA® combines worldwide expertise with local insights, delivering solutions in 30 markets and 6 languages. SAGA® Products: SAGA® Platform: A cloud-based solution that automates monitoring across various web layers, offering robust protection against cyber threats. SAGA® AI: This tool leverages generative AI to provide intuitive and detailed risk assessments from vast amounts of web data. SAGA® API: Integrate SAGA®'s intelligence directly into your existing systems with our RESTful API, seamlessly enhancing your MSSP offerings. Air Gap Option: For highly sensitive projects, including government or state clients, SAGA® offers an on-premises solution with a data diode, ensuring one-way data flow and enhanced security.

Who Is the Company Behind SAGA?

ScamDekho Partner URL Check API

ScamDekho Partner URL Check API is a B2B website-risk screening API for platforms, marketplaces, fintech applications and online businesses. Partners submit a URL to a Bearer-authenticated endpoint and receive a trust score, normalized verdict, confidence level, summary, number of security sources checked and a link to the full report. It uses ScamDekho's 14-source URL analysis engine and supports per-partner API keys, configurable monthly limits, usage tracking and rate-limit headers.

Who Is the Company Behind ScamDekho Partner URL Check API?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 22, 2025